Earlier quoted context omitted.
not only allowing, but approving? they signed driver, right? linux also allows, by approval is decentralized
>by approval is decentralized Translation: it's up to whoever is the sysadmin is, which probably was responsible for crowdstrike being installed in the first place. Such "approval" would have made no difference in preventing this disaster.
Microsoft's global sprawl under fire from regulators after Windows outage
21–30 of 104 posts
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#22It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?
is not it the case that kernel drivers are signed and approved by microsoft?
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#23Re: Microsoft's global sprawl under fire from regulators after Windows outage
#24It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?
is not it the case that kernel drivers are signed and approved by microsoft?
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#25Earlier quoted context omitted.
>by approval is decentralized Translation: it's up to whoever is the sysadmin is, which probably was responsible for crowdstrike being installed in the first place. Such "approval" would have made no difference in preventing this disaster.
how 8.5M devices got approval to install? may they came with hard to disable windows autoupdate?
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#26Earlier quoted context omitted.
Would the disaster have been prevented if there was no code signing? Or are you arguing that Microsoft should scrutinize code even harder?
Microsoft isn’t scrutinizing this code, at all, right? It’s not like they’re doing code reviews of every vendor that does code signing in Windows.
said ms tests drivers
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#27It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#28It's CrowdStrike's fault that the kernel was faulty. It's Microsoft's fault that it caused a never ending bootloop that needed manual intervention to fix.
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#29It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?
Re: Microsoft's global sprawl under fire from regulators after Windows outage
#30It seems baffling that Microsoft is getting heat for this. They didn't cause the issue, a third party vendor's software did. Even if you were trying to make an argument of "if we had more diversity it wouldn't be as bad", shouldn't you be focusing on the EDR vendors rather than the OS vendor?
Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management.