8 ms·
This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account sus
by zx2c4 6mo ago
This is the same problem I'm currently facing with WireGuard. No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows. That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? (That's just hypothetical; don't freak out!) In that case, Microsoft would have my hands entirely tied.
If anybody within Microsoft is able to do something, please contact me -- jason at zx2c4 dot com.
- gib444 6mo agoY'all need to form an alliance or something, get some press coverage (wireguard, veracrypt, libreoffice)
- duskdozer 6mo agoTrue, but really even if it gets resolved for them it should basically be a huge warning sign to everybody. Projects like those might get reinstated but it would only be because of how big they are that it would matter. Any person or small or 'undesirable' project would not get the same resolution.
- teruakohatu 6mo agoI am astounded that the maintainer and inventor of Wireguard is in this position. Microsoft even supports Wireguard in Azure Kubernetes Service.
- miroljub 6mo agoMaybe time for a custom license that would require M$ to sign up for special T&Cs if they want to use this software? Who cares if it's OSI-approved or not, a line saying "M$, Google, and the like need written permission for every use case" would help to make those leeches honest. Just learn from the JSLint example.
- UqWBcuFx6NV4r 6mo agoWe literally just did this. Now we have Valkey. Nobody won.
- pocksuppet 6mo agoDid anyone lose? Valkey is better because all of the new development work happens on Valkey, not because of the license. If the actual developer changed the license, that would be a different situation.
- greenavocado 6mo agoThis license modifier already exists for others to use (I can't post the direct links here because this site will sanction me for doing so) plus n-word dot com hosts information about the plus n-word license which purports: - The software will not be used or hosted by western corporations that promote censorship - The software will not be used or hosted by compromised individuals that promote censorship - Users of the software will be immune to attacks that would result in censorship of others
- gzread 6mo agoIt's even GPL compatible, because the GPL makes provision for additional notice requirements. That would be both hilarious and horrifying if the only thing stopping the corporate dystopia is that Microsoft doesn't want to say the N word.
- kbelder 6mo agoWhy "Western" corporations that promote censorship? Non-western censorship is allowed?
- greenavocado 6mo agoThey don't care as much about things like this
- 6mo ago
- nelox 6mo agoAgree. Single point of failure. One developer, one account. Crazy.
- ptx 6mo agoHaving multiple accounts wouldn't help, as Microsoft could easily suspend all the accounts of everyone associated with the project if any account looks suspicious. The single point of failure is Microsoft.
- jamesnorden 6mo agoHow would more than one account help in this scenario, exactly?
- hirako2000 6mo agoAny account can sign any (same) piece of software. Of course Microsoft could detect the it's signing a software related to a banned signed and ban the new account. So veracrypt (and wireguard) is stuck. It's outrageous. MS is simply enforcing some Government crackdown on encryption software that would interfere with backdoors.
- raxxorraxor 6mo agoNo, that is not the issue here. The source of the problem is something different. This is a wrong root cause analysis.
- pjc50 6mo agoYou're not actually allowed to avoid this by having multiple accounts, that falls under "ban evasion". But yes, there's a lot of critical single maintainer projects.
- windowliker 6mo agoIs this another example of their old modus operandi: https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguis... ?
- riskable 6mo agoNo. Embrace, Extend, Extinguish was replaced by the AAA strategy: Acquire, Assimilate, Abandon. They were trying to be more Google-like with that "Abandon" step I think. They've since moved on to the SSS strategy: Ship, Slip, Slop.
- arcanemachiner 6mo agoGood heavens! My acronymical notes on Microsoft's product strategy are two revisions out of date!
- wtyvn 6mo agoDamn, I thought it was "Slop, Ship, Smile"
- Already__Taken 6mo agoIt's got a lot of analogy to restaurants banning Uber delivery for not handling their food to their standards.
- xiconfjs 6mo agoWhat? How?
- HackerThemAll 6mo agoThat actually is not analogy at all and it makes sense. When a low-paid Uber Eats delivery person just throws the box carelessly and brings damaged dish to the customer, that's a real issue. In digital services there's no such thing. There's only a damned corporation employing idiots who don't care about community.
