16 ms·
Windows 10 will use protected folders to thwart crypto ransomware
- Someone 9y ago"If an app attempts to make a change to these files, and the app is blacklisted by the feature, you’ll get a notification about the attempt,” Microsoft explains." I don't understand. If they have a blacklist, why ask the user? Or is "blacklisted" used loosely here to include code flagged by heuristics?
- firebird84 9y agoPerhaps "brownlist" would be more appropriate
- cube00 9y agoI've always wondered why Windows and other OSes don't offer a 'cold storage' area where you need thaw out files before editing. Files not modified within a selected time freeze from further modification. I've got plenty of files that are archived that I'd never want to change, but it's a hassle to unmount/remount just to add a new file to an existing directory.
- VectorLock 9y agoHow is 'thawing' your files more/less of a hassle than mounting a drive?
- masklinn 9y agoThe file would still be there and available, even more so as it would be "frozen readonly", you just get a request on write access. Whereas with drives you don't have access to the file if it's not mounted, you have to know on which drive the file you're looking for is, go through the mounting process, then actually find the file. And if you want to alter the file you have to remount the entire thing, and possibly need to track down that one daemon which still has a handle open and prevents you from unmounting it.
- KekDemaga 9y agoAn idea I have is implement simple versioning on the thaw folder. If edited the changes can then be reverted.
- elmigranto 9y agoAnd I have counter idea — encrypt N times, so every shadow copy is borked; certainly you are not storing "infinite" history?
- KekDemaga 9y agoI presume the thaw folder would have an upper limit on storage, once hit you forbid writes entirely.
- masklinn 9y agoIsn't that just a CoW filesystem? Just use e.g. ZFS and configure it to take regular snapshots (though you may want to be careful, a few years back if a zpool got completely full things got wonky, dunno if they've fixed it, so you may want to keep some disk space outside the zpool just in case, so you can expand the zpool enough to work if it gets completely full)
- rainbowzootsuit 9y agoOpenSolaris derivatives (eg OmniOS, SmartOS) are able to present the snapshots over SMB as windows previous versions. I have the server at work, which only has windows desktop clients, making 1-minute snapshots with a one-day lifetime in addition to daily, weekly, monthly etc. It's very handy for the occasions where you accidentally save over a document and slap yourself in the head immediately afterwards.
- balls187 9y agoInteresting idea. Can you explain the thawing procedure, and how a normal everday user would experience it?
- cube00 9y agoFor Windows it could just prompt the user when an application attempts a write operation; just like UAC, if permission is granted the calling application wouldn't even notice the difference except for the pause while the open for write access call blocks pending user permission. Done at the same level as UAC in theory it should be impossible for malware to bypass approval, heck I'd even be happy typing my user account password to thaw it out.
- balls187 9y agoThats how I would envision working as well. Seems like the classic tradeoff between better security and better UX. Users would complain, and/or try to disable it.
- megamindbrian 9y agoHow about just enabling Shadow copies by default! I don't understand why Windows has great "Time machine like features", but every fucking time I right click and go to Properties and look at the "Previous versions" tab and it is completely empty.
- gruez 9y agoransomware typically delete shadow copies (and any other local backups they can get their hands on)
- sgift 9y agoProbably because the typical anti-MS comments would be worse for them than the risk of ransomware (from their perspective): "Windows eats all my hard disk!! I've updated to <windows xy>/Windows did an update and now all my disk space is gone!!! Don't update!!!!" "New MS update steals your disk space, here's how to stop it" And so on, and so on.
- cm2187 9y agoNo it wouldn't be turned on by default. If it was every software that you run occasionally would break. This would be opt-in for certain folders.
- brainfire 9y agoNo, this thread is about shadow copies being turned on by default.
- drdaeman 9y agoCould be worse, like a circulating recipe how to completely remove VSS by removing system files related to shadow copy services, or something like that.
- mc32 9y agoMy observation is that people who buy Macs also buy an external drive for Time Machine but Windows PC buyers don't usually buy an external drive and turn on File History. Slightly different culture, I guess.
