Microsoft Locks OSR Out of Driver Signing After VeraCrypt, WireGuard, Windscribe — Meme Explained
Level 1: The Only Key-Maker in Town
Imagine a town where, by law, every shop's front-door key must be cut by one single locksmith — no exceptions, no competitors. One week the locksmith's shop starts turning people away over paperwork mix-ups: first a small bakery, then the pharmacy, then the hardware store, and finally the person who taught the locksmith how to cut keys in the first place. Nobody can open their shops, the locksmith won't explain, and the whole town is yelling. The post is one bystander watching this unfold and concluding that this many "coincidences" means the problem isn't the shopkeepers — something is badly broken inside the locksmith's office, and everyone is locked out until someone there notices.
Level 2: Words You'll Meet in the Postmortem
- Driver: software that runs inside the operating system's core (the kernel) to talk to hardware or hook low-level behavior. Kernel code can do anything, so Windows refuses to load drivers that aren't cryptographically signed.
- Driver signing / attestation: the vendor uploads their driver to Microsoft's Partner Center, and Microsoft applies a digital signature vouching for it. No signature, no load — there's no "Are you sure? [Yes]" button for kernel drivers on a normal machine.
- OSR, VeraCrypt, WireGuard, Windscribe: respectively, the most respected Windows-internals consultancy, the standard open-source disk-encryption tool, a widely admired VPN protocol, and a commercial VPN. All need kernel drivers; all reported being locked out.
- Single point of failure: when one component's outage takes down everything depending on it. Junior engineers learn this about databases and load balancers; this episode teaches that bureaucratic processes can be one too. Your CI/CD pipeline can be green everywhere and your release still dies in someone else's approval queue.
Level 3: The Disrespect and Disregard
"After 30+ years of signing windows drivers, we have been locked out of driver signing like many other companies."
That quoted line is from @OSRDrivers — and if that name means nothing to you, that's exactly the point of the poster's "Holy FUCKING shit." OSR is the consultancy that effectively wrote the institutional knowledge of Windows driver development: the seminars, the NT Insider articles, the debugging lore Microsoft's own documentation quietly leans on. Locking OSR out of driver signing is like the DMV revoking the license of the person who designed the driving test.
The escalation pattern the poster narrates is the truly damning part. One lockout (VeraCrypt — disk encryption) is an anecdote. Two (WireGuard — the VPN protocol whose Windows kernel driver is a model citizen) is a coincidence. Then Windscribe, and then OSR — and the charitable explanation he initially offered ("oh two people probably made a small mistake, bureaucracy, dumb stuff, weird coincidence") collapses into "a galactic level of fuck up happening somewhere." That's an experienced observer doing incident triage in public: ruling out user error as the lockouts correlate, concluding the fault is systemic — a policy change, a compliance sweep, or an automated trust-and-safety process that nobody with judgment is reviewing.
This is the recurring nightmare of platform gatekeeper risk, the same dynamic developers know from app-store delistings and ad-account bans: your entire business depends on a counterparty whose enforcement arm is an unaccountable queue, whose support channel is a black hole, and whose mistakes are rate-limited only by public shaming on X. The companies hit here aren't fly-by-night adware shops; they're security-critical open-source projects and a 30-year institution. When the compliance process designed to keep malware out of the kernel ends up blocking VeraCrypt while actual attackers cheerfully abuse stolen EV certs and vulnerable signed drivers (the whole BYOVD cottage industry), you get the bitter punchline: the gate inconveniences the law-abiding and merely annoys the criminals. The channel caption — "Legal department vibing really hard too I guess" — lands because everyone assumes the root cause will turn out to be some compliance or legal-process change that nobody war-gamed against its own ecosystem.
Level 4: Ring 0 Has a Landlord
Since 64-bit Windows Vista, Kernel-Mode Code Signing (KMCS) has meant the kernel refuses to load any driver whose signature doesn't chain to a Microsoft-trusted root. Windows 10 build 1607 tightened the screw: new kernel drivers must be signed by Microsoft itself through the Hardware Dev Center / Partner Center attestation process — vendors submit a .cab, Microsoft's portal signs the binary with the "Windows Hardware Compatibility Publisher" certificate, and only then will ci.dll (Code Integrity) bless its load. Cross-signing with third-party CAs was sunset; there is no alternate path short of telling users to disable Secure Boot or boot with testsigning on, which no legitimate vendor can ship.
The security rationale is real — signed-driver enforcement plus HVCI raises the cost of kernel rootkits enormously — but the architecture is a textbook single point of failure: every kernel-mode vendor on Earth funnels through one bureaucratic pipeline with one account system, one email-verification flow, and one appeals process. The kernel's threat model assumes a hostile world; the signing portal's threat model apparently assumes everyone clicks their verification emails on time. When the gatekeeper hiccups, the failure isn't graceful degradation — it's a hard STATUS_IMAGE_CERT_REVOKED-shaped wall between a vendor and 1.4 billion machines.
Thirty years of writing the book on Windows drivers, defeated not by PatchGuard but by an email verification flow - the kernel's most privileged ring turns out to be Partner Center
The root of trust is apparently a support ticket with a 90-day TTL.
Don't interrupt your enemy making a mistake
Just stop using Windows and let's see how fast they drop their crap
WTF is OSR?
Noname company
Anyway, after intervention from MS VP it got resolved
"Someone". "Something", to be precise. And you can't blame it because its a thing not a person
I don't know what the hell this OSR is and what they do, but this guy is seriously talking about respect from Microslop. 🤡
horray centralization
@morryrebbykh hello
So, how is wine doing nowadays?
What wrong with veracryp?
Ms forgot this
Now they'll face the consequences
Centralized signing is bullshit in the first place, especially when it's done by the platform owners
ong ong bro dawg this is fucked up bad BAD!
Not sure if step supports nondestructive editing, I'll check it later. BTW still not a single word about what are this Linux alternatives.
What's up with animations in libreoffice impress?)
Also, isn't switching to google contradicts with "let's avoid corporate slop such as bindows"?