The Register Home Page

back to article Microsoft dials up the nagging in Windows, calls it security

Microsoft is introducing a raft of Windows security features that users and administrators alike might assume are already part of the operating system. Dubbed "Windows Baseline Security Mode" and "User Transparency and Consent," the updates are intended to deal with suspect behavior behind the scenes while also prompting the …

  1. Andy Non
    Coat

    "or wanders into a user's sensitive files."

    WARNING: Windows is trying to access your files! You are recommended to block this action.

    1. seven of five Silver badge

      Re: "or wanders into a user's sensitive files."

      "A program tries to access you outlook address book...."

      What did I do? right click a file in explorer, "send to email reciepient"

      1. Ramis101

        Re: "or wanders into a user's sensitive files."

        You might joke but yonks ago i installed Skype and was quite horrified when i found it had accessed my outlook .pst file and hoovered up all the contacts in it and added them to Skype.

        It did not ask before doing so. that was the day i stopped using outlook to store contacts.

        I find it ironic that the mighty MS is suggesting it will protect us from things it has done before itself, and probably continues to do now.

        1. Anonymous Coward
          Anonymous Coward

          Re: "or wanders into a user's sensitive files."

          Yeah, adding unrequested features like Recall and Copilot, that are security nightmares, then putting bandaids over other people's apps is ludicrous.

  2. Dan 55 Silver badge
    Meh

    This should be entertaining

    It's what Apple added to Mac OS because when they've run out of ideas the only thing left is to make it more like iOS. I think Apple only managed to make it work because of the more organised home directory format, but even so it's just a pointless pain in the arse. I can't see this working at all in Windows with the amount of files thrown around everywhere.

    1. T. F. M. Reader Silver badge

      Re: This should be entertaining

      "Apple only managed to make it work" for an independent freelance graphics designer who needs to confirm any system action 6 times and type the right password at least twice in the process. Unattended operations in a corporate setting are only possible - sometimes - with the help of companies like JAMF who need to be paid separately and keep chasing Apple's tail themselves all the time, not always successfully.

      Cue cursing from sysadmins and CISOs who need to deploy/update en mass, aa well as from QA engineers (especially with cybersecurity vendors whose products need elevated permissions to do their job) who need to test, among other things, installs, upgrades, uninstalls, reinstalls, compare different versions to check for regressions, and can't automate it because Apple decided that a user must get a password prompt, twice, and grudgingly admit there is no programmatic way around it.

      Frankly, I doubt that MSFT will manage to do something like this and keep their corporate customers happy, even with CrowdStrike's help.

    2. Anonymous Coward
      Anonymous Coward

      Re: This should be entertaining

      This is because Apple has app sandboxing by default (the change that you are referring to is when this became the default in MacOS - having previously been the standard in iOS).

      By default every app downloaded from the App Store launches in a private container. It is least privilege by default. By default, the app can only access its own container and declared (by the developer to Apple during app submission) resources - i.e. printer, or the network adapter. It can't break out of this container and access the file system, or RAM, etc.

      Most importantly, no app can ever access the data from another container/app without user permission. This is why your Facebook app needs permissions to access the data contained within your Photos app. They are two completely separate containers, hence requiring user permission.

      If you and the 23 other people who upvoted your comment still think this is a "pointless pain in the arse", you may want to consider an offline device, because whatever threat level exists in your head is about 30 years out of date.

      p.s. Windows 11 also somewhat does this (not as common, not as secure, but a start...) - msix apps from the MS Store, for example, run in AppContainer.

      1. FirstTangoInParis Silver badge

        Re: This should be entertaining

        Except when apps start asking to track your activity across other apps. Looking at you, Adobe Acrobat.

  3. Doctor Syntax Silver badge

    It looks like what's needed is a big global No.

  4. ParlezVousFranglais Silver badge

    intended to deal with suspect behavior behind the scenes...

    ...like, for instance, Copilot hoovering up all your data and activities and sending them off to Redmond?...

