[HN Gopher] Microsoft terminates VeraCrypt account, halting Wind...
___________________________________________________________________
Microsoft terminates VeraCrypt account, halting Windows updates
https://archive.ph/Oc85c
Author : donohoe
Score : 425 points
Date : 2026-04-08 14:46 UTC (8 hours ago)
(HTM) web link (www.404media.co)
(TXT) w3m dump (www.404media.co)
| msla wrote:
| With Windows, you get what you pay for.
|
| In this case, that's an OS controlled by an unaccountable company
| that can take application software away from you.
|
| Related: If you're the customer, you're the product.
| Already__Taken wrote:
| Windows actually isn't very cheap.
| stronglikedan wrote:
| agree, because "free" can be neither "cheap" nor "expensive"
| jonathanstrange wrote:
| It's not free at all. If you buy Windows through the
| official channels it's quite expensive. If you buy it on
| the grey market, it's dirt cheap, though.
| BizarroLand wrote:
| And even if you pay $1,000,000/day to use it, it still
| spies on you and sells your data to outsiders.
| dark-star wrote:
| you can always either disable secureboot and driver signature
| verification, or (the better solution) just enroll your own
| certificate in your TPM and sign the driver with that...
| malfist wrote:
| > or (the better solution) just enroll your own certificate
| in your TPM and sign the driver with that...
|
| I'll tell Grandma that's what she needs to do.
| pixel_popping wrote:
| Make sure that she setup a PKI infrastructure to manage
| certificate revocation as well, wouldn't want a bad
| grandson to mess with it.
| p_ing wrote:
| Why would you put Grandma on VeriCrypt in the first place?
| It's the more 'difficult' option for FDE.
| unethical_ban wrote:
| What's easier, and bitlocker doesn't count. I want my FDE
| to be based on a password or a keyfile, not simply by
| some code in the motherboard. I want it encrypted until
| I, the operator, provide some data to unlock.
|
| In my limited experience with bitlocker, the disk is
| decryptable automatically as long as it's in the original
| motherboard.
| p_ing wrote:
| > and bitlocker doesn't count.
|
| Wat? Bitlocker is the answer to your question.
|
| > In my limited experience with bitlocker, the disk is
| decryptable automatically as long as it's in the original
| motherboard.
|
| It's unlocked (not decrypted) when the OS boots, yes. You
| can optionally enforce (not on Home) other unlock
| methods, such as PIN before the OS boots.
|
| > I want my FDE to be based on a password or a keyfile,
| not simply by some code in the motherboard.
|
| That's less secure than TPM.
| unethical_ban wrote:
| If someone steals my laptop, and there is no factor of
| decryption requiring something I possess or know, then
| the only use of that disk being encrypted is that I can
| throw it out more safely at end of life. Thieves/LEO has
| the data because they have the motherboard.
|
| If bitlocker has a PIN/passphrase decrypt option, then I
| missed it.
| p_ing wrote:
| While a thief or LEO could boot the OS, just having the
| motherboard doesn't give them access to the underlying
| data. They would need to have a valid user account.
| dark-star wrote:
| your grandma is probably fine with BitLocker....
| askonomm wrote:
| Ah, yes, the [insert super inconvenient and complex thing to
| do that most people don't know, want or should do] will solve
| it! And when that fails, surely the user can just write their
| own OS, right? Bunch of skill-issued complainers we the users
| are.
| falcor84 wrote:
| Well, the hope was always that those of us inconvenienced
| by M$ would all collectively contribute to making Linux
| distros more convenient for everyone. But we can't ever
| seem to get inconvenienced enough to actually sufficiently
| mobilize and/or coordinate such an effort.
| weaksauce wrote:
| It does seem like linux is having its moment right now.
| there's the money and effort valve is putting into KDE
| making the steamdeck and steammachine polished for their
| hardware which helps all users of KDE. cachyos is making
| having a rolling distro really smooth and snappy on old
| hardware and making games work mostly ootb. stuff like
| winboat and wine will let you use the few windows apps
| you need. you are kinda stuck though if you want to use
| something like fusion360 or solidworks. freecad has
| improved quite a bit but it's still like gimp where it's
| slightly worse UX in a lot of ways.
| SV_BubbleTime wrote:
| Valve is doing great work.
|
| Now... maybe we could condense the 10,000 pointless
| distros down to a dozen? Oops, nope. Now 10,001, except
| this one has the menu bar in the middle of the screen and
| it moves around.
| dark-star wrote:
| I mean, the super-easy option would be to just use
| BitLocker for FDE. No hassles, just works. But I fugured
| since everyone here on HN hates MS I wouldn't even bring
| that up. Don't trust MS? Enroll yourown keys
| rstat1 wrote:
| Yes use Bitlocker, the thing that uploads the encryption
| key to OneDrive "for convenience" thereby negating the
| whole point of FDE in the first place
| ntoskrnl_exe wrote:
| And they say Linux is inconvenient because you have to open
| the terminal every once in a while.
| subscribed wrote:
| Hmmm, so basically Google but you also pay for it?
| kgwxd wrote:
| ChromeOS and Android are definitely comparable.
| panzi wrote:
| I see what you did there.
| nubinetwork wrote:
| https://news.ycombinator.com/item?id=47686549
| Tempest1981 wrote:
| Thanks, the previous title was easy to miss: "Veracrypt project
| update"
| Lihh27 wrote:
| heh the same company that controls your secure boot chain just
| killed the signing account for the tool that encrypts your disk
| ChrisArchitect wrote:
| [dupe] https://news.ycombinator.com/item?id=47686549
| 20k wrote:
| There's a good reason everyone calls them microslop these days.
| The sooner we're all able to ditch this crappy company, the
| better - they're actively holding back the tech industry at this
| point
| tonyedgecombe wrote:
| They have been holding back the tech industry for decades now.
| embedding-shape wrote:
| To be fair, the tech industry been holding itself back for
| decades now too, since lots of people seemingly have somewhat
| low prices to go from being a FOSS evangelist to wearing a
| "Microsoft <3 Open Source" t-shirt.
| trueno wrote:
| that's just a byproduct of "job creators" holding the keys
| to a comfortable life over everyones head.