- mtgx 9y agoI'd also really like Microsoft to develop the Application Guard (app in a VM) feature faster and make it widely available to almost any app, or at least any browser, and of course to everyone, not just enterprise users. Microsoft has some interesting new security features on its roadmap. Unfortunately, 90% of them are for enterprise users-only and some only for its own applications. It also wouldn't hurt to overhaul/replace UAC with something better, but I imagine that would require deeper architectural changes (which I think would be worth the pain). Microsoft should also push users towards creating a Standard account when installing Windows, and setting up an Admin password, too. It shouldn't be too difficult/disruptive. They just need to create an easy process for it at installation. The vast majority of Windows malware infections happen because users are also Admins. This alone would give Windows a huge security boost on average. https://www.avecto.com/news-and-events/news/94-of-critical-microsoft-vulnerabilities-mitigated-by-removing-admin-rights https://www.avecto.com/news-and-events/news/94-of-critical-m... Once they do this, they could also start encrypting Windows devices by default with the Admin key, similar to how Android does default encryption. Windows is pretty much the last major operating system not to encrypt by default. Hopefully, if they do this, they at least give users the option to keep the key locally, and not automatically upload it to Microsoft's servers, as they do now if you login to your Microsoft account.
- pjmlp 9y agoIt still won't help against dumb users that think security is only about inconvenience. Go to macOS user forums and you will see lots of discussions about how to turn off Gatekeeper or be "always root" user.
- rbanffy 9y ago> don't offer a 'cold storage' If the malware gets privileged access, it's game over. If it can't, good file system permissioning fixes the problem.
- Mo3 9y ago.. what about the existing file versioning and backup tools?
- sitkack 9y agoHow about using ML to detect profiles of access and disallowing un-common access patterns? If I only use VS Code to access my source, prevent win-malwr.sys from accessing that folder.
- yjftsjthsd-h 9y agoAnd then one day you want to zip up the project to send to a friend, run an external linter on it, or make backups. ML depends on an adequate training set, and real life uses change quickly enough to break it.
- sitkack 9y agoThe OS would confirm that it was an end user making the action not malware. It is about the automatic creation of security rules based on observed behavior. The other option would be to create everything manually, which doesn't happen.
- ric129 9y agoBrowsers have already taught us how useless this is, users will always click through.
- d8421l01vv4r 9y agoHaving an OS that arbitrarily denies applications access to files would drive me mad very quickly. I'm guessing that seemingly unpredictable behaviour would annoy the average user as well.
- revmoo 9y agoCountdown to malware using this feature to prevent removal
- ocdtrekkie 9y agoThis seems like a good idea, and I'm pretty excited to see this step. Though I suspect if certain apps are whitelisted to edit in those folders, ransomware will simply turn to finding exploits in those apps. And most of your document and photo editing apps out there may not have been designed with security in mind, as they never expected to be gatekeepers of file access. This will also probably be a UAC-level nightmare for getting old software to work on newer PCs, as today's software generally just assumes it can have file access to document folders.
- Santosh83 9y agoMany of the ideas seem good for a corporate/enterprise setup where you lock the system down to run a few business/tech apps, but not so pain-free for desktop users. I mean, nearly every app on my system needs access to the usual folders. Unless MS bundles a good whitelist of approved apps, granting permissions is going to get really annoying.
- ocdtrekkie 9y agoAkin to Windows SmartScreen and stuff, I expect Microsoft to offer the whitelist as a service. Obviously, they wouldn't want to cause extra headaches in getting Microsoft Office and the like to have access to your documents.
- hippich 9y agoSo last ransomware we seen in the news actually tried to reboot system and encrypt files before OS is loaded. So unless that new tech gonna protect MBR (which should be protected anyway) - not sure how it going to stop encryption.
- bArray 9y agoYep!
- satysin 9y agoThis is why Secure Boot is a thing.
- KallDrexx 9y agoWouldn't secure boot just prevent you from booting into the invalid MBR? At that point your files are already encrypted and your MBR already over-written, Secure boot is just preventing further exploitation.
