Windows 10: Improved Windows Security? Microsoft launches Win32 app isolation

Discus and support Improved Windows Security? Microsoft launches Win32 app isolation in Windows 10 News to solve the problem; Microsoft launched a preview of a new security feature for Windows earlier this month that it calls Win32 app isolation. The feature uses containers... Discussion in 'Windows 10 News' started by GHacks, Jun 28, 2023.

  1. GHacks
    GHacks New Member

    Improved Windows Security? Microsoft launches Win32 app isolation


    Microsoft launched a preview of a new security feature for Windows earlier this month that it calls Win32 app isolation. The feature uses containers and Microsoft claims that it adds security protections to Windows to help protect against vulnerabilities of the application that uses Win32 app isolation.

    In one sentence: Win32 App Isolation needs to be implemented by developers to give users more control and limit the capabilities of exploits.

    Microsoft notes on the official Windows Developer blog that a main focus of Win32 app isolation is zero-day attacks.

    Microsoft's Windows operating system has a number of tools and security features to prevent or limit malware attacks. From the User Account Control, introduced in Windows Vista, to modern features such as Windows Sandbox or Microsoft Defender Application Guard.

    Windows Sandbox, for instance, is an excellent tool for Windows 10 and 11 systems to run files in an isolated environment. Windows Sandbox supports configuration files, which allow administrators to customize the environment.

    Win32 App Isolation


    Improved Windows Security? Microsoft launches Win32 app isolation [​IMG]

    Microsoft wants Win32 App Isolation to become the default isolation standard on Windows clients. It works well together with other security features, such as Smart App Control, according to Microsoft. Smart App Control is limited to new Windows 11 systems, however.

    Win32 applications, classic programs for Windows, that run with user rights have access to all user data currently. Microsoft notes that this is a big risk, especially since users are not informed about access or get a say in the matter.

    The company writes: "Consequently, there is a risk of unauthorized access to the user’s privacy data by malicious actors without their knowledge or consent."

    Microsoft lists three key objectives of Win32 App Isolation:

    • Make it significantly harder for attackers to cause damage on Windows systems.
    • Provide a seamless user experience for isolated apps.
    • Reduce developer effort to onboard apps.

    When an application utilizes app isolation on Windows, it can't access a user's private data without permission anymore. While it may access some system files, such as .NET libraries or protected Registry keys, it needs to prompt users when it wants to access images, documents, the location, microphone or files.

    Microsoft is aware that users could be tricked into granting access by malicious apps and it implemented preventive measures into the technology. Developers need to include support for prompting users to access private data in their application. If they don't, they can't be exploited to ask users for permission.

    File access, furthermore, is limited to specific files that the user selects. These do not necessarily require prompts, as selecting a file is automatically seen as granting permission to access that particular file.

    Microsoft explains: "When the user grants consent to a specific file for the isolated application, the isolated application interfaces with Windows Brokering File System (BFS) and grants access to the files via a mini filter driver. BFS simply opens the file and serves as the interface between the isolated application and BFS".

    Win32 App Isolation supports a learn mode, which logs the additional capabilities required for access, but does not prevent access.

    Closing Words

    It is doubtful that Win32 App Isolation will get a lot of traction in the coming months and even years. The biggest hurdle is that developers need to implement it in their applications. While some may do, especially those with a focus on privacy, security or important data, most will likely ignore the feature.

    There is also the chance that Win32 App Isolation prompts may annoy users, if they see too many prompts for data access throughout their workday.

    Last but not least, Win32 App Isolation will likely be exclusive to Windows 11 and future versions of Windows.

    Taken together, there is a good chance that some Windows programs will implement Win32 App Isolation, but the vast majority will likely ignore the feature.

    Now You: what is your take on the new feature?

    Thank you for being a Ghacks reader. The post Improved Windows Security? Microsoft launches Win32 app isolation appeared first on gHacks Technology News.

    read more...
     
    GHacks, Jun 28, 2023
    #1
  2. R-T-B Win User

    Microsoft Adds Ability to Block Win32 Apps from Install on Windows 10

    Yeah, if you can't tell by the editorial, I know a few who would benefit too.

    I'm just concerned about the fact its possibly a step towards putting Win32 in a coffin. Albeit a small one. But we all start somewhere.

