Microsoft points finger at the EU for not being able to lock down Windows
neowin.net
neowin.net
It's already horrible with their 'recommendations' left and right, and preinstalled stuff that you cannot remove.
And then it just becomes too easy for Microsoft to let their Windows Defender run in kernel mode and 3rd parties can't do that, so obviously they can outperform them.
Kinda like iOS' Safari. Hell, that one runs in user mode, but it required laws for 3rd parties to be able to provide native alternatives.
An OS that is secure by design arguably needs no third-party malware protection, and therefore there's nothing to permit.
Truly one of the most brain-off takes I have ever had the misfortune of being privy to. "Hey, lets lock out one of the most basic computing primitives because the hardware form factor happens to be consistent with a telephony handset."
Seriously. People who think like this are the same people who are draining the life out of computing. Trying to turn it into little more than a top-down orchestrated, network-access trickling device, instead of what it should be, which is an emancipator of the physical limitations of the human brain; a bicycle for the mind.
You can't think of a single valid use-case? Really? Then it's a waste of time talking to you.
Honestly, any semblance of modern, secure system architecture would help as long as it's combined with a willingness to obsolete the bullshit that got us into this mess in the first place.
The problem is that malware has basically an infinite number of tries to get you to run something. As there is almost no consequence when they fail.
Why can't they apply this architecture to Windows?
Consent of the user to do what? If a program can't even ask permission to walk the entire filesystem, zip it up and encrypt it, then it simply can't do that at all. The user never even becomes a factor.
I'll reiterate that I'm not saying all malware goes away, but entire classes of malware would cease to exist.
> if you really require code to get permission for all resources they require customers will immediately look for ways to avoid having to manually do this step.
If you go in your pocket, you'll find a compelling case study to the contrary. For the most part, permission grants are a one-time thing for any given service. They don't even register as a mild nuisance.
> The problem is that malware has basically an infinite number of tries to get you to run something. As there is almost no consequence when they fail.
And what does AV software do to solve either of these problems?
The only model that has worked in practice is the model where malware is checked upstream (eg during App Store ingestion) and users are never even offered it.
But yes, in a corporate environment it might be prudent to have some kind of policy restricting users from installing applications from non-approved sources (or at least limiting what permissions such unapproved applications can have). Thankfully the permissions model of Android makes such restrictions trivial to enforce and minimally inconvenient compared to what you have to do to get an inferior version of the same thing on Windows.
Android is actually an outright majority of all malware in the wild... 50.31% of all malware infestions, which includes windows, OSX, IOT, and all other sources (ie ios).
https://vpnoverview.com/wp-content/uploads/nokia_threat_inte...
(see also page 17-19 which discusses key threats and mitigation strategies, particularly surrounding the play store and the android ecosystem.)
Pretty sure stalkerware is openly carried in the play store, it definitely is carried in some of the seedier stores.
If you have actual data that contradicts this, fire away, but every time it's objectively measured android comes out way way way worse on the malware front.
Secondly, the #1 and #2 "malware apps" in that report are parental control software, arguably not malware at all. Several more are ad click fraud related and have nearly zero security impact on the user on account of having no permissions other than internet access. I also didn't see any data in the report on how many of the handful of truly dangerous apps they listed were successful in getting the permissions needed to do any significant damage. Unlike with Windows, merely installing a malicious app on Android often isn't enough; that's the whole point of having a sandbox.
Thirdly, the "50.31%" figure you're quoting is, again, skewed by the fact that this data is coming from a company that specializes in mobile anti-virus software and they don't seem to be normalizing by number of devices NetGuard Endpoint Security is installed on. (Do they even have an iOS app? The report doesn't seem to include data from iOS.)
cough* NGO cough*
UAC didn't help, isn't it ?
If Microsoft would concentrate a bit on GUIs and UXs maybe they would be able to fix it. /s
That's IMO quite the defeatist attitude.
Is there any way around this? And if so, who can go that way?
In my opinion it's only Microsoft that can unilaterally improve the situation, not the least by letting the user make those decisions in the first place and also have him live with the consequences (loss of time / money).
They will learn, especially after experiencing pain due to a wrong decision.
A nanny OS that decides by itself won't make the user learn and it will always have loopholes.
I like my Macbook, but I prefer my Windows desktop so much more because it still largely feels like my system instead of Apple's/Microsoft's.
People. Stop asking Microsoft to lock down Windows.
Mostly due to Teams or Edge eating up all the memory, and the OS being unable to handle it gracefully.
So I find it pretty hard to take whatever Microsoft says as the last word on anti-malware, even on Windows, when it's at the same time the biggest purveyor of malware.
Why would Cloudstrike need a kernel driver on Windows, and not their other platforms? Microsoft is responsible for that design and not moving past it at the pace alternative systems have.
Additionally, there are other things Microsoft could have done. For example - if your computer fails to boot 3 times in a row, with a third party driver, how about automatically disabling the driver? If the driver manufacturer doesn’t like that, tell them to suck it up and write a driver that doesn’t crash.
You mean the same issues that Linux also faced?
