Hacker News new | past | comments | ask | show | jobs | submit login

These files cannot be deleted or modified by the user, even with admin privs. That would make it trivial to disable the antivirus. It's only possible by mounting the file system in a different OS, which is typically prevented by Bitlocker.



The files are deletable through safe mode, no? Iā€™m assuming they are writable by a program outside of the driver, right?


Yes, but you need the Bitlocker key to get into safe mode


Not in the BitLocker configurations I've seen over the last few days. The file is deletable as a local administrator in safe mode without the BitLocker recovery key in at least some configurations.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: