frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Veracrypt Project Update

https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/
156•super256•2h ago

Comments

dizhn•1h ago
Microsoft disabled the developer's certificate so no windows releases can be made.
jonathanstrange•48m ago
As someone who is just planning to publish signed desktop software for Windows, this is deeply worrying. What reasons could there be for cancelling a certificate, especially when it has been used for years and the identity is already established?

Are there some ways to combat such decisions legally?

politelemon•34m ago
This is a concern and risk that has realised itself multiple times over the past decades. There have been multiple stories linked to multiple developers in the past.

If you publish to any closed platform including ios, mac, win, android, this is the risk you run and a condition of operating you will need to accept.

shelled•17m ago
Realistically speaking - anything could be a reason. A shakedown or blocking based on some "nudge" (this might come across as tin-foiled though). Some flag/trip-wires going wrong, more worryingly due to a bug/false alarm - and this is more worrying because in this case semi-incompetent large orgs like MSFT find it really hard to accept it, fix, and move on. Some change in OP's account that either they don't see or haven't realised - some edge case, you never know.

And of course, it doesn't affect their earnings and there are no consequence, or significant, so they won't care and won't respond or tell what went wrong.

Can one move legally? Sure. But then it effectively is a combo of who blinks first and who can hold their breath longer.

technion•1m ago
There's more to it. Signed desktop software can be signed by any CA.

Veracrypt has kernel drivers. Microsoft's ability to control what you can sign is specific to kernel drivers, and Microsoft's trigger finger around bans exists in the world where bad drivers BSOD machines.

In general this isn't your problem.

ErroneousBosh•1h ago
Jesus, sourceforge is still on the go?
SXX•1h ago
Might be it even not using all your code to train AI. Or at least not asking your explicit permission to do it.
karel-3d•55m ago
sourceforge was always very scummy, I think they would definitely use the code for that if they could
mbreese•32m ago
It wasn’t always scummy… but there was a definite shift after they got bought. It’s kept getting worse since then.

Then again, this was something like 20 years ago. Back then, Sourceforge was something closer to GitHub today. It was the de facto public source repository. You could even get an on-premise version, IIRC.

Actually, this is sounding a lot like GitHub these days… not sure what that means.

JimDabell•23m ago
Not every conversation has to be a conversation about AI.
egorfine•1h ago
And unfortunately some projects exclusively use sourceforge. Which breaks some of my CI pipelines.
kome•21m ago
yeah, it just works
firen777•1h ago
It's like LibreOffice all over again: https://www.neowin.net/news/microsoft-bans-libreoffice-devel...
pogue•1h ago
They need to get some tech site like Arstechnica to write about it, like they did when neocities couldn't get ahold of bing. The only way to contact these tech companies to speak to a real human being and not a chatbot is if you know somebody who works there or if the media writes about it.
CR1337•30m ago
I blew the lid on X today:

https://x.com/i/status/2041698657368703484

ninjagoo•38m ago
Looks like Linux and some of the BSDs are the only remaining truly open OSes.
nixpulvis•35m ago
We need a better way to sign and verify software. Clearly companies like Microsoft and Apple have not been good for the open source communities and are inhibiting innovation.
PunchyHamster•33m ago
Just add code cert generation to letsencrypt, it's not like MS validates the code that you sign used certs from them anyway
mr_mitm•18m ago
What would be the point? How would you prevent malware from being signed? Currently, code signatures are used as a signal for trustworthiness of the code.
Eldt•6m ago
Misplaced trustworthiness?
iamniels•15m ago
We need better OSes such that signing of software is not required to keep your computer safe.
speedgoose•27m ago
It's perhaps naive, but could he create a new organisation, like a "TotallyNotVeraCrypt" French loi 1901 association, at a different address, and create a new microsoft account by making sure it passes all the requirements.
orbital-decay•3m ago
That's what VeraCrypt is, a fork of the original TrueCrypt after all drama, security doubts, and eventual discontinuation. It took a long time and two independent audits to establish trust in it.
RandomGerm4n•19m ago
That's especially ridiculous because this whole security mechanism that Microsoft is forcing on Windows user doesn't even work. There are tons of leaked certificates and on forums dedicated to game hacking you can find guides on how to get your hands on one yourself. People there use them to write kernel drivers for cheating in games. Game developers often blacklist these in their anti-cheat software so that the game no longer launches on a computer using a driver with that certificate. Microsoft however does not do this and malware developers can then simply use the certificates for their own purposes. So all this nonsense is basically just a restriction on regular users and honest developers while the “bad guys” can get around it.
shelled•14m ago
I am somewhat also concerned that this software was still being distributed on SourceForge.
_s_a_m_•11m ago
Microsoft doing everything in their power to be assholes, as always
krylon•1m ago
As much as I like bashing Microsoft, never underestimate people's capacity for incompetence, especially where large organizations are involved. I don't see how they would gain anything from this move.

