• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Say goodbye to ransomware with Windows 10 Fall Creators Update

Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
Yes, ransomware will be a thing of the past with Windows 10 Fall Creators Update thanks to something called "Controlled Folder Access" in Windows Defender.

Windows 10 will hide your important files from ransomware soon | The Verge

Microsoft is making some interesting security-related changes to Windows 10 with the next Fall Creators Update, expected to debut in September. Windows 10 testers can now access a preview of the changes that include a new controlled folder access feature. It’s designed to only allow specific apps to access and read / write to a folder. If enabled, the default list prevents apps from accessing the desktop, pictures, movies, and documents folders.

“Controlled folder access monitors the changes that apps make to files in certain protected folders,” explains Dona Sarkar, head of Microsoft’s Windows Insiders program. “If an app attempts to make a change to these files, and the app is blacklisted by the feature, you’ll get a notification about the attempt.”

The new controlled folder feature is designed to protect against viruses and ransomware from locking machines out of certain folders. Ransomware has hit the headlines recently as WannaCry and Petya wreak havoc on older Windows machines worldwide. Microsoft is also including exploit protection into its Windows Defender software in Windows 10, which should help prevent viruses and malware from exploiting vulnerabilities in the first place.

These are protections for your files against ransomware at the kernel and Windows Defender level. Rest easy, your files are safe.

About damn time Microsoft!
 
Joined
Aug 3, 2016
Messages
152 (0.05/day)
System Name Ryzen 3 Build
Processor Ryzen 5 5600x
Motherboard Gigabyte Aorus Elite b550
Memory GSkill Ripjaws V (2x16GB)
Video Card(s) MSI GeForce RTX 3080 Trio 10GB
Storage SSD (250GB) + SSD (500GB) + HDD (1TB)
Case Phanteks Enthoo Pro PH-ES614P
Power Supply EVGA SuperNova 750W 80+ Gold
Software Windows 10 64Bit
Didn't the recent attacks encrypt the MBR? Not sure how this is supposed to stop that, but it's a nice addition I guess.
 

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
8,744 (1.48/day)
System Name OrangeHaze / Silence
Processor i7-13700KF / i5-10400 /
Motherboard ROG STRIX Z690-E / MSI Z490 A-Pro Motherboard
Cooling Corsair H75 / TT ToughAir 510
Memory 64Gb GSkill Trident Z5 / 32GB Team Dark Za 3600
Video Card(s) Palit GeForce RTX 2070 / Sapphire R9 290 Vapor-X 4Gb
Storage Hynix Plat P41 2Tb\Samsung MZVL21 1Tb / Samsung 980 Pro 1Tb
Display(s) 22" Dell Wide/24" Asus
Case Lian Li PC-101 ATX custom mod / Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G502 Lightspeed Wireless / Logitech G502 Proteus Spectrum
Keyboard K68 RGB — CHERRY® MX Red
Software Win10 Pro \ RIP:Win 7 Ult 64 bit
I wonder if that would help against the new notPetya, which takes aim at the bios level...

"
NotPetya encrypts the Master File Table (MFT) on compromised PCs before discarding this key, other experts point out.

"‪#Petya‬ actually deletes its own MFT encryption key, making decryption virtually impossible, even for the author. ‪#NotRansomware‬," said Rik Ferguson, VP of security research at Trend Micro.
"




Didn't the recent attacks encrypt the MBR? Not sure how this is supposed to stop that, but it's a nice addition I guess.
beat me to it :), went to verify my recall.
 
Joined
Mar 11, 2009
Messages
1,778 (0.32/day)
Location
Little Rock, AR
System Name Gamer
Processor AMD Ryzen 3700x
Motherboard AsRock B550 Phantom Gaming ITX/AX
Memory 32GB
Video Card(s) ASRock Radeon RX 6800 XT Phantom Gaming D
Case Phanteks Eclipse P200A D-RGB
Power Supply 800w CM
Mouse Corsair M65 Pro
Software Windows 10 Pro
Yet again, looks like more security theater. :rolleyes:
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
25,895 (3.79/day)
Location
Alabama
System Name Rocinante
Processor I9 14900KS
Motherboard EVGA z690 Dark KINGPIN (modded BIOS)
Cooling EK-AIO Elite 360 D-RGB
Memory 64GB Gskill Trident Z5 DDR5 6000 @6400
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 500GB 980 Pro | 1x 1TB 980 Pro | 1x 8TB Corsair MP400
Display(s) Odyssey OLED G9 G95SC
Case Lian Li o11 Evo Dynamic White
Audio Device(s) Moondrop S8's on Schiit Hel 2e
Power Supply Bequiet! Power Pro 12 1500w
Mouse Lamzu Atlantis mini (White)
Keyboard Monsgeek M3 Lavender, Akko Crystal Blues
VR HMD Quest 3
Software Windows 11
Benchmark Scores I dont have time for that.
Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
I'm about to load it myself in a VM and actually test it out. I have a test program written in VB.NET and once installed I'm going to find out if this unknown program will be able to touch said files.
 
