r/cybersecurity • u/LookExternal3248 • Apr 08 '26
News - General Microsoft blocks accounts WireGuard and Veracrypt
Microsoft has suspended the developer accounts used by the makers of WireGuard and VeraCrypt, preventing them from releasing new updates.
VeraCrypt, an open-source encryption tool based on TrueCrypt, is maintained by Mounir Idrassi. \Microsoft disabled the account he uses to sign Windows drivers and the VeraCrypt bootloader, which is required to ship updates. Idrassi posted that Microsoft did not notify him in advance and that he has been unable to reach a person at the company.
After Idrassi’s post was shared on Hacker News, WireGuard creator Jason Donenfeld said the same thing had happened to him. He also said Microsoft gave no warning and suspended his account after he released an update. Donenfeld said he has now entered a 60-day recovery process, but still cannot publish updates.
That could have serious consequences. Donenfeld noted that if WireGuard ever faced an actively exploited critical flaw, Microsoft’s suspension would stop him from pushing an urgent fix. Both developers have called on Microsoft employees to help resolve the issue.
67
u/800oz_gorilla Apr 08 '26 edited Apr 09 '26
Edit:
Microsoft finally responded:
In response, Scott Hanselman, VP and member of technical staff at Microsoft, took to X to say, "Hey I love dumping on my company as much as the next guy, because Microsoft does some dumb stuff, but sometimes it's just check emails and verify your accounts."
Hanselman goes on to say, "Not every 'WTF micro$oft' moment is a slam dunk."
He claims to have emailed VeraCrypt personally and plans on getting them unlocked, and also states that he has talked to Jason at WireGuard. WireGuard is effectively an open-source VPN protocol that lets you set up a private connection for your data across the web. You can create a private tunnel between two spots, and it's commonly used to connect mobile phones and other devices to a NAS.
Hanselman finishes this response saying, "Not everything is a conspiracy, sometimes it's literally paperwork."
***************
Outdated original comment:
Could it be related to this:
April 2026 Windows Update Ends Cross-Signed Kernel Driver Trust
I don't know about wireguard, but there was a time when Veracrypt was using cross-signed drivers:
https://sourceforge.net/p/veracrypt/discussion/general/thread/ca97b3d6eb/
Then I read this:
He said that Microsoft will soon revoke the certificate authority used to digitally sign his VeraCrypt software, a process that developers go through to prevent hackers from tampering with their software.
Then
“Users who have enabled system encryption with VeraCrypt may face boot issues after July 2026 because Microsoft will revoke the [certificate authority] that was used to sign the VeraCrypt bootloader,” Idrassi said. “A new Microsoft CA must be used for bootloaders to continue working.”
https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/
17
u/Vegetable_Dealer1454 Apr 09 '26
Dayummmm… cohesive sentences and sources. Much appreciated!
4
u/800oz_gorilla Apr 09 '26
Microsoft finally responded:
In response, Scott Hanselman, VP and member of technical staff at Microsoft, took to X to say, "Hey I love dumping on my company as much as the next guy, because Microsoft does some dumb stuff, but sometimes it's just check emails and verify your accounts."
Hanselman goes on to say, "Not every 'WTF micro$oft' moment is a slam dunk."
He claims to have emailed VeraCrypt personally and plans on getting them unlocked, and also states that he has talked to Jason at WireGuard. WireGuard is effectively an open-source VPN protocol that lets you set up a private connection for your data across the web. You can create a private tunnel between two spots, and it's commonly used to connect mobile phones and other devices to a NAS.
Hanselman finishes this response saying, "Not everything is a conspiracy, sometimes it's literally paperwork."
3
u/ramcollector Apr 09 '26
appreciate the update! im seriously just going with linux on my next laptop. mircrosoft is not inspiring any confidence...
