<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx</link><description>As mentioned before on this blog (regarding our UAC changes ) and on the IE blog (regarding the SmartScreen® filter for malware ), we have an increased focus to enable customers to be in control and feel confident about the software that they choose to</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9572850</link><pubDate>Tue, 28 Apr 2009 06:24:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9572850</guid><dc:creator>Nehemoth</dc:creator><description>&lt;p&gt;Nice job, as always.&lt;/p&gt;
&lt;p&gt;Keep the information.&lt;/p&gt;
&lt;p&gt;W7 best OS from Microsoft Ever.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9572917</link><pubDate>Tue, 28 Apr 2009 07:07:23 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9572917</guid><dc:creator>RyGuy12</dc:creator><description>&lt;p&gt;I like the fact that security is taking precedence here, but this can be bad in certain situations. &amp;nbsp;For example, I have a flashdrive running Portable Apps. &amp;nbsp;Because AutoRun is disabled, it will be much more difficult to launch the program. &amp;nbsp;The option to reenable AutoRun for removeable media should be able to be changed through the control panel, so those who actually know what they are doing can have ease of access as well as security.&lt;/p&gt;
&lt;p&gt;Thanks, and I can't wait for the release of this awesome OS!&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9572939</link><pubDate>Tue, 28 Apr 2009 07:28:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9572939</guid><dc:creator>Xepol</dc:creator><description>&lt;p&gt;This is a short-sighted half solution.&lt;/p&gt;
&lt;p&gt;Code-signing the autorun.exe applications would be more significant for future looking improvements.&lt;/p&gt;
&lt;p&gt;Using mutlitple hashes to check against a database &amp;nbsp;in a method similar to IE's phishing filter can cover older software.&lt;/p&gt;
&lt;p&gt;If the system is off the internet or an item is not in the database on way or the other, you can use a warning dialog to indicate that there is no way to verify the authenticity of the application much in the way that unsigned activeX controls get treated in an intranet setting.&lt;/p&gt;
&lt;p&gt;For corporate environments, allow AD policies to supliment these databases.&lt;/p&gt;
&lt;p&gt;And then apply this across autoplay unilaterally.&lt;/p&gt;
&lt;p&gt;When possible you verify what IS trustworthy, protect users when recognized threats are found and warn them against potential threats when nothing can be verified. &amp;nbsp;This way, the system can grow, be reactive and actually engender a sense of trust that users can actually rely upon.&lt;/p&gt;
&lt;p&gt;Just randomly turning off autoplay leaves gaping holes in the system that WILL eventually be exploited in ways you have not yet expected. &amp;nbsp;Surely, we have seen enough of those types of solutions?&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9572985</link><pubDate>Tue, 28 Apr 2009 08:02:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9572985</guid><dc:creator>soumyasch</dc:creator><description>&lt;p&gt;This is a good move, but unfortunately this won't cover those malware which deliberately use an icon that looks like a folder for their executable. Those cannot be differentiated from folders at a first glance, unless extension hiding is disabled. That also make the user &amp;quot;lost confidence and don't feel in control&amp;quot;. Why not provide an option to disable silent code execution from removable drives (prompt before any executable can be run from a removable drive), with an user-managed whitelist to allow certain executables (verified by hash-checks) to bypass the prompting?&lt;/p&gt;
&lt;p&gt;Or overlay all executables with a marker that identifies them as executable files.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9572986</link><pubDate>Tue, 28 Apr 2009 08:03:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9572986</guid><dc:creator>Domenico</dc:creator><description>&lt;p&gt;Nice nice nice JOB &amp;nbsp;!!!&lt;/p&gt;
&lt;p&gt;Windows 7 is coming.. resistence ?? FUTILE :D&lt;/p&gt;
&lt;p&gt;Go Team !! &lt;/p&gt;
&lt;p&gt;5 May coming soon &lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573057</link><pubDate>Tue, 28 Apr 2009 09:10:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573057</guid><dc:creator>Kein</dc:creator><description>&lt;p&gt;5 may eh?&lt;/p&gt;
&lt;p&gt;Isn't 7100 build was compiled few days ago? And the article dated april 27. So, I barely doubt any features after build7100 date will be included in RC.&lt;/p&gt;
