4 ms·
Exactly, the developers of Defender decided it needed to lock the file, arguably for alot of reasons. To prevent tampering etc, it's an antivirus, it doesn't wa
by maldev 4y ago
Exactly, the developers of Defender decided it needed to lock the file, arguably for alot of reasons. To prevent tampering etc, it's an antivirus, it doesn't want you to be able to bypass a scan of a file, or change it. Windows has things like Datastreams(Which come from Mac), so the same "file", can actually have two different files in it, and require different file openings. IE, "Foo.exe" and "Foo.exe:MALWARE" would be completely different file contents, despite both being foo.exe. And OpenFile("Foo.exe"), would not open foo.exe:MALWARE.
Alot of the confusion comes from people not understanding the functionality. Delete file means "Delete it now" on windows(ignoring slack space). But on linux it means "Queue up the file to be deleted". Windows also has this, but it's going to be a transacted operation, which is literally called DeleteFileTransacted vs DeleteFile, so the Kernel sees noone is using it and then will delete it.
And honestly, if you go up to any lay person and ask them "What does 'DeleteFile'" do. They'll probably respond it deletes the file. Not queues it up for deleted, but other people can still access it. So I think the windows verbage makes more sense, with another function appending Transacted to it, which signifies it will be done eventually.
- Brian_K_White 4y agoThere is nothing about antivirus that requires file deletion block on other processes including the antivirus. For one thing, you just said Windows has a similar functionality available anyway just invoked a different way. Is that a way around Defender? It better not be. If it exists as something you can use, and yet still isn't a way around Defender, then it's silly to even be talking about Defender to justify this 70's behavior. The understanding of laypeople in how a multitasking operating system kernel coodinates a graceful teardown of a shared resource, or fails to in the case of Windows, has exactly no bearing on anything. Why isn't it exactly as reasonable to presume that "any lay person" would expect that they can simply issue a delete command and it happens, without having sit there and wonder why they're stuck and go worry about other processes that they didn't write and don't have any knowledge or control over? It is exactly as reasonable. And both are pure meaningless presumption, and don't matter anyway since the understanding of a lay person would be a ridiculous way to design the inner workings of ... anything, definitely including an operating system. These arguments are swiss cheese.