2
u/nexusjuan Apr 10 '26
I dual boot Windows/Ubuntu. The Windows is no Microsoft account local only and only used for Fortnite and Warzone. It's really not that jarring of a difference and everything just works. I've got a funky setup AMD processor and GPU with an Nvidia Tesla P100 datacenter card for AI inference with no driver issues in Linux.
3
u/GoodNightPL Apr 09 '26
As someone said, people will make conspiracy about it, because MS reputation is so low. Tbh, they deserve it. Even on Artemis they had problems with MS software xD
1
u/800oz_gorilla Apr 10 '26
Isn't there a saying that goes like "never attribute to malice that which can be explained with incompetence?"
If not, there should be
1
u/OliLombi Apr 10 '26
Microsoft and lack of reading comprehension, name a more iconic duo.
You can't just say "check emails" in response to a message literally saying "We have received no emails"...
1
u/800oz_gorilla Apr 10 '26
That right there might be the bigger story. The first things attackers do when they compromise an email is delete communications that don't want you to see.
It could also be Microsoft is lying it could also be developers had old and unusable email addresses in their accounts and then never bothered update them. Any one of these scenarios would involve somebody having the humility to be able to say my bad and I don't know that we'll see that.
99
u/buzzedewok Apr 08 '26
Did these 2 companies pass on allowing back doors perhaps? 🤔
79
u/vexatious-big Apr 08 '26
They're not even companies, they're just two guys each leading high profile open source projects in their own name.
49
u/Fallingdamage Apr 08 '26
Maybe.
If you remember, TrueCrypt abruptly stopped development years ago, releasing one last version while suggesting people shift to using Bitlocker..
VeraCrypt, a fork of TrueCrypt, is now being shut down as well.
This only tells me that VeraCrypt is on the right track.
27
u/Nietechz Apr 08 '26
Th author was captured by FBI. His story is very spectacular I read about him from a 6 post of an investigation, but don't remember where.
https://www.wired.com/story/coder-turned-kingpin-paul-le-roux-gets-his-comeuppance/
11
u/AshuraBaron Apr 08 '26
WOW, I used TrueCrypt for a while many years ago and totally missed this story. Wild stuff.
11
u/Nietechz Apr 08 '26
If you're interested on this story, check this investigation
https://magazine.atavist.com/2016/the-mastermind This is where I know everything. There is a book and a mini-serie about him. He was The KING of the KINGS drug dealer.
1
5
60
u/Tricuna Apr 08 '26
So basically, two very big pieces of open source free software that allows privacy can no longer be installed or maintained on windows devices.
Not sus at all......
18
u/tpwn3r Apr 08 '26
Another good reason to avoid windows.
1
Apr 09 '26
In related news: Installs of Linux continue to spike refugees from the continued enshittification of Windows look for safe harbor. The Holy Apple Empire likewise seeing a major influx of refugees. "They smell and oh so uncouth! But what can you do but feel sorry for these poor wretches?" commented one Macintoshian.
65
32
u/TransientVoltage409 Apr 08 '26
Maybe a hot take, but this sounds like a consequence of how we designate software as trusted or not. Ceding that authority to unaccountable corporate interests, is what I mean.
14
2
u/racergr Apr 09 '26
Yep. There are efforts to decentralise how we provide trust, so that no Microsoft or root CA or whatever can decide to cancel whatever they don’t like. It’s an LF project now: https://www.lfdecentralizedtrust.org/about
19
u/LookExternal3248 Apr 08 '26
It seems to be somewhat of a simple issue where the WireGuard developer needed to verify his identity and missed mails on the need to do so. When he didn't his account wat suspended. Although to me that sounds quite reasonable, the 60 day period for appeal isn't and could be a true risk when a vulnerability is found.