&lt;p&gt;Or, may be, it is just delayed articles, idk...&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573091</link><pubDate>Tue, 28 Apr 2009 09:36:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573091</guid><dc:creator>mludwig</dc:creator><description>&lt;p&gt;What is annoying the hell out of me is that whenever I dock my laptop I get an Autoplay window, since I have a USB hard drive for backups connected to the dock.&lt;/p&gt;
&lt;p&gt;It makes me mad that I cannot disable it, only if I get rid of it for all USB removable devices.&lt;/p&gt;
&lt;p&gt;I would like the option to turn off Autoplay for specific devices, not just categories.&lt;/p&gt;
&lt;p&gt;@Kein&lt;/p&gt;
&lt;p&gt;You shouldn't expect the developers to run here and quickly type in their newest changes whenever they decide on them. Most of the articles are in-depth views of features that are already implemented.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573347</link><pubDate>Tue, 28 Apr 2009 13:01:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573347</guid><dc:creator>Asesh</dc:creator><description>&lt;p&gt;soumyasch: Ya man I agree with you. I wish Microsoft had done that. It would be really great even for a novice.&lt;/p&gt;
&lt;p&gt;And this is another good move by Microsoft :)&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573382</link><pubDate>Tue, 28 Apr 2009 13:35:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573382</guid><dc:creator>someone</dc:creator><description>&lt;p&gt;Excellent. AutoRun has always had security issues, AutoPlay was a much better effort. Removing AutoRun from AutoPlay is a solid improvement as AutoPlay handlers are fully customizable. But when malware gets onto the system in the first place and registers as an AutoPlay handler, we will get a UAC prompt right? If not, why not introduce UAC prompts when AutoPlay handlers are registered?&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573421</link><pubDate>Tue, 28 Apr 2009 14:22:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573421</guid><dc:creator>Jalf</dc:creator><description>&lt;p&gt;Two comments here. First, where is the secure workaround to allow autoplay? We're providing a product to some clients who specifically want absolutely automatic and transparent install just by plugging in a USB stick. Admittedly, they're not running Win7, and the chance of them upgrading to it any time soon are nonexistent, but it doesn't change that in a couple of cases autoplay may pretty much be a necessity. So some option to sign the executable or similar, to allow autorun to work, please?&lt;/p&gt;
&lt;p&gt;Second, a more personal annoyance. This means that most of the time, we will s the autoplay dialog pop up *with only one option*. So why show it at all? Why not just open Explorer directly, if that is the only option displayed anyway?&lt;/p&gt;
&lt;p&gt;The alternative is clumsy, and looks unprofessional. It gives the impression that you never even thought about how to make this convenient for the user (which may be true, but shouldn't be)&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573448</link><pubDate>Tue, 28 Apr 2009 14:46:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573448</guid><dc:creator>acaldwell@live.com</dc:creator><description>&lt;p&gt;I've read every entry on this blog and I've been astonished how well thought out and engineered it's all been.&lt;/p&gt;
&lt;p&gt;This concept however seems like a knee-jerk reaction to recent security hole. Some of the other suggestions in these comments sound like a much more sensible way of dealing with the problem rather than &amp;quot;someone hacked it, so just disable all of it!&amp;quot;&lt;/p&gt;
&lt;p&gt;Thanks for your great work so far and I hope you'll consider changing this decision. &lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573517</link><pubDate>Tue, 28 Apr 2009 15:44:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573517</guid><dc:creator>krsanford</dc:creator><description>&lt;p&gt;I would have to agree with a few of the other posts on here. &amp;nbsp;This feels like a dodgy workaround for a deeper issue. &amp;nbsp;Simply not showing the autorun tasks in removable media doesn't really stop any infection, it just prolongs the process. &amp;nbsp;I like the ideas that Xepol had posted for more secure autorun actions.&lt;/p&gt;
&lt;p&gt;Maybe you just need to provide us with a bit more detail on this method. &amp;nbsp;However, right now, I don't get any warm fuzzy feelings about what you just wrote.&lt;/p&gt;
