Hacker News new | ask | show | jobs
by Cthulhu_ 692 days ago
In the article it states that Microsoft HAD to allow Crowdstrike to run in kernelspace by EU laws, because else MS would have the monopoly on kernel-level security solutions / integrations.
4 comments

They probably had to, in the same way that banks had to use crowdstrike. Much as it's easy for banks to say "we use crowdstrike, like everyone else" rather than implement a bespoke and accountable framework for risk assessment and mitigation for every type of endpoint use case (and argue that case to both the auditor and regular). In this case it's easier for Microsoft to say "see, they can run in kernel space" rather than provide a bunch of API functions that achieve what's needed, convince all third party vendors to use them, and put in place a process to convince an auditor that Microsoft security software will never use any knowledge or functionality from the OS outside this.
Exactly this. Microsoft did this poorly, so they were forced to allow others to do things poorly too.
I guess I don't think that's the sole reason, as I think the incentives would still be in place even if Microsoft authored security software did not run anything in kernel space.
You mean in terms of third-parties wanting that level of access regardless? I agree, but it would be an easy "no" then.
In terms of Microsoft convincing regulators that they aren't and won't use any OS knowledge or private APIs ever.
Did they have to?

Or did they choose to keep their own security software to run in kernel space thus forcing themselves to let others play by the same rules?

They had to allow the same kind of access they have on their own "security" software.

Nothing in that means they need ring-0 access.

So why didn't MS lock it down in the US if it's an EU-local rule? Their excuse isn't plausible.
You're spilling cheap propaganda. Microsoft likely never had[0] an appropriate userland-level API in place and them blaming the EU should not be repeated by someone calling themselves a journalist.

[0] https://www.youtube.com/watch?v=EGttFWntctU - I need to state here that I do not possess the level of knowledge the author of video presents and therefore am unable to confirm findings included in the video

> Microsoft likely never had

And we're back to Microsoft -- they are responsible for not having a proper way to handle such third-party apps, nor they maintained a process and controls to prevent such rogue breaking updates.