4 ms·
Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. Whilst telling their corporate customers that using Microsoft InTune will allo
by guidedlight 2y ago
Microsoft are signing kernel drivers for over-the-air updates pushed by vendors.
Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management.
- gruez 2y ago>Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. The crash was caused by a configuration update pushed by crowdstrike, not a new driver. >Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management. How is this relevant? This wasn't caused by some sysadmin that goofed a config change using intune, it's something pushed by crowdstrike itself.
- guidedlight 2y ago> The crash was caused by a configuration update pushed by crowdstrike, not a new driver. Microsoft didn’t do enough due diligence on the behaviour of CrowdStrike updates. It shouldn’t allow out-of-band updates. Third-parties should not be signing code that allows third-parties to reach into corporate services and push files. Microsoft InTune is the mechanism that all configuration updates should use. It appears to me that Microsoft makes it harder for third-parties to update an Xbox game, than the configuration of a kernel driver.
- gruez 2y ago>Microsoft didn’t do enough due diligence on the behaviour of CrowdStrike updates. It shouldn’t allow out-of-band updates. You want Microsoft to be doing code reviews of third party software? That might have prevented this disaster but would get them in hot waters for other reasons (eg. anti-competition accusations). Not even Apple gatekeeps that hard. >Third-parties should not be signing code that allows third-parties to reach into corporate services and push files. So dropbox should be banned as well? It's also a third party service that pushes files onto computers. >Microsoft InTune is the mechanism that all configuration updates should use. Okay, so crowdstrike pushes its virus definition updates via intune instead. The bad file still lands on computers, the kernel mode driver still crashes before the computer can boot and the computer is bricked. How is this any better?
- guidedlight 2y agoWe’re talking about kernel drivers here. I think they warrant some extra attention by Microsoft.
- averageRoyalty 2y agoWhy are you arguing about the responsibility of MS or CS when the owner of these enterprise computers is clearly the one responsible for what's on them? The companies affected are the ones who chose to install the software and run it with the inherit risks. > Microsoft InTune is the mechanism that all configuration updates should use. That would make it one of the most locked down operating systems in the world, killing millions of applications overnight. Enterprise IT already have the ability to control installs, updates and patches, why move that burden to Microsoft?
- pjmlp 2y agoBasically more iOS, less PC.