&lt;p&gt;On the whole, I think Microsoft is doing a wonderful job, but this area is deffinately lacking.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9573846</link><pubDate>Tue, 28 Apr 2009 19:59:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9573846</guid><dc:creator>wolrah</dc:creator><description>&lt;p&gt;A very nice start, but while this will slow the spread of malware via flash drives, there's still a huge hole open if you're keeping the optical drive autorun feature. &amp;nbsp;People are still generally dumb and a number of them will still put in a CD without thinking about it. &amp;nbsp;There are also U3 USB keys which appear to Windows as an optical drive.&lt;/p&gt;
&lt;p&gt;I think disabling all executable autorun whatsoever is the better option. &amp;nbsp;Yes it means the user might need to (oh no!) double-click setup.exe on their own, but it's far better for security. &amp;nbsp;Neither OS X nor Linux has autorun for a reason.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9574061</link><pubDate>Tue, 28 Apr 2009 22:03:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9574061</guid><dc:creator>Tihiy</dc:creator><description>&lt;p&gt;Autorun from portable devices has never been useful, don't listen to the short-minded asses here.&lt;/p&gt;
&lt;p&gt;It's only matter of several minutes to write, say, lightweight shell service which will reintroduce this functionality better way for caring program vendors.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9574273</link><pubDate>Tue, 28 Apr 2009 23:54:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9574273</guid><dc:creator>manicmarc</dc:creator><description>&lt;p&gt;&amp;quot;To enable customers to be in control and feel confident about the software that they choose to run on their computers&amp;quot;&lt;/p&gt;
&lt;p&gt;This may be slightly off topic, but for while now I have been thinking, what Windows really needs is a repository based install system like Linux.&lt;/p&gt;
&lt;p&gt;Microsoft are working on an &amp;quot;App Store&amp;quot; for Windows Mobile, why not Windows 7 (ok too late, maybe Windows 8)&lt;/p&gt;
&lt;p&gt;We need to condition users so when a web page says you need to install this piece of software they click start &amp;gt; app store and search for it.&lt;/p&gt;
&lt;p&gt;I believe this would help in the fight against drive-by downloads.&lt;/p&gt;
&lt;p&gt;What do guys think? &lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9574735</link><pubDate>Wed, 29 Apr 2009 04:02:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9574735</guid><dc:creator>Don Reba</dc:creator><description>&lt;p&gt;Manicmarc, a Microsoft app store would surely require signed code, which would become a $200-$500/year entry fee that would exclude a lot of software.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9574970</link><pubDate>Wed, 29 Apr 2009 07:25:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9574970</guid><dc:creator>Xlfdll</dc:creator><description>&lt;p&gt;Why not turn General Options to green buttons?&lt;/p&gt;
&lt;p&gt;Like &amp;quot;Open folder to view files&amp;quot; option, why not turn it to a green button or a green-circle button?&lt;/p&gt;
&lt;p&gt;A autorun malware cannot simulate this behavior, I think. Unless malware was activated first, it wouldn't interfere.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9575363</link><pubDate>Wed, 29 Apr 2009 12:04:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9575363</guid><dc:creator>kaiwai</dc:creator><description>&lt;p&gt;How about this idea; get rid of the feature. It is of no measurable benefit to anyone and is a massive security vulnerability that you could fly a 747 through.&lt;/p&gt;
&lt;p&gt;If you want to install something - you have to manually open the cd and double click on the setup.exe file - something that most people are used to anyway so there is no loss by removing the feature in the first place.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9575733</link><pubDate>Wed, 29 Apr 2009 16:38:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9575733</guid><dc:creator>limulus</dc:creator><description>&lt;p&gt;This will break most GPRS modems! (For non-tech-savvy users.)&lt;/p&gt;
&lt;p&gt;Those usually come in the form of a USB drive with the modem driver installing through Autorun once the drive is plugged in - a very convenient, zero-configuration system that works well.&lt;/p&gt;
&lt;p&gt;With Autorun turned off for USB drives, the user will have to navigate to the drive and often make his choice between multiple executables with nondescriptive filenames. At least some GPRS modems (I have one like it) do NOT provide any instructions for this case in their manual. The &amp;quot;no knowledge required&amp;quot;, plug-and-play experience is definitely gone this way.&lt;/p&gt;
