3 ms·
The real question is why the hell can said infostealer malware access the file. Can we PLEASE have proper per-process file access restrictions on Windows alrea
by andersa 2y ago
The real question is why the hell can said infostealer malware access the file.
Can we PLEASE have proper per-process file access restrictions on Windows already - like MacOS has had for a decade now ????? Why is win32 app isolation still not done?
- buro9 2y agohttps://learn.microsoft.com/en-us/defender-endpoint/enable-controlled-folders https://learn.microsoft.com/en-us/defender-endpoint/enable-c... this works surprisingly well to prevent an app from going too far into folders it should not access. It's a bit opaque though, not as simple as *nix owner/group/everyone permissions.
- andersa 2y agoThis seems like a start, but just marking applications as "trusted" doesn't cut it. We need real rules like each program can only access its own installation folder, its own user data folder, and any folders the user has explicitly granted access to for that program. I may "trust" a video editing app, for example, so I can access my raw content folders. It should still be completely impossible for that process (or any spawned from it) to access my browser session information in case of an RCE from loading a malicious video.