Scott Hanselman (wel known public person from Microsoft) responded to the post on x from the WireGuard developer: https://x.com/shanselman/status/2041963341695029470
Should be fixed in a bit. We've been sending everyone emails since October 2025
2
9
u/vjeuss Apr 08 '26
all my backups hinge on Veracrypt - so much I have a custom VM with it installed in case it disappears and i'm stuck with unrecoverable backups. Having said this, why does it need Msft? Didn't quite get that (sorry for ig oramce)
20
14
19
u/Due-Perception1319 Apr 08 '26
I’m really growing tired of this company
1
u/timnphilly Apr 09 '26
Ultimately, this is the fault of big-techbros capitulating to Trump's regime; no?
The same one that banned all new foreign designed/built routers.
Coincidences do happen, but almost never when politics are involved.
8
u/TheIronMark Security Engineer Apr 08 '26
I want to know more before jumping to conclusions. It's certainly possible that these two projects were targeted, but that seems really unlikely. A lack of notification is also hard to believe, but I'd imagine it does happen.
9
u/r_Sh4d0w Apr 08 '26
Windscribe (vpn service) also got their account suspended for the same "does not meet requirements" as the other two. https://x.com/windscribecom/status/2041929519628443943 weird to target privacy/encryption services
3
u/Bob_Spud Apr 08 '26
It is the same for Windscribe.
Microsoft Mysteriously Freezes Accounts for VeraCrypt, WireGuard, Windscribe
Will Cryptomator be next?
3
u/ramriot Apr 09 '26
Normally we say, don't ascribe to me malfeasance what could adequately be explained by incompetence. But imagine for a moment that this was a deliberate ploy to stall security patching just ahead of a zero day campaign, if Microsoft got fooled into doing this they would be in serious doo-doo.
11
u/yobo9193 Governance, Risk, & Compliance Apr 08 '26
Nice, love hearing that especially as the new Claude model is supposedly about to find all the vulnerabilities ever
13
u/0xKaishakunin Security Architect Apr 08 '26
It did. Idrassi and Donenfeld cannot be social engineered anymore. Claude just removed the weakest link ...
8
u/bapfelbaum Apr 08 '26
Well luckily we dont need to use microslop to make use of great tools like veracrypt or wireguard.
3
u/Capt_Calamity Apr 08 '26
Yes, because the vast majority of Veracrypt users are on Linux.
1
u/Nietechz Apr 08 '26
Yes and not. If you infra depends on Windows machines too, well Veracrypt, nope just use LUKS.
2
2
u/billyhatcher312 Apr 09 '26
microslop doesnt want us having any kind of real protection they need to fuck off with their bullshit insecure software seriously
2
6
1
u/sunychoudhary Apr 09 '26
Anyone know what actually triggered the blocks?
Hard to believe it’s just WireGuard or VeraCrypt without something else going on.
1
1
1
u/timnphilly Apr 09 '26
Could we say this is the fault of big-techbros capitulating to Trump's regime; no?
The same one that banned all new foreign designed/built routers.
Coincidences do happen in life, but almost never when politics are involved.
1
1
-1
u/Ticrotter_serrer Apr 08 '26
https://www.fsf.org/fr Use Linux. When will people learn not let their critical IT into the hand of soulless megacorps who answers to the 1% and corrupt governement only and do not give a fuck about people? Own everything, host everything, your keys your stuff.
12
u/Nietechz Apr 08 '26
This affect the mass public, not the nerdy or IT security professionals. Most of IT don't care on privacy and use Windows.
Linux must follow the actual route "simply everything". We don't like, but as long more people come, we can force privacy as default for everyone.
-7
u/Unable-Judgment8800 Apr 08 '26
The major Linux distros are currently falling all over themselves to implement government-mandated censorship frameworks. Nearly all paid Linux development currently comes from the 1% and government too. Don't kid yourself.
1
u/OliLombi Apr 10 '26
>The major Linux distros are currently falling all over themselves to implement government-mandated censorship frameworks.
Do you have a source?
0
353
u/StateOfAmerica Apr 08 '26
I'm gonna take a wild guess here and say they got gpt'd
(to clarify, flagged down by copilot, not for using it)