3 ms·
Sure, it does sound interesting. Now what about all EMET mitigations that Microsoft is deprecating by saying Windows 10 is "secure enough" as is?
by MohammadLee 10y ago
Sure, it does sound interesting. Now what about all EMET mitigations that Microsoft is deprecating by saying Windows 10 is "secure enough" as is?
- ryuuchin 10y agoMost of them are just built into Windows now and are accessible through both the registry[1] and at runtime[2][3]. The latter requires recompiling with source code changes but the former can be applied to any application. The EMET mitigations which are no longer supported have either been depreciated because of better ones (control flow guard) or are not terribly effective (EAF/EAF+, use of debug registers). [1] https://theryuu.github.io/ifeo-mitigationoptions.txt https://theryuu.github.io/ifeo-mitigationoptions.txt [2] https://msdn.microsoft.com/en-us/library/windows/desktop/ms686880%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/ms6... [3] https://msdn.microsoft.com/en-us/library/windows/desktop/hh769088%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/hh7...
- MohammadLee 10y agoI get your point, but most does not mean all, and hardening is all about adding layers. https://insights.sei.cmu.edu/cert/2016/11/windows-10-cannot-protect-insecure-applications-like-emet-can.html https://insights.sei.cmu.edu/cert/2016/11/windows-10-cannot-... is a complete review of the mitigations we are loosing.