That's not to say that there haven't been other Crowdstrike fails on Linux, especially pre-eBPF module, but that's not one, and that class of failures has been eliminated in the move to the eBPF based module.
I don't think computers got to that level of refinement. Yes, we have AI, but this is mostly used to spread propaganda. Last i looked, you cannot fix Linux or Windows without human intervention.
MS isn't testing either.
One of the problems with CrowdStrike was the update was a definition/config file that was pushed out by CrowdStrike. There was no driver update and the BSOD was caused by the existing driver failing to parse/load the new file pushed out. This means there was no last known good state to rollback to in terms of driver updates.
Granted I still agree that MS can hopefully improve things to avoid this problem in the future but this isn't a simple problem that the OS can guard from short of stopping 3rd party kernel drivers.
Windows should unload the misbehaving driver after a couple of failed boots.
Why does it have to be automatic?
The Open Source Operating Systems that are around have much tighter security than Windows, yet their openness hasn't hurt them.
Perhaps the problem is more with Microsoft than anything else?
ClownStrike Falcon is famously flaky software on macOS and Linux. That's no surprise to anyone.
If so, this feels like a red herring.
This has been the case at least since the late 90s if I remember correctly.
Some unscrupulous drivers will detect that they are being run by WHQL and disable various features so they pass certification. Of course, they also run dog slow in the WHQL lab, but that’s okay, because WHQL is interested in whether the driver contains any bugs, not whether the driver has the fastest triangle fill rate in the industry.
The most common cheat I’ve seen is drivers which check for a secret “Enable Dubious Optimizations” switch in the registry or some other place external to the driver itself. They take the driver and put it in an installer which does not turn the switch on and submit it to WHQL. When WHQL runs the driver through all its tests, the driver is running in “safe but slow” mode and passes certification with flying colors.
The vendor then takes that driver (now with the WHQL stamp of approval) and puts it inside an installer that enables the secret “Enable Dubious Optimizations” switch. Now the driver sees the switch enabled and performs all sorts of dubious optimizations, none of which were tested by WHQL.
Which actually happened in one of the Windows 11 preview releases.
It might not be Widgets next time - but there’s enough stupid in Windows that it could be anything from SmartScreen to Defender to Copilot to Edge. It could also be just something widespread and stupid, like Intel or NVIDIA’s driver analytics imploding.
https://www.neowin.net/news/how-an-ad-from-microsoft-broke-t...
I also don't know if Microsoft's security software can rollback from bad definition updates.
I can't see why this wouldn't work. A should be in B's stack trace, outside of esoteric interactions.
The rollback didn't work for the Crowdstrike problem because despite being a ".sys" file, the file that was updated wasn't a driver.
Does that include "boot-start" drivers?
> A boot-start driver is a driver for a device that must be installed to start the Microsoft Windows operating system.
* https://learn.microsoft.com/en-us/windows-hardware/drivers/i...
CS designated their software as one, and when it crashed so did the whole OS to the point that the rollback process doesn't seem to be able to kick-off.
I'm not sure... I don't actually know what driver it was that failed; although I suspect it was a video driver. Computer made some noises, blue screened, restarted, repeat N times, then came up, and after login said something about a bad update and may have told me which device, but I forgot. I was across the room for most of it.
Which means, if Microsoft had made a more carefully scoped way of extending the kernel, or even avoided extending the kernel at all for their own security products, they would have perfectly been at liberty to demand it for everyone else.
Isn't a headline that will ever exist, therefore they'll point fingers at any entity (EU being the most recent) that's making them do things they don't want to do in order to further an unrelated agenda.
Let no catastrophe go unexploited, as they say.
And made APIs available specifically for user-space EDR: https://developer.apple.com/documentation/endpointsecurity
This decision means security software vendors have a greater ability to muck up systems as CrowdStrike did this week when it crippled 8.5 million Windows PCs worldwide.
...and what about when Microsoft inevitably screws something up with its automatic updates and undoubtedly affects even more machines? They already have, multiple times. One of the most recent memorable occurrences: https://news.ycombinator.com/item?id=18189139
As the old saying goes, "Those who give up freedom for security deserve neither."
Why Microsoft should have more access then others ? Becouse Crowdstrike / public internet straight to kernel updates combo ?
Whole thing is about locking _computers_ from buyers and that is a no go. We need more os'es and more freedom - just fact of MS existence (domination) is a proof that hardware-os monopoly owned by one company is not some natural law.
Now let's make IBM unlock their hardware-os monopoly to software vendors :)
As an aside, it is sickening that so many simple displays and dedicated devices with simple UIs that could be implemented as static scenarios using proper capability-based multiserver architectures (such as the leading seL4 / LionsOS) do instead use complicated software stacks based on Linux (and sometimes even worse, Windows).
This has been a thing since the 90s, maybe longer. I remember walking through Caesars Palace (Las Vegas, NV) circa 1999 and seeing a BSOD on several of their screens. People will always make expedient choices as long as it works well enough most of the time.
I guess even M/S has a hard time with reading comprehension. "make available" does not mean "no lock down". So does that mean when someone boots windows into Safe Mode, they are breaking the law in the EU ? I do not think so.