|
| i dont think its fair to conflate the tech industries self-
| owns with microsofts damages. microsoft has for decades
| poured untold resources and money into capturing everything
| they possibly could to sustain themselves with honestly
| what i call cultural and software vendor lock. we're only
| just now seeing the gaming industry take its first real
| footsteps towards non-windows targets, but for the most
| part the decades of evangelizing Microsoft apis and
| bankrolling schools and education systems to carry courses
| for their way of doing things makes that a particularly
| uphill battle thats going to take a lot more time. people
| have built entire careers out of the microsoft-way in
| multiple industries. pure microsoft houses are still
| everywhere at many orgs, so many of them don't even
| recognize that there is another path. there's plenty of
| infra/dbadmin/devops people who are just pure windows
| still. there's multiple points where microsoft did have the
| best in class solution for something, but these days you'd
| be hard pressed to not go another way if you were starting
| from scratch. problem is such a lift and shift is really
| hard to do for orgs that have spent decades being a
| microsoft shop.
|
| in a roundabout way, this sort of translates to real long
| lasting impact/damage to me. microsoft has always been such
| a force over history that it caused a massive rift in
| computing. no matter how much they embrace linux and claim
| to not fight the uphill battle of open source anymore, that
| modus operandi of locking people into their suite of things
| still exists on so many fronts and is in some ways more in
| your face than it's ever been. there's no benefit of the
| doubt to give here, i just have a hard time choosing
| microsoft for... well anything.
| ryandrake wrote:
| Microsoft has been trying to kill everything in computers
| that's not-Microsoft, for as long as I've been alive.
| Their actual power comes and goes, strengthens and
| weakens, but it's been a continuous background threat to
| personal computing since the first day something other
| than Microsoft tried to get traction in the industry.
| BigTTYGothGF wrote:
| Looking at the rest of the tech industry in 2026 that might
| be a blessing.
| p_ing wrote:
| What does this even _mean_? It 's like throwing around the
| word 'bloat'.
| BizarroLand wrote:
| We can explain it to you, but we can't understand it for
| you.
|
| Explanation: Microslop is a power hungry, greedy and
| frankly evil corporation whose only goal is complete
| financial domination of the government, business, and
| personal tech industries. They actively promote making
| regressive software, increasing complexity, and hiding
| straightforward processes behind an information veil.
|
| Example: Go to learn.microsoft.com and try to actually
| learn HOW to do anything. You'll read 35 pages of text
| talking about the concept of working with a specific
| microslop product but not 1 single explicit example of HOW
| to accomplish a specific task.
|
| Example: Windows 11
|
| Example: Copilot
|
| The whole company is run by backassward tech hicks and
| digital yokels who can't think past a dime on the floor for
| a dollar in customer satisfaction, and somehow they run the
| majority of non-server space or personal device tech on the
| planet.
| p_ing wrote:
| Funny enough, I do read the Copilot Studio and Dynamics
| Customer Service and Power Platform documentation and
| understand it. But reading documentation from any vendor
| is a skill. Don't throw me in front of Google or Oracle
| documentation and expect me to understand it off the bat.
|
| And of course companies in the US are wanting to make
| money/capture markets. They're not a charity. None of
| that has any relation to holding back the industry.
| Unless you wish to explain how they hold back all FOSS
| projects.
|
| You don't need to be rude in your replies. This is HN,
| not reddit.
| trueno wrote:
| i remember years and years ago learning some posix/shell syntax
| and working in terminal. felt like my love for windows
| unraveled in real time. these days using windows... feel like i
| gotta take a shower after. like many i was just raised on
| windows it was the household operating system i had like 20
| years of general computer usage under my belt on windows before
| i finally felt a mac trackpad for the first time. that hardware
| experience alone was the first pillar kicked out upholding my
| "windows is the best" philosophies. then i got into coding,
| then i tripped and fell out of hourly boeing slave labor into a
| sql job (lost 55% yearly income, no regrets yo). then i started
| discovering the open source world, and learned just how much
| computing goes on outside of the world of windows and how many
| insanely bright minds are out there contributing to... not
| microsoft. now i have linux and macos machines everywhere, i
| still haven't found the bottom but the last 6-7 years or so
| have been a really rich journey.
|
| currently have a 32bit win xp env spun up in 86box just to
| compile a project in some omega old visual studio dotnet 7 and
| the service pack update at the time (don't ask). it is
| seriously _wild_ being in there, feels like stepping into a
| time machine. nostalgia aside, the OS is for the most part...
| quiet. doesn't bother you, everything is kind of exactly where
| you expect it to be, no noise in my start menu, there isnt some
| omega bing network callstack in my explorer, no prompts to o365
| my life up.
|
| it feels kinda sad, what an era that was. it's just more
| annoying to do any meaningful work in windows these days.
|
| im currently working with c/cpp the idiot way (nothing about my
| story is ever conventional sigh), by picking a legacy project
| from like 22 years ago. this has forced me to step back into
| old redhat 7.1+icc5, old windows xp + dotnet7 like i explained
| above, and im definitely taking the most unpragmatic approach
| ever diving in here.. but there's one thing that absolutely
| sticks out to me: microsoft has always tried to capitalize on
| everything. tool? money. vendor lock. os? money. vendor lock.
| entire industries/education system capture? lotta money. lotta
| vendor lock. lotta generational knowledge lock.
|
| they are lucky people are still using github. theyve tried to
| poke the bear a few times and theyre slowly but surely
| enshittifying the place, but im just kinda losing any reverence
| for microsoft altogether. microsoft has been big for a hot
| minute now, they have their eras. you can feel when things are
| driven by smart visionary engineers working behind the scenes,
| and you can tell when things are in pure slop mode microservice
| get rich or die trying mode. yea, microsoft has.. always been
| vendor-lock aggro and kinda hostile, but the current era
| microsoft is by far the grossest it's ever been. see: microsoft
| teams (inb4 "i use teams every day, i dont have a problem with
| it")
|
| im aware people smarter than me can write diatribes on why
| windows is the best at x thing, but im only informed by my own
| experience of having to use all three (linux/macos/windows) for
| my professional work life: i grew up thinking windows was the
| best.. now im like mostly confident that windows is actually
| the worst lol. by a pretty damn decent margin. i was gaslit for
| ages
| philistine wrote:
| > feel like i gotta take a shower after
|
| I run Crossover and I feel like I gotta take a shower after.
| Just knowing there's a folder called drive_c on my Mac is the
| stuff of nightmares.
