Filter drivers vs hooking

Neal

One feature of the Cm callback mechanism at the moment is that there is no
way to observe explicit changes to the security descriptor of an open key.
Is this something that is planned to be fixed?

Thanks
Lyndon

“Neal Christiansen” wrote in message
news:xxxxx@ntfsd…
The registry hooking API documentation will be apart of the next DDK and
IFSKit.

Neal Christiansen
Microsoft File System Filter Group Lead
This posting is provided “AS IS” with no warranties, and confers no
rights.

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Tobias Sasse
Sent: Wednesday, April 14, 2004 10:24 AM
To: Windows File Systems Devs Interest List
Subject: Re: [ntfsd] Filter drivers vs hooking

I’d like to apologize for posting to this list using my badly configured
mail client. Please allow to post my questions again, since they’re of
great interest for me. So here it goes…

Neal Christiansen wrote:

> Note that we are in the process of making the Registry “hooking” APIs
> publicly available.

Hello Neal, I’m curious about the registry hooking APIs and would
appreciate if you could answer some questions.

When will they actually be available? Or better, what do I have to do to
receive a preliminary version asap?

Will there be documented ways to filter other functions besides the
registry related?

Thanks
Tobias


Questions? First check the IFS FAQ at
https://www.osronline.com/article.cfm?id=17

You are currently subscribed to ntfsd as: xxxxx@windows.microsoft.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

> We have more products in Market which is developed by Less-Knowledgeable

peoples then More
knowledgeable peoples.

There are people (American small startup company leads with sales/marketing
background usually) who do agree to pay for very, very dirty code. Sometimes
such a code is done to impress investors. Sometimes - to look better then a
competitor in a comparison matrix by adding one more feature (can be hardly
functioning and unsafe, this is OK for marketing. When the market will notice
this, the next version will have it rewritten and properly implemented).

Some of these managers are constantly exploring the offshore facilities in
India, Russia and Ukraine to find somebody cheaper. For instance, some of them
are unwilling to pay for project management expenses, and are trying to pay
only the programmer’s salary. With per-hour rate (and they insist on it, while
per-feature rate would be better for both sides strategically) - such tricks
are easy to play.

Surely they do find the underbidders, and then having all problems connected to
this. For instance, if the underbidder will get another project - better paid -
from another customer - he can just stop the first project, if not drop it on
the floor. Or the underbidder can stop the work in the middle, not provide the
source code to the customer and require more money for rewritten “and this time
realistic” project spec :slight_smile:

With system-level code, changing the contractors on the fly is disastrous, and
with underbidders, it will be this way.

That’s why there is a market for dirty code writing, for small Russian/Indian
offshores especially - larger ones have several major customers like Boeing
and are going on writing accounting/enterprise apps for them, and are reluctant
of accepting any system-level technically hard projects. The latter is often
due to too rigid business procedures in these companies, modelled by Rational,
UML and other kinds of scholastics.

I personally think that even Microsoft will not be able to bring this down. For
instance, if some hardware violates the SCSI spec, but the manufacturer/major
consumer of it says “hey we want this yesterday!” and is agree to pay - then
yes, somebody will patch the SCSIPORT.SYS binary to support this hardware. This
is how market works.

Yes, the world is going imperfect. Seriously imperfect. But, if we will try to
find the guilty - then sorry, the developers will blame the marketoids, and the
marketoids will blame the market. The conclusion: the masses of users are
guilty :slight_smile: the whole business seems to run off users with “Hey that’s kinda
cool!” attitude who can pay some small sums for well-painted logo and popup
boxes.

Worse so is that the hardware/peripheral market started to “develop” in this
direction too, especially for El Cheapo USB hardware.

I personally think that the only thing Microsoft can do to really improve the
situation (and yes, this is in their interests - they want users being
satisfied by Windows, and not higher profits for a small Bangalore or Nizhny
Novgorod company) - is to create a blackmailing site where the bugs and issues
in all kinds of small apps will be published, so that people will stop blaming
OS for instability of the apps and OS-add-ons by third parties.