&lt;p&gt;I strongly believe that this should be reevaluated. Ideally, a prompt would be shown asking whether the drive should be autorun, along with an appropriate warning message (something which, by the way, should be introduced with optical drives as well).&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9576488</link><pubDate>Thu, 30 Apr 2009 00:04:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9576488</guid><dc:creator>Xepol</dc:creator><description>&lt;p&gt;limulus -&amp;gt; Break is perhaps an overstatement since you can manually run the app and some people already have the feature disabled anyways.&lt;/p&gt;
&lt;p&gt;It will, however, degrade the end user experience.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9576798</link><pubDate>Thu, 30 Apr 2009 01:32:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9576798</guid><dc:creator>cyberdrop</dc:creator><description>&lt;p&gt;I think disabling autorun alltogether is a realy bad idea. &lt;/p&gt;
&lt;p&gt;There are good reasons to use autorun. I'm using a USB-Harddisk with TrueCrypt. If you plug in the drive you can automaticly mount the truecrypt volume using the entry displayed in the autorun dialog.&lt;/p&gt;
&lt;p&gt;Without autorun you have to start truecrypt and set all the options, which are normally set by using command line options in autorun.ini, manually.&lt;/p&gt;
&lt;p&gt;I think enabling autorun for signed executables is a good compromise.&lt;/p&gt;
</description></item><item><title>re: crippling AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9576826</link><pubDate>Thu, 30 Apr 2009 01:36:54 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9576826</guid><dc:creator>davidmahaffy</dc:creator><description>&lt;p&gt;Short-sighted move. &amp;nbsp;I've found autorun very useful for utilities I place on a USB drive. &amp;nbsp;For example, insert the USB drive, launch the portable TrueCrypt to auto-mount my secure volume.&lt;/p&gt;
&lt;p&gt;Vista had a good practice of asking if you wanted to autorun. Disabling it totally will be annoying. &amp;nbsp;If you're going to disable it, at least give those of us who know what we're doing the option to go into Control Panels and turn it back on.&lt;/p&gt;
&lt;p&gt;It worked with UAC: giving me the option to turn it off completely kept me from hurling my Vista PC out the window. &amp;nbsp;(Three separate UAC prompts to create a new folder in my start menu and move something into it kinda sent me over the edge.) &amp;nbsp;I turned off UAC and have no problems with malware. Autorun (especially with the &amp;quot;ask first&amp;quot;) is not going to cause me problems either.&lt;/p&gt;
</description></item><item><title>Response to feedback</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9577194</link><pubDate>Thu, 30 Apr 2009 02:43:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9577194</guid><dc:creator>arikc</dc:creator><description>&lt;p&gt;Thank you for the feedback. &amp;nbsp;I wanted to chime in directly on limulus's comment about GPRS modems.&lt;/p&gt;
&lt;p&gt;In our testing, most of the GPRS modems are not affected by the change because they expose their driver partition as a emulated CD drive. &amp;nbsp;This partition can continue to display an AutoRun task to you. &amp;nbsp;For example, the TRU-Install driver installation used by many of these devices like the Sprint Compass 597 or O2 Compass 885 continues to run without any changes. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Because a particular device must declare itself as a emulated CD drive in the firmware of the device, we can trust that the IHV has done that for the purpose of exposing the device content like their physical installation CDs and malware cannot cause a generic USB flash drive to mimic this experience.&lt;/p&gt;
&lt;p&gt;- Arik Cohen&lt;/p&gt;
</description></item><item><title>Signature requirements</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9577759</link><pubDate>Thu, 30 Apr 2009 04:53:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9577759</guid><dc:creator>MikeMS</dc:creator><description>&lt;p&gt;I was wondering what the requirements are for &amp;quot;Publisher not specified&amp;quot; vs. &amp;quot;Published by ...&amp;quot;&lt;/p&gt;
&lt;p&gt;Microsoft tends to be somewhat inconsistent here, and it could be a healthy opportunity to revise the specs.&lt;/p&gt;
&lt;p&gt;At different times (security warnings when running a local/online/blocked file, properties, etc.), the publisher name shown to the user is either taken from the digital signature, or from the resource (RC). This duality is not good, especially when the two strings are different.&lt;/p&gt;