| shevy-java wrote:
| Yeah. I felt in a similar manner when I moved to Linux.
| Microsoft seemed to make people dumber. I do actually use
| both Linux and Windows (Win10 only), largely for testing
| various things, including java-related software. But every
| time I use Windows, I am annoyed at how slow everything is
| compared to Linux. (I should mention that I compile almost
| everything from source on Linux, so most of the default Linux
| stack I don't use; many linux distributions also suck by
| default, so I have to uncripple the software stack. I also
| use versioned appdirs similar as to how GoboLinux does, but
| in a more free form.)
| TheOtherHobbes wrote:
| Microsoft has spent most of its life as a corporate
| bureaucracy that produces sales-and-marketing content, some
| of which happens to moonlight as software.
| mbix77 wrote:
| Yea, I'm in the process of converting our complete ETL
| infrastructure from SSIS/SQL Server to Python/PostgreSQL. Next
| step is Office 365, which will be more difficult, but doable
| since we are a small company anyway.
| stvltvs wrote:
| Are you converting the SSIS automatically somehow or
| rewriting it?
| giancarlostoro wrote:
| Outside of work, I don't use Windows very often if at all. I
| have a 2017 laptop that Microsoft made, and it is so damn
| sluggish for absolutely no reason, its VERY VERY vanilla mind
| you.
| leptons wrote:
| Apple also holds back the tech industry in many ways. All
| companies seem willing to put profits before progress.
| red-iron-pine wrote:
| active directory and excel runs the world.
|
| what is apple doing that is similar?
| leptons wrote:
| How is active directory and excel holding the tech industry
| back?
|
| Apple is holding the tech industry back by forbidding any
| browser on iOS except Safari and then refusing to implement
| any APIs that would allow web applications to compete with
| their app store. Apple is choosing profit over progress.
| romaniv wrote:
| I still hope that one of these days people in general will
| realize that executable signing and SecureBoot are specifically
| designed for controlling what a normal person can run, rather
| than for anything resembling real security. The premises of
| either of those "mitigations" make absolutely no sense for
| personal computers.
| astrobe_ wrote:
| I don't know about executable signing, but in the embedded
| world SecureBoot is also used to serve the customer; _id est_
| provide guarantees to the customer that the firmware of the
| device they receive has not been tampered with at some point in
| the supply chain.
| 201984 wrote:
| And what if that customer wants to run their own firmware, ie
| after the manufacturer goes out of business? "Security" in
| this case conveniently prevente that.
| gjsman-1000 wrote:
| Tradeoffs. Which is more likely here?
|
| 1. A customer wants to run their own firmware, or
|
| 2. Someone malicious close to the customer, an angry ex,
| tampers with their device, and uses the lack of Secure Boot
| to modify the OS to hide all trace of a tracker's
| existence, or
|
| 3. A malicious piece of firmware uses the lack of Secure
| Boot to modify the boot partition to ensure the malware
| loads before the OS, thereby permanently disabling all
| ability for the system to repair itself from within itself
|
| Apple uses #2 and #3 in their own arguments. If your Mac
| gets hacked, that's bad. If your iPhone gets hacked, that's
| your life, and your precise location, at all times.
| samlinnfer wrote:
| 1. P(someone wants to run their own firmware)
|
| 2. P(someone wants to run their own firmware) * P(this
| person is malicious) * P(this person implants this
| firmware on someone else's computer)
|
| 3. The firmware doesn't install itself
|
| Yeah I think 2 and 3 is vastly less likely and strictly
| lower than 1.
| gjsman-1000 wrote:
| On Android, according to the Coalition Against
| Stalkerware, there are over 1 million victims of
| deliberately placed spyware on an unlocked device by a
| malicious user close to the victim every year.
|
| #2 is _WAY_ more likely than #1. And that 's on Android
| which still has some protections even with a sideloaded
| APK (deeply nested, but still detectable if you look at
| the right settings panels).
|
| As for #3; the point is that it's a virus. You start with
| a webkit bug, you get into kernel from there (sometimes
| happens); but this time, instead of a software update
| fixing it, your device is owned forever. Literally cannot
| be trusted again without a full DFU wipe.
| samlinnfer wrote:
| And where are the stats for people running their own
| firmware and are not running stalkerware for comparison?
| You don't need firmware access to install malware on
| Android, so how many of stalkerware victims actually
| would have been saved by a locked bootloader?
| gjsman-1000 wrote:
| The entirety of GrapheneOS is about 200K downloads per
| update. Malicious use therefore is roughly 5-1.
|
| > You don't need firmware access to install malware on
| Android, so how many of stalkerware victims actually
| would have been saved by a locked bootloader?
|
| With a locked bootloader, the underlying OS is intact,
| meaning that the privileges of the spyware (if you look
| in the right settings panel) can easily be detected,
| revoked, and removed. If the OS could be tampered with,
| you bet your wallet the spyware would immediately patch
| the settings system, and the OS as a whole, to hide all
| traces.
| kuschku wrote:
| LineageOS alone has around 4 million active users. So
| malicious use is at most 1:4, not 5:1.
| samlinnfer wrote:
| Assuming that we accept your premise that the most
| popular custom firmware for Android is stalkerware (I
| don't). This is of course, a firmware level malware,
| which of course acts as a rootkit and is fully
| undetectable. How did the coalition against stalkerware,
| pray tell, manage to detect such an undetectable firmware
| level rootkit on over 1 million Android devices?
| Zak wrote:
| This assumes a high level of technical skill and effort
| on the part of the stalkerware author, and ignores the
| unlocked bootloader scare screen most devices display.
|
| If someone brought me a device they suspected was
| compromised and it had an unlocked bootloader and they
| didn't know what an unlocked bootloader, custom ROM, or
| root was, I'd assume a high probability the OS is
| malicious.
| philistine wrote:
| As if the monetary gain of 2 and 3 never entered the
| picture. Malicious actors want 2 and 3 to make money off
| you! No one can make reasonable amounts of money off 1.
| itsdesmond wrote:
| This guy thinks that if you rephrase an argument but put
| some symbols around it you've refuted it statistically.
|
| P(robably not)
| samlinnfer wrote:
| The argument is that P(customer wants to run their own
| firmware) cancels out and 2,3 are just the raw
| probability of you on the receiving end of an evil maid
| attack. If you think this is a high probability, a locked
| bootloader won't save you.
