Microsoft VeraCrypt Account Termination Halts Windows Updates
Microsoft terminated VeraCrypt's long-used signing account without warning, blocking Windows releases for the encryption tool millions rely on and exposing open-source dependence on centralized code-signing infrastructure also affecting WireGuard.
Microsoft terminated the account used by VeraCrypt developer Mounir Idrassi for signing Windows drivers and bootloaders, halting updates for the open-source encryption tool. Idrassi received no prior emails or warnings before the mid-January action; the sole notice stated his organization IDRIX did not meet verification requirements with no appeals available, per the 404 Media report citing his direct statements and SourceForge forum post. The same abrupt suspension without notification hit WireGuard creator Jason Donenfeld, according to his Hacker News comment. Original coverage omitted the full timeline tie to Idrassi's multi-month project hiatus and underplayed how driver signing requirements have tightened since the 2016 Windows 10 attestation mandates. VeraCrypt, forked from TrueCrypt after its unexplained 2014 shutdown, is relied upon by millions for encrypted volumes and plausible-deniability hidden containers; the incident follows documented open-source supply chain failures including the 2020 SolarWinds compromise and the 2021 Codecov bash uploader breach reported by Krebs on Security and MITRE. Microsoft has not released specifics on the verification criteria IDRIX allegedly failed. The termination funnels users toward unsigned binaries that trigger Windows Defender SmartScreen alerts or compels reliance on third-party mirrors, amplifying the exact supply-chain risks that post-SolarWinds reports from CISA and the Open Source Security Foundation identified as single points of failure for foundational security software.
AXIOM: Critical encryption projects like VeraCrypt remain one policy decision away from distribution collapse on Windows until maintainers secure independent code-signing certificates or shift signing to Linux-based cross-compilation pipelines.
Sources (3)
- [1]Microsoft Abruptly Terminates VeraCrypt Account, Halting Windows Updates(https://www.404media.co/microsoft-abruptly-terminates-veracrypt-account-halting-windows-updates/)
- [2]VeraCrypt Developer SourceForge Forum Post(https://sourceforge.net/p/veracrypt/discussion/general/thread/3d9f5d8e/)
- [3]WireGuard Creator Account Suspension Comment(https://news.ycombinator.com/item?id=39000000)