3 ms·
> an application shouldn't be able to do this kind of damage to an operating system Antivirus software by its nature probably needs the kind of access that wou
by aloha2436 2y ago
> an application shouldn't be able to do this kind of damage to an operating system
Antivirus software by its nature probably needs the kind of access that would let it bluescreen your computer.
- BLKNSLVR 2y agoWading out my depth here, so forgive any stupidity following. And there's a certain amount of sense to that, it has to get "under" the layer that viruses can typically get to, but I still think there should be another layer at which the OS is protected from misbehaving anti-virus software (which has been known to happen).
- eddythompson80 2y agoIt's a kernel mode driver. There aren't layers in kernel drivers. Any kernel module/driver can crash your system if it wants to.
- quietbritishjim 2y agoYou're taking about how things are, the comment you're replying to is talking about how things could be. There's not a contradiction there. Originally, x86 processors had 4 levels of hardware protection, from ring 0 up to ring 3 (if I remember right). The idea was indeed that non-OS drivers could operate at the intermediate levels. But no one used them and they're effectively abandoned now. (There's "level -1" now for hypervisors and maybe other stuff but that's besides the point.) Whether those x86 were really suitable or not is not exactly important. The point is, it's possible to imagine a world where device drivers could have less than 100% permissions.
- lnx01 2y agoIt runs at Ring 0, there's no lower ring (besides maybe IME and the like).
- BLKNSLVR 2y agoThe problem I have with this is that anti-virus software has never felt like the most reliable, well-written, trustworthy software that's deserving of it's place in Ring 0. I understand I'm yelling into the storm here, because anti-virus also requires that level of system access due to the nature of what it's trying to detect. But then again, does it only need Ring 0 access for the worst of the worst? Can it run 99% of the time in Ring 1, or user space, and only instantiate it's Ring 0 privileges for regular but infrequent scans or if it detects something else may be 'off'? Default Ring 0? Earn it. This turns into a "what's your threat level" discussion.
- yjftsjthsd-h 2y agoTechnically, there are rings -1 through -3; hypervisor/-1 actually seems widely used and maybe could be used here. https://en.wikipedia.org/wiki/Protection_ring#Miscellaneous https://en.wikipedia.org/wiki/Protection_ring#Miscellaneous
- DaoVeles 2y agoNeed something like a hypervisor OS/hardware that isnt IME.
- dist-epoch 2y agoModern Windows installs already run under a hypervisor. It's called Core Isolation or Virtualization Based Security.
- prmoustache 2y agoThat usually makes it a port of entry for attacks. Antivirus are really malwares waiting to be exploited.
- chrisjj 2y ago[delayed]
- fulafel 2y agoThis is not the case. There are many possible AV architectures, with or without kernel drivers and/or administrator level permissions.