Auditing every data file update seems just as error/system failure prone as Crowdstrike's process was. I don't see a clear reason why Microsoft would have any better incentive than Crowdstrike here.
I do think that maybe the commercial OS vendor has _some_ support responsibilities to at least warn and discourage customers from using the product in dangerous ways? I mean, it's not like we're talking about a couple people installing bad kernel drivers here, we're talking about a worldwide incident. WHQL seems like an admission that Microsoft knows they need to keep dangerous drivers out of the ecosystem.
Nearly all banks have long long lists of certification, they still have extremely bad customer-side security processes because you can "interpret" various guidanecs and pay the right auditors enough to have it ignored.
That leaves you either not responding quickly or responding with uncertified updates. In the past, we have examples of not responding quickly that took down large chunks of the internet (I don't remember the examples, but they were quite famous at the time). Now we have an example of a fast, uncertified update taking down a large chunk of the internet.
So, given that it can take down much of the internet no matter which we choose, now what do we do?
What can we do?
Require them to have documented processes, and require periodic (like every 6 months) third-party auditing that they have the right processes, and they are complying with their own processes.
More info: https://en.wikipedia.org/wiki/System_and_Organization_Contro...