8 ms·
but it's kind of their fault? they designed the api that way, they decided what can be done in userland and what must be done via kernel. they at least _allowed
by fishywang 2y ago
but it's kind of their fault? they designed the api that way, they decided what can be done in userland and what must be done via kernel. they at least _allowed_ it to happen every time.
- lozenge 2y agoYou can't just let people do anything from userland, the performance would tank. As for restricting kernelland, EU competition regulators would not be happy if MS was the only one able to write anti virus software that runs in kernelland.
- deleted 2y ago[deleted]
- justinclift 2y ago[flagged]
- throwaway237289 2y ago[flagged]
- justinclift 2y ago[flagged]
- pixl97 2y agoThere is literally a ton of existing software out there that is keeping MS from doing exactly that. When it comes to avoiding breaking legacy applications MS scores far higher than any other operating systems out there.
- justinclift 2y agoAnd that has absolutely nothing to do with them coming up with better approaches then discussing them with industry for potential roll out, adoption, etc. But instead, now they're in trouble they're trying to blame the EU for stopping their monopoly. Do you honestly believe MS being unhindered by competition restraints would lead to better results? Are you forgetting MS has already demonstrated how that goes, and been literally convicted for it? https://en.wikipedia.org/wiki/Microsoft_Corp._v._Commission https://en.wikipedia.org/wiki/Microsoft_Corp._v._Commission (there are plenty of other examples)
- sashank_1509 2y agoLet me try to make it extremely simple so that maybe you might understand something. Say I am running a shop, the EU tells me that under no circumstance can I not allow a product to be sold in my shop, even if that product is a ticking time bomb that can blow up the shop. And so hearing this, I create a document “Good approaches to sell time bombs”, and I mention helpful stuff like ensure the timer in your bomb is switched off when it is in shop. I also create an industry wide forum with all time bomb manufacturers and discuss best practices and time bomb methods with them to best sell it in the shop etc. In spite of all this, there exists an idiot timebomb manufacturer who ignores all best practices, does not consider industry and builds a shitty time bomb that blows up the shop. Now please educate me, apart from doing the only surefire thing and banning shitty time bomb manufacturers from selling in their shop, what should MS do?
- justinclift 2y ago> the EU tells me that under no circumstance can I not allow a product to be sold in my shop That doesn't seem to be a good faith representation of what the EU was requiring. > ... so that maybe you might understand something. It looks like there's literally no getting through to you nor other MS apologists. :( :( :( sigh
- intern4tional 2y agoHere's an actual compliant at MS to the EU from an anti-malware vendor: https://www.techtarget.com/searchsecurity/news/450420491/Microsoft-accused-of-blocking-independent-antivirus-competition https://www.techtarget.com/searchsecurity/news/450420491/Mic... This is and has been a thing for quite some time. Windows is a highly regulated OS.
- justinclift 2y agoSeems like a complaint that MS was using underhanded tactics, so Kaspersky complained to an organisation that might do something about it. It doesn't really seem like an example of MS coming up with a better solution then discussing it with industry, unless I'm misunderstanding it? Instead it seems a lot like MS figuring out a solution that advantages themselves then just rolling it out, at the expense of others. (?)
- intern4tional 2y agoAs someone that worked at MS, on a team that worked directly on this issue (among other things) some years ago, MS did figure out better solutions and did discuss it with industry. MS has an entire forum for discussing these things with industry (https://learn.microsoft.com/en-us/defender-xdr/virus-initiative-criteria https://learn.microsoft.com/en-us/defender-xdr/virus-initiat...) and has had variants of said forum for some time (I think the first effort was in 2010). Kaspersky was running an SSL/TLS Proxy in the kernel IIRC and didn't want to have to move it elsewhere due to the fact it would require them to rework their product quite a bit. The solutions MS (we) proposed were agnostic and overall better, the anti-malware industry simply doesn't want to make the changes as these things do impose technical work on existing products.
- justinclift 2y agoNo worries. That wasn't at all evident from the above complaint. Was the drive for this industry forum coming from dealing with the EU, or was it more from MS trying to make things better without needing the prodding?
- dang 2y agoPlease don't respond to a bad comment by breaking the site guidelines yourself. That only makes things worse. (Your comment would be fine without that first bit.) https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- hilbert42 2y agoThere are ways around this that I've discussed elsewhere so I won't repeat them here. However, think of it this way: Windows restarts, tries to load with new patch and crashes. Question: why can't Windows be designed so that on crash it automatically restarts and loads the previous state sans patch? Answer: Windows could be designed that way but it would require Microsoft to do many things it doesn't want to do. Some of which would require Microsoft to go back to the beginning and reengineer quarter-century or more old code from scratch, that means redesigning APIs and the underlying architecture from first principles. Why doesn't Microsoft want to do this? It's obvious so I won't bother to spell it out. Nevertheless, when the dust fully settles and someone outlines these alternative design strategies in great detail then it'll be obvious to everyone what a fragile stack of cards Windows has been constructed on.
