Software Review The biggest risk with Windows: LOLBINS

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
PC Security Channel
You can literally add WDAC exceptions via ImageFileExecutionOptions.

The link you provided is a breakdown of Pointer Authentication (PAC) on ARM64, not a validation of your confused registry hacks. You are conflating Windows Defender Application Control (WDAC) with Windows Defender Exploit Guard (WDEG).

Your "evidence" actively dismantles your own claim. The document explicitly states that Image File Execution Options (IFEO) is the supported method to enable "process mitigation at process creation".

This applies safety goggles (DEP, ASLR, PAC, CFG) to a process. It effectively wraps the "Exploit Protection" UI settings.

WDAC (App Control), This is the bouncer. It checks ci.dll in the kernel to see if the binary is allowed to enter the club. It does not check the IFEO registry key for a VIP pass. If WDAC respected IFEO "exceptions," the security model would be non-existent.

IFEO is parsed in user-mode (or early process init) to apply flags like PROCESS_CREATION_MITIGATION_POLICY.

WDAC operates at the memory mapping level in the kernel. It enforces "Can this code run?", whereas IFEO enforces "How safely should this code run?".

You found a manual on how to configure seatbelts (Exploit Mitigations in IFEO) and are trying to argue it explains how to start the engine without a key (WDAC Bypass). The file confirms IFEO handles mitigation policies, not execution control lists.
 
Thanks for the reply. In my case, I'd tend towards DefenderUI. I'm familiar with its, IMO, more user friendly, informative layout, and would do a little more research of selective options to enable, other than maximum setting across the board. (to possibly not conflict or hinder F-Secure's protection or cause possible pop-ups etc. out of nowhere)
No matter which default deny the user selects, using any of them at maximum settings does not "conflict" with any AV.

Hard_Configurator includes a capability to create LOLBin firewall block rules, harden MIcrosoft Defender which can still run alongside another AV, and other protection features. It is the most comprehensive.
 
Then it's MS fault.

Apple did a better job locking its system down and it provides better overall security out of the box.

MS created a vulnerable OS and users are blamed for it.

Not everyone has the time or the knowledge to study OS architecture to harden it. Most people buy a PC to use.

No one in their right mind would expect a teacher, a linguist or a graphic designer to spend days studying the OS architecture because MS failed to create a secure system out of the box. And here I am not talking about corporate and business users (which btw they hire people to secure their systems)
It's not Microsoft's fault. It's people like you who are at fault. It is users that created the entire security problem in the first place.

Apple defies users and their "Users want to use stuff" and then what happens? Apple gets sued to allow "Users to use stuff" and break its protections.

When Microsoft has tried to make Windows far more secure, each and every time home users have caused the company to abandon its efforts.
 
Recovery doesn't have to be expensive.
@Victor M , thanks for taking the time to explain everything in such detail. It’s clear you know the topic very well, and I’ll keep your advice in mind because it always helps to listen to those who know more.From a more basic user’s point of view, I rely on simple things: for example, I use Acronis True Image for my backups, and it gives me peace of mind knowing I have a fallback if something goes wrong.In the end, I think those small layers of prevention make the difference. When I said “cheap prevention is better than expensive recovery”, I didn’t mean money, but rather the time and hassle it brings. Sorry if I don’t always find the right words in the forum’s language. :)
 
Last edited:
Use Hard_Configurator and set everything to maximum protection. Read the Manual. Study it. Learn it.
Good if not perfect advice, everyone should try H_C then study what is blocked. It's almost impossible to get around, you can't pwn what you can't access.

Not saying a persistent attacker can't get you but why make it easy?
 
You praise Apple for "locking its system down" better. Do you understand how they do it?

MacOS is safer "out of the box" because it aggressively blocks you from running software that Apple hasn't personally blessed (Gatekeeper). On iOS, you literally cannot install software outside their store without jailbreaking.

Microsoft allows you to run code from 1995, code written by a teenager in a basement, and code that modifies the kernel. This backward compatibility and openness is the entire reason Windows owns the market.

You want the freedom of Windows (install anything) with the safety of Apple (install only approved things). You cannot have both. If Microsoft locked down Windows like Apple does, you would be the first to scream about "Monopoly" and "Freedom."

You argue that teachers and graphic designers shouldn't have to study architecture. They don't.

Microsoft gave you the solution. It is called the Standard User Account.

It takes exactly 30 seconds to set up. You create the account once. That is not "days of study." That is basic appliance maintenance, like cleaning the lint trap in your dryer.

Refusing to spend 30 seconds to click "Create Account" because "Microsoft should have done it" is not a valid defense. It is laziness masquerading as victimhood.

