微软突然终止 VeraCrypt 账户,导致 Windows 更新停止。
Microsoft Abruptly Terminates VeraCrypt Account, Halting Windows Updates

原始链接: https://www.404media.co/microsoft-abruptly-terminates-veracrypt-account-halting-windows-updates/

微软 неожиданly 终止了 VeraCrypt 开发者 Mounir Idrassi 的账户,阻碍了这款流行的开源加密软件未来的 Windows 更新。Idrissi 在一月中旬发现账户被终止,事先没有收到任何警告或解释,只收到一条消息称他的组织 IDRIX 不再符合验证要求——他对此表示异议。 这严重影响了 VeraCrypt,因为大多数用户依赖 Windows。虽然 macOS 和 Linux 更新仍然可行,但向 Windows 用户交付更新现在已被阻止。Idrissi 无法从微软支持获得明确答复,只收到自动回复,可能是 AI 生成的。 这个问题并非孤立事件;VPN 客户端 WireGuard 的创建者报告了微软类似的账户暂停,引发了对依赖大型科技基础设施的开源软件供应链脆弱性以及账户终止缺乏透明度的担忧。微软尚未回应评论请求。

微软意外终止了VeraCrypt的代码签名账户,实际上停止了这款流行的开源磁盘加密工具的自动Windows更新。这引发了用户担忧,许多人指出该公司控制着安全启动链 *和* 禁用保护用户数据的工具,这其中的讽刺意味。 Hacker News上的评论员强调了用户对Windows操作系统缺乏控制权,将其描述为一种“产品”的付费版本,而客户本身就是被出售的商品。虽然有些人建议使用禁用安全启动或通过TPM注册自定义证书等解决方法,但这些方案被认为对于普通用户来说过于复杂。这一事件加剧了人们对厂商锁定以及大型公司单方面限制访问基本软件的担忧。
相关文章

原文

Microsoft has terminated an account associated with VeraCrypt, a popular and long-running piece of encryption software, throwing future Windows updates of the tool into doubt, VeraCrypt’s developer told 404 Media.

The move highlights the sometimes delicate supply chain involved in the publication of open source software, especially software that relies on big tech companies even tangentially.

“I didn't receive any emails from Microsoft nor any prior warnings,” Mounir Idrassi, VeraCrypt’s developer, told 404 Media in an email.

💡

Do you know anything else about this termination or others like it? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at [email protected].

VeraCrypt is an open-source tool for encrypting data at rest. Users can create encrypted partitions on their drives, or make individual encrypted volumes to store their files in. Like its predecessor TrueCrypt, which VeraCrypt is based on, it also lets users create a second, innocuous looking volume if they are compelled to hand over their credentials. 

Last week, Idrassi took to the SourceForge forums to explain why he had been absent for a few months. The most serious challenge, he wrote, “is that Microsoft terminated the account I have used for years to sign Windows drivers and the bootloader.”

“Regarding VeraCrypt, I cannot publish Windows updates. Linux and macOS updates can still be done but Windows is the platform used by the majority of users and so the inability to deliver Windows releases is a major blow to the project,” he continued. “Currently I'm out of options.”

Idrassi told 404 Media the termination happened in mid-January. “I was surprised to discover that I could no longer use my account,” he said.

On the forum and in the email to 404 Media, Idrassi shared what he said was the only message he received connected to the account shutdown. “Based on the information you have provided to date, we have determined that your organization does not currently meet the requirements to pass verification. There are no appeals available, we have closed your application,” it reads.

Idrassi told 404 Media the message is concerning his company IDRIX. “As you can read in their message, they say that the organization (IDRIX) doesn't meet their requirements, but I don't see which requirement IDRIX suddenly stopped meeting,” he said.

The message Idrassi said he received.

Idrassi said he has tried contacting Microsoft support, but he received automated responses that he believes contained AI-generated text. “This is frustrating because they could at least explain what's wrong,” Idrassi said.

“The lack of communication by Microsoft when they take such decisions adds uncertainty about the future, combined with automated AI feedback which gives an inhuman aspect to such decisions,” Idrassi said.

According to a post on Hacker News, the popular VPN client WireGuard is facing the same issue. “No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended,” Jason Donenfeld, the creator of WireGuard, wrote.

Microsoft acknowledged a request for comment but did not provide a response in time for publication.

联系我们 contact @ memedata.com