- onehair 6mo agoNow this is even more alarming! Wireguard's creator has their Microsoft account suspended... <Tin foil hat on> Microsoft doesn't want to allow software that would allow the user to shield themselves, either by totally encrypting a drive, or by encrypting their network traffic! </Tin foil hat on>
- ngetchell 6mo agoOr more likely, some automated security system flagged popular but suspicious apps for further review.
- nelox 6mo agoMaybe they let Mythos loose and it suggested the safest approach was to remove access ;)
- raxxorraxor 6mo agoWhere are the people that tried to sell us software signatures as security benefit? The reality is that they are a very specific security problem. In theory and in practice.
- Gigachad 6mo agoAutomated systems breaking things without any human contact to get them resolved seems to be the theme of the last 10 years.
- burnt-resistor 6mo agoThis phenomenon is so Orwellian with insufficient awareness, it should both be an SNL skit and a John Oliver episode. It's illiberal, neoliberal, corporate bullshit that causes harm to individuals. These companies need to be treated as utilities and the "companies can do whatever they want" arguments must be debunked and defeated because of the pervasive power they hold and immense harm they can cause to individuals without a remedy when they rug pull access without clear cause. It also reminds me of the case of the entire family who lost all of their payment-linked individual accounts including business data and an academic dissertation because the son allegedly behaved inappropriately with a bot. Collective punishment on top of technofeudal instant banishment.
- jchw 6mo agoI tried to set up a partner account for driver signing last year (as a business entity) and it already seemed basically impossible. I think they're getting ready to just simply not allow it at all. This is stupid. If Microsoft wants people to stop writing kernel drivers, that's potentially doable (we just need sufficient user mode driver equivalents...) but not doing that and also shortening the list of who can sign kernel drivers down to some elite group of grandfathered companies and individuals is the worst possible outcome. But at this point I almost wish they didn't fix it, just to drive home the point harder to users how little they really own their computer and OS anymore.
- tamimio 6mo agoI think it’s intentional, those encryption (at rest/transit) applications are outside of MS control and you can assume outside of potential backdoors by three letters agencies, bitlocker vs veracrypt? Of course bitlocker is favorable from their perspective. I wouldn’t be surprised if NSA already had a list of these applications and the strategies on how to cripple them or worse, compromise them.
- nelox 6mo agoOr found they’ve been compromised by someone else? ;)
- ransom1538 6mo ago[flagged]
- prosopts 6mo agoWhat are you basing your remark here on?
- malfist 6mo ago[flagged]
- 0xC0ncord 6mo agoI have a hard time believing this to be true when for a while now it's always been some automated system that goes completely unchecked and unmonitored. It's not until someone who is wrongfully affected complains on Xitter does anyone notice.
- ComputerGuru 6mo agoThat’s not how any of this works. There are separate teams within (each division of) Microsoft that could easily pull the plug on your account (or if not the entire account then your account’s access to the specific service or family of services) for any of a myriad purported reasons or alleged ToS violations. No one is calling an executive meeting to discuss banning an OSS dev’s account.
- pocksuppet 6mo agoThe other day I tried to create a Github account and was repeatedly told I am fraudulent. Nothing else. Try again later, it says. This is the same thing that's happened every time I've tried to have a Microsoft account. I don't think Microsoft wants to have customers who aren't rich.
- jandrese 6mo agoMaybe some bot signed up using your email and then did bot things on it. I've had that happen a lot over the years. My Microsoft account is still stuck in German because that's the language the bot used when creating the account (to spam X-Box apparently).
- hirako2000 6mo agoI got a 20y old hotmail/live account deleted by Microsoft because a bot tried to reset my password too many times. Considering the magnitude of the targeted attack, MS found the safest way to keep me secure was to wipe my account. That way the attacker could not get into my account.
- reincarnate0x14 6mo agoI had something similar with a 6-letter apple account that has never been compromised but I guess got put on some kind of list, because I had to go through account recovery almost every time I logged in, which wasn't a big deal until I got an iphone. Apple support was completely useless. Random old buried forum post in a stall marked "beware the leopard" mentioned the behavior and suggested changing the account name. Nothing in the Apple site or phone stuff would even clue the user in to what was happening, much less how to resolve it.