It's not Microsoft's fault. It's people like you who are at fault. It is users that created the entire security problem in the first place.

Apple defies users and their "Users want to use stuff" and then what happens? Apple gets sued to allow "Users to use stuff" and break its protections.

When Microsoft has tried to make Windows far more secure, each and every time home users have caused the company to abandon its efforts.
People like me live in peace without self-centrism and without attention seeking. I'm not defending anything like a fanboy and I am not acting like a smarty pants.

I pointed out sth and I stand by it and I am entitled to express my opinion and I know how exactly to reply to creatures like you.
 
His brilliance in determining my location is one of its kind 😂
You’ve been exposed, stop posing!

@rashmi stop projecting already onto system directories.

I am tired of your projections.

The kernel has written a grievance. Suspend your kernel violations at once.

IMG_3385.jpeg
 
Yep; Russia
Russia is not EU.

Not saying a persistent attacker can't get you but why make it easy?
A persistent enemy is going to find a way to get around anything, eventually - even air-gapped. You know this, but to talk about it here it just turns into the trite answers "Home users are not targeted like that." It's their systems, their money, their lives and I could care less what happens to them.

People like me live in peace without self-centrism and without attention seeking. I'm not defending anything like a fanboy and I am not acting like a smarty pants.

I pointed out sth and I stand by it and I am entitled to express my opinion and I know how exactly to reply to creatures like you.
Nobody said you did anything wrong. You're entitled to believe and think as you wish, however what you believe and think is not part of global reality.

If you use Windows then you agree to its Terms of Service which put 100% of everything onto the user. This is no different than any other software publisher in the world. Everything that you do with code written by others is at your own risk and you are responsible for the overall security. If it were not otherwise, then the global software publishing industry would collapse due to liability. Nobody in their right mind would write a single line of code under any system which they are liable for what people do with their software. Period. Full stop.

Love the thread, love the civility. I have nothing more to add besides saying that this thread was so good that you bastards made me get my glasses.
This is the internet. It is social media. It is called "entertainment" and everybody loves it.
 
When you read a Microsoft Service Agreement or Windows EULA (End User License Agreement). You are paying for a product, yet the contract essentially says, "If this breaks your computer or loses your data, it's not our fault."

This "100% responsibility" model isn't just a Microsoft quirk; it is the industry standard for almost all commercial software. There are three primary reasons—legal, economic, and technical—why these agreements are written this way.

1. The "As-Is" Legal Shield​

Software is rarely sold as a "guaranteed product" in the same way a toaster is. Instead, it is legally classified as a license to use code. Because code is infinitely complex, Microsoft uses "As-Is" and "Where-Available" clauses to disclaim all warranties.
  • Implied Warranties: In standard commerce, there is an "implied warranty of merchantability" (the product must do what it says it does). Microsoft explicitly disclaims this to prevent users from suing if a bug causes a minor inconvenience or a major system crash.
  • Limitation of Liability: Most agreements cap Microsoft’s financial responsibility at the amount you actually paid for the software. If Windows crashes and costs a business millions in lost revenue, Microsoft’s legal "shield" ensures they are only liable for the $100–$200 cost of the license.

2. The Problem of "Correlated Risk"​

This is the biggest economic reason why software companies can't take 100% responsibility. Unlike a car manufacturer who might have a defect in 5,000 vehicles, a bug in Windows affects 1.4 billion devices simultaneously.
  • Systemic Failure: If Microsoft were legally responsible for every data loss or minute of downtime caused by a bug, a single bad update could result in trillions of dollars in claims—literally more money than exists in the company.
  • Insurability: No insurance company would ever insure a software developer if they were liable for all "consequential damages" (the indirect losses caused by a software failure).

3. The "Security is a Process" Argument​

Microsoft argues that they provide the tools, but you control the environment. They place security responsibility on you because they cannot control:
  • Human Error: If you click a phishing link or use "Password123," Microsoft argues they shouldn't be liable for the resulting breach.
  • Third-Party Software: Windows runs millions of different apps and drivers. If a 3rd-party printer driver creates a security hole, Microsoft uses their terms to ensure they aren't the ones being sued for the "weakest link" in your specific setup.

Summary of Responsibility​

FeatureWho is responsible?Why?
Code BugsUser (At your own risk)Avoids bankrupting the company over one error.
System SecurityUserMicrosoft cannot control your passwords or physical access.
Data BackupsUserStorage is local/private; Microsoft has no "custody" of it.
Initial LicensingMicrosoftThey must prove they have the right to sell you the code.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top