BlueHat v17 || Securing Windows Defender Application Guard

preview_player
Показать описание
Saruhan Karademir, Microsoft
David Weston, Microsoft

Windows Defender Application Guard (WDAG) brings the next generation isolation into the browser space. It merges the best of Hyper-V virtualization and Microsoft Edge sandboxing technologies to bring hardware-enforced isolation of untrusted websites from the user’s data and operating system. In this talk, we will walk through the WDAG security promise and architecture. We will explain how it was built from the ground up with security as the number one priority showcasing the architectural decisions that added layers of defense. Finally, we explore how Microsoft’s internal security teams engaged from the very beginning of this feature’s development, helping shape WDAG’s design, finding and fixing critical vulnerabilities, and building additional defense-in-depth layers before the product reached a single customer.

Рекомендации по теме
Комментарии
Автор

Yes but actual owner cannot get into thier pen data due to bitlocker
Which most users don't know exists
Moving to mac or Linux never again microsoft

Threadbow