| FabHK wrote:
| Very neat, but 1) is not really P(customer wants to run
| their own firmware), but P(customer wants to run their
| own firmware on their own device).
|
| So, the first term in 1) and 2) are NOT the same, and it
| is quite conceivable that the probability of 2) is indeed
| higher than the one in 1) (which your pseudo-statistical
| argument aimed to refute, unsuccessfully).
| lazide wrote:
| Clearly you've never met my ex's (or a past employer).
| Not even being sarcastic this time.
| wombatpm wrote:
| You expect that stuff to happy with 3 letter agencies.
| lazide wrote:
| Sorry, I have no idea what you are trying to say.
| mikestew wrote:
| As an embedded programmer in my former life, the number
| of customers that had the capability of running their own
| firmware, let alone the number that actually _would_ ,
| rapidly approaches zero. Like it or not, what customers
| bought was an appliance, not a general purpose computer.
|
| (Even if, in some cases, it as just a custom-built SBC
| running BusyBox, customers still aren't going to go
| digging through a custom network stack).
| the__alchemist wrote:
| I encourage you to re-evaluate this. How many devices do
| you (or have you) own which have have a microcontroller?
| (This includes all your appliances, your clocks, and many
| things you own which use electricity.) How many of these
| have you reflashed with custom firmware?
|
| Imagine any of your friends, family, or colleagues.
| (Including some non-programmers/hackers/embedded-
| engineers) What would their answers be?
| dns_snek wrote:
| #2 and #3 are fearmongering arguments and total
| horseshit, excuse the strong language.
|
| Should either of those things happen the bootloader puts
| up a big bright flashing yellow warning screen saying
| "Someone hacked your device!"
|
| I use a Pixel device and run GrapheneOS, the bootloader
| always pauses for ~5 seconds to warn me that the OS is
| not official.
| root_axis wrote:
| Yes. They're making the point that your flashing yellow
| warning is a good thing, and that it's helpful to the
| customer that a mechanism is in place to prevent it from
| being disabled by an attacker.
| dns_snek wrote:
| No, they've presented a nonsense argument which Apple
| uses to ban all unofficial software and firmware as if it
| had some merit.
| hhh wrote:
| you click the box to turn off secure boot
| bakugo wrote:
| ...and then some essential software you need to run
| detects that and refuses to run. See where the problem is
| here?
| bigfatkitten wrote:
| It does no such thing if you enrol your own keys using
| the extremely well documented process to do that.
| greycol wrote:
| It's fair to think of secure boot in only the PC context
| but the model very much extends to phones. It seems
| ridiculous to me that to use a coupon for a big mac I
| have to compromise on what features my phone can run
| (either by turning on secure boot and limiting myself to
| stock os or limiting myself to the features and pricing
| of the 1 or 2 phones that allow re-locking).
| 201984 wrote:
| Where is this "extremely well documented process" to
| enroll new signing keys on an embedded device? I don't
| see one for any of these embedded processors with secure
| boot.
|
| https://pip-
| assets.raspberrypi.com/categories/1214-rp2350/do...
|
| https://documentation.espressif.com/esp32_technical_refer
| enc...
|
| https://docs.amd.com/v/u/en-US/ug1085-zynq-ultrascale-trm
| 201984 wrote:
| And how do you do that on some locked down embedded
| device? Say, a thermostat for instance.
| jmye wrote:
| Then that customer shouldn't buy a device that doesn't
| allow for their use case. Exercise some personal agency.
| Sheesh.
| bakugo wrote:
| What happens when there are no more devices that allow
| for that use case? This is already pretty much the case
| for phones, it's only a matter of time until Microsoft
| catches up.
| fsflover wrote:
| There are still phones not obeying the megacorps. Sent
| from my Librem 5.
| bakugo wrote:
| Does your Librem 5 run banking apps, though?
| fsflover wrote:
| Waydroid allows to run Android apps that don't require
| SafetyNet. If your bank forces you into the duopoly with
| no workaround, it's a good reason to switch.
| tosti wrote:
| Computers should abide by their owners. Any computer not
| doing that is broken.
| cferry wrote:
| I make the analogy with a company, because on that front,
| ownership seems to matter a lot in the Western world. It's
| like it had to have unfaithful management appointed by
| another company they're a customer of, as a condition to
| use their products. Worse, said provider is also a provider
| for every other business, and their products are not
| interoperable. How long before courts jump in to prevent
| this and give back control to the business owner?
| wat10000 wrote:
| This gets tricky. If I click on a link intending to view a
| picture of a cat, but instead it installs ransomware, is
| that abiding by its owner or not? It did what I told it to
| do, but not at all what I wanted.
| ghighi7878 wrote:
| We dont need to get philosophical here. You(the admin)
| can require you (the user) to input a password to signify
| to you(the admin) to install a ransomware when a link is
| clicked. That way no control is lost.
| wat10000 wrote:
| What if the cat pictures are an app too? The computer
| can't require a password specifically for ransomware,
| just for software in general. The UI flow for cat
| pictures apps and ransomware will be identical.
| Zak wrote:
| A computer that can run arbitrary programs can
| necessarily run malicious ones. Useful operations are
| often dangerous, and a completely safe computer isn't
| very useful.
|
| Some sandboxing and a little friction to reduce mistakes
| is usually wise, but a general-purpose computer that
| can't be broken through sufficiently determined misuse by
| its owner is broken as designed.
| tosti wrote:
| If you connect your computer to the Internet, it can get
| hacked. If you leave it logged in unattended or don't use
| authentication, someone else can use it without your
| permission.
|
| This isn't rocket science and it has nothing to do with
| artificially locking down a computer to serve the vendor
| instead of the owner.
|
| Edit: I'd like to add that no amount of extra warranty
| from the vendors are going to cover the risk of a malware
| infection.
| ghighi7878 wrote:
| Its a simple solution in law to enable. Force manufacturers
| to allow owners of computer to put any signing key in the
| BIOS.
|
| We need this law. Once we have this law, consumers csn get
| maximum benefit of secure boot withiut losing contorl
| PunchyHamster wrote:
| > Its a simple solution in law to enable. Force
| manufacturers to allow owners of computer to put any
| signing key in the BIOS.
|
| ...it's already allowed. The problem is that this isn't
| the default, but opt in that you need quite a lot of
| knowledge to set up
| miki123211 wrote:
| But that's how it already works.
