Earlier quoted context omitted.
>Microsoft are signing kernel drivers for over-the-air updates pushed by vendors. The crash was caused by a configuration update pushed by crowdstrike, not a new driver. >Whilst telling their corporate customers that using Microsoft InTune will allow them to be in full control of their configuration management. How is this relevant? This wasn't caused by some sysadmin that goofed a config change using intune, it's so…
> The crash was caused by a configuration update pushed by crowdstrike, not a new driver. Microsoft didn’t do enough due diligence on the behaviour of CrowdStrike updates. It shouldn’t allow out-of-band updates. Third-parties should not be signing code that allows third-parties to reach into corporate services and push files. Microsoft InTune is the mechanism that all configuration updates should use. It appears to m…
You want Microsoft to be doing code reviews of third party software? That might have prevented this disaster but would get them in hot waters for other reasons (eg. anti-competition accusations). Not even Apple gatekeeps that hard.
>Third-parties should not be signing code that allows third-parties to reach into corporate services and push files.
So dropbox should be banned as well? It's also a third party service that pushes files onto computers.
>Microsoft InTune is the mechanism that all configuration updates should use.
Okay, so crowdstrike pushes its virus definition updates via intune instead. The bad file still lands on computers, the kernel mode driver still crashes before the computer can boot and the computer is bricked. How is this any better?