C's Biggest Mistake

https://digitalmars.com/articles/C-biggest-mistake.html
1•mhh__•46s ago•0 comments

What "Open" Means: Abliterating Gemma 4 in 24 Minutes

https://thenewguard.ai/features/abliterating-gemma-4/
1•mattezell•3m ago•0 comments

VR Undermines the Laws of the Internet

https://yadin.com/notes/vr-amends/
1•dryadin•6m ago•0 comments

The World Needs More Software Engineers

https://www.oreilly.com/radar/the-world-needs-more-software-engineers/
1•BerislavLopac•6m ago•0 comments

ELI: Programming with Arrays [pdf]

https://apl-germany.de/wp-content/uploads/2020/11/Cheng20201124EliProject.pdf
1•tosh•7m ago•0 comments

Fairwords NPM packages compromised by credential worm stealing tokens and

https://safedep.io/malicious-fairwords-npm-credential-worm/
1•birdculture•11m ago•0 comments

I've Sold Out

https://mariozechner.at/posts/2026-04-08-ive-sold-out/
2•doppp•11m ago•0 comments

Your data stack is about to get a lot more contributors

https://getcassis.com/blog/your-data-stack-is-about-to-get-a-lot-more-contributors
2•matthieu_bl•12m ago•1 comments

Lunar Gateway or Moon Direct? (2019)

https://spacenews.com/op-ed-lunar-gateway-or-moon-direct/
1•JumpCrisscross•14m ago•0 comments

Show HN: The 323, a 32-bit computer in Conway's Game of Life

https://256-32.com/computers/323
1•256_•16m ago•0 comments

Make Every Click Count with Real-Time Personalization

https://www.beaconmatch.com
1•Notorious_DAO•19m ago•0 comments

Mario and Earendil

https://lucumr.pocoo.org/2026/4/8/mario-and-earendil/
1•doppp•20m ago•0 comments

Volunteers turn a fan's recordings of 10K concerts into an online treasure trove

https://apnews.com/article/aadam-jacobs-collection-concerts-internet-archive-chicago-b1c9c4466a2d...
1•geox•22m ago•0 comments

Grokking the MariaDB test runner (MTR)

https://optimizedbyotto.com/post/grokking-mariadb-test-run-mtr/
1•mariuz•22m ago•0 comments

Apple is running out of A18 Pro chips for the MacBook Neo

https://www.tomsguide.com/computing/macbooks/macbook-neo-is-so-popular-apple-is-running-out-of-a1...
1•Lwrless•23m ago•0 comments

Active Incident with Atlassian Services

https://status.atlassian.com
1•svedin•25m ago•0 comments

Developing Creative Identity

https://michaelnotebook.com/dci/index.html
1•walterbell•28m ago•0 comments

Show HN: Rootcx.com – open-source AI agents and internal software

https://github.com/RootCX/RootCX
2•seyz•30m ago•0 comments

Hindsight Simulator: Go back in time and get rich

https://chrispattle.com/hindsight-simulator
1•pattle•31m ago•0 comments

OpenAI Doubling Down on Text Models, Shifting Strategies to Superapp Plan

https://www.bigtechnology.com/p/openai-president-greg-brockman-doubling
3•lschueller•35m ago•4 comments

Show HN: SharpSkill – We built the future of AI coding interviews

https://sharpskill.dev/en
2•Enjoyooor•36m ago•0 comments

AI-Ready Modular Data Center Slashes Deployment Time

https://spectrum.ieee.org/modular-data-center
1•JeanKage•37m ago•0 comments

Aether – Auto-extract entities and build a knowledge graph from any URL

https://github.com/bugrax/aether
2•bugrax•38m ago•2 comments

Passgen-Moz

https://github.com/loperfido/passgen-moz
1•loperfido•39m ago•0 comments

The Git Commands I Run Before Reading Any Code

https://piechowski.io/post/git-commands-before-reading-code/
2•grepsedawk•39m ago•0 comments

Is Entire.io hype or is it the future of GitHub?

https://techstackups.com/guides/entire-io-hands-on-what-it-actually-captures/
1•sixhobbits•40m ago•0 comments

Failing the Fix (2026): Grading laptop and cell phone companies on fixability

https://pirg.org/edfund/resources/failing-the-fix-2026/
1•doener•41m ago•0 comments

Škoda DuoBell: A bicycle bell that penetrates noise-cancelling headphones

https://www.skoda-storyboard.com/en/skoda-world/skoda-duobell-a-bicycle-bell-that-outsmarts-even-...
38•ra•42m ago•9 comments

UK's grand plan to fuel AI with public data faces uphill battle

https://www.theregister.com/2026/04/08/national_data_library_plan/
2•jjgreen•46m ago•1 comments

I made this to enhance the surfing experience

https://github.com/StyleSwift/StyleSwift
1•zane12580•46m ago•0 comments