Microsoft Experimenting with Controlled Folders in Windows 10 against ransomware

Published by

Click here to post a comment for Microsoft Experimenting with Controlled Folders in Windows 10 against ransomware on our message forum
data/avatar/default/avatar13.webp
About time M$ did something. Have had exploit mitigations since 2013 and ransomware protection for a while.
https://forums.guru3d.com/data/avatars/m/239/239175.jpg
I got access to the source code of that feature:
if (nsa_backdoor_we_were_ordered_to_add_is_in_use()) {
    return true;
}
return false;
data/avatar/default/avatar04.webp
I got access to the source code of that feature:
if (nsa_backdoor_we_were_ordered_to_add_is_in_use()) {
    return true;
}
return false;
FTFY
return nsa_backdoor_we_were_ordered_to_add_is_in_use();
data/avatar/default/avatar15.webp
i think it will block nothing and make everything slower. To protect some folders the software has to listen to each write access, check the app, return something, then the write/change can happen right?
https://forums.guru3d.com/data/avatars/m/196/196284.jpg
Now they just need to add something to protect against MS ignorance.....and a feature to protect users from MS Customer Support's hatred of customers...
https://forums.guru3d.com/data/avatars/m/259/259654.jpg
This is just an ACL rule that says that an application that hasn't create a specific folder, then it can't change it. Which makes sense and it would block the vast majority of ransomware, since they won't be able to write to folders they haven't created. The comments in this thread gave me a brain tumor.
https://forums.guru3d.com/data/avatars/m/232/232349.jpg
Now they just need to add something to protect against MS ignorance.....and a feature to protect users from MS Customer Support's hatred of customers...
HAHAHAHAHAHAH..... Right on..... One reason I pay for an "official license" from MS as I prefer to speak to someone of my native speaking tongue as opposed to "pooky pooky" asking you some lame arse questions...
https://forums.guru3d.com/data/avatars/m/196/196284.jpg
HAHAHAHAHAHAH..... Right on..... One reason I pay for an "official license" from MS as I prefer to speak to someone of my native speaking tongue as opposed to "pooky pooky" asking you some lame arse questions...
I have an "official license"....but since all my systems are "up-to-date", they're now telling me I have to wipe my system and reinstall Windows to activate it....which sounds like they broke the activation scheme, but they also tell me it was intentional, which means MS should be covering any and all related costs for people who upgrade after installing CU, since that's when they intentionally broke the activation scheme. Then they had the nerve to tell me it's my fault Windows won't activate because I chose to upgrade my hardware.... Makes me happy that Windows is no longer the #1 OS worldwide. Hopefully ChromeOS will overtake Windows next... They get all pissy when you refuse to allow a remote connection....lol
https://forums.guru3d.com/data/avatars/m/56/56686.jpg
The build is a test version of the Fall Creators Update that is scheduled for the end of this year
I tell you I am NOT keen on this every 6 month lets have USER reinstalled windows. cause they cant do these with out screw the process up some how. Hell clean installs of CU has issues, namely the startmenu/bar be broke right off the bat, I have had no less then 4 clean installs on 4 different computer that never had Startmenu/bar issue have broke startmenu/bar on install. Either pin to start didnt work, or removing stuff from it, and closing off the tile part, would all be revert back to way it was upon restarts. had atlest 2 computer that did the in place upgrade upon first boot had ALL pinned tiles become invalid and pin to start didnt work, along with all installed programs where no longer listed in "all apps" they were all still installed though and reinstalling said program does put any of entries back in the "all apps" list. I wonder is next build update will continue the thrend of fix startmenu/bar bug from last build but add diffrent one on the new build
https://forums.guru3d.com/data/avatars/m/268/268700.jpg
"When users mark a folder as being a Controlled Folder, then only software which is not blacklisted can make modifications". So you will have to wait for microsoft to blacklist new malware, is it any difference between waiting for releasing patch and waiting for blacklist? Will it blacklist suspicious behavior automatically? Will it blacklist windows itself? If you not mark folder then will windows defender allow harmful software to modify everything? Or will it just block everything what is not from ms store?
https://forums.guru3d.com/data/avatars/m/242/242134.jpg
A feature i can already get in form of a small prog thats free and not from MS.. Cyberreason protection..
https://forums.guru3d.com/data/avatars/m/243/243702.jpg
This is just an ACL rule that says that an application that hasn't create a specific folder, then it can't change it. Which makes sense and it would block the vast majority of ransomware, since they won't be able to write to folders they haven't created. The comments in this thread gave me a brain tumor.