For now, the things are as the following:

  • the small company releases the product which uses hacks or undocumented
    techniques (have anybody noticed the large interest to undocumented and
    unsupported TDI filtering during the last months? most of these tasks could be
    solved by good old NDIS IMs. Then why go to unsupported land?)
  • the small company does nearly no interop testing. They do the interop testing
    only with major products which are likely to be installed on most desktops, but
    not with the minor products.
  • then the Average Joe who have read too much sites on “this brand new cool
    software!” installs around 10 or 15 small apps - from such small companies - on
    his machine.
  • the machine starts to deteritoriate, and nothing surprising - the main
    evilness of undocumented hacks is the interop issues they produce with 2 such
    products.
  • then the Average Joe…blames Microsoft for this :slight_smile:

Maxim Shatskih, Windows DDK MVP
StorageCraft Corporation
xxxxx@storagecraft.com
http://www.storagecraft.com

> -----Original Message-----

From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com]On Behalf Of Maxim S. Shatskih
Sent: Friday, April 16, 2004 4:21 PM
To: Windows File Systems Devs Interest List

There are people (American small startup company leads with
sales/marketing
background usually) who do agree to pay for very, very dirty
code. Sometimes
such a code is done to impress investors. Sometimes - to look
better then a
competitor in a comparison matrix by adding one more feature (can
be hardly
functioning and unsafe, this is OK for marketing. When the market
will notice
this, the next version will have it rewritten and properly implemented).

Some of these managers are constantly exploring the offshore facilities in
India, Russia and Ukraine to find somebody cheaper. For instance,
some of them
are unwilling to pay for project management expenses, and are
trying to pay
only the programmer’s salary. With per-hour rate (and they insist
on it, while
per-feature rate would be better for both sides strategically) -
such tricks
are easy to play.

Surely they do find the underbidders, and then having all
problems connected to
this. For instance, if the underbidder will get another project -
better paid -
from another customer - he can just stop the first project, if
not drop it on
the floor. Or the underbidder can stop the work in the middle,
not provide the
source code to the customer and require more money for rewritten
“and this time
realistic” project spec :slight_smile:

With system-level code, changing the contractors on the fly is
disastrous, and
with underbidders, it will be this way.

If the Managers is really knowledgeable person, If he has capability to
detect wheather it is better code or junk code ( along with other good
skills to handle offshore projects ) he will get the proper output when he
offshore the project. No matter wheather he does offshoring to Cheaper
countries or another company within the same country. :slight_smile:

Some of the companies want to make Quick money, doesn’t matter where they
locate, doest matter wheather they have required knowledge or not.

btw, I am from India/Bangalore :slight_smile:

Regards,
Satish K.S

> If the Managers is really knowledgeable person, If he has capability to

detect wheather it is better code or junk code

Most software development managers are unable to read the C code.

Some of the companies want to make Quick money,

I would replace “some” to “most of”. :slight_smile:

btw, I am from India/Bangalore :slight_smile:

I’m from Russia :slight_smile:

Maxim Shatskih, Windows DDK MVP
StorageCraft Corporation
xxxxx@storagecraft.com
http://www.storagecraft.com

Adam,

I agree OS installation isn’t a good time to ask; especially when many computers are sold with preinstalled OS.

Best regards,

Michal Vodicka
UPEK, Inc.
[xxxxx@upek.com, http:://www.upek.com]


From: xxxxx@lists.osr.com[SMTP:xxxxx@lists.osr.com] on behalf of Adam Landefeld[SMTP:xxxxx@windows.microsoft.com]
Reply To: Windows File Systems Devs Interest List
Sent: Thursday, April 15, 2004 10:39 PM
To: Windows File Systems Devs Interest List
Subject: RE: [ntfsd] Re:Filter drivers vs hooking

Michal,

I agree that it should be up to the user what software he/she runs, but
it’s important to avoid unnecessary confusion :).
Something along the lines of driver signing, as you mentioned, seems
like a reasonable solution; especially since the average user would not
run into this very often. Only have to deal with it when you install
the software instead of exposing the choice to every user who installs
the OS.

Adam Landefeld

“This posting is provided “AS IS” with no warranties, and confers no
rights.”

-----Original Message-----
From: xxxxx@lists.osr.com
[mailto:xxxxx@lists.osr.com] On Behalf Of Michal Vodicka
Sent: Thursday, April 15, 2004 12:41 PM
To: Windows File Systems Devs Interest List
Subject: RE: [ntfsd] Re:Filter drivers vs hooking

Another possibility is something as current driver signing options:
Allow / Warn / Block and maybe a user-defined list of exceptions from
rule. No problem if hooking is blocked by default but there should be a
way how to change it. It is user’s desicision what kind of software
wants to use. Don’t underestimate users (in both good and bad direction
:).

Best regards,

Michal Vodicka
UPEK, Inc.
[xxxxx@upek.com, http:://www.upek.com]


Questions? First check the IFS FAQ at https://www.osronline.com/article.cfm?id=17

You are currently subscribed to ntfsd as: xxxxx@upek.com
To unsubscribe send a blank email to xxxxx@lists.osr.com

Installation by an OEM is NOT installation for the user. When you get
one of those machines, the setup begins almost again. You have to enter
the product key and it then goes off and detects the hardware. That
install works for every machine in the same product line even if the
motherboard sound chip is used or a high end PCI sound card because the
manufacturer puts all the drivers into the distribution. The OEM can
then mass copy the images to many hard drives and just install them in
each machine in that product line.

