Such as say in 20 years when you want to be able to run custom code in a then old console.
Such as say in 20 years when you want to be able to run custom code in a then old console.
Citation needed. Log4j comes to mind as a logic bug disaster, but all the data I've seen is that >65% of the high severity bugs come from memory unsafety in most software projects.
https://security.googleblog.com/2022/12/memory-safe-language... https://alexgaynor.net/2020/may/27/science-on-memory-unsafet...
Microsoft is so confident in their security model that they openly explained how it works: https://www.youtube.com/watch?v=U7VwtOrwceo
All of this will become e-waste without the ability to run unsigned code. And not only, by allowing custom code, which some do not allow, the usefulness or even purpose of the device can be extended or altered.
I dont' want to throw away a perfectly usable device just because the company made it obsolete.
Check "Windows 11 Security", "App Isolation", "Sandbox", "Standard User", "Pluton".
Or skim the presentation slides,
https://github.com/dwizzzle/Presentations/blob/master/David%...
To name just a few examples: they want all code to be signed but Windows code signing certs are more expensive than the Apple developer programme membership, much harder to obtain, the rules actually make it "impossible" in some cases like if your country issues ID cards without an address on them, they're now forcing mandatory HSMs and if your CA decides to change your subject name you're just SOL because only Windows 11 anticipates that problem but Microsoft can't be bothered maintaining Windows 10 anymore so their solution was never backported. Yet, the Windows 11 security hardware requirements mean many people won't upgrade.
So whilst building a theoretical strategy around sandboxing apps, they aren't even able to get the basics right. If the people making these decisions were actually writing Windows apps themselves, they might realize this and Microsoft would be able to get its teams marching in the same direction but there's not much sign of that from the outside.
Compare to how Apple does it: they run their own code signing CA, assign stable arbitrary identifiers to companies and people, and still manage to sell these certs for less than a Windows certificate whilst also throwing a couple of support incidents into the mix too, something you can't even get from Microsoft at all as far as I can see (and I've tried!).
By the way, some of this stuff is already on Window 11 Previews and can be enabled.
Even if they botch this, like it happened to UWP, the alternative will be moving everything to Azure OS with thin clients, so one way or the other, it will happen.
The issue is that a lot of their security strategy is inherited from UWP. So it's already botched.
[1] - https://learn.microsoft.com/en-us/windows/package-manager/wi...
That doesn't mean we should just ignore security elsewhere. Many users know not to trust mysterious executables from the internet, but don't expect a PDF or font file to be able to infect their machine.
I think being able to trust that non-executable files like these won't compromise your system could be a big deal.