- cross-posted to:
- nottheonion
- technology
- cross-posted to:
- nottheonion
- technology
Microsoft has Windows Defender, its in-house alternative to CrowdStrike, but because of the 2009 agreement made to avoid a European competition investigation, had allowed multiple security providers to install software at the kernel level.
Its all the EU’s fault for having the temerity to think users should be able to control their own hardware instead of us!
I’m still to see the doc where MS is forced to give ring-0, certified, boot-start to everyone.
JUST LET US BE A MONOPOLY!!!
If a EU regulation was at fault, only systems in the EU should’ve been affected. There would be no reason to adhere to complicated EU rules everywhere else globally.
This doesn’t add up. They need to find a more believable fall guy.
I blame their parents!
And video games!
And satanic music!There would be no reason to adhere to complicated EU rules everywhere else globally.
But there are a ton of websites that do adhere to complicated GDPR rules even though they serve 99.99% US based clients.
I think this has nothing to do with EU and it’s just some far fetched bullshit excuse from Microsoft.
This argument makes zero sense.
Why exactly?
So I don’t agree with this blame game, but in order to limit the scope of this to EU, they would have had to maintain two different designs, so it just makes sense to change the global design to suit the EU agreement. If it were something like bundling, then that’s light enough to maybe change regionally, but it’s too much to maintain a whole other kernel architecture.
Happens all the time with regulations. For example my company doesn’t have different products to comply with different environmental regulations, they just compose the strictest superset of the international regulations and follow those. California passes a law and it may change the global strategy.
deleted by creator
Why is Microsoft defending Crowdstrike?
My guess: Because they reviewed and signed the kernel space code which calls code that is unreviewed and unsigned (or, at the very least, pulls directly from files that are unreviewed and unsigned without proper validation or error checking), calling out CrowdStrike’s failure puts them on the hook too.
They aren’t, it’s more “it’s the EUs fault for forcing us to allow businesses like cloud strike to write kernel level antivirus, because we already have our own.”
Exactly, wtf.
Typical MS gaslighting and manipulation to subvert meaningful regulation.
Then,Microsoft,just leave EU. Simple.
Msexit
blEU screen of death
They should, but then they’d be replaced by other US multinationals. So they won’t.
The EU (and not just the EU by the way) loves US tech. It can’t get enough. They both play a cat and mouse game with each other for the public but the EU aren’t going to force MS out and MS aren’t going to leave.
Put it another way, of the EU wanted to be principled and demand fairness for EU citizens they’d take away MS (and other US multinational’s) tax breaks via Dublin. But they’re not going to do that.
Put it another way, of the EU wanted to be principled and demand fairness for EU citizens they’d take away MS (and other US multinational’s) tax breaks via Dublin. But they’re not going to do that.
The EU is literally doing that.
Literally dragging their heels over this. The biggest opposition was from EU bloc nations.
Now Ireland have eventually signed up to this but it’s a minimum threshold. i.e. they’re still highly comfortable about letting US multinational’s get away with complex tax arrangements in the EU to lower the amount they pay.
tl;dr The crash came from kernel level influence that Microsoft was blocked from denying by regulation.
This is a good thing for consumers as it continues to allow the user more control over the computer.
This doesn’t have anything to do with user control - modern windows versions need drivers to be WHQL signed to get that kind of access. Alternatively you’ll need to enable developer mode on your system, and install your own developer certificate into its keyring for running own code, which has its own drawbacks.
Crowdstrike is implemented as a device driver - but as there is no device Microsoft could’ve argued that this is abusing the APIs, and refused the WHQL certification. Microsofts own security solution (Defender) also is implemented as a device driver, though, and that’s what the EU ruling is about: Microsoft needs to provide the same access they’re using in their own products to competitors. Which is a good thing - but if Microsoft didn’t have Defender, or they’d have done it without that type of access it’d have been fully legal for them to deny the certification for Crowdstrike.
Both MacOS and Linux have the ability to run the type of thing that requires those privileges on Windows in an unprivileged process - and on newer Linux versions Crowdstrike is using that (older versions got broken by them the same way they now broke Windows). So Microsoft now trying to blame the EU can be seen as an attempt to keep people from questioning why Microsoft didn’t implement a low privilege API as well, which would’ve prevented this whole mess.
Yeah, it’s all the EU’s fault and not at all companies pushing updates whenever. “Here’s a new update, we’ll install and restart your PC. Fuck you”
I know, it was a security update, patching a possible attack vector. I will take a very wild guess here and say that this has caused much more damage than what the update would ever protect from