In the wake of the CrowdStrike outage, Microsoft has adopted the industry partnership stance I suggested last weekend: It's calling on the security industry to work with it to make the ecosystem safer. There aren't many details yet, but given the software giant's security push this year—generally and with Windows 11 specifically—and the ongoing fallout from the CrowdStrike outage, the timing couldn't be better.
"The recent CrowdStrike incident underscores the need for mission-critical resiliency within every organization, and our unique ability to support the change required," Microsoft's John "the fixer" Cable writes in a new post to the Windows IT Blog. "This incident shows clearly that Windows must prioritize change and innovation in the area of end-to-end resilience. These improvements must go hand in hand with ongoing improvements in security and be in close cooperation with our many partners, who also care deeply about the security of the Windows ecosystem."
Reading that, I thought to myself, that sounds familiar.
And that's because it's almost exactly what I wrote this past Sunday in CrowdStrike Outage Has Roots in Microsoft’s Antitrust Problems. There's been a lot of finger pointing in the wake of the CrowdStrike outage, which is understandable. And Microsoft is likewise understandably sensitive to the assumptions that it was the cause of this outage. Maybe overly sensitive: In blaming EU antitrust regulators, though, Microsoft was out of line and, worse, it was factually incorrect. But that was the point of Sunday's missive: Let's put aside regulators and antitrust concerns in this case because the industry should just agree, collectively, that fixing this type of problem and securing our infrastructure is a bigger and more important concern.
"[Solving this problem] is something Microsoft can’t do by itself," I wrote. "Perhaps this is a good opportunity: In a year in which Microsoft has pledged to take security seriously again by making it a top priority, and as more specifically announced a major new Windows security push, it’s time for the industry—with or without regulators—to agree to new levels of security in Windows that will benefit everyone. This platform is too widespread and too obvious a target to allow this to ever happen again."
So, Microsoft agrees with this. Great. But what's next?
Cable points to two recent security innovations that speak to the resiliency Microsoft wants for Windows, VBS enclaves and Microsoft Azure attestation. But with little in the way of detail.
Here's my overly simplistic take on this. I'm not a security expert.
If you're familiar with the security work that Microsoft did for the Copilot+ PC platform, then that first one might feel familiar: VBS, or virtualization-based security, is the core technology behind Windows Hello Enhanced Sign-in Security (ESS), and the reason for its stringent hardware requirements.
VBS, in Microsoft's words, uses the security hardware in...
With technology shaping our everyday lives, how could we not dig deeper?
Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.