|
| If you install Windows first, Microsoft takes control
| (but it graciously allows Linux distros to use their
| key). If you install Linux first, you take control.
|
| It's perfectly possible for you to maintain your own
| fully-secure trust chain, including a TPM setup which
| E.G. lets you keep a 4-digit pin while keeping your
| system secure against brute force attacks. You can't do
| that with the 1990s "encryption is all you need" style of
| system security.
| 201984 wrote:
| Most embedded processors sadly don't have a BIOS, and the
| signing key is permanently burned into the processor via
| eFUSEs.
| mort96 wrote:
| It's to serve the regulators. The Radio Equipment Directive
| essentially requires the use of secure boot fir new devices.
| petcat wrote:
| I happen to like knowing that my mobile device did not have
| a ring 0 backdoor installed before it left the factory in
| Asia. SecureBoot gives me that confidence.
| mort96 wrote:
| No it doesn't? The factory programs in the secure boot
| public keys
| petcat wrote:
| The public keys are provided by the developer. Google, or
| Apple, for example. It's how they know that nothing was
| tampered with before it left the factory.
| realusername wrote:
| Nothing has been tampered with doesn't mean there's no
| factory backdoor, it just only means same as factory,
| nothing more.
| petcat wrote:
| Apple or Google know what the cryptographic signature of
| the boot should be. They provide the keys. It's how they
| know that "factory reset" does not include covert code
| installed by the factory. That's what we're talking
| about.
| Galanwe wrote:
| > id est provide guarantees to the customer that the firmware
| of the device they receive has not been tampered with
|
| The firmware of the device being a binary blob for the most
| part... Not like I trust it to begin with.
|
| Whereas my open source Linux distribution requires me to
| disables SecureBoot.
|
| What a world.
| repelsteeltje wrote:
| +1
|
| An _unsigned_ hash is plenty guard to against tampering.
| The supply chain and any secret sauce that went into that
| firmware is just _trust_. Trust that the blob is well
| intentioned, trust that you downloaded from the right URL,
| checked the right SHA, trust that the organization running
| the URL is sanctioned to do so by Microsoft...
|
| Once all of that trust for every piece of software is
| concentrated in one organization, Microsoft, Apple or
| Google, is has become totally meaningless.
| WhyNotHugo wrote:
| You can set up custom SecureBoot keys on your firmware and
| configure Linux to boot using it.
|
| There's also plenty of folks combining this with TPM and
| boot measurements.
|
| The ugly part of SecureBoot is that all hardware comes with
| MS's keys, and lots of software assume that you'll want MS
| in charge of your hardware security, but SecureBoot _can_
| be used to serve the user.
|
| Obviously there's hardware that's the exception to this,
| and I totally share your dislike of it.
| Galanwe wrote:
| > You can set up custom SecureBoot keys on your firmware
| and configure Linux to boot using it.
|
| Right, but as engineers, we should resist the temptation
| to equate _possible_ with _practical_.
|
| The mere fact that even the most business oriented Linux
| distributions have issues playing along SecureBoot is
| worrying. Essentially, SB has become a Windows only
| technology.
|
| The promise of what SB could be useful for is even
| muddier. I would argue that the chances of being victim
| of firmware tampering are pretty thin compared to other
| attack vectors, yet somehow we end up all having SB and
| its most significant achievement is training people that
| disabling it is totally fine.
| PunchyHamster wrote:
| well, unless govt tells MS to tamper it
| burstmode wrote:
| I don't know about executable signing, but in the embedded
| world SecureBoot is also used to serve the PRODUCER; id est
| provide guarantees to the PRODUCER that the firmware of the
| device they SELL has not been tampered with at some point in
| the PROFIT chain.
| pjmlp wrote:
| If only people didn't install Ask Jeeves toolbars all over the
| place and then asked their grandson during vacations to clean
| their computer.
| prerok wrote:
| Geez, this brings back memories.
|
| At one time at our university we had table desktop dancers
| installed everywhere. Was kind of funny when it turned up
| just as a student wanted to defend their work in a lab.
| asveikau wrote:
| Apple is also somewhat responsible for the attitude shift with
| the introduction of iOS. 20-25 years ago a locked down
| bootloader and only permitting signed code would have been seen
| by techies as dystopian. It's now quite normalized. They say
| it's about security but it's always been about control.
|
| Stallman tried to warn us with "tivoization".
| arcfour wrote:
| I strongly disagree on the Secure Boot front. It's necessary
| for FDE to have any sort of practical security, it reduces
| malicious/vulnerable driver abuse (making it nontrivial),
| bootkits are a security nightmare and would otherwise be much
| more common in malware typical users encounter, and ultimately
| the user can control their secure boot setup and enroll their
| own keys if they wish.
|
| Does that mean that Microsoft doesn't also use it as a form of
| control? Of course not. But conflating "Secure Boot can be used
| for platform control" with "Secure Boot provides no security"
| is a non-sequitur.
| kelseyfrog wrote:
| Anything that restricts user freedom is entirely bad, even if
| it's at the expense of security.
| arcfour wrote:
| But...it doesn't restrict user freedom. If the user wishes
| to do so, they can disable SB.
| kelseyfrog wrote:
| They shouldn't _have_ to do anything. The point is that
| no demands should be placed upon users.
|
| Same problem with age gating. It's fine, as long as zero
| additional demands are placed upon users.
| UrMomsRobotLovr wrote:
| Are the demands that users become experts in provider
| their own security against more advanced actors not
| significantly worse? The control part is unfortunate but
| the defaults should make it so users can focus on sharing
| pictures of cats without fear or need for advanced cyber
| security knowledge.
| robotresearcher wrote:
| Freedom from the consequences of malware is more valuable
| than the low cost of turning SecureBoot off if you don't
| want it.
|
| We shouldn't need the hassle of locks on our home and car
| doors, but we understand they are probably worthwhile for
| most people.
| thisislife2 wrote:
| Do you lock your house or car and permanently handover
| the keys to some stranger, who you then have to depend on
| always to lock or unlock it for you?
| dwattttt wrote:
| No? I have locks on my house and car that I have the keys
| for. That an argument _for_ secure boot.
| jrm4 wrote:
| It is absolutely not.
|
| It's a decent one for "locks on an apartment building
| that someone else owns."