    1. xcdb

      Re: intended to deal with suspect behavior behind the scenes...

      Don't be silly! That will be controlled with a specific combination of 15 switches, found behind "Beware of the Leopard" signs...

      1. seven of five Silver badge

        Re: intended to deal with suspect behavior behind the scenes...

        ...behind the "Beware of the Leopard" sign on door behind the Leopard.

        1. The Oncoming Scorn Silver badge
          Pint

          Re: intended to deal with suspect behavior behind the scenes...

          This must be a patch Tuesday... I never could get the hang of patch Tuesdays.

          1. Anonymous Coward
            Anonymous Coward

            Re: intended to deal with suspect behavior behind the scenes...

            On this particular Patch Tuesday, things were moving through the filesystem far below the surface. Several huge, yellow, blob-like, somethings.

      2. shodanbo

        Re: intended to deal with suspect behavior behind the scenes...

        Don't forget that the switches get XORed together and 1 means "yes" and 0 means "hell yes"

    2. steviebuk Silver badge

      Re: intended to deal with suspect behavior behind the scenes...

      And Recall

  5. may_i Silver badge

    Long gone

    The time where anything Microsoft does with Windows could be described as "laudable" has well passed.

    1. GregC

      Re: Long gone

      I dunno, they could take it out back and put it out of our misery. I'd appreciate that.

      1. Anonymous Coward
        Anonymous Coward

        Re: Long gone

        I think the word you were looking for is 'applause', its a different word.

  6. elsergiovolador Silver badge

    Crawl

    Windows is crawling with just the Teams on and they want to mimic malware with a host of pop ups?

    What could go wrong.

    1. ThatOne Silver badge
      Facepalm

      Re: Crawl

      > What could go wrong.

      For Microsoft, nothing. For the users though...

      Anyway, once this is released, you will run to buy that new computer with a beefy CPU (or two) and at least 64 GB of RAM. Just to run Windows.

      1. PCScreenOnly Silver badge

        Re: Crawl

        Not spending £10k on a machine with that much RAM

        1. David 132 Silver badge
          Happy

          Re: Crawl

          Indeed, does @ThatOne think we're all made of money? 64GB?!?

      2. Derezed
        Trollface

        Re: Crawl

        Don't forget it will definitely need one of those AI chips so Recall works properly.

  7. Alberto Malich
    Alert

    App signing

    "This means only properly signed apps, services, and drivers. However, users and administrators can still override the safeguards for that one weird legacy app, and app developers can check if the protections are active and if any exceptions have been granted."

    I agree that a way of allowing granular access to whether or not software should be able to access the microphone and camera, should be present (and optional). However the above quote about "app signing" has me worried. How long will it be until they turn the screws some more and don't allow any unsigned software at all? Android is currently about to face this reality thanks to Google having complete control over the vast majority of the platform, and as a result a lot of software simply won't be able to run any more, or else it will be subject to restrictions put in place by Google.

    I am not against the idea of software being able to be signed by the developer: rather, I worry that the signing keys, and ability to meaningfully distribute Windows software, will be locked behind an agreement dictated by Microsoft at some point.

    1. Derezed
      Gimp

      Re: App signing

      Corporation leopards ate my face. I guess this was always going to happen...enshittification and monopoly. Not great for humanity....good for shareholders though.

    2. X5-332960073452
      Megaphone

      Re: App signing

      Remember Windows "S" Mode?

  8. JcRabbit

    They really are intent on making everyone move to Linux (or anything else BUT Windows).

    Not even properly OV signed apps from independent developers can escape SmartScreen now (unless you are a corporation and can afford/get EV certs), and most AV software assumes anything writing to a sub-folder of Public Documents (a perfectly legit folder to hold read/write application data until the advent of ransomware) can only be malware trying to encrypt all your files, so it MUST be SILENTLY blocked without warning the user MUCH LESS giving him a choice (daddy knows best, and users are too stupid to know what they are doing anyway). The application being silently blocked will take the fall as being "buggy" anyway, so win-win for the AV companies.

