A mandatory verification requirement Microsoft introduced in October took them out.

  • ɔiƚoxɘup@infosec.pub
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 hours ago

    Anyway, this doesn’t look good, and leaving developers of critical security software without recourse for weeks only erodes trust. But, in the end, this won’t really affect a behemoth like Microsoft, who has a dominating hold on the operating system market.

    I’m going to be hosting a community class to get rid of Windows and switch to Linux.

    • other_cat@piefed.zipOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 hours ago

      That’s extremely cool! Are you holding it at the library or something? What distro will you be going with in your demonstration, or are you going to be talking about multiple ones? Do you know how many people will be attending yet?

      I’m sorry for all the questions, it’s just super cool to me haha

      • ɔiƚoxɘup@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        7 hours ago

        All good questions! I need to try Zorin first to see what it’s like and figure out interest levels.

        At the moment, it’s just a good idea.

  • Schwim Dandy@piefed.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 hours ago

    If someone is using a VPN, they’re at least a little tinkery and privacy-focused so maybe this will be the straw that breaks some of their decency on Microsoft.

    • floofloof@lemmy.ca
      link
      fedilink
      English
      arrow-up
      19
      arrow-down
      1
      ·
      1 day ago

      Microslop, who bundle their OS with a competing encryption product that probably has government backdoors, “accidentally” shutting out open source encryption software. Nothing to see here. Perfectly legitimate business behavior.

  • BobbyTables@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    6
    ·
    edit-2
    1 day ago

    Is it just me or is the headline misleading and wrong?

    Why would WireGuard, VeraCrypt or Windscribe push windows updates in the first place?

    If you read the actual text it says Microsoft locked out the accounts these 3 projects used to publish new versions of their software.

    • W98BSoD@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      19 hours ago

      I believe it’s the driver they install that becomes the problem if they don’t have a valid Microsoft account; it’s no longer valid and untrusted by the system.

      • ɔiƚoxɘup@infosec.pub
        link
        fedilink
        English
        arrow-up
        3
        ·
        9 hours ago

        Yes. Since they have kernel level drivers, they need those drivers signed by MS for them to be able to install.

        There used to be a way around this as an end user, but I think now, the only way is to disable ALL driver signature checking. A decidedly unwise choice.

        There used to be the ability to make an exception for a single driver. Certainly an argument can be made that if you’re making an exception for one, it doesn’t matter you might as well turn it off entirely because that one driver could be compromised through modification by any binary on the system.

        Anyway, switch to Linux.

    • TheSambassador@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      ·
      1 day ago

      They’re probably using “Windows updates” to mean “updates to their software on Windows” but it’s obviously confusing.

    • Serinus@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      21 hours ago

      It also seems like somewhat reasonable anti-malware practices, for the most part. They want a government ID if you’re going to push kernel level drivers. They have a process for doing so.

      Could have been smoother, such as allowing them to recover their existing account.

    • ReluctantMuskrat@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      19 hours ago

      I’m guessing you might be able to install VeraCrypt through the Microsoft Store, and if so receive update notifications.

      • floofloof@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        14 hours ago

        You can’t do full-disk encryption without the signed driver, and Microsoft is preventing them signing the driver for new releases. So Microsoft is making it impossible for them to publish updates for the Windows versions of their software.