TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft’s out-of-date driver list left Windows PCs open to malware attacks

85 点作者 bubblehack3r超过 2 年前

7 条评论

coredog64超过 2 年前
I can no longer find the thread as this link has spammed Twitter search, but there was some drama earlier in the week about this same issue. Apparently some security researchers were unable to make the feature work and reached out to Microsoft. A Microsoft VP then condescended to their good faith questions and gave a weasel-wordy response that the fix for the feature is in the pipeline. However, if you're not aware of this specific issue, his response reads like the feature is enabled.
评论 #33227366 未加载
gw99超过 2 年前
I&#x27;m more worried that this is unsurprising to me now rather than it being an issue. The sheer amount of fragmentation, poor engineering, poor commercial decisions and quality issues that surround the Microsoft ecosystem is quite frankly at this point inexcusable.<p>They really need to get themselves together on the Windows front. Actually all fronts. Even Office is a fucking shit show these days and that was the last bastion of common sense on the platform.<p>As a former MS dev dating all the way back to the early 1990s, I don&#x27;t own or work with their platforms as of 2021. My pain threshold isn&#x27;t high enough. I implore the shareholders to kick the entire board out and install some people with good intentions and clue sticks.<p>Until then I will be doing my absolute best to steer everyone I know away from the pain.
评论 #33227185 未加载
评论 #33226573 未加载
评论 #33226551 未加载
评论 #33295599 未加载
tinus_hn超过 2 年前
Windows 10 has for years automatically loaded a driver for certain Logitech webcams that adds a class driver to all media devices, which can’t be loaded if you have the security turned up. So the result is you can’t load sound drivers anymore, because the class driver which can’t be loaded now is a prerequisite.<p>I sincerely doubt anyone at Microsoft ever tests all those drivers that are shipped with Windows and the automatic driver loading service in Windows Update.
stjohnswarts超过 2 年前
Ars has a good article as well as mentions a script to help<p><a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2022&#x2F;10&#x2F;how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2022&#x2F;10&#x2F;how-a...</a>
ocdtrekkie超过 2 年前
I assume this didn&#x27;t get as high a level of scrutiny because it still fundamentally requires you admin-elevate the running of code from a questionable source. Sure a bad driver might claim it&#x27;s from Dell, but it wasn&#x27;t one you downloaded from dell.com so you probably shouldn&#x27;t be trusting it.<p>Raymond Chen has largely pointed out the position of Microsoft that if you authorize code to run with elevated permissions and it does things it can do with elevated permissions, it&#x27;s not really a security flaw.
评论 #33227347 未加载
评论 #33226956 未加载
评论 #33228638 未加载
评论 #33226841 未加载
rodgerd超过 2 年前
A reminder that &quot;support arbitrary hardware&quot; and &quot;secure&quot; is a really, really fucking difficult problem.
评论 #33227524 未加载
评论 #33228649 未加载
pedro2超过 2 年前
Wow. Just wow.