3 ms·
I’d also maybe add another one on the Windows end: 6) some form of sandboxing/error handling/api changes to make it possible to write safer kernel modules (not
by ratorx 2y ago
I’d also maybe add another one on the Windows end:
6) some form of sandboxing/error handling/api changes to make it possible to write safer kernel modules (not sure if it already exists and was just not used). It seems like the design could be better if a bad kernel module can cause a boot loop in the OS…
- leosarev 2y agoThere is sandboxing API in Windows. It's called running programs in userspace.
- hello_moto 2y agoRun what a userspace?
- layer8 2y agoIt’s a tough problem, because you also don’t want the system to start without the CrowdStrike protection. Or more generally, a kernel driver is supposedly installed for a reason, and presumably you don’t want to keep the system running if it doesn’t work. So the alternative would be to shut down the system upon detection of the faulty driver without rebooting, which wouldn’t be much of an improvement in the present case.
- ratorx 2y agoI can imagine better defaults. Assuming the threat vector is malicious programs running in userspace (probably malicious programs in kernel space is game over anyway right?), then you could simply boot into safe mode or something instead of crashlooping. One of the problems with this outage was that you couldn’t even boot into safe mode without having the bit locker recovery key.
- layer8 2y agoYou don’t want to boot into safe mode with networking enabled if the software that is supposed to detect attacks from the network isn’t running. Safe mode doesn’t protect you from malicious code in userspace, it only “protects” you from faulty drivers. Safe mode is for troubleshooting system components, not for increasing security. I don’t know the exact reasoning why safe mode requires the BitLocker recovery key, but presumably not doing so would open up an attack vector defeating the BitLocker protection.
- Uvix 2y agoNormally BitLocker gets the key from the TPM, which will have its own driver that's likely disabled in Safe Mode.
- discostrings 2y agoThe BitLocker configurations I've seen over the last few days don't require the recovery key to enter safe mode.
- sm_1024 2y agoDoesn't microsoft support eBPF on Windows? https://github.com/microsoft/ebpf-for-windows https://github.com/microsoft/ebpf-for-windows
- nullfrigid 2y agoIf you know the answer why are you asking the question?
- 0xBDB 2y agoNo. Not in production yet. But that should solve this problem once it's available for any company that uses it (and I believe CrowdStrike is heavily involved with it).