Microsoft To Revamp Windows Kernel Access for Security Vendors (theverge.com)
(Friday September 13, 2024 @03:00AM (msmash)
from the moving-forward dept.)
Microsoft announced plans to modify Windows, enabling security vendors like CrowdStrike to operate outside the operating system's kernel. The move follows the July incident where [1]a faulty CrowdStrike update caused widespread system failures. From a report:
> Microsoft says it has now "discussed the requirements and key challenges in [2]creating a new platform which can meet the needs of security vendors " with partners like CrowdStrike, Broadcom, Sophos, and Trend Micro.
>
> [...] While Microsoft isn't directly saying it's going to close off access to the Windows kernel, it's clearly at the early stages of designing a security platform that can eventually move CrowdStrike and others out of the kernel. Microsoft last tried to close off access to the Windows kernel in Windows Vista in 2006, but it was met with pushback from cybersecurity vendors and regulators.
[1] https://it.slashdot.org/story/24/07/19/0943232/global-it-outage-linked-to-crowdstrike-update-disrupts-businesses
[2] https://www.theverge.com/2024/9/12/24242947/microsoft-windows-security-kernel-access-features-crowdstrike
> Microsoft says it has now "discussed the requirements and key challenges in [2]creating a new platform which can meet the needs of security vendors " with partners like CrowdStrike, Broadcom, Sophos, and Trend Micro.
>
> [...] While Microsoft isn't directly saying it's going to close off access to the Windows kernel, it's clearly at the early stages of designing a security platform that can eventually move CrowdStrike and others out of the kernel. Microsoft last tried to close off access to the Windows kernel in Windows Vista in 2006, but it was met with pushback from cybersecurity vendors and regulators.
[1] https://it.slashdot.org/story/24/07/19/0943232/global-it-outage-linked-to-crowdstrike-update-disrupts-businesses
[2] https://www.theverge.com/2024/9/12/24242947/microsoft-windows-security-kernel-access-features-crowdstrike