    Right now, just a discussion starter more than a serious issue.

    PS: I'm very tired today, so this is a bit more of a "wild and loose" editorial than my usual.
     
    R-T-B, Jun 28, 2023
    #2
  3. Microsoft Adds Ability to Block Win32 Apps from Install on Windows 10

    What about the apps from Windows Store that got the bugs? What more, Windows seem to be oblivious to them.
     
    Hossein Almet, Jun 28, 2023
    #3
  4. Brink Win User

    Improved Windows Security? Microsoft launches Win32 app isolation

    Microsoft wants to close the UWP and Win32 divide with Windows Apps

    Read more:
     
    Brink, Jun 28, 2023
    #4
Thema:

Improved Windows Security? Microsoft launches Win32 app isolation

Loading...
  1. Improved Windows Security? Microsoft launches Win32 app isolation - Similar Threads - Improved Security Microsoft

  2. Microsoft is phasing out VBScript in Windows to improve security

    in Windows 10 News
    Microsoft is phasing out VBScript in Windows to improve security: Microsoft announced plans to deprecate Visual Basic Script (VBScript) support in its Windows operating system. The company introduced VBScript, which is modeled on Visual Basic, in 1996. Web developers were the initial target of the scripting language, but it soon gained...
  3. Core Isolation is off in Microsoft Security

    in AntiVirus, Firewalls and System Security
    Core Isolation is off in Microsoft Security: Windows Security says core isolation is off. Fix íncompatible drivers. Then I deleted those drivers. After that I turned on memory integration. Then it says you have to restart pc. I restarted pc and I get blue screen that windows is crashed. After windows opened and memory...
  4. Microsoft improves App Management in the Windows 11 Settings app

    in Windows 10 News
    Microsoft improves App Management in the Windows 11 Settings app: When Microsoft releases its Windows 10 operating system in 2015, it made it clear that the days of the classic Control Panel were numbered. Back then, Microsoft introduced the Settings application as a replacement. [ATTACH] Only some of the preferences, tools and options of...
  5. Can win32 app be published in Microsoft store?

    in Microsoft Windows 10 Store
    Can win32 app be published in Microsoft store?: Hello everybody,I found here a community post of 2020 that states win32 app should be packaged through UUP bridge to publish in the store.Is there any policy change regarding win32 app publishing in recent times? Is it possible now to publish non-packaged desktop app?...
  6. Alien Isolation Game not launching

    in Windows 10 Gaming
    Alien Isolation Game not launching: I am currently having an issue with my game on windows 10. I cannot currently run Alien Isolation on my computer I got it from Steam. I have looked around all the files and have seen lines from the dll files that say the error is Could Not Find D3DKMTEscape in gdi32.dll. And...
  7. Win32 apps in the Microsoft Store?

    in Microsoft Windows 10 Store
    Win32 apps in the Microsoft Store?: Hello everybody, in the last month it was repeatedly in the media, that Microsoft will not only allow UWP but also win32 apps like games in the Microsoft Store. Does this currently still "only" concern apps which have been converted to UWP apps using deskop bridge or can now...
  8. Windows Defender or Security denying launch of app?

    in AntiVirus, Firewalls and System Security
    Windows Defender or Security denying launch of app?: I use an app that monitors my Internet usage and reports out to a server and then to friends who see where I've been on the web. It's an accountability application that I choose to use. On November 6 at about the time 3 Security Intelligence Updates for Windows Defender...
  9. Google Chrome Improving Site Isolation for Stronger Browser Security

    in Windows 10 News
    Google Chrome Improving Site Isolation for Stronger Browser Security: The Chrome Security team values having multiple lines of defense. Web browsers are complex, and malicious web pages may try to find and exploit browser bugs to steal data. Additional lines of defense, like sandboxes, make it harder for attackers to access your computer, even...
  10. Windows 10 19H1 to come with Windows Security app improvements

    in Windows 10 News
    Windows 10 19H1 to come with Windows Security app improvements: Microsoft is currently working on its next major update 19H1 which is planned for a public release of April 2019. The update will be coming with many new features and improvements for the users to work with. Microsoft has already released a preview build 18305 earlier in the...