Microsoft suspends dev accounts for high-profile open source projects
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户已经提供了文章内容,我得先仔细阅读并理解主要内容。 文章主要讲的是微软暂停了一些开发者的账户,这些开发者维护着多个知名的开源项目,比如WireGuard、VeraCrypt等。开发者们没有收到任何通知,也无法快速恢复账户,导致他们无法发布新的软件构建和安全补丁。微软后来解释说是因为这些账户没有完成强制的验证流程,但开发者们表示他们没有收到相关通知。 接下来,我需要将这些信息浓缩到100字以内。重点包括:微软暂停账户、影响的项目、开发者未收到通知、微软的解释以及后续的回应。 可能会遇到的问题是如何简洁地表达所有关键点而不遗漏重要信息。比如,提到多个项目和开发者的困境,同时说明微软的解释和后续措施。 最后,确保语言简洁明了,符合用户的要求。 </think> Microsoft暂停了多个知名开源项目开发者的账户,导致其无法为Windows用户发布新软件和安全补丁。受影响项目包括WireGuard、VeraCrypt等。开发者未收到任何通知或解释,并无法联系到微软支持。微软称因未完成账户验证流程而自动暂停账户,但开发者表示未收到相关提醒。 2026-4-9 07:0:26 Author: www.bleepingcomputer.com(查看原文) 阅读量:5 收藏

Microsoft

Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users.

The list of affected projects includes, but is not limited to, Virtual Private Network (VPN) software WireGuard, on-the-fly encryption (OTFE) utility VeraCrypt, the MemTest86 Random Access Memory (RAM) testing and diagnosis tool, and the Windscribe VPN software.

"Microsoft terminated the account I have used for years to sign Windows drivers and the bootloader. [..] Microsoft did not send me any emails or prior warnings. I have received no explanation for the termination and their message indicates that no appeal is possible," VeraCrypt developer Mounir Idrassi said last week.

Wiz

"I have tried to contact Microsoft through various channels but I have only received automated replies and bots. I was unable to reach a human. [..] I cannot publish Windows updates. Linux and macOS updates can still be done but Windows is the platform used by the majority of users and so the inability to deliver Windows releases is a major blow to the project."

The same experience was shared by developers behind other widely used projects, including WireGuard maintainer Jason A. Donenfeld and the dev teams for Windscribe and MemTest86, all of whom said they've been trying to contact a human at Microsoft Support for weeks without success.

"No warning at all, no notification. One day I sign in to publish an update, and yikes, account suspended. Currently undergoing some sort of 60 days appeals process, but who knows," Donenfeld said. "That's kind of crazy: what if there were some critical RCE in WireGuard, being exploited in the wild, and I needed to update users immediately?"

Microsoft account suspension message
Microsoft account suspension message (Jason A. Donenfeld)

​However, after TechCrunch reported on the issue on Wednesday, Microsoft Vice President Scott Hanselman said the developer accounts were automatically suspended because they failed the "mandatory account verification for all partners in the Windows Hardware Program who have not completed account verification since April 2024" that the company had been emailing "everyone" about since October 2025.

As explained in a Hardware Dev Center article published on October 1, the account verification process began on October 16 and would trigger an automatic suspension from the Windows Hardware Program if partners failed to complete it within 30 days.

"Account verification for the Windows Hardware Program has now concluded," Microsoft said in a March 30 update. "Accounts that did not successfully complete account verification and received a Rejected verification status have been suspended from the Windows Hardware Program, and submissions from these accounts are no longer permitted."

While BleepingComputer has yet to receive a reply after reaching out to a Microsoft spokesperson for more details, Hanselman said that the issue will be addressed "in a bit" but didn't share why the project maintainers weren't notified of the suspension.

This was confirmed by IdrassiWindscribe, and Pavan Davuluri (Microsoft EVP for Windows and Devices), with Idrassi saying that Hanselman reached out to help reinstate the suspended Partner Center account and adding that "social media postings and interview with journalists helped trigger a response from Microsoft."

"We worked hard to make sure partners understood this was coming, from emails, banners, reminders," Davuluri also noted. "And we know that sometimes things still get missed. We're taking this as an opportunity to review how we communicate changes like this and make sure we're doing it better."

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/microsoft/microsoft-suspends-dev-accounts-for-high-profile-open-source-projects/
如有侵权请联系:admin#unsafe.sh