Random Things

Posts on anything and everything

Labels

Airlines Amazon Auto Electronics Entertainment Faith FB Finance Fix Things Food Gaming Geography Google HaHa's Health Information Mac Microsoft Military Movies Music News Personal Photography Politics Recalls Reviews Riddle Science Security SM Space Sports Tech Terms Thoughts Tools Travel Trivia Videos VR World News

Thursday, November 1, 2018

Ultra Secure Sandbox Mode


Windows Defender Now Offers Ultra Secure Sandbox Mode, Here’s How To Turn It On

CHRIS HOFFMAN  @chrisbhoffman 


Windows 10’s built-in antivirus can now run in a sandbox. Even if an attacker compromises the antivirus engine, they wouldn’t have access to the rest of the system. As Google’s Tavis Ormandy puts it, “this is game changing.”

In fact, Windows Defender is the first complete antivirus product that can run in a sandbox. None of the paid (or free) antivirus products you can download boast this feature.
This news comes from the official Microsoft Secure blog. As Microsoft puts it:
Security researchers both inside and outside of Microsoft have previously identified ways that an attacker can take advantage of vulnerabilities in Windows Defender Antivirus’s content parsers that could enable arbitrary code execution. While we haven’t seen attacks in-the-wild actively targeting Windows Defender Antivirus, we take these reports seriously…
Running Windows Defender Antivirus in a sandbox ensures that in the unlikely event of a compromise, malicious actions are limited to the isolated environment, protecting the rest of the system from harm.
In other words, the Windows Defender antivirus process that analyzes downloaded files and other content will run with very few permissions. Even if there was a bug in the antivirus process and a maliciously crafted file managed to compromise the antivirus itself, that now-dangerous antivirus process wouldn’t provide any access to the rest of your system. The attack would have failed.
Sure, an antivirus still needs a lot of access to your system. But the main antivirus process that runs with a lot of permissions won’t analyze files. It hands content off to a low-privilege sandboxed process, which does the dirty and dangerous work in a secure area.
Microsoft’s blog post goes on to describe how this feature was implemented without any noticeable performance drops:
Performance is often the main concern raised around sandboxing, especially given that antimalware products are in many critical paths like synchronously inspecting file operations and processing and aggregating or matching large numbers of runtime events. To ensure that performance doesn’t degrade, we had to minimize the number of interactions between the sandbox and the privileged process, and at the same time, only perform these interactions in key moments where their cost would not be significant, for example, when IO is being performed.
There’s much more detail than that in Microsoft’s blog post, so check it out if you’re interested.

When Will You Get It?

While this feature is exciting, it isn’t enabled by default on Windows 10 systems—yet. Microsoft says it will “gradually enable” this feature for Windows Insiders and analyze how it works in the real world.
Warning: Microsoft isn’t confident enough in this feature to enable it by default for everyone yet, so you may experience bugs after enabling this. We enabled it on our system and everything seemed to work fine, though.
To enable this feature today, launch a Command Prompt or PowerShell window as Administrator, run the following command, and then restart your PC:
setx /M MP_FORCE_USE_SANDBOX 1
This command works on Windows 10 version 1703, also known as the Creators Update, and newer versions of Windows 10. That version of Windows 10 was released in April 2017, so your PC almost certainly has that version or newer by now.
If you want to undo this change, run the same command, replacing the “1” with a “0,” and reboot your PC once again. If you have problems booting your PC for some reason, try booting into Safe Mode and then running the command.
After enabling sandboxing, you will see a special content process named MsMpEngCP.exe with less permissions running alongside the standard MsMpEng.exe antimalware process.

The sandboxed Windows Defender process, as seen in Microsoft’s Process Explorer.

We were once pretty critical of Microsoft’s antivirus, but we think the latest versions are pretty good. We recommend using Windows Defender to keep your PC secure without any of the upsells and bugs that third-party antivirus software brings to the table. And it’s included by default with Windows 10, so all Windows users finally have a solid antivirus.
We just wish Microsoft’s antivirus was more aggressive about blocking crapware by default.
Image Credit: Gorlov-KV/Shutterstock.com, Microsoft
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Facebook Badge