    So sick of this.

    1. ParlezVousFranglais Silver badge
      Coat

      users are too stupid to know what they are doing anyway

      In fairness though, users usually ARE too stupid to know what they are doing anyway... ツ

      1. Boris the Cockroach Silver badge

        Re: users are too stupid to know what they are doing anyway

        I think thats unfair

        Users are smart enough to dump the problems they cause onto the likes of the IT support........ then blame IT support for their computer being borked...

        Wheres the 'fed up with this shit' icon ?

  9. Sloth77

    Open source?

    Good luck running any open source software. When binaries are provided, they are rarely signed.

    1. Doctor Syntax Silver badge

      Re: Open source?

      Simple solution - run them on an open source OS. However, Microsoft signed motherboard firmware is a problem. Digital sovereignty is going to need coreboot.

  10. mickaroo

    Deja Vu All Over Again...

    Didn't they try this with Windows Vista?

    Every time the user clicked on ANYTHING, a UAC warning appeared to prevent you from achieving anything meaningful. Like regular work...

    Or am I mis-remembering?

    1. Syn3rg

      Re: Deja Vu All Over Again...

      I wonder if Apple will recycle these ads?

  11. Steve Davies 3 Silver badge
    Black Helicopters

    Another FootGun moment from Microsoft

    That's around five already this calendar year.

    As one poster said, this is another move in their attempts to get users to give Windows the middle finger.

  12. blu3b3rry Silver badge

    Feels like another step in turning Windows machines into overpowered dumb terminals with a "store" of MS approved crapware (likely with poor gatekeeping to boot) and nothing more.

    Or am I just being cynical?

  13. Blue Screen of Bleurgh

    Microsslop will ramp up security even further by insisting your webcam is constantly enabled so that a secret security app that no one knows about but was installed by stealth in a future security update will act as a retina scanner. If you haven't been "scanned" then you can't use Windows. Password, passkeys will be a thing of the past. They will want your blood (literally) to use future Windows versions.

  14. ZedaZ80
    Linux

    This'll be a win for the people (like me) who like when programs explicitly ask for permissions, but this just trains most people to click "okay" without a second thought. Though, I'm Windows-free, so it doesn't even apply to me!

  15. Anonymous Coward
    Anonymous Coward

    Secure and resilient runtime model :o

    Why not design an OS that can't be hacked by opening an email attachment or clicking on a malicious URL? That way we wouldn't need such protections as:

    Application Guard for Microsoft Edge

    Attack Surface Reduction (ASR)

    BitLocker

    BitLocker secure-boot

    Credential Guard

    DNS-based protections

    Encrypting File System (EFS)

    Exploit protection, including DEP, ASLR, CFG and GPO.

    Hypervisor-Enforced Code Integrity (HVCI)

    Kernel-mode Code Integrity (KMCI)

    Local Security Authority (LSA)

    Microsoft Defender Antivirus

    Microsoft Defender SmartScreen

    Microsoft Defender’s cloud-delivered protection

    Microsoft security

    Network Access Protection

    Ransomware protection

    Rights Management

    Secure Boot (UEFI)

    Smart Card and FIDO2

    System Guard

    Trusted Platform Module (TPM) support

    User Account Control (UAC)

    Virtualization-Based Security (VBS)

    Windows Defender Application Control (WDAC)

    Windows Defender Firewall

    Windows Hello

    Windows Information Protections

    1. Anonymous Coward
      Anonymous Coward

      Re: Secure and resilient runtime model :o

      On the other hand, at least a majority of the poor programmers still work for Microsoft. Can you imagine them going to work for the banks, not they need that kind of help....

  16. Blackjack Silver badge

    So... Windows is coping more that just ads from Android it seems.

  17. Uh, Mike

    Says one prostitute to another

    "Hey, stop working my side of the street"

  18. M.V. Lipvig Silver badge
    Facepalm

    I wonder...

    Edge lets you save usernames and passwords for websites.