- sedachv 9y agoYou can get around UEFI Secure Boot by installing an old signed bootloader with known exploits (if I understand correctly this is why the "Secure Golden Key Boot" exploit of last year[1] cannot be patched without changing public keys in the UEFI firmware). Not only that, the code that is shared by most UEFI implementations is garbage[2] with a large attack surface; exploits against the firmware is a possibility. The primary function of UEFI Secure Boot is for Microsoft to prevent other operating systems from being installed on as many systems as they can get away with (right now there is no provision that end users should be allowed to disable Secure Boot on ARM devices, for example). The "security" functionality is an unworkable side-effect that provides a convenient fiction to accomplish that goal. [1] https://www.reddit.com/r/netsec/comments/4wybax/writeup_of_secure_boot_bypass_which_i_dub_secure/ https://www.reddit.com/r/netsec/comments/4wybax/writeup_of_s... [2] https://www.youtube.com/watch?v=V2aq5M3Q76U https://www.youtube.com/watch?v=V2aq5M3Q76U
- olyjohn 9y ago
- rix0r 9y agoThe UI is not really explained. I hope this is not going to train more generations of Windows user to click "yes yes yes" in response to annoying dialogs.
- deleted 9y ago[deleted]
- callesgg 9y agoTo me it seams like a part of the definition of a zero day exploit makes it impossible to stop.
- deleted 9y ago[deleted]
- Shorel 9y agoPart of the definition of a zero day exploit requires software providers to constantly fix issues, otherwise a thousand days exploit would be enough to compromise a system, and no zero day concept would have been necessary, they would be just called exploits.
- schoen 9y agoAt least, it requires someone to be able to act in mitigation. That might also be the user of the software (if they can patch it, find a workaround, have some other software validate inputs or detect attacks, etc.).
- d--b 9y agoThis sounds like a feature that will be painful to work with for regular apps, but that malware will easily work around. I mean I am no security expert at all, but you kind of need administrative privilege to install a malware, so why not keep it to access all the folders you need?
- muricula 9y agoYou don't need administrator privilege. You just need to double click an exe.
- deleted 9y ago[deleted]
- bArray 9y agoThis seems like a rushed reaction to recent events - I think there will be problems as a result of the rushed implementation. I could only begin to imagine the embarrassment if this was the cause of the next zero day attack.
- BrandonLive 9y agoWhat?
- deleted 9y ago[deleted]
- dboreham 9y agoPerhaps the place to implement countermeasures is in the disk drive (SSD these days)? e.g. arrange for the drive to never delete anything unless some key exchange has recently been done, that depends on user input (bio parameters, or password). From a user perspective you'd see this as : All deletes (and file version changes) go to a recycle bin. Emptying the bin can only be done upon presentation of the secret.
- mtgx 9y agoDo you trust any of the SSD makers to implement proper and updated (obviously necessary) counter-measures against ransomware? They can't even get encryption right. https://motherboard.vice.com/en_us/article/mgbmma/some-popular-self-encrypting-hard-drives-have-really-bad-encryption https://motherboard.vice.com/en_us/article/mgbmma/some-popul... https://www.theregister.co.uk/2015/10/20/western_digital_bad_hard_drive_encryption/ https://www.theregister.co.uk/2015/10/20/western_digital_bad...
- pjc50 9y ago.. and overwrites? This screws up savegames, autosaves, swap, browser caches, and so on. (note that the drive is the wrong place, it doesn't know what a "file" is)
- ChuckMcM 9y agoOne of the "features" (back in the day) of running a diskless system was that you could set change policy on the server hosting the file which was completely out of reach of the "client" machine that was running the program. For nearly all of the system files there was no reason for them to change. NetApp turned this into a huge win when they could use snapshots to support multiple VM images with just the small configuration changes. Given the well known benefit there, and that the processor on your hard drive is about as powerful as your phone, why not have the drive set up files that are 'read only' unless allowed to change out of band. Here is how it would work. Your disk works like a regular SATA drive, except that there is a new SATA write option which can write a block as 'frozen'. Once written that way the block can be read but not written. You add an out of band logic signal and wire it up to a switch/button that you can put on the front (and/or) back panel. When the button is pressed the disk lets you 'unfreeze' or write frozen blocks, when it it isn't pressed they can't be changed. Now your hard drive, in conjunction with a locally operated physical switch, protects sensitive files from being damaged or modified.
- klodolph 9y agoSo basically, there's a switch on my computer which I have to flip every so often or things stop working? Or maybe I can just leave it in R/W mode because I'm tired of flipping a switch every time I ctrl+S...
