虎嗅

Session 0: Twenty Years of Microsoft Paying for its "Performance Greed"

原文:Session 0:微软为“性能贪婪”买单的二十年

Summary of Key Points

This article discusses the evolution of the "Session 0 isolation" mechanism in Microsoft's Windows operating system: from an early design that shared the same execution space between system services and user programs (Session 0) for performance and convenience, to a later decision to completely separate them due to security vulnerabilities, ultimately sacrificing short-term ecological compatibility to address underlying security issues. The entire process reflects the eternal trade-off among "performance, security, and compatibility" in technical decisions.

I. Early Windows: "Elegant but Slow" – Why Did NT3.1 Crash Users?

When Microsoft released Windows NT3.1 in 1993, its goal was to compete with UNIX in the server market, so the design was particularly "elegant": the graphics rendering (GDI/USER) was made into an independent user-mode process (csrss.exe). All programs, whether background services or desktop software, had to rely on inter-process communication (LPC) to request graphics rendering from this process.

However, this design was a disaster under the hardware conditions of the time: when a user moved a window, the system had to switch between multiple processes hundreds of times, resulting in a laggy and unresponsive interface. For example, moving a browser window would take a long time, leading to a poor user experience. This was the price of achieving good security isolation at the expense of performance.

II. Compromising for Performance: NT4.0 Moved Graphics into the Kernel – Session 0 Became a Double-Edged Sword

In 1996, Microsoft decided to move the graphics subsystem (GDI/USER) directly into the kernel (as win32k.sys). This eliminated the need for inter-process communication, significantly improving graphics rendering speed and making the Windows desktop much smoother – a crucial step in its later dominance on PCs.

But there were hidden drawbacks: to allow services to display pop-ups to users (such as backup notifications saying "Disk is full"), Microsoft allowed background services and the first logged-in user to share the same Session (Session 0), as well as the desktop and message queue. While this seemed convenient, it was like putting high-privilege system services in the same room as regular user programs, potentially introducing security risks.

III. The Security Crisis: The Shatter Attack

After 2000, security experts discovered the "Shatter Attack," which allowed a low-privilege program to send malicious messages to high-privilege service windows within Session 0. For instance, sending a message that prompted a service to execute certain code could grant the low-privilege user full system privileges (SYSTEM). This was not a bug in any specific software but a fundamental design flaw: as long as services and users were in the same Session, such attacks were unavoidable. At the time, Microsoft was promoting "trusted computing" and placing security at the forefront; Bill Gates personally ordered the resolution of this issue, dealing with a problem that had been created for performance reasons ten years earlier.

IV. Session 0 Isolation: A Victory for Security, but at a Cost to the Ecosystem

With the release of Vista in 2006, Microsoft completely separated services from user programs, keeping services in Session 0 (which could not display any interfaces) and users in Session 1. This effectively prevented the Shatter Attack, but it came at a heavy cost:

Numerous older software applications, such as enterprise backup tools and antivirus programs, relied on service-generated pop-ups, which caused widespread failures when Vista was launched. Users complained about incompatibility. Microsoft had to implement a temporary workaround: when a service tried to display a pop-up, a message would appear in the lower right corner, and clicking it would switch to a blank, temporary Session 0 desktop. Although the experience was poor, it was necessary to maintain compatibility with older software. It wasn't until Win10 that Microsoft eliminated this transitional solution.

V. The Eternal Dilemma of Technical Decisions: Security Borders vs. Performance Efficiency

This history illustrates a common cycle in technology: first, there is a merge for performance/convenience (NT4.0), followed by a split for security/long-term stability (Vista). Modern technologies like Linux containers, browser sandboxes, and WebAssembly face similar trade-offs.

For example, browser sandboxes isolate each web page to prevent malicious attacks, but they increase memory usage; Linux containers package applications in separate environments, which are more secure but less efficient. Essentially, there is no "perfect solution" in technical decisions; only the most appropriate one for the current context. Early Microsoft prioritized performance to capture the PC market, while later security issues forced a shift that came at an ecological cost. This is similar to business strategies: short-term gains may require sacrificing quality for growth, with potential longer-term costs to restore balance.

This article teaches us that technological progress is never smooth sailing; every optimization may carry future challenges, and the process of resolving those challenges is part of maturing technology.