Windows 10 Enterprise Getting 'InPrivate Desktop' Sandboxed Execution Feature (bleepingcomputer.com)
An anonymous reader quotes a report from Bleeping Computer: A recent Windows 10 Insider Feedback Hub quest revealed that Microsoft is developing a new throwaway sandboxed desktop feature called "InPrivate Desktop." This feature will allow administrators to run untrusted executables in a secure sandbox without fear that it can make any changes to the operating system or system's files. This quest is no longer available in the Feedback Hub, but according to it's description, this feature is being targeted at Windows 10 Enterprise and requires at least 4 GB of RAM, 5 GB of free disk space, 2 CPU cores, and CPU virtualization enabled in the BIOS. It does not indicate if Hyper-V needs to be installed or not, but as the app requires admin privileges to install some features, it could be that Hyper-V will be enabled. "InPrivate Desktop (Preview) provides admins a way to launch a throwaway sandbox for secure, one-time execution of untrusted software," the Feedback Hub questions explains. "This is basically an in-box, speedy VM that is recycled when you close the app!"
Sorry Trump traitors!
Something upbeat about another redmond fart
From an impressively bad "source", like bleepingcomputer
By one of the three most inane slashdot editors ever.
Three marks out of five.
(The other marks would be involving "hackers" and painting a SJW-theme.)
....today, ANY corporation or government agency that is not very actively doing everything they can to eliminate any dependency on Windows of any version is guilty of IT Malpractice.
Yes, yes, there are (way too) many "Windows-only" apps extant, but it is fundamentally up to the purchasing community to drive the change necessary.
Painful, time-consuming...yeah! Ultimately rewarding? Fuck yeah!
Dude comitted securities fraud lol
This is exactly what bromium have been doing for years now:
bromium.com
regards
John Jones
Why bother with inPrivate desktop when you can have '90s inSex bondage porn ??
Clit Boner
exploitacitis stupidicous a new disease that the dipsh!ts at MS want you to pay to get targeted on a virtual server that then oh nvm they just wont learn fuck them and everyone that uses it
rest of you get to pay monthly for using none of this and unless hollywood , the us govt and ms want you to use shit ....you cant thus according to this statement
are they saying if i want to design something and not get there god damn permission i cant
GO FUCK YOURSELF MS
But it has it up the wazoo.
So it's like an ephemeral ec2? Which has been around for a while.
Rowhammer, Spectre, Meltdown and all of their variants didn't just disappear. In fact they will likely get replaced by new versions of themselves in new operating systems. Each one of those can be used by malevolent software to break out of a sandbox.
Also the Windows API is vast and was not meant to have security in mind. For example usually every application can fill out forms in every other application. That way you can inject code. The timer message, which everyone can send, includes a "callback" field, which contains an address your software will very likely ignore all the security warnings around it and just call that address. If you put the address of the data of the input field you have just overwritten in, you get clean and simple code execution by seemingly harmless features.
Hi,
Thanks for sharing this blog with us, your blog contains very important information about Windows 10, I appreciate your work and effort. Please keep sharing more blogs.
Just like RAID is not a backup solution,
virtualization is not a security solution.
You still need an application firewall.
> This feature will allow administrators to run untrusted executables in a secure sandbox without fear [...]
Windows administrators don't fear anything. That's why they are Windows administrators!
Hmmm!?
So why in the world would you run a untrusted executable in the first place? So you can run a potentially malware invested EXE in a sandbox. That's like telling a driver to drive recklessly because we installed more air bags.
I work at a University, and we use Windows 10 Education. Will the Sandboxed Execution Feature be enabled/available for Education edition of Windows?
This is exactly what every good administrator, and most good power users, have been doing for years now with VirtualBox or something similar. And with significantly less resources required on the computer to do it, I might add.
Typical Microsoft. Take something everyone already does. Add the ability to do it in Windows automatically, but require more resources than it already takes. Drive the sales of new hardware, computer manufacturers are happy, Microsoft is happy. If adoption isn't high enough, then they start interfering with the old ways users were already doing it.
And they wonder why they are constantly accused of not innovating.
If so, then they can hardly be called "private."
Cool, but I'm not renting my OS
Can we put that in isolation? Better yet get microsoft to turn off the evil parts of windows 10?
I'll be dumping lin-sux immediately as soon as this is available and so will millions more users!
Just another layer of crap. Isn't this what a proper OS is supposed to do? You know, divide up computer resources between various applications in a secure way. If you can't trust the OS to do that, how are you going to trust yet another layer of crap?
What? Like WIndows 10?
It's okay APK you don't need to hide. Remember your are the tough guy and can kick Mohammad I'm Hard Bruce Lee's ass. I bet you can even fight off 500 ninjas at a time.
I see the secret meaning in the headline...
Windows. Execution. Feature.
I'm starting to get really tempted to change from Windows 7 to 10. If they just gave back privacy stuff and made Windows classic theme (win 95 theme) possible I might do it.