Microsoft is addressing the recent CrowdStrike update issue that affected 8.5 million PCs.
The company is now suggesting changes to Windows and hinting at making the operating system more resilient.
This could potentially limit security vendors’ access to the Windows kernel.
CrowdStrike’s recent buggy update caused widespread issues because its software operates at the kernel level – the core of the operating system.
This level of access means errors can cause serious problems, like Blue Screens of Death.
Microsoft’s Response John Cable, vice president of program management for Windows servicing and delivery, stated in a blog post, “This incident shows clearly that Windows must prioritize change and innovation in the area of end-to-end resilience.” He called for closer collaboration with partners to enhance Windows security.
While not specifying exact improvements, Microsoft hinted at new directions:
Cable explained, “These examples use modern Zero Trust approaches and show what can be done to encourage development practices that do not rely on kernel access.” He added, “We will continue to develop these capabilities, harden our platform, and do even more to improve the resiliency of the Windows ecosystem, working openly and collaboratively with the broad security community.”
Microsoft attempted to restrict kernel access in Windows Vista in 2006 but faced opposition from security vendors and EU regulators.
In contrast, Apple successfully locked down macOS kernel access in 2020.
Any changes to Windows kernel access will require careful consideration.
Cloudflare CEO Matthew Prince has warned about potential negative effects of Microsoft locking down Windows further.
Microsoft needs to balance improving system resilience with the needs of security vendors who rely on kernel-level access.
The company suggests it’s open to collaboration, but the path forward may involve significant changes to how security software interacts with Windows.
The recent CrowdStrike update issues were caused by its software operating at the kernel level, leading to widespread problems like Blue Screens of Death.
Microsoft is suggesting changes to Windows to enhance end-to-end resilience, potentially limiting security vendors’ access to the Windows kernel and collaborating more closely with partners.
Microsoft is hinting at introducing features like VBS enclaves, which don’t require kernel mode drivers for tamper resistance, and leveraging the Azure Attestation service for security improvements.
Kernel-level access is a concern because it can cause severe system issues if there are errors in the software, highlighting the need for more resilient and secure operating system practices.
Microsoft needs to balance improving system resilience while considering the needs of security vendors who rely on kernel-level access, ensuring any changes are carefully implemented.
Also Read: Microsoft and CrowdStrike Update: Global IT Outage Triggers Major Disruptions Across Sectors
Also Read: The Great Windows Crash of 2024: CrowdStrike Update Causes Global Chaos
Highlights OnePlus Nord CE 6 has received its second price increase in India, now ₹4,000…
Highlights Oppo Reno 15A 5G debuts in Japan with three colour options. It is priced…
Highlights Vivo X Fold 6 confirmed with a 7,000mAh Blue Ocean battery using 5th‑gen silicon‑anode…
Highlights Vivo Y500 4G teased via Instagram in Nepal confirming global debut soon. Teasers confirm…
Highlights Honor X80 Pro Max will debut in China on June 22 and will be…
Highlights Vivo X Fold 6 will launch in four colours such as Blue Cave, Salt…
This website uses cookies.