NT 3.5 had the GUI entirely outside the kernel. For compatibility with Windows 95, much of the Windows 95 GUI code was moved into the kernel. 20 years later, that decision is still causing bugs.
NT 3.5 had the GUI entirely outside the kernel. For compatibility with Windows 95, much of the Windows 95 GUI code was moved into the kernel. 20 years later, that decision is still causing bugs.
Also, it could be argued that vulnerabilities like these which are only locally exploitable are not all that scary, as a personal computer should be by definition one that obeys its user no matter what. It's a bug, but not a "someone can take over your computer without you doing anything". Maybe it's because I grew up with personal computers that practically invited you to do whatever you want with them and had absolutely no "protection" whatsoever (early 8-bit machines, then DOS on a PC) that I find it hard to get scared or excited by local-only exploits like these.
But this is basically orthogonal to the modern application of (OS-level) privilege boundaries, which is to protect the user from compromised application processes. This escalation doesn't let someone "take over your computer without you doing anything" by itself, but once someone has exploited an IE bug and found themselves able to run arbitrary code on users' computers in a sandbox - which happens all the time - that's exactly what it allows.
I'm not that familliar with Docker but looking at http://en.wikipedia.org/wiki/Docker_%28software%29 it is built on the same resource isolation features as LXC which I am using on two of my test systems.
The resource isolation features are, in fact, built on top of a large multi-user system, which happens to have powerful security context support and abstractions built in. The contained applications operate, from a userspace perspective, as if they are their own system when in reality their kernel is actually the host kernel and their users really virtually re-mapped to distinct accounts within the host kernel.
It's the internet age, now. Local-only really isn't any more.
Part of the reason it's so easy to infect technically illiterate crowd nowadays is that they didn't develop an immunity system - something us who grew up with computers take almost for granted. It doesn't really take that much to become almost completely immune to malware - 90% of it is simple to spot (don't download things from CNET or any other site that has lots of ads, and especially those that try to trick you into clicking them; don't open .exe's you didn't explicitly requested; know what's an .exe; don't open attachments you didn't expect; etc.) - but somehow the society at large doesn't bother. And yet they expect someone else to fix it for them. As the saying goes, "Any fool can use a computer. Many do.".
I understand how we got there. I don't like it, but well, Moloch does what he wants. The thing to remember is, the increased sterility of the ecosystem and all those things done "for Security!" come at the cost of the ability of general-purpose computation. Future systems will tend to be dumbed down to the point they're not general-purpose computers anymore.
I wish, I hope, they'll let us keep PCs as specialized machines, like lathes and mills.
You're spot on that most people don't bother learning these things anymore, and particularly in the tablet ecosystem where apps are expected to be doctored for them as they come from a trusted source.
Security is fundamentally broken - there is a lot of innovation that needs to happen to make our computers more secure. There are a lot of non mainstream systems that have better security, we need to move their practices/architecture into the mainstream.
Hell, when you see things like quantum insert - how can any user be expected to keep their machine secure.
For all these years, I never clearly understood just what was meant by open an attachment. I don't have a clear description, definition, or explanation. Help! [No joke]
Background.
In about 1995, I was using some OS/2 e-mail program that wanted to put an icon somewhere for each e-mail message, screamed bloody murder at all those absurd icons until my throat was sore, got out the e-mail RFCs, and in about an hour used the TCP/IP interface of the scripting language Rexx to write my own POP3 e-mail software. Did all the e-mail reading and writing in just my favorite text editor, KEdit. The pair worked great -- used them for years.
Then, sure, just as in the e-mail RFCs, especially about multi-media internet mail extensions (MIME) or some such, there were attachments. So, again in Rexx, I wrote the basic base 64 en/decode software to handle attachments.
So, of course, I could receive a virus via e-mail totally safely -- to me, an attachment was just some simple ASCII characters to be interpreted as the base 64 encoding of something, maybe a JPG file. No harm in receiving the ASCII characters -- they look like just gibberish of simple typing by a very busy kitty cat walking on a keyboard, no harm in that -- or the base 64 code or translating that base 64 code to bytes and storing the bytes in a disk file. A file is just a sequence of bytes, any bytes at all -- harmless. Simple. Save.
So, if an attachment claimed that it was a JPG, then I might give the corresponding file from translation from base 64 to some graphic software to display the JPG. If in fact the attachment was an EXE to do harm to my computer data, etc., then I would trust the graphics program to notice that the attachment was not a JPG -- should be easy enough for the graphics program to tell.
Then I moved to Windows XP and then SP3 and Outlook 2003, and I'm still there and see little or no reason to change but just want to get on with my real work where XP SP3 is fine.
So, Outlook has attachments. Still, I never knew just what the heck was meant by open an attachment. So, if an attachment, say, in some MIME e-mail header line or some such, claims that it is a JPG file, then maybe give the attachment, translated from base 64, to some graphics program and trust that the graphics program will (1) display a real JPG without harm or (2) give an error message at anything else. Similarly for PNG, GIF, BMP, HTML, CSS, JS, etc.
For an EXE, of course, certainly, no way would Windows let the thing try to execute as software, right? I mean, not a chance, true? Or, the old, rock solid, first rule of computer security was to never, but never permit data from an untrusted source to execute as software, right? Handle such data just as bytes, sure, okay, safe, etc., but just no way ever let it execute as software, and that should be okay, right?
So, what does open do that is not safe?
No joke: In all these years, I've heard about e-mail and open an attachment and still have no clear description, definition, or explanation that would say just what open does or why it's dangerous.
As far as I can tell, the people, maybe who wrote Outlook 2003, who talked about doing an open on an e-mail attachment never really made at all clear just what the heck they were talking about.