- ChuckMcM 9y agoActually its a switch you would have to switch, when you wanted to update the OS or any file that had been marked as read only. All it does it convert something which is currently invisible (the bad guys escalate privledges and then can stomp all over anything) to something that requires you to stop and say "ok you can stomp on things." Typically that would be unexpected if you weren't updating the OS but sure social engineering always works as is mentioned elsewhere. The goal is just to add depth to the security to slow them down.
- walterbell 9y ago
- Kenji 9y agoI'm skeptical. The cost of managing these permissions might outweigh the benefit. But hey, why not try it. As long as I can disable it when it ends up getting in my way...
- jakobdabo 9y agoCompletely unrelated, but am I the only with an impression that MS has switched Windows into a rolling release OS (like Gentoo or Arch) with infinite updates of Windows 10? This would be a genius move to solve the issue of the users remaining on the old unmaintained release like it was with XP, and like it is now with 7.
- nix0n 9y agoMS has officially confirmed this. https://www.theverge.com/2015/5/7/8568473/windows-10-last-version-of-windows https://www.theverge.com/2015/5/7/8568473/windows-10-last-ve...
- deleted 9y ago[deleted]
- Volundr 9y agoThat's more or less the plan: https://www.theverge.com/2015/5/7/8568473/windows-10-last-version-of-windows https://www.theverge.com/2015/5/7/8568473/windows-10-last-ve...
- ctrlaltdestroy 9y agoYes. Windows 10 would be the last OS from MS. I think they confirmed it.
- copperx 9y agoJust like OS X (10). It's like everybody is afraid to go to 11. To be fair, software is a recent human endeavor, and except for Emacs, I'm not familiar with software versions over 10.
- codewithcheese 9y agoI'll bite. Chrome, Firefox, plenty Adobe products.
- floatboth 9y agoPlenty of Spinal Tap reference opportunities in going to 11 though. The iOS 11 presentation did just that :)
- Meph504 9y agoMy concern is first off, this seems like it is going to break a massive number of applications. It also seems that they are pushing this layer of access management that doesn't have proper support on any platform but UWP. I see this as Microsoft taking yet another step to force people to move to their new Appstore model. by choking the access to the operating system away from any other platform, which I find really amusing because their own top tier applications aren't built on these platforms (office, visual studio, etc..).
- ctrlaltdestroy 9y agoI imagine Office, VS etc are too big to "port" to Appstore model. Also people still use these applications in Windows 7 and so that would mean having two parallel versions of the same app and release features and support for both.
- pjmlp 9y agoOffice will be "store only" on the upcoming version for Windows 10, check Build presentations.
- cube00 9y agoIsn't that just wrapped for the store in their AppV model not a true UWP app?
- WorldMaker 9y agoThe distinction of what makes a "true UWP app" certainly gets blurrier with the "Centennial" desktop bridge, but it's still rather more "true UWP" than AppV is/was.
- pjmlp 9y agoWhile it isn't a pure UWP app, it is a step into that direction and already a big difference from being a standard desktop app.
- 9y ago
- TekMol 9y agoHow often are browsers affected by 0-day exploits these days? I they are not, wouldn't using web-applications and keeping your system up to date solve the whole issue?
- lucb1e 9y agoWhat are "end-to-end security features"? They mention it once but then never again. As far as I know, the term end to end is about communications: an exchange between two or more parties, or endpoints, which can be encrypted "end to end". I'm afraid they just dropped it as another term nobody knows the meaning of, so we'll have to find a new term to describe why Signal and Wire are better than (non-PGP) email.
- Meph504 9y ago"end to end" has been a term in common use in language since the 1800s meaning complete coverage. look it up on the oxford english dictionary for more details.
- lucb1e 9y agoOh, right, objects can lie end to end and have nothing to do with encryption. I had never heard it in security context without meaning e2e encryption.
- zeta0134 9y agoOkay, so I know Windows probably doesn't actually work this way, but from a user interface perspective... what's the rationale on giving an App permanent access to the user's home folder directories? Don't most well behaved apps have a file open / folder open dialog, which should be able to grant access to files at runtime? If the file opening dialog is provided and controlled by the operating system (I realize many, many legacy apps work differently in Windows) then the OS can silently grant permissions at the time of open, rather than letting apps either have free reign or no access at all. I feel like this is the expected behavior anyway; Power Users may run utilities that need to touch the whole system, but most regular users are doing pretty good to juggle more than a handful of open files in their mental model of the machine while they're using it. The idea of file permissions is already pretty foreign to the average end user. Applications already have a designated area (%APPDATA%) where they can store their temporary files and things, so perhaps the documents folders should be more locked down by default.
- simcop2387 9y agothis is essentially how the sandbox works on macos from what I understand. 90% of applications should work fine for this. Some though like antivirus (as an example) can't really do so.
- vbezhenar 9y agoReality is that almost all applications do not use sandbox, unless they are forced too. At least in my experience. I have 16 installed apps and only 2 from AppStore. Check out Android. It has very fine-grained permissions model. But most developers don't care and ask a lot of permissions even for simplest apps. It turns out that users don't care too. I'm not sure how it works for iPhone, where App requests access to some specific very privacy-related functionality, like location or address book, but I think that even on iPhone most users will press "Yes" without second thinking or even careful reading.
- pjmlp 9y agoThat is how Windows sandbox for store apps works, the applications cannot access files directly. The problem is getting everyone on the store train, and to move away from classical desktop.
- MichaelBurge 9y agoLinux has had the same issue for the longest time: You need root or a capability to set the time, but any program you run can wipe your entire home directory.
- tormeh 9y agohttps://xkcd.com/1200/ https://xkcd.com/1200/
- ComodoHacker 9y agoI always thought protecting users from malicious code they willingly download and run themselves is futile and a waste of developers' resources. Do I miss something and this is actually a viable security approach?
- akerl_ 9y agoIt's one of the few non-futile uses of developer resources, when it comes to security. It's a virtual certainty that users will download malicious code, so as a security person you're left trying to mitigate the impact when they do.
- callumjones 9y agoGiven malicious code is hidden in applications that appear to be safe or appealing to users I don’t think they are usually willingly downloading malicious code.
- pfg 9y agoIt's not going to do much for targeted attacks, but there are definitely ways to limit the damage for large-scale ransomware attacks. As it is right now, ransomware doesn't even need to bother with privilege escalation because files valuable to users are most likely owned by them. Not to say that all ransomware malware sticks to just user privileges, but it's usually enough do get the job done. Having a sort of firewall for file systems that's enforced by the system means that in addition to getting code to run with user privileges, the malware authors need to trick the victims into giving the software root (which might be impossible on enterprise networks), or use a privilege escalation vulnerability to do that. Of course, people could still click through prompts, allow access to all apps due to warning fatigue, etc., but it's an improvement - if done correctly.
- faragon 9y agoThe filesystem itself is a risk: per-user default permissions so any application launched by one user can trash all his files is scary. Even applications being able to access other installed applications is dangerous. I hope the industry find a way between all closed (a la Apple) and all open.
- ksk 9y agoI wonder MS has given any thought to 'sealing' executable regions so no new instructions can leak into memory. IOW Once executed, a process can only reference instructions present in the binary itself. Basically make running JIT-ed code, self-modifying code, etc, a special process privilege, that can then have a limited process context for I/O.
- pjc50 9y agoIsn't that a subset of W^X / DEP https://support.microsoft.com/en-sg/help/875352/a-detailed-description-of-the-data-execution-prevention-dep-feature-in https://support.microsoft.com/en-sg/help/875352/a-detailed-d... ? Can be defeated by "return-orientated programming", which uses only the existing instructions in the binary and a modified stack.
- ksk 9y agoYeah, DEP + ASLR already addresses some of this. Perhaps the stack regions could partially be set to read-only to protect return addresses.
- kevingadd 9y agoControl Flow Integrity is one technique for addressing these sorts of attacks: https://www.microsoft.com/en-us/research/wp-content/uploads/2005/11/ccs05.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/... IIRC there are even some experimental efforts to add hardware support for CFI techniques to new processors (Intel I think?) but there's work going on to add support for it to modern compilers, which would allow you to compile libc and other system libraries with it turned on. EDIT: It appears Clang actually ships with some CFI support already: https://clang.llvm.org/docs/ControlFlowIntegrity.html https://clang.llvm.org/docs/ControlFlowIntegrity.html
- muricula 9y agoA lot of code in the windows ecosystem uses UPX unpackers. The code extracts itself before executing the actual application. This is common for certain installers. Windows does a pretty good job of enforcing Data Execution Prevention for code which opts in.