- dang 2y agoPlease don't post in the flamewar style to HN, such as you did here and downthread (https://news.ycombinator.com/item?id=41096774 https://news.ycombinator.com/item?id=41096774). It's not what this site is for, and destroys what it is for. If you'd please review https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
- ahepp 2y ago> You can't just let people do anything from userland, the performance would tank Isn't the point of userland that you can (try to) do anything from there? It seems like MacOS and Linux provide substantially safer alternatives that are still performant? > As for restricting kernelland, EU competition regulators would not be happy I keep seeing people say this. Is there a basis for that assertion, or is that mere speculation? Again, hasn't MacOS already deprecated kexts?
- intern4tional 2y agoThere is basis for that assertion. Via Google: https://www.techtarget.com/searchsecurity/news/450420491/Microsoft-accused-of-blocking-independent-antivirus-competition https://www.techtarget.com/searchsecurity/news/450420491/Mic... (Also via myself, as I was at MS when we wanted to make this change and the EU said no.)
- philistine 2y agoWell Microsoft did not publicly commit to using the same APIs, and no privileged access, for its own antivirus products. That's why the EU said no way; not because kernel access was revoked.
- guiriduro 2y agoYes, but then of course Microsoft is being obligated to open part of kernelspace to competitors, which is arguably "OK" from a competitive regulation perspective, but that then places a special burden on competitors to maintain code hygiene given the potential for crashes. It makes CrowdStrike's negligence all the more unacceptable.
- ahepp 2y agoI believe what philistine is suggesting is that Microsoft could have implemented their own security offering using a safer alternative like eBPF, and then opened that interface to competitors as well. I think that would have been a proactive approach. That said, I'm not entirely convinced that the EU was right to place the restriction in the first place.
- Iwan-Zotow 2y agoit's like userland video driver - thousands context switches per second, performance will dive...
- deleted 2y ago[deleted]
- skissane 2y ago> they designed the api that way, they decided what can be done in userland and what must be done via kernel They didn’t have much of a choice - it is very hard to get adequate performance with real-time filesystem filtering without doing it in kernel mode. Not aware of any other mainstream OS which succeeds at that. And they kind of had to provide this feature, since they’ve supported it since forever (antivirus vendors were already doing it back in the days of MS-DOS and Windows 3.x/9x/Me), and there is a lot of market demand for it. It is easy for Linux to say “no” when it never has had support for it (in official kernels) But, as the blog post points out, it sounds like CrowdStrike is doing a lot of stuff in kernel mode that could be done in user mode instead - whether due to laziness or lack of investment or lack of sophistication of their product architects > they at least _allowed_ it to happen every time Microsoft, in allowing third party code to be loaded into their kernel, is no different from other major OS kernels, such as Linux or Apple XNU. Apple is (increasingly) the most restrictive about this, and a lot of people criticise them for it. Even Linux imposes some restrictions-which kernel symbols to export (at all or as GPL-only)—although of course being open source, you can circumvent all restrictions by changing the code and recompiling
- fsociety 2y agoMac and Linux run EDRs in userspace without an issue. No one here has an excuse or no choice.
- dralley 2y agoLinux these days tends to use eBPF which isn't really in userspace per-se.
- djbusby 2y agoeBPF is like the Twilight Zone. I'm in kernel space but, I'm not.
- speed_spread 2y agoeBPF is Linux denying the fact that it's turning into a microkernel and that Linus was wrong.
- a-dub 2y agoi would have thought that in 2024 a bad driver update is something that windows would automatically roll back. or at least provided some level of protection against crashes in third party kernel code.
- VohuMana 2y agoI think if I understand the systems right Windows can roll back a bad driver update but the CS update wasn’t an update to the driver but instead updated a configuration file which CS updated outside of Windows Update. So from the Windows Update perspective the system started failing to boot with no changes to the system. Again though I don’t know if I totally understand what CS did and what capabilities Windows Update has.
- sashank_1509 2y agoNo you can’t roll back bad driver updates in any OS, if you could then by definition they do not sit in the kernel space. You just want the security code to not run in kernel space, which is a decision MS could maybe make and become like Apple, though most security software would in that case rebel.
- a-dub 2y ago> No you can’t roll back bad driver updates in any OS, if you could then by definition they do not sit in the kernel space. drivers and kernel binaries are typically installed and maintained by user space programs that run with some sort of elevated privileges. "kernel space" is just a runtime context, what gets loaded into there typically comes ordinary (protected) files on the disk.
- fragmede 2y agoit depends on how bad. in Linux you can rmmod to get rid of the bad one if you haven't wedged it and fix your code, compile, and try again. I can't imagine that's actually different on windows if you know what you're doing. how do you think driver development happens?