Since many people still are afraid of open, where I see little chance of harm, maybe others would like some clarity, too.
Help! [no joke].
Attachments, be it EXEs or DOCs or whatever, exist as bytes in memory but don't (at least, they shouldn't) get processed - that is, opened - until you explicitly ask to.
So, JPEGs get handled by the JPEG shell handler. DOCs get handled by the DOC shell handler.
And unfortunately EXEs get handled by the EXE shell handler. This breaks the rule that you stated, that you should never ever permit data from an untrusted source to execute. This is where the problem lies!
As far as "open" means, it is a piece of terminology to explain the concept of saving data to a temporary store and then passing that file reference to the shell, which typically for most programs gets passed as a parameter to that file-type-handling program. Explorer > Tools > Folder Options will list file types in there and you can see how different types are handled, and the parameters passed to programs.
Of course, the base64 encoding, temporary file saving, shell passing is a bit more complex to explain to someone than using the expression "open", hence why people just say "open the attachment".
It's a terminology thing.
https://news.ycombinator.com/item?id=9050436
about
http://www.nytimes.com/2015/02/15/world/bank-hackers-steal-m...
in that NYT piece on hacking banks in Russia there is:
"In many ways, this hack began like any other. The cybercriminals sent their victims infected emails — a news clip or message that appeared to come from a colleague — as bait. When the bank employees clicked on the email, they inadvertently downloaded malicious code. That allowed the hackers to crawl across a bank’s network until they found employees who administered the cash transfer systems or remotely connected A.T.M.s."
So, to get infected all they had to do was just click "on the email"? Not even click on an attachment! That must be some strange, dangerous e-mail software!
In the 8-bit world, if you don't have a hard drive, and your only "network" is trading floppies with your friends, and "Elk Cloner"[1] is the nastiest virus you have to worry about, then there isn't much reason to be scared.
Nowadays, though...if you consider inserting an infected USB stick to be a local-only attack vector, then Stuxnet was local-only.
That didn't seem to be the case to me? It seemed to be a privilege escalation bug.
EDIT: I'm stupid. Some other user talked about physical access bugs, so confused that with locally exploitable.
Meaning instead of doing things with your user account, they can instead hijack your whole system. A keylogger on windows, for instance, does not need ring0 to function. The difference isn't really that large on a personal single-user windows setup. You're pretty screwed even if they don't manage to get ring0.
If we are talking about a corporate user, then it means a lot more.
I think MS is eternally hamstrung by performance and legacy issues because those two things are in demand for so many of their customers. Windows fits this market, which is fairly sizeable. Of course now with hardware at the speed its at, you can get a lot more slack. I've found the linux desktop to be horribly slow until the past couple of years where there's a glut of CPU/GPU performance on even the most commodity equipment. I can run, and have run, Win7 on equipment that shipped with XP and its been a fairly pleasant experience. Running, say, a gnome or KDE WM on that equipment is a nightmare. MS, for all its faults, is fairly conservative in many regards, especially performance.
At the end of the day this is yet another security issue that needs to be patched. The larger issue in my mind isn't MS decisions from 15 years ago, but why so much of our software infrastructure is being written in languages that more or less beg for stack/malloc vulnerabilities. These constant tirades about MS are just more "the beatings will continue until morale improves" and not really a constructive conversation about security. I think in the near future we'll be looking at all our stuff written in Rust-like languages and wonder why the hell it took so long to do.
Lastly, Win10 is a technical preview. Finding bugs is exactly what should be going on here. Are we really being this critical on pre-release software? I don't see any other software held up to such a standard.
FTA: "We have verified this exploit against all supported Windows desktop versions, including Windows 10 Technical Preview."
The specific "Windows 10" aspect is click-bait; the exploit is for Windows
and for a windows system, it needs to support a range of hardware configurations...Some could be really slow...
[1] https://en.wikipedia.org/wiki/NTFSDOS [2] https://web.archive.org/web/20000126093942/http://sysinterna...
This sounds nonsensical, like folk history. You can already create a boot disk to do this using all Microsoft tools: Assuming the volume is not BitLocker'd it's pretty simple to do all of this stuff with WinPE [1], including the version that shipped in 2006, or with a Windows setup DVD. Or you could simply move the drive to a machine where you are an admin.
I am pretty sure they bought winternals because they wanted to hire MarkRuss.
[1] http://en.wikipedia.org/wiki/Windows_Preinstallation_Environ...
I think MS just wanted to hire one of the best Windows hackers of all time, and they pounced as soon as they got a window of opportunity for whatever reason. Everything else was a bonus.
Great programs he produced though! Really really helpful. One of the first things I install on a new OS.
[1] http://windowsitpro.com/systems-management/making-windows-cl...
Well i don't buy that part. When I first came across sysmon/regmon/procmon, I found it to be an amazing piece of work. An extremely small free standalone program that gave you a realtime insight into the OS? Heck, if I kept a list of people to hire, he would definitely be on it!
That thing was even 1/10 of the "hello world" Go program I compiled!!!*
*(~100Kb vs 1Mb) I know Garbage Collection adds a lot to size but its still a fun comparison.
Having said that, he was quite vocal at the time, and I personally think that he may have been a large part of the huge Vista -> Win7 improvements, although have no evidence to support this. The timing just seems about right.
... and they tasked him with this obnoxious and highly dispensable cloud computing project. Anything just to keep Mark shut up, ANYTHING.
On my last count, you needed to swallow 11 different types of messages.
it's pretty core to the idea of windows though. kind of like a printer - i wouldn't be surprised if a printer driver was in the kernel. or age of empires, which is a Microsoft property. just load it into the kernel in case you need it and you dont need much DRM, if people end up buying it it can get unlocked.
in essence i was agreeing that a microkernel is no place for a scroll bar!