“Michal Vodicka” wrote in message
news:xxxxx@ntfsd…
Adam,

I agree OS installation isn’t a good time to ask; especially when many
computers are sold with preinstalled OS.

Best regards,

Michal Vodicka
UPEK, Inc.
[xxxxx@upek.com, http:://www.upek.com]

> ----------
> From:
xxxxx@lists.osr.com[SMTP:xxxxx@lists.osr.com
] on behalf of Adam Landefeld[SMTP:xxxxx@windows.microsoft.com]
> Reply To: Windows File Systems Devs Interest List
> Sent: Thursday, April 15, 2004 10:39 PM
> To: Windows File Systems Devs Interest List
> Subject: RE: [ntfsd] Re:Filter drivers vs hooking
>
> Michal,
>
> I agree that it should be up to the user what software he/she runs,
but
> it’s important to avoid unnecessary confusion :).
> Something along the lines of driver signing, as you mentioned, seems
> like a reasonable solution; especially since the average user would
not
> run into this very often. Only have to deal with it when you install
> the software instead of exposing the choice to every user who installs
> the OS.
>
> Adam Landefeld
> --------------
> “This posting is provided “AS IS” with no warranties, and confers no
> rights.”
>
>
>
> -----Original Message-----
> From: xxxxx@lists.osr.com
> [mailto:xxxxx@lists.osr.com] On Behalf Of Michal Vodicka
> Sent: Thursday, April 15, 2004 12:41 PM
> To: Windows File Systems Devs Interest List
> Subject: RE: [ntfsd] Re:Filter drivers vs hooking
>
> Another possibility is something as current driver signing options:
> Allow / Warn / Block and maybe a user-defined list of exceptions from
> rule. No problem if hooking is blocked by default but there should be
a
> way how to change it. It is user’s desicision what kind of software
> wants to use. Don’t underestimate users (in both good and bad
direction
> :).
>
> Best regards,
>
> Michal Vodicka
> UPEK, Inc.
> [xxxxx@upek.com, http:://www.upek.com]
>
> —
> Questions? First check the IFS FAQ at
https://www.osronline.com/article.cfm?id=17
>
> You are currently subscribed to ntfsd as: xxxxx@upek.com
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>

> ----------

From: xxxxx@lists.osr.com[SMTP:xxxxx@lists.osr.com] on behalf of David J. Craig[SMTP:xxxxx@yoshimuni.com]
Reply To: Windows File Systems Devs Interest List
Sent: Friday, April 16, 2004 9:15 PM
To: Windows File Systems Devs Interest List
Subject: Re:[ntfsd] Re:Filter drivers vs hooking

Installation by an OEM is NOT installation for the user. When you get
one of those machines, the setup begins almost again. You have to enter
the product key and it then goes off and detects the hardware. That
install works for every machine in the same product line even if the
motherboard sound chip is used or a high end PCI sound card because the
manufacturer puts all the drivers into the distribution. The OEM can
then mass copy the images to many hard drives and just install them in
each machine in that product line.

OK, I usually don’t buy machines myself. However, when my relatives bought a computer recently, OS was fully installed (installation CDs and keys included). I guess it depends on hw supplier; small companies can make full installation as an extra service for customer.

Best regards,

Michal Vodicka
UPEK, Inc.
[xxxxx@upek.com, http:://www.upek.com]

Maxim S. Shatskih wrote:

>> Some of the companies want to make Quick money,
>
> I would replace “some” to “most of”. :slight_smile:

Why not replacing it to “all”… they’re human.

Tobias

Michal Vodicka wrote:

> I agree OS installation isn’t a good time to ask; especially when
> many computers are sold with preinstalled OS.

Great objection! When a user meets the product needing the hook he
wouldn’t have the chance to enable hooking again in many cases. So
please forget about my suggestion. :slight_smile:

Tobias

What OSs and SPs are these “hooking” APIs available
in?

— Neal Christiansen
wrote:
> Note that we are in the process of making the
> Registry “hooking” APIs
> publicly available.
>
> Neal Christiansen
> Microsoft File System Filter Group Lead
> This posting is provided “AS IS” with no warranties,
> and confers no
> rights.

__________________________________
Do you Yahoo!?
Yahoo! Photos: High-quality 4x6 digital prints for 25¢
http://photos.yahoo.com/ph/print_splash