<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal.]]></title><description><![CDATA[<p><a href="https://federate.social/tags/Microsoft" rel="tag">#<span>Microsoft</span></a> locks account that <a href="https://federate.social/tags/VeraCrypt" rel="tag">#<span>VeraCrypt</span></a> maintainer uses to sign <a href="https://federate.social/tags/Windows" rel="tag">#<span>Windows</span></a> bootloaders with no explanation or route for appeal. If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" /><br />If this doesn't convince you big tech has too much control, I don't know what will.<br />h/t <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span><br /><a href="https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/" rel="nofollow noopener"><span>https://</span><span>techcrunch.com/2026/04/08/vera</span><span>crypt-encryption-software-windows-microsoft-lock-boot-issues/</span></a><br /><a href="https://federate.social/tags/infosec" rel="tag">#<span>infosec</span></a> <a href="https://federate.social/tags/privacy" rel="tag">#<span>privacy</span></a> <a href="https://federate.social/tags/TechIsShitDispatch" rel="tag">#<span>TechIsShitDispatch</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/9a90af40-56d7-46fa-91eb-57ef5c7a023d/microsoft-locks-account-that-veracrypt-maintainer-uses-to-sign-windows-bootloaders-with-no-explanation-or-route-for-appeal.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 09 Apr 2026 12:18:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/9a90af40-56d7-46fa-91eb-57ef5c7a023d.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Apr 2026 15:44:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 20:34:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> big tech can eat a big dick</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/ap/users/115588296584761431/statuses/116370997194605453</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/ap/users/115588296584761431/statuses/116370997194605453</guid><dc:creator><![CDATA[ox1de@cyberplace.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 20:34:59 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 18:39:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/jaap/statuses/116370542028015131</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.bsd.cafe/users/jaap/statuses/116370542028015131</guid><dc:creator><![CDATA[jaap@mastodon.bsd.cafe]]></dc:creator><pubDate>Wed, 08 Apr 2026 18:39:13 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 18:22:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> what</p><p>Why would being unable to sign stuff stop you from booting and decrypting your disk "in a few months"</p><p>What did VeraCrypt do</p><p>Why do they even have M$ signing keys</p><p>Whay</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.minionflo.net/ap/users/116346548544271763/statuses/116370475677302813</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.minionflo.net/ap/users/116346548544271763/statuses/116370475677302813</guid><dc:creator><![CDATA[tranquillity@mastodon.minionflo.net]]></dc:creator><pubDate>Wed, 08 Apr 2026 18:22:21 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 18:20:43 GMT]]></title><description><![CDATA[<p><a href="/user/jik%40federate.social">@jik@federate.social</a> <a href="/user/zackwhittaker%40mastodon.social">@zackwhittaker@mastodon.social</a> depending on microslop has consequences tbh</p>]]></description><link>https://board.circlewithadot.net/post/https://mk.magicka.org/notes/aktxu79vkos5001k</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mk.magicka.org/notes/aktxu79vkos5001k</guid><dc:creator><![CDATA[jeff@mk.magicka.org]]></dc:creator><pubDate>Wed, 08 Apr 2026 18:20:43 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:50:36 GMT]]></title><description><![CDATA[<span><a href="/user/gsuberland%40chaos.social" rel="ugc">@<span>gsuberland</span></a></span> <span><a href="/user/diagprov%40mathstodon.xyz" rel="ugc">@<span>diagprov</span></a></span> <span><a href="/user/manawyrm%40chaos.social" rel="ugc">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange" rel="ugc">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social" rel="ugc">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="ugc">@<span>zackwhittaker</span></a></span> there are two types of revocation lists, the old one that can revoke certs and binaries by hash (two different lists for boot and drivers), and the new one that's just a CiPolicy and can therefore revoke by anything that a CiPolicy supports.]]></description><link>https://board.circlewithadot.net/post/https://labyrinth.zone/objects/baec1378-f1ab-4512-ad6b-0c1153e9f77f</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://labyrinth.zone/objects/baec1378-f1ab-4512-ad6b-0c1153e9f77f</guid><dc:creator><![CDATA[rairii@labyrinth.zone]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:50:36 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:47:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> yeah, I just decided never to back up anywhere that wasn't a disk I owned...</p>]]></description><link>https://board.circlewithadot.net/post/https://jawns.club/users/acm_redfox/statuses/116370337193957203</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jawns.club/users/acm_redfox/statuses/116370337193957203</guid><dc:creator><![CDATA[acm_redfox@jawns.club]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:47:08 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:46:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> me neither but given how closely uefi code looks to Microsoft C code I bet the mechanism of dbx is very similar to the kernel.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370335705099126</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370335705099126</guid><dc:creator><![CDATA[diagprov@mathstodon.xyz]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:46:45 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:43:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/diagprov%40mathstodon.xyz">@<span>diagprov</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> yup that tracks with my understanding of it. Windows does have a driver cert revocation mechanism and a more general blocklist to prevent loading known-vulnerable drivers, but I haven't studied it in detail.