4 ms·
Does anyone know the status of drivers using WinUSB[0] under this policy? Also, have there been many instances of malware in device drivers recently that would
by pedrow 10y ago
Does anyone know the status of drivers using WinUSB[0] under this policy?
Also, have there been many instances of malware in device drivers recently that would require a tightening up of the rules?
[0]: Microsoft's user-mode USB driver, which did (IIRC) need a signed .inf file but you didn't need to submit it for validation since all the actual code was Microsoft's (https://msdn.microsoft.com/en-gb/library/windows/hardware/ff540196(v=vs.85).aspx https://msdn.microsoft.com/en-gb/library/windows/hardware/ff...)
- gtirloni 10y agoOnce malicious code gets into the kernel address space, the sky is the limit. I don't think it matters if there has been one or a million occurrences of kernel-space malware. Look for more details on "ModPOS" for a particularly disastrous one.
- IshKebab 10y agoCode using WinUSB runs in user-space, so you don't need a custom kernel driver. This policy doesn't affect WinUSB at all.