Joined
Jun 6, 2017
Messages
88 (0.03/day)
System Name Xena
Processor 2x X5660 2.8 Ghz
Motherboard Tyan S7010
Memory 48 GB DDR3 1333Mhz ECC registered
Video Card(s) Gigabyte GTX 660 ti windforce
Storage 3 TB WD red
Case MaxData platinum 500
Power Supply Chieftec APS-850CB
Software Win 7 X64 ultimate

Ebo

Joined
May 9, 2013
Messages
778 (0.19/day)
Location
Nykoebing Mors, Denmark
System Name the little fart
Processor AMD Ryzen 2600X
Motherboard MSI x470 gaming plus
Cooling Noctua NH-C14S
Memory 16 GB G.Skill Ripjaw 2400Mhz DDR 4
Video Card(s) Sapphire RX Vega 56 Pulse
Storage 1 Crucial MX100 512GB SSD,1 Crucial MX500 2TB SSD, 1 1,5TB WD Black Caviar, 1 4TB WD RED HD
Display(s) IIyama XUB2792QSU IPS 2560x1440
Case White Lian-Li PC-011 Dynamic
Audio Device(s) Asus Xonar SE pci-e card
Power Supply Thermaltake DPS G 1050 watt Digital PSU
Mouse Steelseries Sensei
Keyboard Corsair K70
Software windows 10 64 pro bit
Its just a matter of time until the purbs find out a way to get pass that.
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
25,895 (3.79/day)
Location
Alabama
System Name Rocinante
Processor I9 14900KS
Motherboard EVGA z690 Dark KINGPIN (modded BIOS)
Cooling EK-AIO Elite 360 D-RGB
Memory 64GB Gskill Trident Z5 DDR5 6000 @6400
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 500GB 980 Pro | 1x 1TB 980 Pro | 1x 8TB Corsair MP400
Display(s) Odyssey OLED G9 G95SC
Case Lian Li o11 Evo Dynamic White
Audio Device(s) Moondrop S8's on Schiit Hel 2e
Power Supply Bequiet! Power Pro 12 1500w
Mouse Lamzu Atlantis mini (White)
Keyboard Monsgeek M3 Lavender, Akko Crystal Blues
VR HMD Quest 3
Software Windows 11
Benchmark Scores I dont have time for that.
Its just a matter of time until the purbs find out a way to get pass that.

Cat and Mouse. you got it. Security is best practiced in layers (depth) not a one off solution implemented into windows defender or any other utility.

Your door lock is only as good as the frame.
 

dorsetknob

"YOUR RMA REQUEST IS CON-REFUSED"
Joined
Mar 17, 2005
Messages
9,105 (1.30/day)
Location
Dorset where else eh? >>> Thats ENGLAND<<<
Your door lock is only as good as the frame.
And the lock is only good if the locksmith can be Trusted ( and wilkileaks dont get hold and blab the info from you know/suspect who).
 

Ahhzz

Moderator
Staff member
Joined
Feb 27, 2008
Messages
8,744 (1.48/day)
System Name OrangeHaze / Silence
Processor i7-13700KF / i5-10400 /
Motherboard ROG STRIX Z690-E / MSI Z490 A-Pro Motherboard
Cooling Corsair H75 / TT ToughAir 510
Memory 64Gb GSkill Trident Z5 / 32GB Team Dark Za 3600
Video Card(s) Palit GeForce RTX 2070 / Sapphire R9 290 Vapor-X 4Gb
Storage Hynix Plat P41 2Tb\Samsung MZVL21 1Tb / Samsung 980 Pro 1Tb
Display(s) 22" Dell Wide/24" Asus
Case Lian Li PC-101 ATX custom mod / Antec Lanboy Air Black & Blue
Audio Device(s) SB Audigy 7.1
Power Supply Corsair Enthusiast TX750
Mouse Logitech G502 Lightspeed Wireless / Logitech G502 Proteus Spectrum
Keyboard K68 RGB — CHERRY® MX Red
Software Win10 Pro \ RIP:Win 7 Ult 64 bit
And the lock is only good if the locksmith can be Trusted ( and wilkileaks dont get hold and blab the info from you know/suspect who).
And that's a completely naive hope to have. The security segments of our government have proven again and again that they believe in a NOBUS policy, which is ridiculous.
 

