3 ms·
Yeah, the fact that Windows requires kernel-level access to be able to do EDR stuff is really unfortunate. MacOS has been very successful with their userspace E
by roblabla 2y ago
Yeah, the fact that Windows requires kernel-level access to be able to do EDR stuff is really unfortunate. MacOS has been very successful with their userspace EndpointSecurity Framework for this purpose.
On the other hand, Linux is similarly crippled: eBPF LSM are fairly recent and don't work everywhere (I'm looking at you Ubuntu[0]), and the only real alternative if you want to be able to block processes is a kernel module. Which comes with the same dangers as Windows.
[0]: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2054810 https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2054810
- sgift 2y agoWell, Microsoft says that's because of the EU commission: https://news.ycombinator.com/item?id=41029590 https://news.ycombinator.com/item?id=41029590 I have my doubts, but that's at least what they give as the reason for the kernel-level access of EDR tools.