5 ms·
You are only as good as your weakest link: > A Microsoft spokesman said it cannot legally wall off its operating system in the same way Apple does because of a
by theoa 2y ago
You are only as good as your weakest link:
> A Microsoft spokesman said it cannot legally wall off its operating system in the same way Apple does because of an understanding it reached with the European Commission following a complaint. In 2009, Microsoft agreed it would give makers of security software the same level of access to Windows that Microsoft gets.
https://www.wsj.com/tech/cybersecurity/microsoft-tech-outage-role-crowdstrike-50917b90?st=pkas1bzrhcoj0os&reflink=desktopwebshare_permalink https://www.wsj.com/tech/cybersecurity/microsoft-tech-outage...
- kevincox 2y agoMaybe Windows Defender should also not have the ability to crash the kernel. Instead Microsoft can provider proper hooks to pluggable drivers that can be used by both themselves and third party AV.
- usr1106 2y agoIt's not Microsoft that should wall off the operating system. It's banks, airlines, health care providers that should not use Windows the way they currently do. No employee there needs the possibility to install any software themselves. Without the possibility to install software you don't need anti-virus software. These systems should just run immutable images, in A/B deployment, just in case the new image is broken. Of course that does solve the supply chain security. How do you make sure that the images contain know malware? But the problem does not not need to be addressed on millions of machines with millions of employees. It gets reduced to thousands.
- wpm 2y agoPresumably, these employees probably need email, web access, and file sharing. There you go. Those are your threat vectors now.
- xqt40 2y agoYour suggestion simply shows that you have no understanding of how things work. Terminals already does not allow users to install anything. As for rest of workstations and work laptops - users already don't install anything on them. The issue with Crowdstrike is not with users but with service that is maintaing these computers. A very frightening thing that all those companies are dependant on the f*ck off of their service provider and it costs them all their business. No viruses need installation - in fact it would be easiest thing if viruses were listed among installed programms. Are yiu representing your whole generation or you are only one such strange person? Also your suggestion os outdated by at least 60 years as it assumes that hardware that has no software update capabilities can't be hacked...
- sunaookami 2y agoThat's just Microsoft's incompetence blaming the EU. MS should start making their products not full of security holes.
- jpgvm 2y agoMicrosofts products aren't full of security holes. If you have an 0day on fully patched Windows that is worth a pretty penny, which implies they aren't they easy to come by. They aren't worth quite as a much as an iOS 0day but they are by no means cheap. Of course if you think otherwise you can be making 7 figures per bug (assuming you are OK selling to brokers for the 3 letter agencies) so go dig some up?
- sunaookami 2y ago>Microsofts products aren't full of security holes They are though, just look at Exchange[1] and what problems Microsoft itself has.[2] There is no such thing as a "secure Microsoft product". Microsoft is single-handedly responsible for making the IT world worse because they do not care and have a monopoly. >If you have an 0day on fully patched Windows that is worth a pretty penny, which implies they aren't they easy to come by. It's what the market pays for it, not what it's actually worth as you have already pointed out. Three-letter agencies buy these 0-days themselves for a big sum and support the black market so the prices go even higher because they have infinite money. [1] https://en.wikipedia.org/wiki/2021_Microsoft_Exchange_Server_data_breach https://en.wikipedia.org/wiki/2021_Microsoft_Exchange_Server... [2] https://edition.cnn.com/2024/04/02/tech/us-government-microsoft-hack/index.html https://edition.cnn.com/2024/04/02/tech/us-government-micros...
- ikekkdcjkfke 2y agoAre there any guard rails against an npm package install script reading cookies from chrome data folder?
- WorldMaker 2y agoThe predecessor anti-virus to Windows Defender was originally meant to be released in-box with Windows XP. Due to pressure from both the US and the EU (themselves pressured by massive lobbying by Mcafee and Symantec/Norton) Microsoft was not allowed to ship the anti-virus with XP and had to release it separately on a web page as an "optional" download. This gave the anti-virus vendors an additional "free decade" (just about exactly) of being able to advertise that Windows was insecure by default and pretend like this was Microsoft incompetence. Today a lot of average users (and as CrowdStrike has indicated, many large enterprises) still believe that Windows doesn't have built-in anti-virus because of "Microsoft incompetence" despite Defender having been bundled with Windows since Vista (2007). Microsoft has spent decades removing security holes but doesn't get even half the credit for it because it still has to deal with an open Kernel because people want to pay for security blanket "products" like CrowdStrike's and Symantec/Norton's bloatware. That's in part because the US DOJ and the EU in trying to do the "right thing" for anti-trust reasons did the exact "wrong thing" for consumer protection reasons and left all these shady vendors with too much "everyone knows Windows has no anti-virus out of the box" PR based on Microsoft forced to remove it from Windows XP to an "optional download" and that still being the benchmark version of Windows in many minds.