Microsoft Blames European Commission for Major Worldwide Outage
macrumors.com
macrumors.com
A Microsoft spokesman said it cannot legally wall off its operating system in the same way Apple does because of an understanding it reached with the European Commission following a complaint. In 2009, Microsoft agreed it would give makers of security software the same level of access to Windows that Microsoft gets.
Isn't that XProtect?
Fixing one’s kernel extensions does not violate anticompetitive laws. It does however make for click bait headlines if you as a corp choose to troll everyone affected by CrowdStrike instead of offering mitigations.
I think people don't know that Microsoft also has a Crowdstrike Falcon competitor that isn't too bad at all. While it would be funny to call out the hypocrisy in the tech world, I think the DoJ would indeed sue Microsoft unless it extracted it's own EDR and had it use the same API's it is asking other companies to use. Furthermore, there is something called the anti-malware scanner interface (AMSI) which Falcon and other EDRs indeed use and there is an ETW api that allows them to do additional monitoring as well. But that just isn't enough to counter many real world threats. In effect, the EDR must be like a rootkit to get complete system visibility and be able to stop any and all threats, kernel or userspace. Also, a user space process can prevent booting or freeze systems up.
Which one? Defender isn't a CS competitor.
I _think_ at least, the enterprise software space is confusing as hell :)
You are responding to a statement from Microsoft that compares its own behavior to that of Apple. Why do you characterize it as everyone else thinking Microsoft should be more like Apple?
> Apple has not been forced to make changes to how Macs work, but the European Commission has been targeting the closed nature of iOS, and Apple has warned that the updates that have already been implemented could lead to security risks in the future.
This is a valid and interesting comparison - Microsoft complied and Apple fought tooth and nail.
But also, it's kind of a moot point because absolutely no one is running Apple hardware at a flight kiosk.
If MS is really not allowed to protect their kernel, that part of whatever EU understanding they have should probably be revisited. I’m not sure it’s gonna hamper things legally too much to let MS, and everyone else for that matter, Apple, Linux, Android, whoever, erect defensive walls around their own kernels. This is just security 101 for devices these days, and it doesn’t stop anyone else from participating in the windows, android, apple ecosystem.
Those would have access of course, and hence have an extreme competitive advantage relative to other products. Even more than they do now.
Kiss any non-Microsoft antivirus or security software goodbye.
Not just that, but that would break backwards compatibility with a lot of niche but important apps, since Windows was very popular with use cases where companies have developed kernel space drivers for their Windows products. Yanking that away for security with break backwards compatibility.
It’s already a major performance impact, throwing it into user space would kill those products entirely.
But misguided, as usual when someone defends Microsoft.
> If MS is really not allowed to protect their kernel, that part of whatever EU understanding they have should probably be revisited
They are allowed to protect “their kernel”. (And / or everything else, which AFAIK is what anti-virus software is supposed to do.) It's just that they're only allowed to do it the same way they allow everyone else to do the same thing.
So, being the lazy arseholes they are, they let everyone else into the kernel like they do it, in stead of doing what they should have done: Do it from userspace like anti-virus software used to work, or build a secure API that lets software protect the kernel without being able to take it down / prevent it from booting up — and use that API themselves, in their own separate anti-virus product.
Then that product would have been on an even footing in the marketplace with its competitors, which is what the agreement with the EU sought to achieve.
But Microsoft cheaped out and took the easier, cheaper — and riskier! — route. This debacle is as much on them as on Crowdstrike.
Also, let’s not forget why these restrictions are applied in the first place - they kick in when the corp grows to become a gatekeeper, integrating multiple product categories and the expense of users and 3rd party vendors.
They are offering "safe" access, it's called userspace.
If anything, the Crowdstrike incident highlights the lack of diversity in the OS/security space.
Everyone using the same stack makes everyone vulnerable to the same bugs.
Obviously, it seems ludicrous to implement spell-checking in the kernel. Imagine if MS imposed the discipline upon themselves to provide enough API that their own security products didn't reach for the kernel crutch.
Linux is different because it is open source. If a vendor wants to reach into the kernel, it's completely possible. If they want to provide patches to the kernel that allow their or any other product to do what it needs outside the kernel, they can. But even if the kernel provided all the necessary APIs, vendors could ignore those and insist on being inside the kernel. It is up to the user to use wisdom about what they install. And there is no unfair advantage to the OS vendor competing with third-party apps.
It is silly to blame regulators instead of the app vendor in this case. I'm not sure why MS feels the need to deflect blame. I know that some are eager to point the finger at MS, but MS shouldn't be so defensive. It makes it look like they think there is some merit to those arguments that has to be deflected.
Everyone is editorializing. Microsoft never actually blamed the EU. They just were explaining why their kernel was open to third parties in the first place.
And they were of course mostly unaffected by the Cloudstrike outage.
Either way, I think it’s a strong point for Apple that antivirus is not required because the iOS security model protects against viruses pretty thoroughly. That’s just not the case for Windows most of the time. Also, do tech companies run antivirus on their linux-based containerized cloud workflows? Not really, the security model doesn’t require it. Points against windows server here
Apple pretends they don't need antivirus the same way some Linux advocates will, but viruses exist on both platforms. Very few companies run their digital signage or internal application databases on macOS hosts, mostly because Apple stepped out of that market years ago.
