Microsoft Sandboxes Windows Defender
bleepingcomputer.com
bleepingcomputer.com
https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
That specific bug and others were of course fixed.
The issue is that such complex code is hard to write well in the language they're using, and running as SYSTEM is just asking for a zero day take over from simply visiting a site with a malicious file or an unread email.
I hope other AV vendors follow suit on the component sandboxing. They're scanning untrusted files, who will happily try to crash or take-over the AV process itself.
I am not trying to get them sweet sweet up-votes. Just engage in my community.
I have to say that the latter says to me: "Go to sleep," but the first says "Hey this is interesting". Plus, the article in the first has pictures. The headline is punchier too:
* "Microsoft Sandboxes Windows Defender" (bleepingcomputer.com)
* "Windows Defender Antivirus can now run in a sandbox" (cloudblogs.microsoft.com)
Here's one approach.
https://blog.trailofbits.com/2017/08/02/microsoft-didnt-sand...
Notice how the child process is running with an "AppContainer" integrity level.
I know the reasoning is "if SYSTEM can kill it then so can malware", but still a bit unsettling that there's processes running on your system that even the owner doesn't have privilege to control.
IMHO, it's wrong to say that TrustedInstaller and WinDefend have "higher privileges" to SYSTEM as that is only true for specific files/executables and in most of those cases SYSTEM can take direct control even without impersonating them.
Welcome to Windows 10 Home Edition!
It's like Android, but you pay. Worst of both worlds.
(it's especially bad when something creates a lot of small files, because Service Executable starts scanning them, and whitelisting processes doesn't seem to do much to deter it)
"Users can also force the sandboxing implementation to be enabled by setting a machine-wide environment variable (setx /M MP_FORCE_USE_SANDBOX 1) and restarting the machine. This is currently supported on Windows 10, version 1703 or later."
I take a handful of basic precautions along the lines of closing ports, installing OS updates, having my eMail text only and passive, disabling a few things on the web browser and never downloading/running anything suspicious. It's been good enough that the last time I installed a new Win, a dedicated antivirus didn't even occur to me.
On occasion I'll run a malware finder when I'm seeing odd behaviour and want to be sure, but I can't remember the last time there was a genuine positive find.
I believe I ran some Symantec search tool once when things seemed off and was able to install a targeted removal tool by them and remove them afterward.
Same principles with my macs.
Any Linux machine I use tends to be virtual and pretty blackboxed save web, ssh, and ssl ports. (And maybe a port open connected to a database)
There have been stories that other vendors are even worse but it doesn't matter, they should've updated Defender 12 years ago concurrently with IE as they were developing the tech for Vista, because.. Defender has high false negative detection ratio and so is a plan B, hail marry kind of technology - you should do everything so that you don't rely on it working as it works only passably well for a percentage of stale threats. That's why if it and similar software is enabled it should affect your security only additively and should never contribute to attack surface. Instead in an effort to check if a file contains any of months old malware you get pwned by a bug in decompression function for a file that that you didn't even open that just passed your system and so you'd survive the attack if it weren't for the system that tries to help you survive attacks stupidly.
How was that determined xD.... wtf. There have been trivial sandbox escapes for most sandboxes in existence...
stopped reading there >.> pure speculation on how effective this thing will really be in the first paragraph, casts doubt on the accuracy of the rest of the information.
I for one haven't trusted Windows Defender in a while, both because I don't trust Microsoft not to be malicious with it (at the very least they've steadily increased the amount and types of telemetry they collect through it) and also because it's such an easy target for all sorts of attackers.