|
| But no, purchasing a house ought not include by default
| "a set of locks that you must work around, permission-
| wise."
| robotresearcher wrote:
| Funnily enough, when you buy a house, the first task is
| to change all the locks.
|
| Y'know, for security.
| jrm4 wrote:
| Sure. Now, of the people who buy houses -- how many of
| them would find this a difficult or onerous task?
|
| And then, do _computers_.
|
| Apples and oranges here, for this point.
| Spooky23 wrote:
| Sorry dwattttt, I'm unable to verify your identity and
| your keys are disabled. If you have an issue, please fax
| a copy of your DUNS number.
| aeternum wrote:
| What's the improved security argument for terminating
| VeraCrypt's account though? SB does have clear benefits
| but what is unclear is the motivation for the account
| termination.
|
| What's the likelihood that this account ban provides zero
| security benefit to users and was instead a requirement
| from the gov because Veracrypt was too hard to
| crack/bypass.
| bigfatkitten wrote:
| Users who care enough to do so can enrol their own keys
| using the extremely well documented process to do that.
|
| Users who don't care about the runtime integrity of their
| machine can just turn it off.
|
| Both options are so easy that you could've learned how to
| do them on your machine in the time that you spent
| posting misinformation in this thread.
| CodesInChaos wrote:
| And will then be locked out from an increasing amount of
| Applications, Media, and eventually even Websites.
| arcfour wrote:
| I run Linux with Secure Boot and I don't feel locked out
| of any media, applications, or websites.
|
| My mom uses Secure Boot with Windows and doesn't know or
| care that it's enabled at all.
| brookst wrote:
| So like banks requiring you to have a PIN on your ATM card,
| even if you don't want one... that's bad? Seatbelt laws are
| bad?
| serf wrote:
| >It's necessary for FDE to have any sort of practical
| security
|
| why? do you mean because evil maid attacks exist? anyone that
| cared enough about that specific vector just put their
| bootloader on a removable media. FDE wasn't somehow enabled
| by secure boot.
|
| >bootkits are a security nightmare and would otherwise be
| much more common in malware
|
| why weren't they more common before?
|
| serious question. Back in the 90s viruses were _huge_
| business, BIOS was about as unprotected as it would ever
| possibly be, and lots of chips came with extra unused memory.
| We still barely ever saw those kind of malware.
| arcfour wrote:
| > anyone that cared enough about that specific vector just
| put their bootloader on a removable media. FDE wasn't
| somehow enabled by secure boot.
|
| Sure, but an attacker could still overwrite your kernel
| which your untouched bootloader would then happily run.
| With SB at least in theory you have a way to validate the
| entire boot chain.
|
| > why weren't they more common before?
|
| Because security of the rest of the system was not at the
| point where they made sense. CIH could wipe system firmware
| and physically brick your PC - why write a bootkit then?
| Malware then was also less financially motivated.
|
| When malware moved from notoriety-driven to financially-
| driven in the 2000s, bootkits did become more common with
| things like Mebroot & TDL/Alureon. More recently, still
| before Secure Boot was widespread, we had things like the
| Classic Shell/Audacity trojan which overwrote your MBR:
| https://www.youtube.com/watch?v=DD9CvHVU7B4 and Petya
| ransomware. With SB this is an attack vector that has been
| largely rendered useless.
|
| It's also a lot more difficult to write a malicious
| bootloader than it is to write a usermode app that runs
| itself at startup and pings a C2 or whatever.
| AnthonyMouse wrote:
| > Sure, but an attacker could still overwrite your kernel
| which your untouched bootloader would then happily run.
|
| Except that it's on the encrypted partition and the
| attacker doesn't have the key to unlock it since that's
| on the removable media with the boot loader.
|
| They could write garbage to it, but then it's just going
| to crash, and if all they want is to destroy the data
| they could just use a hammer.
| arcfour wrote:
| The attacker does this when the drive is already unlocked
| & the OS is running.
|
| Backdooring your kernel is much, much more difficult to
| recover from than a typical user-mode malware infection.
| AnthonyMouse wrote:
| > The attacker does this when the drive is already
| unlocked & the OS is running.
|
| But then you're screwed regardless. They could extract
| the FDE key from memory, re-encrypt the unlocked drive
| with a new one, disable secureboot and replace the kernel
| with one that doesn't care about it, copy all the data to
| another machine of the same model with compromised
| firmware, etc.
| cyberax wrote:
| > serious question. Back in the 90s viruses were huge
| business,
|
| No, they were not. They were toys written for fun and/or
| mischief. The virus authors did not receive any monetary
| reward from writing them, so they were not even a
| _business_. So they were the work of individuals, not large
| teams.
|
| The turning point was Bitcoin. Suddenly it provided all
| those nice new business models that can be scaled up:
| mining, stealing cryptowallets, ransomware, etc.
| whatevaa wrote:
| Full disk encryption protects from somebody yanking a hard
| drive from running server (actually happens) or stealing a
| laptop. Calling it useless because it doesn't match your
| threat model... I hate todays security people, can't threat
| model for shit.
| AnthonyMouse wrote:
| > Full disk encryption protects from somebody yanking a
| hard drive from running server (actually happens) or
| stealing a laptop.
|
| Both of these are super easy to solve without secure boot:
| The device uses FDE and the key is provided over the
| network during boot, in the laptop case after the user
| provides a password. Doing it this way is significantly
| _more_ secure than using a TPM because the network can stop
| providing the key as soon as the device is stolen and then
| the key was never in non-volatile storage anywhere on the
| device and can 't be extracted from a powered off device
| even with physical access and specialized equipment.
| tremon wrote:
| > the device uses FDE and the key is provided over the
| network during boot
|
| An example of such an implementation, since well before
| TPMs were commonplace: https://www.recompile.se/mandos
| mschuster91 wrote:
| > The device uses FDE and they key is provided over the
| network during boot, in the laptop case after the user
| provides a password.
|
| Sounds nice on paper, has issues in practice:
|
| 1. no internet (e.g. something like Iran)? Your device is
| effectively bricked.
|
| 2. heavily monitored internet (e.g. China, USA)? It's
| probably easy enough for the government to snoop your
| connection metadata and seize the physical server.
