• Womble@lemmy.world
    link
    fedilink
    English
    arrow-up
    140
    arrow-down
    3
    ·
    5 months ago

    Microsoft has Windows Defender, its in-house alternative to CrowdStrike, but because of the 2009 agreement made to avoid a European competition investigation, had allowed multiple security providers to install software at the kernel level.

    Its all the EU’s fault for having the temerity to think users should be able to control their own hardware instead of us!

  • norimee@lemmy.world
    link
    fedilink
    English
    arrow-up
    91
    arrow-down
    6
    ·
    5 months ago

    If a EU regulation was at fault, only systems in the EU should’ve been affected. There would be no reason to adhere to complicated EU rules everywhere else globally.

    This doesn’t add up. They need to find a more believable fall guy.

    • Tetsuo@jlai.lu
      link
      fedilink
      English
      arrow-up
      28
      ·
      5 months ago

      There would be no reason to adhere to complicated EU rules everywhere else globally.

      But there are a ton of websites that do adhere to complicated GDPR rules even though they serve 99.99% US based clients.

      I think this has nothing to do with EU and it’s just some far fetched bullshit excuse from Microsoft.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          5 months ago

          So I don’t agree with this blame game, but in order to limit the scope of this to EU, they would have had to maintain two different designs, so it just makes sense to change the global design to suit the EU agreement. If it were something like bundling, then that’s light enough to maybe change regionally, but it’s too much to maintain a whole other kernel architecture.

          Happens all the time with regulations. For example my company doesn’t have different products to comply with different environmental regulations, they just compose the strictest superset of the international regulations and follow those. California passes a law and it may change the global strategy.

    • Thurstylark@lemm.ee
      link
      fedilink
      English
      arrow-up
      45
      arrow-down
      1
      ·
      5 months ago

      My guess: Because they reviewed and signed the kernel space code which calls code that is unreviewed and unsigned (or, at the very least, pulls directly from files that are unreviewed and unsigned without proper validation or error checking), calling out CrowdStrike’s failure puts them on the hook too.

    • Strykker@programming.dev
      link
      fedilink
      English
      arrow-up
      12
      ·
      5 months ago

      They aren’t, it’s more “it’s the EUs fault for forcing us to allow businesses like cloud strike to write kernel level antivirus, because we already have our own.”

    • mannycalavera@feddit.uk
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      5 months ago

      They should, but then they’d be replaced by other US multinationals. So they won’t.

      The EU (and not just the EU by the way) loves US tech. It can’t get enough. They both play a cat and mouse game with each other for the public but the EU aren’t going to force MS out and MS aren’t going to leave.

      Put it another way, of the EU wanted to be principled and demand fairness for EU citizens they’d take away MS (and other US multinational’s) tax breaks via Dublin. But they’re not going to do that.

      • mosiacmango@lemm.ee
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        5 months ago

        Put it another way, of the EU wanted to be principled and demand fairness for EU citizens they’d take away MS (and other US multinational’s) tax breaks via Dublin. But they’re not going to do that.

        The EU is literally doing that.

        • mannycalavera@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 months ago

          Literally dragging their heels over this. The biggest opposition was from EU bloc nations.

          Now Ireland have eventually signed up to this but it’s a minimum threshold. i.e. they’re still highly comfortable about letting US multinational’s get away with complex tax arrangements in the EU to lower the amount they pay.

  • Toes♀@ani.social
    link
    fedilink
    English
    arrow-up
    17
    ·
    edit-2
    5 months ago

    tl;dr The crash came from kernel level influence that Microsoft was blocked from denying by regulation.

    This is a good thing for consumers as it continues to allow the user more control over the computer.

    • aard@kyu.de
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      5 months ago

      This doesn’t have anything to do with user control - modern windows versions need drivers to be WHQL signed to get that kind of access. Alternatively you’ll need to enable developer mode on your system, and install your own developer certificate into its keyring for running own code, which has its own drawbacks.

      Crowdstrike is implemented as a device driver - but as there is no device Microsoft could’ve argued that this is abusing the APIs, and refused the WHQL certification. Microsofts own security solution (Defender) also is implemented as a device driver, though, and that’s what the EU ruling is about: Microsoft needs to provide the same access they’re using in their own products to competitors. Which is a good thing - but if Microsoft didn’t have Defender, or they’d have done it without that type of access it’d have been fully legal for them to deny the certification for Crowdstrike.

      Both MacOS and Linux have the ability to run the type of thing that requires those privileges on Windows in an unprivileged process - and on newer Linux versions Crowdstrike is using that (older versions got broken by them the same way they now broke Windows). So Microsoft now trying to blame the EU can be seen as an attempt to keep people from questioning why Microsoft didn’t implement a low privilege API as well, which would’ve prevented this whole mess.

  • I Cast Fist@programming.dev
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    5 months ago

    Yeah, it’s all the EU’s fault and not at all companies pushing updates whenever. “Here’s a new update, we’ll install and restart your PC. Fuck you”

    I know, it was a security update, patching a possible attack vector. I will take a very wild guess here and say that this has caused much more damage than what the update would ever protect from