    Lately, it requires me to enter my password to allow it to use my stored password, which is the same password...

  19. Filippo Silver badge

    At the time I'm posting this, nearly all of the comments on this article have exactly 1 downvote, including fairly tame comments. I can't help wonder who is going around downvoting everything on this article, and why.

    1. Doctor Syntax Silver badge

      A Microsoft bot. An assumption to ignore content and simply assume any comment on an article about Microsoft would critical is going to be right more often than not and certainly meets Microsoft coding standard.

    2. The Central Scrutinizer Silver badge

      Some people are just small minded idiots.

  20. Is there anybody out there?

    Oh Good

    Great. I'll be able to block Co-pilot from accessing anything. I will won't I?

  21. Anonymous Coward
    Anonymous Coward

    More popups mean users will have more to click, so will read fewer of them. Why is winblows getting more complicated?

  22. _wojtek

    "security" my arse

    I'm so fed up with pushing stupid changes on the guise of "security". this particular one will only result in more mindless clicks because users will confirm it either way...

    but hey, we can say that we are "more secure", some stupid c-suite will get a bonus and the world will be a worst place in the end...

    on the other hand microslop is first to force-fed it's shitty copilot, which is basically abomination if any security and privacy, because people send / upload there virtually anything... and there is no prompt...

    1. OhForF'
      Devil

      Use case for agentic AI

      Hey Copylot, start an agent that automatically confirms those annoying security pop ups unless you are sure they are triggered by malware.

  23. Anonymous Coward
    Anonymous Coward

    Actually, per-app permissions are a good idea.

    What's wrong in per-app permission? It's the right way to ensure better security. It should be extended to system resources (CPU, memory, disk space and even directories, bandwidth, etc.)

    If one set you are no longer "nagged" - and application can know what settings have been applied to them, that's a sensible design decision. That should have been taken earlier.

    1. _wojtek

      Re: Actually, per-app permissions are a good idea.

      It may sound sensible but then reality is that each app naggs user for all required permissions, USRR accept everything without reading and then ia bombarded by (usually) notifications...

      It's enough to take any phone of your (less technical) friends and are their notifications area... "why font you disable those, you just ignore them!?" ia usually followed by "I don't know why / I Don't care"

      1. Anonymous Coward
        Anonymous Coward

        Re: Actually, per-app permissions are a good idea.

        That should be done at setup time - add a button "enable all" if you wish, trying to counter user stupidity is useless. But at least skilled enough users can reduce the attack surface.

        After all, is not much different than what AppArmor is trying to do under Linux - and I found it blocking Ceph from using some SSD disks because their /dev paths were not in the allowed list, finding it was a bit more difficult than flipping some switches in a GUI - or not lliking a database on a different mounted directory....

        Anyway, if you want security without any effort, you don't get security, and then you get the effort to clean up the mess....

        But of course whatever MS does is to blame per se.

        1. OhForF'

          Re: Actually, per-app permissions are a good idea.

          If Micros~1 had provided a list of changes that are coming in a future release and provided a preview so app developers can change the installation process to include a list of permissions the app needs for a clearly stated purpose to allow the admin/user to deal with this at installation time (or first run of the app) that would be fine.

          Microsoft's announcement linked in the article says:

          "We recognize that change takes time. That’s why this will roll out through a phased approach guided by clear principles".

          I fear they'll use an "agile process" to keep changing stuff forcing users and admins and app developers to play catch up and keep configuring permissions for applications even if they were in daily use for years.

  24. Omnipresent Silver badge

    They don't know the difference

    between engineering, security, and advertising. It's all the same. lol

  25. N.Jones

    So Vista has returned in Windows 11?

    "Your pointing out Vista's flaws. Cancel or Allow?"

  26. Anonymous Coward
    Anonymous Coward

    " also prompting the user when an app tries to use a sensitive resource, such as the device's camera or microphone, or wanders into a user's sensitive files."

    This of course does not apply to Microslop themselves or 'associated partners', i.e. ad slingers.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon