The 24H2 Update will include Windows Protected Print (WPP). If you have a compatible printer or no printer at all, I really encourage those who care about security to enable the feature. Enabling WPP switches users to the new print stack which kills a LOT of attack surface in Windows. It is one of the largest reductions of overall attack surface in Windows that I can recall. Moreover, it disables all 3rd party drivers. In the next month or two, the Restricted Worker update will also be applied which will remove SYSTEM privileges. We wanted to land it with the release, but we had a small last minute bug to address.

You can find me previous blog on the topic here -> techcommunity.microsoft.com/t5

Docs here: learn.microsoft.com/en-us/wind

This will be the default in future versions of Windows

@spoofy
> Moreover, it disables all 3rd party drivers

how does that work?

Are there printer-specific drivers included with Windows that are considered first-party?

Or are all printers now required to use some standardized communication protocol, so that no model-specific driver is necessary?

Follow

@wolf480pl @spoofy IPP is that standard. Been defacto standard for print on Linux for a decade or so
Not sure what Mac does

@falken @wolf480pl @spoofy macOS uses CUPS as well; the Linux version is a fork of it. The proprietary Mopria standard Windows is using just specifies exactly what subset of IPP options and print data needs to be supported.

@carey @falken @spoofy
I thought IPP works only over network... does it also work over USB?

Also, do printers these days no longer require the documents to be first converted to a vendor-specific format before sending? (eg. the old HP 1018 required converting to ZJS using foo2zjs)

@wolf480pl @falken @spoofy Yes, there's an IPP over USB standard.

I've never found a good description of exactly what's in the Mopria standard from anyone involved in it, but OpenPrinting lists two bitmap formats plus PDF as what's required from compatible printers: openprinting.github.io/driverl

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.