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370321906871424</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370321906871424</guid><dc:creator><![CDATA[gsuberland@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:43:15 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:42:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> they're blocked on signing new builds.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370319798086227</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370319798086227</guid><dc:creator><![CDATA[diagprov@mathstodon.xyz]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:42:42 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:41:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> the certificates used to sign them do have an expiry but timestamps solve both expired cert and expired CA. The only way to revoke it is to add that cert to a CRL and leave it there permanently. I've no idea if the windows kernel checks crls or just maintains a list of blocked certs but I'd expect it to share the logic with windows and keep a cached crl (could be wrong, a long time since I cared much about windows drivers).</p><p>UEFI I don't think checks either expiry or timestamps at all. Instead it has the dbx which can contain blocked certificates or hashes of binaries that should not load.</p>]]></description><link>https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370315214633239</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mathstodon.xyz/users/diagprov/statuses/116370315214633239</guid><dc:creator><![CDATA[diagprov@mathstodon.xyz]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:41:32 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:23:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> <br />Encouraging the switch to a new Windows, a new PC, a new slop.<br />And reminding me I still have a VeraCrypt volume somewhere.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.gamedev.place/ap/users/116092650648397225/statuses/116370244943380303</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.gamedev.place/ap/users/116092650648397225/statuses/116370244943380303</guid><dc:creator><![CDATA[luc0x61@mastodon.gamedev.place]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:23:40 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:09:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>Fair enough. I don't encourage just anyone either. Those who I have encouraged also know to call me if something blows up! <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f602.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--joy" style="height:23px;width:auto;vertical-align:middle" title="😂" alt="😂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370190480134624</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370190480134624</guid><dc:creator><![CDATA[jeffcodes@infosec.exchange]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:09:49 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:09:18 GMT]]></title><description><![CDATA[<span><a href="/user/jik%40federate.social" rel="ugc">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="ugc">@<span>zackwhittaker</span></a></span> <br /><br />&gt; If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" /><br /><br />uhmmm this seems like a pretty big design flaw. Imagine if on FreeBSD or Linux that your GELI / LUKS encryption stops working because some developer's computer was inaccessible....]]></description><link>https://board.circlewithadot.net/post/https://friedcheese.us/objects/6d52df05-8be6-4898-bcfd-af843e39bc39</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://friedcheese.us/objects/6d52df05-8be6-4898-bcfd-af843e39bc39</guid><dc:creator><![CDATA[feld@friedcheese.us]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:09:18 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:08:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/jeffcodes%40infosec.exchange">@<span>jeffcodes</span></a></span> <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> You're absolutely right and will get no argument from me there. I have always supported people encrypting their drives and will give support to people trying to do that. </p><p>Still, VeraCrypt is just a very fragile piece of kit and users need to know that and be able to either fix it themselves or know someone who can do it.</p><p>Telling just random people on the streets to install it will indeed just block access to their data -- even without MS.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/manawyrm/statuses/116370183681044248</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/manawyrm/statuses/116370183681044248</guid><dc:creator><![CDATA[manawyrm@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:08:05 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:06:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>IMO, it is not acceptable to simply overlook these hurdles and say, "this is not available to you because you're not technical like me." These tools are necessary against the mass surveillance of the companies like Microsoft, Google, etc. and governments alike. <br />We, as technologist, should be working to make these more accessible to those who are not technologists too.  Those folks deserve the right and privacy and security like the rest of us.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370175665038226</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370175665038226</guid><dc:creator><![CDATA[jeffcodes@infosec.exchange]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:06:03 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:03:40 GMT]]></title><description><![CDATA[<span><a href="/user/azonenberg%40ioc.exchange" rel="ugc">@<span>azonenberg</span></a></span> <span><a href="/user/gsuberland%40chaos.social" rel="ugc">@<span>gsuberland</span></a></span> <span><a href="/user/jik%40federate.social" rel="ugc">@<span>jik</span></a></span> <span><a href="/user/manawyrm%40chaos.social" rel="ugc">@<span>manawyrm</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="ugc">@<span>zackwhittaker</span></a></span> that said. i wonder if this is MS attempting to do some form of moderation on driver / EFI signers, given the instances of game cheat devs and outright malware actors signing drivers in the past (do i need to cite that unknowncheats thread again?)<br /><br />that said, I quickly browsed around unknowncheats and didn't see anyone complaining about this, so...]]