dorsetknob

"YOUR RMA REQUEST IS CON-REFUSED"
Joined
Mar 17, 2005
Messages
9,105 (1.30/day)
Location
Dorset where else eh? >>> Thats ENGLAND<<<
And that's a completely naive hope to have

You think i trust Them !!! :eek::roll::banghead:
Oh my god that's Funny "You must have overdosed on popcorn"
You need the" Hughy cure"
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.98/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
They'll find a way round it. There's no magic bullet for security. If it can be accessed it can be hacked.
 
Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
I wrote a test program in C# with the following code...
Code:
        private void btnOverwrite_Click(object sender, EventArgs e)
        {
            openFileDialog1.Title = "Choose a file to be overwritten";

            if (openFileDialog1.ShowDialog() == DialogResult.OK) {
                try {
                    System.IO.StreamWriter streamWriter = new System.IO.StreamWriter(openFileDialog1.FileName, false);
                    streamWriter.Write("I have been overwritten! HAHAHA!");
                    streamWriter.Close();

                    MessageBox.Show(this, "File \"" + openFileDialog1.FileName + "\" has been overwritten!");
                }
                catch (Exception ex) {
                    MessageBox.Show(this, ex.Message + "\n" + openFileDialog1.FileName);
                }
            }
        }

        private void btnDeleteFile_Click(object sender, EventArgs e)
        {
            openFileDialog1.Title = "Choose a file to be deleted";

            if (openFileDialog1.ShowDialog() == DialogResult.OK) {
                try {
                    System.IO.File.Delete(openFileDialog1.FileName);
                    MessageBox.Show(this, "File \"" + openFileDialog1.FileName + "\" has been deleted!");
                }
                catch (Exception ex) {
                    MessageBox.Show(this, ex.Message + "\n" + openFileDialog1.FileName);
                }
            }
        }

It's rather simple in its code but it does what I need for the situation. This is the result...
Overwrite a File -- Access Denied.png
Delete a File -- Access Denied.png

Windows prevented it because my program is not a "trusted" program so access to that folder is denied. Since this is in the beta phase things aren't going to work perfectly (you need to whitelist programs to allow access) but I figure that eventually this feature will allow trusted programs from known vendors or digitally signed programs to be automatically whitelisted.
 
Joined
Dec 31, 2009
Messages
19,366 (3.70/day)
Benchmark Scores Faster than yours... I'd bet on it. :)
Meh, this is likely still easy to get through... but hey, one more door is one more door.
 
Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
but hey, one more door is one more door.
Well isn't that good? With the way that ransomware has become such a problem one more way to prevent this kind of attack is more than welcome.
 

rtwjunkie

PC Gaming Enthusiast
Supporter
Joined
Jul 25, 2008
Messages
13,909 (2.42/day)
Location
Louisiana -Laissez les bons temps rouler!
System Name Bayou Phantom
Processor Core i7-8700k 4.4Ghz @ 1.18v
Motherboard ASRock Z390 Phantom Gaming 6
Cooling All air: 2x140mm Fractal exhaust; 3x 140mm Cougar Intake; Enermax T40F Black CPU cooler
Memory 2x 16GB Mushkin Redline DDR-4 3200
Video Card(s) EVGA RTX 2080 Ti Xc
Storage 1x 500 MX500 SSD; 2x 6TB WD Black; 1x 4TB WD Black; 1x400GB VelRptr; 1x 4TB WD Blue storage (eSATA)
Display(s) HP 27q 27" IPS @ 2560 x 1440
Case Fractal Design Define R4 Black w/Titanium front -windowed
Audio Device(s) Soundblaster Z
Power Supply Seasonic X-850
Mouse Coolermaster Sentinel III (large palm grip!)
Keyboard Logitech G610 Orion mechanical (Cherry Brown switches)
Software Windows 10 Pro 64-bit (Start10 & Fences 3.0 installed)
So, we'll be forced to use Defender to get this functionality. No thanks.
Come on, man! If the idiots at MS can figure out how to make Defender protect against this, don't you think the pros who actually work antimalware companies for a living can do it too?
 
Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
I'm surprised that no one else has thought about this kind of protection. It seems like such an easy idea, at least on the surface. I'm sure that injecting kernel code to prevent this kind of access is probably a lot harder.
 
Joined
Jul 16, 2014
Messages
8,120 (2.27/day)
Location
SE Michigan
System Name Dumbass
Processor AMD Ryzen 7800X3D
Motherboard ASUS TUF gaming B650
Cooling Artic Liquid Freezer 2 - 420mm
Memory G.Skill Sniper 32gb DDR5 6000
Video Card(s) GreenTeam 4070 ti super 16gb
Storage Samsung EVO 500gb & 1Tb, 2tb HDD, 500gb WD Black
Display(s) 1x Nixeus NX_EDG27, 2x Dell S2440L (16:9)
Case Phanteks Enthoo Primo w/8 140mm SP Fans
Audio Device(s) onboard (realtek?) - SPKRS:Logitech Z623 200w 2.1
Power Supply Corsair HX1000i
Mouse Steeseries Esports Wireless
Keyboard Corsair K100
Software windows 10 H
Benchmark Scores https://i.imgur.com/aoz3vWY.jpg?2
I can see this as a way for m$ to prevent users from disabling the bloatware, like Cortana and OneDrive, from actually being disabled or deleted. Imagine having your personal files remotely locked with and nothing you can do about it, ever.
 
Joined
Aug 20, 2007
Messages
20,789 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Meh, this won't protect against anything that reads/writes to the filesystem using it's own userspace driver, but nice gesture I guess.

I can see this as a way for m$ to prevent users from disabling the bloatware, like Cortana and OneDrive, from actually being disabled or deleted. Imagine having your personal files remotely locked with and nothing you can do about it, ever.

AFAIK, it's not encrypting your data. It's basically enhanced filesystem permissions. You could just boot linux in this instance and get your files...
 
Joined
Mar 6, 2017
Messages
3,211 (1.23/day)
Location
North East Ohio, USA
System Name My Ryzen 7 7700X Super Computer
Processor AMD Ryzen 7 7700X
Motherboard Gigabyte B650 Aorus Elite AX
Cooling DeepCool AK620 with Arctic Silver 5
Memory 2x16GB G.Skill Trident Z5 NEO DDR5 EXPO (CL30)
Video Card(s) XFX AMD Radeon RX 7900 GRE
Storage Samsung 980 EVO 1 TB NVMe SSD (System Drive), Samsung 970 EVO 500 GB NVMe SSD (Game Drive)
Display(s) Acer Nitro XV272U (DisplayPort) and Acer Nitro XV270U (DisplayPort)
Case Lian Li LANCOOL II MESH C
Audio Device(s) On-Board Sound / Sony WH-XB910N Bluetooth Headphones
Power Supply MSI A850GF
Mouse Logitech M705
Keyboard Steelseries
Software Windows 11 Pro 64-bit
Benchmark Scores https://valid.x86.fr/liwjs3
If the blocking system is being implemented at the kernel level even a userspace driver would be blocked (at least in theory) since everything has to go through the kernel and the NTFS file system driver.
 
Joined
Aug 20, 2007
Messages
20,789 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
If the blocking system is being implemented at the kernel level even a userspace driver would be blocked (at least in theory) since everything has to go through the kernel and the NTFS file system driver.

Nope. Not everything has to go through the NTFS filesystem driver. How do you think FAT32 or similar operates?

Raw writes to the disk are allowed in windows. They have to be. Otherwise partitioning tools and the like would never work. All one needs to do is take one of the freely available open source NTFS drivers and walla, access. I specifically specified userspace as the kernel would treat it as an application, and grant it access to the raw disk.
 
Joined
Jan 8, 2017
Messages
8,944 (3.36/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
A necessary action , but don't say goodbye to ransomewere yet. Nothing will ever fix lack of common sense by the user. And that shit is what opens up all of these opportunities for malware in the first place most of the times , not obscure security holes , which will exist as well no matter what as long as you have a certain degree of freedom with what software can do.
 
Last edited:
Top