"Windows eats all my hard disk!! I've updated to <windows xy>/Windows did an update and now all my disk space is gone!!! Don't update!!!!"
"New MS update steals your disk space, here's how to stop it"
And so on, and so on.
I have seen otherwise smart, famous people flip out in public when they learn that Windows has a built in window recorder. Same folks have no concerns with their video drivers doing the exact same thing.
That said, I think the only really safe way to do this is a history chain that lives off-site. That means copies to azure, and even with great crypto and blocklists, that's not going to fly in the news.
Microsoft has some interesting new security features on its roadmap. Unfortunately, 90% of them are for enterprise users-only and some only for its own applications.
It also wouldn't hurt to overhaul/replace UAC with something better, but I imagine that would require deeper architectural changes (which I think would be worth the pain).
Microsoft should also push users towards creating a Standard account when installing Windows, and setting up an Admin password, too. It shouldn't be too difficult/disruptive. They just need to create an easy process for it at installation.
The vast majority of Windows malware infections happen because users are also Admins. This alone would give Windows a huge security boost on average.
https://www.avecto.com/news-and-events/news/94-of-critical-m...
Once they do this, they could also start encrypting Windows devices by default with the Admin key, similar to how Android does default encryption.
Windows is pretty much the last major operating system not to encrypt by default. Hopefully, if they do this, they at least give users the option to keep the key locally, and not automatically upload it to Microsoft's servers, as they do now if you login to your Microsoft account.
Go to macOS user forums and you will see lots of discussions about how to turn off Gatekeeper or be "always root" user.
If the malware gets privileged access, it's game over. If it can't, good file system permissioning fixes the problem.
Whereas with drives you don't have access to the file if it's not mounted, you have to know on which drive the file you're looking for is, go through the mounting process, then actually find the file. And if you want to alter the file you have to remount the entire thing, and possibly need to track down that one daemon which still has a handle open and prevents you from unmounting it.
Just use e.g. ZFS and configure it to take regular snapshots (though you may want to be careful, a few years back if a zpool got completely full things got wonky, dunno if they've fixed it, so you may want to keep some disk space outside the zpool just in case, so you can expand the zpool enough to work if it gets completely full)
I have the server at work, which only has windows desktop clients, making 1-minute snapshots with a one-day lifetime in addition to daily, weekly, monthly etc. It's very handy for the occasions where you accidentally save over a document and slap yourself in the head immediately afterwards.
Can you explain the thawing procedure, and how a normal everday user would experience it?
Seems like the classic tradeoff between better security and better UX.
Users would complain, and/or try to disable it.