Jim White

Create Your Badge

Followers

Subscribe To Random Things

Posts
Atom
Posts
Comments
Atom
Comments

Blog Archive

  • ►  2019 (697)
    • ►  April (23)
    • ►  March (166)
    • ►  February (188)
    • ►  January (320)
  • ▼  2018 (4481)
    • ►  December (343)
    • ▼  November (346)
      • President Bush Dies @ 94
      • Bribed Postal Workers
      • Watch Out when Booking a Flight
      • Thanksgiving Openings Hurt
      • VA Won't Repay Vets
      • 2020 Rivian R1T Electric Truck
      • Starbucks to Block Porn
      • Marriott Hacked
      • Make Wise Decisions
      • Today's Encouragement
      • Fri Devotional
      • Lego Needs 1.71 Days
      • New Life Expectancy Statistics
      • U.S. Navy: Nukes or Ships?
      • Martial Law Declared
      • GM Closing Plants
      • Creator of 'SpongeBob' Dead
      • Stocks Surge
      • The Possession of Hannah Grace
      • Make a Decision
      • Today's Encouragement
      • Thur Devotional
      • Holiday Hangover
      • Worst Rip-offs
      • Amazon’s Cyber Monday
      • Do or Die for Sears/Kmart
      • A 'Surprise' Discontinued Car
      • Only Type of Bread
      • Entertainment News
      • Whispered
      • Today's Encouragement
      • Wed Devotional
      • Fox launches 'Fox Nation'
      • Millions under Blizzard Warning
      • Genetically Altered Twins
      • Microsoft vs Apple
      • Sports
      • Romaine Lettuce Latest
      • $400K Money Laundering
      • Armor of Protection
      • Today's Encouragment
      • Tues Devotional
      • Stuck on Tracks
      • Black Friday $23B
      • Jail over Cotton Candy
      • Get Paid to Travel
      • Brexit Latest
      • Best Cyber Monday Deals
      • California Camp Fire
      • Storage Unit w/7.5M Inside
      • Weekend Box Office Results
      • Feeling Overwhelmed
      • Today's Encouragement
      • Mon Devotional
      • Sports
      • Shoppers Choose Computers
      • Get a New Passport
      • Escape a Shark Attack
      • Buy a Domain Name
      • New Electronic Device
      • Meet Daily
      • The Last Days
      • Fools for Christ
      • Six Biblical Truths
      • Prevent PP from Auto Resizing
      • Learning a New Language
      • Room Based on Your Mood
      • Most Popular Dog Name
      • Islands 'Creeping' Closer Together
      • Essential Christmas Albums Ranked
      • Couple Is $1.3M Richer
      • NASA's Experimental Supersonic Jet
      • Enjoy What You Have
      • Time for Radical Action
      • Win or Lose
      • Movie Review - Wreck it Ralph 2
      • Teen Loses License in 49 Mins
      • Submarine Aircraft Carrier
      • AI can Finish Sentences
      • 'The Christmas Chronicles'
      • 2018 Oxford Word of the Year
      • Best U.S. Airlines
      • Greenhouse Gas Levels
      • Have a Thankful Heart
      • Today's Encouragement
      • Fri Devotional
      • 200M Dirt Piles
      • Mystery of Square Poop
      • 'Angry Uncle Bot'
      • World News
      • Biometric Technology
      • Pop Culture BF Deals
      • Home Depot BF Deals (Updated)
      • Amazon's Best BF Deals (Updated)
      • Thanksgiving Arctic Blast
      • Being Thankful
      • Today's Encourgement
      • Thur Devotional
      • David's Bridal
      • Musk Renames Rocket
    • ►  October (385)
    • ►  September (373)
    • ►  August (386)
    • ►  July (385)
    • ►  June (359)
    • ►  May (378)
    • ►  April (384)
    • ►  March (396)
    • ►  February (353)
    • ►  January (393)
  • ►  2017 (4506)
    • ►  December (389)
    • ►  November (382)
    • ►  October (399)
    • ►  September (368)
    • ►  August (406)
    • ►  July (386)
    • ►  June (378)
    • ►  May (383)
    • ►  April (354)
    • ►  March (374)
    • ►  February (337)
    • ►  January (350)
  • ►  2016 (3443)
    • ►  December (353)
    • ►  November (360)
    • ►  October (365)
    • ►  September (338)
    • ►  August (329)
    • ►  July (331)
    • ►  June (332)
    • ►  May (356)
    • ►  April (342)
    • ►  March (316)
    • ►  February (21)

Who I B

Dubs
View my complete profile
Picture Window theme. Powered by Blogger.

Translate