- pocksuppet 6mo agoBrand new email account.
- octoberfranklin 6mo agoSame here with github.
- tssva 6mo agoHas your Apple account been suspended for the last few years?
- matheusmoreira 6mo ago> what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately? Honestly, anyone still using Windows probably deserves it.
- iamnothere 6mo agoSurprised to see you here. Thanks for all your hard work. Windows users are in a tough spot, but with the dawn of Copilot, nobody should be surprised. Frankly, those who remain with Windows after this latest betrayal have chosen their fate.
- SV_BubbleTime 6mo ago> those who remain with Windows after this latest betrayal have chosen their fate. Ah. So almost every single business in the world… suckers?
- croes 6mo agoGiven MS‘ track record, yes
- gzread 6mo agoYes.
- serf 6mo agoare you making an argument that businesses worldwide somehow are known to make well thought-out, rational, wise decisions that are in best interest for the business and efficiency of running it? because most managers I know in my professional life go with the vendor that buys them dinner or slips them tickets for box seats.
- rand846633 6mo agoCan you elaborate on how this corruption(?) looks in detail?
- zx2c4 6mo agoEncouraged by this thread, I tweeted about it: https://x.com/EdgeSecurity/status/2041872931576299888 https://x.com/EdgeSecurity/status/2041872931576299888
- varun_ch 6mo agoIf someone was a bad actor, right now would be a pretty good time to start exploiting zero days in WireGuard…
- ninjagoo 6mo agoIt has been clear for a while that certain providers and services need to be regulated as utilities - Microsoft, Google, Apple, Visa, Mastercard, and soon Openai and Anthropic. It should be illegal for these companies, just like utilities, to deny service to anyone or any entity in good standing for dues. There is little hope for getting this through in the US where most politicians of any stripe hate the public, and the ones that don't have hardly any power. But it might be possible to do this in the EU. Then, we non-EU folks need to apply for Estonian e-residency [1] which may get us EU regulatory coverage. [1] https://en.wikipedia.org/wiki/E-Residency_of_Estonia https://en.wikipedia.org/wiki/E-Residency_of_Estonia
- prox 6mo agoWe need a law that a human representative can be spoken to within 24 hours or directly when something critical happens. Also “there is no appeal possible” should be plain illegal.
- gzread 6mo agoIn the EU, under GDPR, it is legally required to explain automated profiling.
- emsixteen 6mo agoHow's that work? Got a link handy to explain to a dummy?
- buzer 6mo agoArticle 13(2)(f) "In addition to the information referred to in paragraph 1, the controller shall, at the time when personal data are obtained, provide the data subject with the following further information necessary to ensure fair and transparent processing: the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject." EDPB Guidelines on automated decision making: https://ec.europa.eu/newsroom/article29/items/612053 https://ec.europa.eu/newsroom/article29/items/612053 especially page 25 is relevant C‑634/21 is also somewhat relevant to understand how courts have applied ADM in general context of credit reporting https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62021CJ0634 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A... though it didn't specify what information actually needs to provided for 13(2)(f).
- rsync 6mo agoYou said: "Currently undergoing some sort of 60 days appeals process, but who knows." .. and the op said: "I have tried to contact Microsoft through various channels but I have only received automated replies and bots. I was unable to reach a human." ... which is a roundabout way of saying you did not spend lawyer hours and you did not contact them through channels that they cannot ignore: registered, physical mail, from a lawyer. I'm sorry for these difficulties, truly, but don't tell me you can't reach a human when you most definitely can reach a human. From my own experience with an organization at least as calloused and indifferent as MS[1], as soon as I sent a real, legal communication I had real live humans lining up to talk to me. [1] Pacific Gas and Electric
- reincarnate0x14 6mo agoMicrosoft hasn't managed to burn down entire towns (But Copilot is probably working on it), so I suppose we do have at least some kind of gauge of callousness to work off of thanks to PG&E. Which was also the company behind that whole slightly famous Erin Brockovich thing, amongst so very many others. Sometimes, it's both incompetence AND malice.
