Tired Bunny :bunhdcomfysleep:
Sleepiest certified shitcoder :verified:
Warnings:
Account can contain small amounts of NSFW content.
-– Contacts + full description —
EN
https://tired-bun.neocities.org/
RU
https://tired-bun.neocities.org/ru/
- 0 Posts
- 1 Comment
Joined 2 年前
Cake day: 2023年7月10日
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
@dueuwuje @mudle
If I understand it correctly, it already has been (at least formally) reviewed by microsoft before signing and allowing that signed code run kernel-mode. But the crowdstrike’s driver module was not just running malware scanner on itself, it was interpreting what is basically unsigned code that was easier and faster to update. This unsigned files were the ones containing faulty update.
At least that what I understand from https://www.youtube.com/watch?v=wAzEJxOo1ts , it may not be entirely correct or I may have misunderstood.
But if it is true, it may be more sensible to make an API so software with specific permissions could access information needed to effectively function as antivirus, without being run in kernel mode.