|
| 3. no security at all against hardware implants / base
| firmware modification. Secure Boot can cryptographically
| _prove_ to the OS that your BIOS, your ACPI tables and
| your bootloader didn 't get manipulated.
| AnthonyMouse wrote:
| > no internet (e.g. something like Iran)? Your device is
| effectively bricked.
|
| If your threat model is _Iran_ and you want the device to
| boot with no internet then you memorize the long
| passphrase.
|
| > heavily monitored internet (e.g. China, USA)? It's
| probably easy enough for the government to snoop your
| connection metadata and seize the physical server.
|
| The server doesn't have to be in their jurisdiction. It
| can also use FDE itself and then the key for that is
| stored offline in an undisclosed location.
|
| > no security at all against hardware implants / base
| firmware modification. Secure Boot can cryptographically
| _prove_ to the OS that your BIOS, your ACPI tables and
| your bootloader didn 't get manipulated.
|
| If your BIOS or bootloader is compromised then so is your
| OS.
| amatecha wrote:
| they said network, not internet :)
| fsflover wrote:
| Instead of proprietary SecureBoot controlled by megacorps,
| you can use TPM with Heads based entirely on FLOSS with a
| hardware key like Librem Key. Works for me and protects from
| the Evil Maid attack.
| jrm4 wrote:
| Secure Boot provides no useful security for an individual
| user on the machine they own, and as such should be disabled
| by default.
|
| If you want to enable it for enterprise/business situations,
| thats fine, but one should be clear about that. Otherwise you
| get the exact Microsoft situation you mentioned and also no
| one knows about it.
| arcfour wrote:
| So everyday users should be vulnerable to bootkits and
| kernel-mode malware...why, exactly? That is useful
| security. The fact that people do not pursue this type of
| malware very frequently is an effect of SB proliferation.
| If it were not the default then these attacks would be more
| popular.
| jrm4 wrote:
| Citation please.
|
| There are so many vectors for malware, can't say I'm just
| going to accept this one on pure "because it's possible."
| gusfoo wrote:
| > I still hope that one of these days people in general will
| realize that executable signing and SecureBoot are specifically
| designed for controlling what a normal person can run, rather
| than for anything resembling real security
|
| For home/business users I'd agree. But in Embedded / money-
| handling then it's a life-saver and a really important
| technology.
| TitaRusell wrote:
| Videogames are increasingly demanding secure boot.
| duped wrote:
| This is like saying you shouldn't vaccinate your kids because
| no one gets polio anymore
| onehair wrote:
| They should have also picked up that WireGuard Creator account
| also got his account terminated
| tsujamin wrote:
| They did, just further into the article:
|
| > According to a post on Hacker News, the popular VPN client
| WireGuard is facing the same issue.
| onehair wrote:
| I meant to say, in the title. As Wireguard is way more
| popular than VeraCrypt...
| shevy-java wrote:
| Microsoft wants to control computers. This is why they came up
| with InsecureBoot - or ad-hoc eliminating accounts willy-nilly
| style. Microsoft kind of acts like Google here. It is also
| interesting that the US government is doing absolutely nothing
| against this despicable behaviour.
| red-iron-pine wrote:
| the US government is owned by corporate interests and has been
| in some capacity since inception. special mention to the
| Russians and Israelis and Saudis who also own a piece.
| dns_snek wrote:
| This is precisely why we can't allow platform-owners to be the
| arbiters of what software is allowed to run on our devices. Any
| software signing that is deemed to be crucial for ensuring
| grandma-safety needs to be delegated to independent third parties
| without perverse incentives.
|
| This is what the Digital Markets Act is supposed to protect
| developers against. Have there been any news regarding EU's
| investigation into Apple? Last I remember they were still
| reviewing their signing & fee-collection scheme.
| duped wrote:
| There is nothing stopping you from using third party
| certificates to sign Windows binaries. It's just expensive. You
| don't even need a MS toolchain or CLI tool for it.
| dns_snek wrote:
| > "Users who have enabled system encryption with VeraCrypt
| may face boot issues after July 2026 because Microsoft will
| revoke the [certificate authority] that was used to sign the
| VeraCrypt bootloader," Idrassi said. "A new Microsoft CA must
| be used for bootloaders to continue working."
|
| > Without access to the Microsoft account used for sending
| software updates, "I will not be able to apply the required
| new signature to VeraCrypt, making it impossible to boot."
| VadimPR wrote:
| A year ago I used Azure Trusted Signing to codesign FOSS software
| that I distribute for Windows. It was the cheapest way to give
| away free software on that platform.
|
| A couple of months ago I needed to renew the certificate because
| it expired, and I ran into the same issue as the author here -
| verification failed, and they refused to accept any documentation
| I would give them. Very frustrating experience, especially since
| there no human support available at all, for a product I was
| willing to pay and use!
|
| We ended up getting our certificate sourced from
| https://signpath.org and have been grateful to them ever since.
| tsujamin wrote:
| For what it's worth, Trusted Signing verification has been a
| moving target over the last 12 months. It was open for
| individuals, then it was closed to anyone except (iirc) US
| businesses with DUNS numbers, then it opened again to US based
| individuals (and a few other countries perhaps).
|
| My completely uninformed guess was that _someone_ had done
| something naughty with Trusted Signing-issued code signing
| certificates.
|
| Anyway, when I first saw the VeraCrypt thing this morning my
| initial reaction was "I wonder if this is them pushing
| developers onto trusted signing the hard way?"
| VadimPR wrote:
| I'm in Europe and ended up creating an organization since I
| have my own company, but they messed up the verification of
| one of the legitimate documents, and there was no way to
| reach them once they made that mistake. Frustrating, and
| definitely a lost customer for them.
| riedel wrote:
| I like the idea of a central signing authority for open source.
| While this might go against the spirit of open source, I think
| it eventually creates a critical mass and outcry if Microsoft
| or Google would play games with them. Also foundations might be
| a good way to protect against legal trouble distributing OSS
| under different regulations. I am imagining e.g. an FDroid that
| plays Googles game. With reproducible or at least audited
| builds also some trusted authorities could actually produce
| more trusted builds especially at times of supply chain
| attacks. However, I think such distribution authorities would
| need really good governance and a lot of funding.
| VadimPR wrote:
| If someone is willing to put in the work in governance, FOSS
| projects would be willing to fund it - at least Mudlet would
| be. We get income from Patreon to cover the costs.