What? That sounds like Android's special user for each application 😀
"When users mark a folder as being a Controlled Folder, then only software which is not blacklisted can make modifications". So you will have to wait for microsoft to blacklist new malware, is it any difference between waiting for releasing patch and waiting for blacklist? Will it blacklist suspicious behavior automatically? Will it blacklist windows itself? If you not mark folder then will windows defender allow harmful software to modify everything? Or will it just block everything what is not from ms store?
Well, everything except binaries present in given installation tree may be blacklisted by default. As long as user is allowed to whitelist app of his choosing. But the mess... I already dislike TrustedInstaller. Adding another evil mechanism is not going to make me happy.
https://forums.guru3d.com/data/avatars/m/259/259654.jpg
What? That sounds like Android's special user for each application 😀 Well, everything except binaries present in given installation tree may be blacklisted by default. As long as user is allowed to whitelist app of his choosing. But the mess... I already dislike TrustedInstaller. Adding another evil mechanism is not going to make me happy.
I actually like TrustedInstaller 🤓 I like Linux for the same reason, it's almost impossible for a single program or use to take down the system. Microsoft should do a logical arrangement of their Windows folder next.
https://forums.guru3d.com/data/avatars/m/196/196284.jpg
I actually like TrustedInstaller 🤓 I like Linux for the same reason, it's almost impossible for a single program or use to take down the system. Microsoft should do a logical arrangement of their Windows folder next.
In a properly configured Linux install, the root account is only logged in for administration purposes. In Windows, the admin account is used by default for most installs. If Windows enforced creation of separate user and admin accounts, it would be more secure.
data/avatar/default/avatar01.webp
In a properly configured Linux install, the root account is only logged in for administration purposes. In Windows, the admin account is used by default for most installs. If Windows enforced creation of separate user and admin accounts, it would be more secure.
Then every 'power user' would be enraged they were forced to create an extra account.
https://forums.guru3d.com/data/avatars/m/259/259654.jpg
In a properly configured Linux install, the root account is only logged in for administration purposes. In Windows, the admin account is used by default for most installs. If Windows enforced creation of separate user and admin accounts, it would be more secure.
Windows doesn't have an admin account active since the days of Windows 8.
https://forums.guru3d.com/data/avatars/m/196/196284.jpg
I'm using the "default" account on my system and it clearly states "Administrator" in the account info screen... I'm running Windows 10 build 1703 Click here for Screenshot
https://forums.guru3d.com/data/avatars/m/259/259654.jpg
I'm using the "default" account on my system and it clearly states "Administrator" in the account info screen... I'm running Windows 10 build 1703 Click here for Screenshot
Sorry, I was mistaken. The admin account is actually disabled since Vista. The administrator you see in your screenshot is your account's escalation allowance. The actual administration account has full privileges and requires no escalation. There is a ton of difference in what they can do.
https://forums.guru3d.com/data/avatars/m/243/243702.jpg
I actually like TrustedInstaller 🤓 I like Linux for the same reason, it's almost impossible for a single program or use to take down the system. Microsoft should do a logical arrangement of their Windows folder next.
That's because you never had to fight your access to folders/files this thing considered as its own. In comparison to linux, you write one command, and you own all you want. In windows, you need to do a lot of steps to get even write rights to TrustedInstaller locations. (read Program Files and such) It is one of the reasons why I install most of the stuff outside PF folders.
https://forums.guru3d.com/data/avatars/m/175/175902.jpg
I like all the effort to secure Windows... But all of this is already in most Linux distro as it is logical. 😛c1: *edit* and unix based OS too btw