></description><link>https://board.circlewithadot.net/post/https://labyrinth.zone/objects/1e51cca7-5a2d-4ae2-b767-6feea3c3aeda</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://labyrinth.zone/objects/1e51cca7-5a2d-4ae2-b767-6feea3c3aeda</guid><dc:creator><![CDATA[rairii@labyrinth.zone]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:03:40 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:03:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/jeffcodes%40infosec.exchange">@<span>jeffcodes</span></a></span> <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> I'm very sorry, but users that aren't capable of getting help with recovering such data from someone that can handle a Linux Live ISO shouldn't be using VeraCrypt to begin with.<br />It's extremely likely to just cause your system to stop booting (and that has happened to me 5+ times in the years I was using it) -- it's just a regular occurance and you'll need to deal with these things as a user.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/manawyrm/statuses/116370164430367097</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/manawyrm/statuses/116370164430367097</guid><dc:creator><![CDATA[manawyrm@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:03:12 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 17:01:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/gsuberland%40chaos.social">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>The data may be fine; however, not everyone who may use VeraCrypt has the same knowledge and skill base to know to pull up a Linux Live USB and go get their data back. I've encouraged non-technical users to use easy breakthroughs to add encryption to their Windows Home environments. They definitely will not have the knowledge do just go do this. Many may not have another device to create the Linux Live USB either. <br />This is still a problem, whether or not the data is still available through other means.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370157848437458</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/jeffcodes/statuses/116370157848437458</guid><dc:creator><![CDATA[jeffcodes@infosec.exchange]]></dc:creator><pubDate>Wed, 08 Apr 2026 17:01:31 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:56:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> (yes just checked and this is exactly how it works)</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370139990811153</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370139990811153</guid><dc:creator><![CDATA[gsuberland@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:56:59 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:56:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/rairii%40labyrinth.zone">@<span>Rairii</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> yup exactly the way I thought it worked</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370138830131236</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370138830131236</guid><dc:creator><![CDATA[gsuberland@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:56:41 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:56:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> fairly sure driver signatures don't have an expiry at all; it's only the CA that has an expiry and an expired CA doesn't invalidate an existing valid signature, as long as that signature's date was within the valid time range of the CA.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370136877592571</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370136877592571</guid><dc:creator><![CDATA[gsuberland@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:56:11 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:55:23 GMT]]></title><description><![CDATA[<span><a href="/user/gsuberland%40chaos.social" rel="ugc">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange" rel="ugc">@<span>azonenberg</span></a></span> <span><a href="/user/jik%40federate.social" rel="ugc">@<span>jik</span></a></span> <span><a href="/user/manawyrm%40chaos.social" rel="ugc">@<span>manawyrm</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="ugc">@<span>zackwhittaker</span></a></span> (talking about at executable load time here)]]></description><link>https://board.circlewithadot.net/post/https://labyrinth.zone/objects/a5ddc2c9-03e6-47eb-9e81-a3158c053f13</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://labyrinth.zone/objects/a5ddc2c9-03e6-47eb-9e81-a3158c053f13</guid><dc:creator><![CDATA[rairii@labyrinth.zone]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:55:23 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:54:55 GMT]]></title><description><![CDATA[<span><a href="/user/gsuberland%40chaos.social" rel="ugc">@<span>gsuberland</span></a></span> <span><a href="/user/azonenberg%40ioc.exchange" rel="ugc">@<span>azonenberg</span></a></span> <span><a href="/user/manawyrm%40chaos.social" rel="ugc">@<span>manawyrm</span></a></span> <span><a href="/user/jik%40federate.social" rel="ugc">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social" rel="ugc">@<span>zackwhittaker</span></a></span> certificate expiry won't be enforced, however if outright revocation of binaries happen, that will be]]></description><link>https://board.circlewithadot.net/post/https://labyrinth.zone/objects/242b103c-1d4b-46a0-9f49-ddf8a3b1d376</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://labyrinth.zone/objects/242b103c-1d4b-46a0-9f49-ddf8a3b1d376</guid><dc:creator><![CDATA[rairii@labyrinth.zone]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:54:55 GMT</pubDate></item><item><title><![CDATA[Reply to #Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. on Wed, 08 Apr 2026 16:54:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/azonenberg%40ioc.exchange">@<span>azonenberg</span></a></span> <span><a href="/user/manawyrm%40chaos.social">@<span>manawyrm</span></a></span> <span><a href="/user/jik%40federate.social">@<span>jik</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> yes, precisely</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370130938842420</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/gsuberland/statuses/116370130938842420</guid><dc:creator><![CDATA[gsuberland@chaos.social]]></dc:creator><pubDate>Wed, 08 Apr 2026 16:54:41 GMT</pubDate></item></channel></rss>