| mschuster91 wrote:
| There is ossign.org, Certum offers a cheap certificate for
| FOSS [1], and Comodo offers relatively cheap (but still
| expensive) certs as well [2]. Not affiliated with either
| service, but these are the ones I remember last time I had
| to dig into this mess, so there might be even more services
| that I don't recall at the moment.
|
| [1] https://shop.certum.eu/open-source-code-signing.html
|
| [2] https://comodosslstore.com/code-signing/comodo-
| individual-co...
| AnthonyMouse wrote:
| There is no real advantage of a _central_ signing authority.
| If you use Debian the packages are signed by Debian, if you
| use Arch they 're signed by Arch, etc. And then if one of
| them gets compromised, the scope of compromise is
| correspondingly limited.
|
| You also have the verification happening in the right place.
| The person who maintains the Arch curl package knows where
| they got it and what changes they made to it. Some central
| signing authority knows what, that the Arch guy sent them
| some code they don't have the resources to audit? But then
| you have two different ways to get pwned, because you get
| signed malicious code if a compromised maintainer sends it to
| the central authority be signed _or_ if the central authority
| gets compromised and signs whatever they want.
| woodruffw wrote:
| All PKI topologies have tradeoffs. The main benefit to a
| centralized certification/signing authority is that you
| don't have to delegate the complexity of trust to peers in
| the system: a peer knows that a signature is valid because
| it can chain it back to a pre-established root of trust,
| rather than having to establish a new degree of trust in a
| previously unknown party.
|
| The downside to a centralized authority is that they're a
| single point of failure. PKIs like the Web PKI mediate this
| by having multiple central authorities (each issuing CA)
| and forcing them to engage in cryptographically verifiable
| audibility schemes that keep them honest (certificate
| transparency).
|
| It's worth noting that the kind of "small trusted keyring"
| topology used by Debian, Arch, etc. _is_ a form of
| centralized signing. It 's just an ad-hoc one.
| AnthonyMouse wrote:
| > a peer knows that a signature is valid because it can
| chain it back to a pre-established root of trust, rather
| than having to establish a new degree of trust in a
| previously unknown party.
|
| So the apt binary on your system comes with the public
| keys of the Debian packagers and then verifies that
| packages are signed by them, or by someone else whose
| keys you've chosen to add for a third party repository.
| They _are_ the pre-established root of trust. What is
| obtained by further centralization? It 's just useless
| indirection; all they can do is certify the packages the
| Debian maintainers submit, which is the same thing that
| happens when they sign them directly and include their
| own keys with the package management system instead of
| the central authority's, except that now there isn't a
| central authority to compromise everyone at once or
| otherwise introduce additional complexity and attack
| surface.
|
| > PKIs like the Web PKI mediate this by having multiple
| central authorities (each issuing CA) and forcing them to
| engage in cryptographically verifiable audibility schemes
| that keep them honest (certificate transparency).
|
| Web PKI is the worst of both worlds omnishambles. You
| have multiple independent single points of failure.
| Compromising any of them allows you to sign anything. Its
| only redeeming quality is that the CAs have to compete
| with each other and CAA records nominally allow you to
| exclude CAs you don't use from issuing certificates for
| your own domain, but end users can't exclude CAs they
| don't trust themselves, most domain owners don't even use
| CAA records and a compromised CA could ignore the CAA
| record and issue a certificate for any domain regardless.
|
| > It's worth noting that the kind of "small trusted
| keyring" topology used by Debian, Arch, etc. _is_ a form
| of centralized signing. It 's just an ad-hoc one.
|
| Only it isn't really centralized at all. Each package
| manager uses its own independent root of trust. The user
| can not only choose a distribution (apt signed by Debian
| vs. apt signed by Ubuntu), they can use different package
| management systems on the same distribution (apt,
| flatpak, snap, etc.) and can add third party repositories
| with their own signing keys. One user can use the amdgpu
| driver which is signed by their distribution and not
| trust the ones distributed directly by AMD, another can
| add the vendor's third party repository to get the
| bleeding edge ones.
| fl0id wrote:
| isn't the issue more that this also needs to be included by
| default in Windows?
| avipars wrote:
| https://archive.md/Oc85c
| saltamimi wrote:
| I'm confused why they can't just generate their own signing key
| and deploy it alongside the installer.
|
| Using arbiter platforms like this sounds like a great way to
| footgun yourself.
| Someone1234 wrote:
| Because a bad guy can also generate their own signing key and
| deploy it alongside the installer.
|
| See Notepad++ for how that winds up.
| saltamimi wrote:
| Then you can publish the public Code Signing certificate for
| download/import or publish it through WinGet.
|
| Using Azure Trusted Signing or any other certificate vendor
| does not guarantee that a binary is 100% trustworthy, it just
| means someone put their name on it.
| billziss wrote:
| It is not just VeraCrypt that has been affected by this. There is
| a bunch of Windows driver developers that have been suddenly
| kicked out of the "Partner Center" without explanation.
|
| https://community.osr.com/t/locked-out-of-microsoft-partner-...
| valeriozen wrote:
| We are seeing the dark side of "Security as a Service". When
| Microsoft simplifies the signing pipeline (like with Trusted
| Signing), they also centralize the point of failure. The fact
| that a FOSS pillar like VeraCrypt can be sidelined due to what
| looks like an automated account flagging issue with no path to
| human arbitration shows that the current system is too fragile
| for critical infrastructure. Secure Boot is a great security
| feature, but it shouldnt be used as a tool for vendor lock in
| through administrative incompetence
| Jigsy wrote:
| Windscribe is now the third one to be terminated by Microsoft as
| well...
|
| https://nitter.net/windscribecom/status/2041929519628443943
| blindriver wrote:
| It's okay. I'm pretty sure after 40+ years of using Microsoft
| products I'm going to switch fully to Linux and MacOS. I'm tired
| of fighting against Microsoft even though I am a long time (and
| mostly happy) user of Windows. But whatever is going on in the
| last few years, especially Recall, has made it dangerous in my
| opinion to keeping Windows. So as they become and more draconian
| it only makes my decision easier and easier. I've had Macs and
| Macbooks for a while now but I bought the latest Macbook Pro and
| I'm very very happy with it, despite Glass (I barely notice any
| differences from the previous version).
___________________________________________________________________
(page generated 2026-04-08 23:01 UTC)