- zx2c4 6mo agoNo. The humans just said 60 days.
- withinrafael 6mo agoWill send some emails.
- sellmesoap 6mo agoWith these big players who are regularly found supporting people with evil intentions: Don't attribute to incompitence what could be ascribed to malice, nay you must trust the gods of the clouds to keep your secrets for you, all for the low low price of $x.99 a month a seat, you may only cancel your service with an arcaine dance and the sacrifice of your first born!
- wolrah 6mo agoNot exactly the same situation, but RustDesk has recently been removed from the official WinGet community repository because their automated scans have been blocking updates since v1.4.2 in September 2025. https://github.com/rustdesk/rustdesk/discussions/13025 https://github.com/rustdesk/rustdesk/discussions/13025 https://github.com/microsoft/winget-pkgs/pull/345601 https://github.com/microsoft/winget-pkgs/pull/345601 tl;dr: ESET Antivirus flags RustDesk as a "Potentially Unsafe Application" because it is a remote administration tool, despite not flagging similar commercial products in the same way, and the WinGet Community repo policy is to block anything flagged as such. Since they were unable to update the repo the RustDesk team requested that the older versions be removed to prevent users from unknowingly installing old versions that could potentially be a security issue in the future. Apparently this has been an issue for a lot of applications especially in the VPN and remote control categories. There is a discussion about how best to handle these sorts of situations where legitimate and desirable applications get flagged as "potentially unsafe" or "potentially unwanted" but so far it's just been a discussion with no actual changes proposed yet. https://github.com/microsoft/winget-cli/issues/6107 https://github.com/microsoft/winget-cli/issues/6107
- Nuthen 6mo agoThank you for the extra visibility on this issue. I'm in the exact same boat: account suspended, waiting for the 60 days appeal process. Hopefully it will be resolved swiftly!
- SergeAx 6mo agoIs there a WireGuard version for Windows above 0.5.3 released in 2021?!
- zx2c4 6mo agoHopefully soon, Microsoft-willing.
- Avamander 6mo agoI saw a tweet saying that there's a requirement for verification. > Effective October 16, 2025, Microsoft will initiate mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024. > Partners who fail to complete Account Verification by the deadline, or who do not meet the requirements, will have their status set to Rejected and will be suspended from the program. https://x.com/shanselman/status/2041974138253013205 https://x.com/shanselman/status/2041974138253013205
- freedomben 6mo ago[dead]
- observationist 6mo ago/tinfoil time 60 days, long enough for the US to exploit the vulnerabilities discovered by Claude Mythos, short enough to plausibly be bureaucratic corporate awfulness by Microsoft when all is said and done. Basically freezing you and other security software out of protecting the bad guys they particularly want to get at until after the bad guys get got, then everything goes back to normal and Microsoft says "oops, here, we fixed your access."
- deleted 6mo ago[deleted]
- number201724 6mo agoDid you also receive the same support email? They always just tell me to ask copilot, then they open a case using copilot, and then they tell me to ask copilot again. I said I wanted to prove that the code didn't contain malicious code, and they still told me to ask copilot... This account has been suspended because the code you submitted contains malware or potential vulnerabilities. If you believe your account was suspended in error and can demonstrate that the code you submitted does not contain malware or vulnerabilities, please follow the below steps, and contact us. . Go here: http://aka.ms/hardwaresupport http://aka.ms/hardwaresupport 2. Click Contact Us 3. Make sure you are signed in with a user associated with the HDC account in Partner Center 4. Select Ask Copilot to receive email support.
- deleted 6mo ago[deleted]
- janc_ 6mo agoHow can you _prove_ (“demonstrate”) that your software doesn’t contain malware or any vulnerabilities? They can’t do that for any of their own software for sure…
- GoblinSlayer 6mo agoI wonder if npcap can route all traffic through a userland service, then handle it there.
- zx2c4 6mo agoMicrosoft got in touch. All sorted out now.
- rogertcb 6mo agoAfter all these statements from M$ claiming they’ve replaced people with AI, wouldn’t be one bit surprised if this “bureaucratic behaviour”, was in fact, some agentic behaviour.