- mynameislegion1 9y agoIt's about time Microsoft peaked out from under their blankets where they've been hiding from cryptography. I remember my first time installing Linux where it asked for a master password to automatically encrypt the entire HDD. I knew then and there, I had found my home.
- unclebucknasty 9y agoOr "Windows Will Protect Vulnerable Client Software With More Client Software". Wouldn't it be much easier and more effective to offer a one-click low cost encrypted cloud backup-service? They could bundle this with Update or Defender to offer point in time recovery.
- vxNsr 9y agoI think that the most recent attack in Ukraine already overcame this obstacle. They were able to use an in-place update system by a trusted software vendor to install their malicious code on the victim's computer. That software would almost certainly have had permissions even under this list, so it's not that effective.
- jamesfmilne 9y agomacOS already does this. System Integrity Protection. https://support.apple.com/en-gb/HT204899 https://support.apple.com/en-gb/HT204899 [edit] apologies, indeed, SIP only protects system files, which is not what this article is about.
- Shank 9y agoThis is about protecting user files and areas, not the system files. A user level ransomware can indeed encrypt all /home/$user contents on macOS just as easily as it can C:\Users\$user on Windows.
- bpodgursky 9y agoI'm surprised Google hasn't run a Chromebook advertising campaign which just says "use a Chromebook and never care about ransomware again"
- FussyZeus 9y agoYeah and if you use Playskool hammers, you'll never break a thumb again either. That doesn't make Playskool hammers better than regular ones.
- romanovcode 9y agoReminds me of a comic. > https://imgs.xkcd.com/comics/cells.png https://imgs.xkcd.com/comics/cells.png
- yellowapple 9y agoOn a tangential note, I'm pretty sure the comic is inaccurate; I'm no microbiologist, but I'm about 61% sure that shooting a petri dish full of cancer cells will just splatter the cancer cells all over the place. Now, if you were to light the dish on fire, on the other hand...
- FussyZeus 9y agoI mean, impact with something as fast moving and hot as a bullet? The ones that directly contacted the bullet at least would likely be dead, from the heat, shock, or both. The ones on the rest of the dish would likely be fine.
- heartbreak 9y agoBecause files on Google Drive cannot be encrypted?
- bpodgursky 9y agoGoogle has old versions of all the files, and would immediately revert them when they detected a virus going around.
- floatboth 9y ago> If an app attempts to make a change to these files, and the app is blacklisted by the feature, you’ll get a notification about the attempt So it's allow default? That sounds useless. We need a deny default thing. Like Little Snitch but for disk. Every time an app accesses a directory it hasn't accessed before, ask. (Skip asking when files are opened using the system "Open file" dialog for a bit less annoyance.)
- topkeker 9y agoThis seems like another strange workaround. We need to change the way the operating system behaves for the future. The problem is default allow for untrusted code to execute. Everyone recognises this as the problem, no one wants to step forward and implement the change. We do it for mobile, mostly, the desktop needs the same shift.
- muricula 9y agoThat basically means forcing everyone to sign their code and offer it through the App Store. You'll see developers complaining about that upthread. Windows 10 does make code signing mandatory for new drivers, and the drivers must pass a suite of acceptance tests.
- topkeker 9y agoYou're right, but people complaining shouldn't dictate life. People also complain about being crushed by ransomware. Not to say they don't have a valid point, but the paradigm needs to change. We used trusted stores for certificates and mobile applications, it's time for the desktop to do the same beyond drivers. Not to say things won't creep through, but default allow needs to go for this to be truly solved, not a new feature or vendor product.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- bsder 9y agoHow about we just have "copy-on-write" filesystems by default? Something which then tries to "encrypt" your hard drive merely winds up creating another layer on top which you wipe out to get back the original files. You only have to flip a "hardware switch" when your disk fills up or you get a catastrophe. I cry every time I see something that IBM or DEC got right 40 years ago that we STILL haven't adopted.
- cctan 9y agoWhy was this not implemented widely? I mean not in source control systems like git or TFS, but built into OSes.