Whenever Apple or Linux are deployed at the scale these CrowdStrike desktops are, you can assume similar software is deployed on any platform. This time it was a kernel crash, next time it could be MDM software locking all iPads out of all network access, or null routing all I/O requests in eBPF.
Sure. But when was the last time a company was in the news when they were hit with macOS-, iOS-, or Linux-based ransomware?
I'm in IT, but Windows was never my thing/niche. Generally I've viewed two problems with it:
1. when it becomes a monoculture where basically everything in the company runs on it
2. something about its architecture/designs appears (to me, at least) for very easy spreading of malware (does it have some weaker SSH-equivalent that allows easy remote control?)
Just ask Maersk about these two points:
* https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...
What about Linux though?
Feels like this is just MS redirecting blame and using it as an opportunity to push the narrative that walled garden = good.
https://www.theregister.com/2024/07/21/crowdstrike_linux_cra...
> mirashii 16 hours ago
The primary one linked there is certainly not the same issue, it was a bug in the Linux kernel's ebpf handling. It happened to be triggered by Crowdstrike, but the bug is undeniably a Linux kernel bug which was subsequently patched, as ebpf programs should never be able to panic the kernel.
That's not to say that there haven't been other Crowdstrike fails on Linux, especially pre-eBPF module, but that's not one, and that class of failures has been eliminated in the move to the eBPF based module.
Microsoft could create a similar safe Windows kernel API if they wanted.
[77384.469522] Modules linked in: falcon_lsm_serviceable(PE) falcon_nf_netcontain(PE) falcon_kal(E) falcon_lsm_pinned_16303(E)True, but they did break Linux a few months back in much the same way they just broke Windows last Friday:
CrowdStrike broke Debian and Rocky Linux months ago, but no one noticed
https://www.neowin.net/news/crowdstrike-broke-debian-and-roc...
But since that break didn't ground a good percentage of global air traffic, it didn't get the same press coverage as this most recent breakage.
They can wreak all kinds of havoc with bad eBPF programs, but so far they haven't as far as I know.
At some level, we would have to accept that if we’re giving people, many of them hackers, access to kernel level facilities, there is a risk involved. If you want no risk, use a walled off OS. If you want a more flexible or permissive kernel architecture, then accept that the burden of securing it is kind of on you after a point.
Put in layman’s terms, I can put that riving knife on your table saw, but there’s still a risk to using it. It’s just a risky tool.
Guys, eBPF provides more limited access to kernel features. That’s by design. Whatever the platform, the idea with eBPF is to limit kernel access and provide safe access only where ‘necessary’.
The entire issue is that MS limited access to their kernel. If you want the people who use eBPF, windows developers, to have the same access to kernel features as the providers of eBPF facilities, MS themselves, then you’re effectively giving them kernel access.
There is no such thing as safe full featured kernel access.
I do have problems with MS or any other vendor using kernel access unnecessarily. MS Paint should not run in the kernel. Just because you can doesn't mean you should.
The question is whether MS or any other vendor could provide the feature set their product enjoys without running in the kernel. If Windows offered anything like eBPF but MS security apps chose to run in-kernel instead of through eBPF, then MS should be forced to give competitors the same kernel access. If MS would play fair and restrict their non-OS teams to userspace they wouldn't have to play fair by providing access to kernelspace.
The argument is that it is impossible for MS non-OS teams to play in userspace because MS doesn't provide the APIs to make it possible. It seems that some other OSes might not suffer from this deficiency.
Are they (e.g., MS) shipping VMs in their cloud (e.g., Azure) with CrowdStrike pre-installed? In which case I think people have a right to be upset with MS, as they've chosen an apparently poor quality vendor, and the EU argument seems like a complete distraction.
Or is the market of "audit checkbox checking security software" just such a monoculture that nigh every Windows VM out there was running this thing, but that it was installed by the owners of the VM (i.e., not by the cloud vendor), and now we see what happens when unfettered updates hit a monoculture? In which case, … I don't see how MS is to blame here; seems like you, the buyer of CrowdStrike, chose poorly. (And the EU thing is even more of a distraction.) (And I guess the cloud status page updates are just out of the goodness of the cloud vendors' hearts, or we don't think Windows sysadmins are competent enough to not blame their cloud, or both.)
https://news.ycombinator.com/item?id=41029590
Microsoft points finger at the EU for not being able to lock down Windows
More discussion: https://news.ycombinator.com/item?id=41029590
UAC, virtualization, hybrid kernel/user-space shenanigans, all were not in the OS at some point, and research and development, listening to other parties and taking inspiration from other OSes brought these advancements in security.
If Microsoft thinks offering kernel drivers for security (antivirus or otherwise) is a bad thing for the 3rd party companies, then by extension it is bad for any antiviral product they offer and they should absolutely find a new paradigm to securely implement them (eBPF like as some other folks suggested).
But saying "but apple does it !" is not a reasonable demande when your software runs respirators and nuclear facilities. (Apple are still cunts for having everything locked down but that's another conversation)