How a Microsoft blunder opened millions of PCs to potent malware attacks

Discussion in 'other security issues & news' started by BoerenkoolMetWorst, Oct 15, 2022.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I might have misunderstood, but I think I read somewhere that SIP on the macOS is supposed to protect against BYOVD attacks, since the kernel is more locked down. So even if drivers are loaded, they shouldn't be able to mess around with usermode hooks. Actually, here is a pretty good article:

    https://addigy.com/blog/key-takeaways-for-system-and-kernel-extensions-on-macos/

    It is indeed probably easier said than done. But with my kernel sandboxing idea, the OS itself should enforce drivers to behave correctly, that's all. So I'm not sure if it would break older drivers or drivers in general. I'm sure those smart guys that are employed by MS could come up with something.
     
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    In first paragraph I was talking about Linux.

    When it comes to macOS I don't know that much aside from knowing it is designed to run on Apple hardware. I suspect this makes things easier to secure against BYOVD.
     
  3. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,147
    Location:
    USA
    Nope. That was the early problem with Vista. They had to rewrite their drivers. It took them about a year to come up with good ones.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Yes I know you was talking about Linux, haven't looked into that. But macOS is supposed to better protect against BYOVD attacks because of the recent design change. So I'm sure this stuff might also be fixable in Windows, but it might cause problems with older software. And yes, having to rewrite apps and drivers is probably the biggest problem, just take a look at UWP which totally flopped.

    On the other hand, I sometimes also think that MS is not in a hurry to improve the inner design of Windows because of the billion dollar computer security industry. Why try to fix the ransomware problem by sandboxing apps when there are billions to be made with selling AV's and EDR systems to millions of companies?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.