&lt;p&gt;Additionally, different requirements exist for what constitutes a &amp;quot;trusted&amp;quot; digital signature: for some parts of the Microsoft universe, only a Class 3 code signing certificate by providers such as VeriSign is good enough (e.g. for Winqual/logo purposes). For others, any signature will do (Thawte, Comodo, etc.)&lt;/p&gt;
&lt;p&gt;As some have posted here, it would be good to at least demand that any executable code that is invoked by AutoRun be signed. I fully agree with that. As the dialogs indicate, the choice has already been made to expose a publisher name to the user, so this should IMHO come from the Authenticode information, and nowhere else (not from the simple file properties).&lt;/p&gt;
&lt;p&gt;While agreeing to the signing requirements, I'd also have to add that this would not solve the issue of malware. Drivers also have to be signed, yet unsigned code can exploit a driver to invoke something else. While this is generally malicious, an AutoRun application usually does this by design, because AutoRun launchers such as MenuBox are there exactly to open a window and propose some options which include launching an installer, running an application from CD or USB, etc. USB itself is increasingly chosen as an application distribution medium (while standards are on the rise to trust the USB medium).&lt;/p&gt;
&lt;p&gt;HTML Applications (HTA files) are another example, similar to an AutoRun launcher application. By design, Microsoft allows HTAs to be unsigned and to run executables. Which is great for AutoRun. Should we break this, only because of some new signature requirements? Even if you signed the first layer, the second layer (invoked by HTA or apps like MenuBox) would still not be subject to the same requirement.&lt;/p&gt;
&lt;p&gt;My opinion is that at the very least, &amp;quot;Published by ...&amp;quot; should have information coming from Authenticode. If the application is unsigned, it should be marked as such. This is because you are providing this information to the user with respect to this specific application, and the information should be as accurate and trackable as possible.&lt;/p&gt;
&lt;p&gt;For the rest, the issue is more complex than it may seem at first sight, and autoRun itself is not the (only) problem. IMHO, code signing should be a requirement for all executables, at least in an optional way, if you want to raise the bar for what may or may not run on a PC. So any user, home or corporate, could have a list of trusted application publishers, if desired, and the surface for malicious code management would be narrowed a lot. Code exploits and social engineering will always exist, but if all code were signed, from Windows system executables, to applications, management would be easier. Doing this in a &amp;quot;leaky&amp;quot; way will always favor the unpatched scenario, be that a USB key that looks like a CD drive to the system, or a second layer that is not subject to the restrictions of the first layer, like unsigned code run by signed code.&lt;/p&gt;
&lt;p&gt;At the end of this, I just noticed that Windows 7 has a feature called &amp;quot;AppLocker&amp;quot;, which I haven't seen yet. It may do what I was talking about, with respect to only allowing signed code with certain requirements to run. I hope that AutoRun and AppLocker will work hand in hand, giving the user the option to add a publisher that is &amp;quot;introduced&amp;quot; in an AutoRun context to the AppLocker list, without jumping through too many dialogs.&lt;/p&gt;
&lt;p&gt;Just my two cents!&lt;/p&gt;
&lt;p&gt;Mike&lt;/p&gt;
</description></item><item><title>Optical discs are historically an attack vector</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9577819</link><pubDate>Thu, 30 Apr 2009 05:18:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9577819</guid><dc:creator>mechBgon</dc:creator><description>&lt;p&gt;Be aware that optical discs (CDs and DVDs) are routinely used as an attack vector by malware. &amp;nbsp;To cite just a few examples, there's the W32.Mabezat, W32.HLLW.Infex, and W32.Serflog families, which add their own executable and autorun.inf to the %UserProfile%\Local Settings\Application Data\Microsoft\CD Burning &amp;nbsp;directory, so any disc the user burns will be infected. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is historically a pretty widespread tactic, so keep it in mind.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9581958</link><pubDate>Fri, 01 May 2009 09:25:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9581958</guid><dc:creator>limulus</dc:creator><description>&lt;p&gt;@ Arik Cohen:&lt;/p&gt;
