@miki I think ClownStrike would've happened regardless of whether Microsoft allowed API access or not – they had a broken parser running in a kernel driver, and that doesn't need any special API access to break.
Top-level
@miki I think ClownStrike would've happened regardless of whether Microsoft allowed API access or not – they had a broken parser running in a kernel driver, and that doesn't need any special API access to break. 1 comment
|
@jernej__s It needs you to be able to run in kernel mode, a capability which Microsoft wanted to deprecate for security software following Apple's lead, but was forbidden to do so by the European Commission.