3 ms·
The prevalence of 3rd party kernel-level code is an important factor too. Lots of windows malware relies on a vulnerable 3rd party kernel driver at some point.
by robhlt 2y ago
The prevalence of 3rd party kernel-level code is an important factor too. Lots of windows malware relies on a vulnerable 3rd party kernel driver at some point.
By comparison, 3rd party kernel modules are rare and looked down upon on Linux and outright banned on macOS.
- makeitdouble 2y agoTo note, Windows isn't allowed to completely block third party kernel code. I don't have the reference at hand but it was part of their various anti-trust fallout, as it would give them an unfair advantage regarding to their own products. PS: an analysis of that situation during the Crowdstrike issue, with the relevant bits of the EU ruling: https://www.computerweekly.com/news/366598838/Why-is-CrowdStrike-allowed-to-run-in-the-Windows-kernel https://www.computerweekly.com/news/366598838/Why-is-CrowdSt...
- spockz 2y agoWhat might be enough is to have windows required to boot in a “install” mode before 3rd party kernel code can be added.
- LinXitoW 2y agoIANAL, but this seems more like a classic temper tantrum thrown by a big corp over reasonable legislation. They could offer an API for security relevant scanning for EVERYONE, including their own antivirus software. But that would make the world better, and make the legislation look justified. It's the exact same thing with the Google Maps integration on Google Search. They could offer an API and a selection of map provider to the user. That would make Google Search better for the user AND enable competition. Instead they threw a temper tantrum and disabled map integration entirely, so they can blame the EU.
- dwattttt 2y ago> They could offer an API for security relevant scanning for EVERYONE, including their own antivirus software I mean, they have _lots_ of APIs. You'll just never have as much control from usermode as you will from the kernel; what API would make you say "yep, don't need a driver now, can do security fine from user"?
- makeitdouble 2y agoI see your point, while also seeing it as a more complex situation. APIs means Microsoft gets to dictate what products exist in the first place. We know security software is a use case, but if for instance VR vendors come up with a completely different use case, will the existing APIs be enough for them ? And what recourse do they have if Microsoft either doesn't give a damn, or purposefully drags their feet for whatever reason ?
- dagmx 2y agoThere’s two parts to it. Microsoft claims they need kernel level access to implement their paid for security product ( Windows defender while free for home use is not free for enterprise ) If they firmly believe that, then they cannot block other software from having the same access or it would be anti trust. They could perhaps make it free and bundled in windows, but they don’t want to lose the enterprise funding.
- camus_absurd 2y agoNot banned, you just have to go through some hoops to enable installation of third party kernel extensions
- heavyset_go 2y agoApple has blessed some external kexts so they aren't outright banned, just very restricted.