- Dylan16807 2y ago
- nilamo 2y agoYour car _allows_ you to drive off a cliff. If you do so, it is your fault, not the fault of the car manufacturer. Kind of weird that anyone is blaming Microsoft for any part of this, imo
- fishywang 2y agoThe big difference is that CS is not the user. In you analogy it's like your car allows you to drive off a cliff, and an (almost) essential part of your car (for example, the pedal) drives the car off a cliff.
- jayd16 2y agoIf it's a custom after market part, how can you blame the car manufacturer and not the part maker?
- nilamo 2y agoRight, so a slightly better analogy would be if you wanted to install a remote starter, but then you find out that they can only be installed into Fords, because other auto manufacturers (Apple, Linux in this case) believe that tampering with the critical path (the engine, kernel) is unsafe. It isn't Ford who's at fault for allowing you to run some random engine modification, it's that mod that is at fault.
- vel0city 2y ago> CS is not the user It got there because a user or administrator approved and installed it. It didn't just appear there, Microsoft didn't install it there. The user ran it.
- wokwokwok 2y agoMmm… meaningless analogies are kind of meaningless? More like: If you install a security product that then prevents your car from starting; are they entirely blameless for letting you install it? If you pull the hood up, tear off the “voids warranty” seal, ignore the “don’t open this” labels, crack the seals open and shove something into the engine… sure. …but if you just slap a widget with the “vendor approved” sticker on your dash and it bricks your car; that’s a bit sucky right? I do feel Microsoft is not entirely blameless in this. It should be easier to recover from this kind of thing. They should have been paying attention and made a fuss that one of the biggest security vendors has been doing this literally since they started. I would bet money that until two weeks ago Microsoft was high-5ing them for best security practices. It’s not “their fault” but they can’t just go “wasn’t us!”. It was them. It wasn’t macOS. It wasn’t *nix. Suck it up. They should’ve done better.
- 999900000999 2y agoAn OS flexible enough where you can do something stupid enough to completely break it. Basically IOS which is so locked you can't even run apps not expressively approved by Apple. Pick one. If I build a bike and you remove the breaks to save weight don't get mad at me when you crash.
- scarface_74 2y agoMicrosoft tried to lock down kernel access in the Windows Vista era. Antivirus vendors went crying to the EU and they forced Microsoft to allow access to the kernel to third parties.
- freeopinion 2y agoWhen a parking valet takes a car on a joy ride and crashes into a tree, we could blame the tree. We could blame the car owner for handing over the key. We could blame the auto manufacturer that didn't provide a "valet mode". We could blame the police for not detecting the joy ride before the crash. All of these parties could do better (stupid tree!). But the real problem is the valet. We can say that it is obvious that the electronics-heavy cars of today should anticipate rogue valets and build in protections. But we shouldn't let rogue valets off the hook for damages. As a consumer, you could choose to only purchase cars that have "valet mode". So should we blame consumers who don't? If so, we should blame the airlines, hospitals, etc.--not Microsoft. How about we prosecute valets unless they refuse to park cars that don't have "valet mode"?
- Proziam 2y agoYou could also prosecute the establishment that keeps a valet with an abominable record on staff. Microsoft took no steps to force-eject them from their ecosystem, despite their long history of issues.
- rk06 2y agoCan Microsoft legally ban a competitor for percieved incompetence? I doubt it . partiuclarly seeing how much competence is shown with windows and MS teams software
- sim7c00 2y agoMicrosoft assigns driver levels to these guys etc. and allows them to load kernel mode components as protected etc.. If they do not allow that - CS cannot cause such damages. ofcourse, as you pointed out, this will then turn into some lawsuit blaming MS for killing competitors, even if they do it to try and protect their customers. wonderful world.
- freeopinion 2y agoJust to be clear within the analogy: are you expecting the auto manufacturers to "force-eject" any hotel on Park Ave that has a record of valet mishaps? Or did you mean individual cars should force-eject the valet? If a Caesars Entertainment property in Macao has enough incidents, should GM update the firmware on their automobiles to force-eject valets at Caesars Entertainment properties in Las Vegas? Now imagine that GM actually operates valet services in Macao and Las Vegas. Should they be allowed to force-eject valets from competing services? I am not a Microsoft apologist. I think they should do better. I think Linux and FreeBSD should do better. I personally avoid Microsoft products. But I place more blame on people who use MS products than I do on MS. After all, I never intend to hand my beat up old Corolla over to a valet so why should I have to pay for a "valet mode" feature that Toyota is forced to build into all their cars? Isn't it reasonable that motorcycles, 18-passenger vans, and scooters don't need "valet mode"? In my book, the auto manufacturer is lower on the list of culprits than the valet, "the establishment that keeps a valet with an abominable record on staff", and the vehicle owner. But some place like Car and Driver could definitely prioritize encouraging GM or Toyota to develop valet modes over berating owners; so I don't mind a place like HN shooting a few arrows at MS. Unless the general public follows their lead and lets bad guys off the hook by shifting too much focus to somebody lower on the list.