&lt;p&gt;That is very interesting. I wasn't aware of this functionality in those drives. To me it always looked like they are just standard USB drives.&lt;/p&gt;
&lt;p&gt;I have to admit that the idea of emulating a CD drive for this purpose is amazing.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9582973</link><pubDate>Sat, 02 May 2009 00:11:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9582973</guid><dc:creator>phongm</dc:creator><description>&lt;p&gt; &amp;nbsp;I understand the threat and concerns of virus spreading through removable drive by Microsoft and limit this auto play feature is a good thing. &amp;nbsp;However, if we totally disable the autorun feature for all removable drive will have an affect with some removable drive products. &lt;/p&gt;
&lt;p&gt; &amp;nbsp;I'm using a secure USB drive where instead of using CDs emulation to auto launch the application to unlock the secure partition by taking advantage of auto play feature for CDs, this drive would just show as a normal read-only removable drive and launching the application to unlock the private partition with the autorun feature. &amp;nbsp;Thus, when this feature is turned-off for all the removable drive the user experience will have an impact.&lt;/p&gt;
&lt;p&gt; &amp;nbsp;In my opinion, to be fare with all the CDs emulator drive where autorun doesn't get turned off, Microsoft products should still let's the autorun and autoplay feature available for all READ-ONLY removable drive, media. &amp;nbsp;Thus it won't affect lots of removable media already out in the market. &amp;nbsp; &lt;/p&gt;
&lt;p&gt;Phong&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9583352</link><pubDate>Sat, 02 May 2009 07:16:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9583352</guid><dc:creator>gabsoftware</dc:creator><description>&lt;p&gt;That's a good thing to disable this thing at all, that was a wide security whole. At present I fear each time someone want to plug a USB drive onto my computer, and most of the time there is some kind of malware. Autorun or Autoplay should never had existed.&lt;/p&gt;
&lt;p&gt;To those who complain about it, it's not that difficult for the user to explore his drive and launch what he wants, only two clicks, are you so lazy ?&lt;/p&gt;
&lt;p&gt;There still remains the kind of malware who hide the folders and create some executables files named accordingly to the hidden folders. For that, it would be nice to have a way to differentiate an executable file from the others !&lt;/p&gt;
</description></item><item><title>sorry about the OFF</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9583548</link><pubDate>Sat, 02 May 2009 12:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9583548</guid><dc:creator>lyesmith</dc:creator><description>&lt;p&gt;Finally installed the RC. Just wondering is there any settings for Aero Peak? It would be great to have an application exclusion list or something. We have the Sticky Note which makes a useful gadget but disappears on Aero Peak. :( Actually what is the reason for Aero Peak if it hides everything? So you can have a peak on your desktop background? Yeah ok it keeps the desktop gadgets. But those are not really useful. it should keep the Calculator, Sticky Notes, Contacts, Character Map basically a there should be a customizable list of software.&lt;/p&gt;
&lt;p&gt;Love the ability for displaying UTC time though.&lt;/p&gt;
&lt;p&gt;Also there should be a way to control network traffic (controlling upload/download speed and schedule) natively in the OS. I use Netlimiter but it is crashing under W7.&lt;/p&gt;
&lt;p&gt;Anyway W7 is nice unforunatelly lots of cool feature have not made it into &amp;nbsp;the RC. (like multiple desktops) Wonder why, concurrent OS-s have that for ages now. All to gather it is how Vista should have looked like 3 years ago. Nothing revolutionary compared to Vista SP1 just more cleaned up.&lt;/p&gt;
&lt;p&gt;Again very nice OS but somehow it is missing the edge, the one that cuts.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9584951</link><pubDate>Mon, 04 May 2009 00:55:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9584951</guid><dc:creator>SwooshyCueb</dc:creator><description>&lt;p&gt;This interferes with Ceedo. WHYYYYYYYYYYYYYYYYYYYY? I LOVE CEEDO!&lt;/p&gt;
