Microsoft is addressing the recent CrowdStrike update issue that affected 8.5 million PCs.
The company is now suggesting changes to Windows and hinting at making the operating system more resilient.
This could potentially limit security vendors’ access to the Windows kernel.
CrowdStrike’s recent buggy update caused widespread issues because its software operates at the kernel level – the core of the operating system.
This level of access means errors can cause serious problems, like Blue Screens of Death.
Microsoft’s Response John Cable, vice president of program management for Windows servicing and delivery, stated in a blog post, “This incident shows clearly that Windows must prioritize change and innovation in the area of end-to-end resilience.” He called for closer collaboration with partners to enhance Windows security.
While not specifying exact improvements, Microsoft hinted at new directions:
Cable explained, “These examples use modern Zero Trust approaches and show what can be done to encourage development practices that do not rely on kernel access.” He added, “We will continue to develop these capabilities, harden our platform, and do even more to improve the resiliency of the Windows ecosystem, working openly and collaboratively with the broad security community.”
Microsoft attempted to restrict kernel access in Windows Vista in 2006 but faced opposition from security vendors and EU regulators.
In contrast, Apple successfully locked down macOS kernel access in 2020.
Any changes to Windows kernel access will require careful consideration.
Cloudflare CEO Matthew Prince has warned about potential negative effects of Microsoft locking down Windows further.
Microsoft needs to balance improving system resilience with the needs of security vendors who rely on kernel-level access.
The company suggests it’s open to collaboration, but the path forward may involve significant changes to how security software interacts with Windows.
The recent CrowdStrike update issues were caused by its software operating at the kernel level, leading to widespread problems like Blue Screens of Death.
Microsoft is suggesting changes to Windows to enhance end-to-end resilience, potentially limiting security vendors’ access to the Windows kernel and collaborating more closely with partners.
Microsoft is hinting at introducing features like VBS enclaves, which don’t require kernel mode drivers for tamper resistance, and leveraging the Azure Attestation service for security improvements.
Kernel-level access is a concern because it can cause severe system issues if there are errors in the software, highlighting the need for more resilient and secure operating system practices.
Microsoft needs to balance improving system resilience while considering the needs of security vendors who rely on kernel-level access, ensuring any changes are carefully implemented.
Also Read: Microsoft and CrowdStrike Update: Global IT Outage Triggers Major Disruptions Across Sectors
Also Read: The Great Windows Crash of 2024: CrowdStrike Update Causes Global Chaos
Highlights Redmi 17 5G global variant leaked with flat-edge design, large camera island, Orange/Black/Blue colours…
Highlights Two Oppo Find X10 models have received network approval in China, suggesting a late…
Highlights iQOO India CEO Nipun Marya has teased the iQOO Z11 with cryptic posts and…
Highlights Redmi K100 Pro Max is powered by Snapdragon 8 Elite Gen 5, AI D2…
Highlights Samsung Galaxy F70 Pro 5G is scheduled to launch in India on August 3.…
Highlights Poco M8 Power leaked unboxed image reveals phone, case, 45W charger, USB cable, SIM…
This website uses cookies.