Microsoft’s out-of-date driver list left Windows PCs open to malware attacks
theverge.com
theverge.com
They really need to get themselves together on the Windows front. Actually all fronts. Even Office is a fucking shit show these days and that was the last bastion of common sense on the platform.
As a former MS dev dating all the way back to the early 1990s, I don't own or work with their platforms as of 2021. My pain threshold isn't high enough. I implore the shareholders to kick the entire board out and install some people with good intentions and clue sticks.
Until then I will be doing my absolute best to steer everyone I know away from the pain.
Another reason to make sure you have automated backups, I guess.
I have no idea how a company like Microsoft releases such a turd to the world. And supposedly they're focused on "The Cloud"(tm) now, not Windows. So it should be in a better state than Windows.
When it comes to Windows, I love the overall kernel design. But when it comes to using the system, it seems to really lack polish. The myriad of little dysfunctional details (mostly in things which were added after Windows 7) just kills my ability to work with the system without getting angry at it.
I sincerely doubt anyone at Microsoft ever tests all those drivers that are shipped with Windows and the automatic driver loading service in Windows Update.
https://arstechnica.com/information-technology/2022/10/how-a...
Raymond Chen has largely pointed out the position of Microsoft that if you authorize code to run with elevated permissions and it does things it can do with elevated permissions, it's not really a security flaw.
1. There has been a precedent in Windows to run everything as local administrator. Linux has always had the user vs. root paradigm, but Windows - at least in the client versions - has always just defaulted to administrative accounts.
2. Features designed to provide more fine-grained control of token privileges, such as UAC, process integrity, and virtualization, have been excluded from security bug bounties as being "not a real security boundary". This stance is somewhat counterintuitive and quite dangerous.
Combine those two with the fact that Microsoft never provided sane secure defaults for any of their software; it just goes to show that Microsoft is not concerned nor bothered with securing their software.
That shifts the issue of "don't run as admin, stupid" responsibility from the user to Microsoft to a large extent.
Yeah it's bad Microsoft built a feature to try to help you in this scenario and it wasn't working, but it's also just one of many many ways to screw you at this point.