</description></item><item><title>PROPOSAL: Use Signed Code For a Better Solution</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9589230</link><pubDate>Tue, 05 May 2009 20:00:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9589230</guid><dc:creator>John T. Haller</dc:creator><description>&lt;p&gt;I believe this solution disables functionality used by millions of users (the ability to easily start legitimate software installed on portable devices like the PortableApps.com Platform) while still leaving a vulnerability that has been used in the past (malware autorunning from CDs/DVDs like Sony's malicious software fiasco).&lt;/p&gt;
&lt;p&gt;A better solution would be to check for signed code. &amp;nbsp;This could be easily accomplished using the existing infrastructure (including revoking remotely) and presented to the user simply with a minimum of coding changes.&lt;/p&gt;
&lt;p&gt;I've put together a complete proposal with the details and screenshots here:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://johnhaller.com/jh/useful_stuff/windows_7_autoplay/"&gt;http://johnhaller.com/jh/useful_stuff/windows_7_autoplay/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>"Improvements" ...really!? (+PROPOSAL)</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9593956</link><pubDate>Thu, 07 May 2009 19:18:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9593956</guid><dc:creator>Duggeek</dc:creator><description>&lt;p&gt;This has been a part of Windows functionality for over a decade. While a few mal-ware proponents have taken liberty with Autoplay and Autorun functionality, many more actual customers and users have found it a boon. &lt;/p&gt;
&lt;p&gt;I agree that security and having confidence in the Windows environment is paramount, however it just seems like you're &amp;quot;throwing out the baby with the bathwater&amp;quot; here.&lt;/p&gt;
&lt;p&gt;The Dev Team sure is proud of their &amp;quot;deep insight&amp;quot; features, why not apply that same thinking to AutoPlay? In the dialog, add visual indicators regarding the validity (digital sig's anyone?) of the executables. Your illustration--with the red and green outlines--seems to be an excellent start; why not grow on that concept?&lt;/p&gt;
&lt;p&gt;&amp;quot;Spoofs&amp;quot; are easy to detect, since they are mocking the appearance of the UI defaults... we don't even need WinDefender to check it, it's obvious because it's a copy-cat!&lt;/p&gt;
&lt;p&gt;(Nodding to others in the thread) Regarding selective AutoPlay actions with respect to individual media; for anyone that works with more than 10 different removable drives in the course of a day, picking specific behavior for each drive could surely be a boon. Moreover, eliminating AutoPlay framework for removable/re-writable media would impact a significant portion of IT professionals that have crafted independent (sometimes ingenious) solutions around that framework.&lt;/p&gt;
&lt;p&gt;AutoPlay was conjured-up in the age of the CD-ROM... well before the advent of flash-memory media. The problem has been that the AutoPlay framework &amp;quot;stood still&amp;quot; while a wave of removable media washed over the industry; today, there's just as much a chance that users will insert USB key drives or card-readers than a CD-ROM or DVD. AutoPlay should reflect that fact, as well as anticipate potential abuses.&lt;/p&gt;
&lt;p&gt;Re-consider this move; have you really come all this way just to axe an idea that was introduced before its time?&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9609735</link><pubDate>Wed, 13 May 2009 19:57:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9609735</guid><dc:creator>vicza</dc:creator><description>&lt;p&gt;It's good that you have removed AutoPlay, but could you please also return the option &amp;quot;Do nothing&amp;quot; in this windows? It was in Win XP. Theoretically, there also was a possibility to remember this choice (did not work always, though). But not in Vista, nor in Win 7. Why? It's *terribly* annoying. Why I insert my flash drive I do not want _any_ windows to appear. Return this option, please.&lt;/p&gt;
</description></item><item><title>Signed applications</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9634992</link><pubDate>Fri, 22 May 2009 13:38:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9634992</guid><dc:creator>Soon Bing</dc:creator><description>&lt;p&gt;I noticed that Internet Explorer 8 automatically checks the hashes of any file downloads, and can block potentially suspicious files. Would it be a better idea to have a similar implementation for the Auto-Play feature?&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9656532</link><pubDate>Fri, 29 May 2009 22:38:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9656532</guid><dc:creator>k0b033</dc:creator><description>&lt;p&gt;Here's a pretty simple idea that I'm surprised no one has mentioned yet. &lt;/p&gt;
