Conversation
Edited 1 year ago

microsoft claiming that Administrator-to-kernel exploits aren't security issues ...

wtf. like wtaf

sure without secure boot or something you can yolo this, but that world is a decade in the past by now

https://arstechnica.com/security/2024/03/hackers-exploited-windows-0-day-for-6-months-after-microsoft-knew-of-it/

1
0
0

root-to-kernel exploits are security bugs. sure sometimes we make the plug conditional on kernel lockdown, but they are security bugs

stuff like this actually pushes me towards the "all bugs are security bugs" crowd, even though I still think that's a bit over the top

2
1
0
@sima "root-to-kernel" "exploits" are not security bugs. People are putting that security barrier in place, but it is not really there, and trying to pretend this fiction actually results in real damage.
0
1
1

@sima Not in most cases.

Remember that the goal of the security boundaries are to protect user data and operate the machine. If you're root you already have access to _that_.

Where this makes a bit more sense is pKVM and other isolation scenarios, but in the general case, not applicable.

1
0
0

@never_released @sima if you are using selinux they certainly are security bugs

0
0
0