&lt;p&gt;Why don't you just disallow anyone from creating an AutoRun/AutoPlay option that is named &amp;quot;Open folder to view files&amp;quot;? (or other variants/languages)&lt;/p&gt;
&lt;p&gt;Prevent ASCII or those ALT+keypad codes or any other workaround, and that should reduce the chances of anyone mistaking file execution from file viewing.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9674115</link><pubDate>Mon, 01 Jun 2009 06:02:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9674115</guid><dc:creator>mucs</dc:creator><description>&lt;p&gt;For me, it would be nice if there's an option to run anti-virus scan on autoplay.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9742968</link><pubDate>Sat, 13 Jun 2009 11:55:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9742968</guid><dc:creator>Thesis Help</dc:creator><description>&lt;p&gt;The problem has been that the AutoPlay framework &amp;quot;stood still&amp;quot; while a wave of removable media washed over the industry; today, there's just as much a chance that users will insert USB key drives or card-readers than a CD-ROM or DVD. AutoPlay should reflect that fact, as well as anticipate potential abuses.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9742976</link><pubDate>Sat, 13 Jun 2009 11:56:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9742976</guid><dc:creator>GCSE Coursework</dc:creator><description>&lt;p&gt;There still remains the kind of malware who hide the folders and create some executables files named accordingly to the hidden folders. For that, it would be nice to have a way to differentiate an executable file from the others !&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9802456</link><pubDate>Thu, 25 Jun 2009 03:06:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9802456</guid><dc:creator>Paddy Power Free Bet</dc:creator><description>&lt;p&gt;I think that a serious problemis the fact that the autoplay framework feature basically froze which a torrent of removable media flooded the market. It is in need of a complete overhaul, I hope to see this in the newly released version of windows.&lt;/p&gt;
</description></item><item><title>Autoplay for blind people</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9810528</link><pubDate>Wed, 01 Jul 2009 11:52:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9810528</guid><dc:creator>laurentz</dc:creator><description>&lt;p&gt;As limulus mentioned, it will break some software, like for instance a usb stick (with CDrom partition)which launches a screenreader for blind people. Under XP, when the user plugs the USB stick, the software is automagically launched without further action, so even a blind people can run it. Now, under W7, it will require the user to click a button... err remember, he's blind !&lt;/p&gt;
&lt;p&gt;What do you suggest ?&lt;/p&gt;
&lt;p&gt;We cannot require that his computer (potentially it could be a public computer) is preconfigured to &amp;quot;always run&amp;quot; the software from CD.&lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9922788</link><pubDate>Mon, 16 Nov 2009 04:07:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9922788</guid><dc:creator>deemon@gmail.com</dc:creator><description>&lt;p&gt;The biggest and easiest improvement to the AutoRun/AutoPlay feature would be an easy and reliable way to turn it off completely. This feature is hugely annoying and a security hole, why is there no checkbox in the control panel to do ABSOLUTELY NOTHING when a new drive is connected? &amp;nbsp;Like, completely and absolutely, no exceptions, no content handlers, no autoinstalls, no nothing. When it's not possible, I feel that I am simply not in control of my own PC, and this absolutely sucks and makes me want to install Ubuntu.&lt;/p&gt;
&lt;p&gt;I don't want the Windows Explorer to hand-hold me, just don't look into my disks until I've told you to, how hard is that? On the Vista, you have to install a patch to be able to disable it, can it get any worse? Why am I not in control of my own PC? &lt;/p&gt;
</description></item><item><title>re: Improvements to AutoPlay</title><link>http://blogs.msdn.com/e7/archive/2009/04/27/improvements-to-autoplay.aspx#9929751</link><pubDate>Sun, 29 Nov 2009 05:22:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9929751</guid><dc:creator>blu ray ripper</dc:creator><description>&lt;p&gt;Great stuff.That sounds pretty cool. Really helpful thanks for the Article, Great job, hope we can expect more advanced....&lt;/p&gt;
</description></item></channel></rss>