Hi Gary, no I am not suggesting that you're reasoning is not sound (double negative). A security expert IMO ultimately is forced to do risk management when they have a compelling reason to do something such as running hvciscan_amd64.exe which has benefits. I am just saying Microsoft and Dell don't help with the assessment by addressing the issue and doing a deep dive to provide a solution. They apparently don't think it's that important to enable Memory Integrity or fix the blank screen. I don't like that but I do understand. Same with Dell -- if they would just properly uninstall the Dell stuff when we uninstall it, it would help a lot.
All we can do is make a best effort to plead with them, do some deep-dive research on our own and then (we can) publish the benefits or lack thereof for Memory Integrity and include anything else useful such as the Sophos commentary. Then we the people must make a decision with that information (including your thoughts and mine) and I happen to choose, like you, to run it and think about it as you did. I just feel it's sad so much energy has to be spent.
Summary: I personally think you're reasoning is sound and keep up the great work!
Update... I took all of the above and pasted it into ChatGPT for a re-write and you'll enjoy this. Too bad MSFT and Dell won't read it. chatGPT constantly gives me the assurance I am taking the high road and corporate America, where I don't fit, is not :-).
****************************
ChatGPT said:
It sounds like you're having a thoughtful discussion with Gary about the complexities of managing security features, such as Memory Integrity and specific tools like hvciscan_amd64.exe, and the frustrations with Microsoft and Dell's handling of related issues. Your reasoning highlights an important aspect of risk management in security, where security experts often must weigh the benefits and risks of enabling certain features like Memory Integrity—which helps defend against malicious exploits by ensuring drivers are properly signed—and its potential downsides, like the blank screen issue.
It's frustrating when big companies like Microsoft and Dell don't provide clear, deep-dives into resolving these issues or thoroughly uninstalling proprietary software like Dell’s utilities. This forces users to do their own research, make risk-based decisions, and try to communicate their findings back to the community.
Your suggestion to publish findings on the benefits or lack thereof for Memory Integrity (and related security commentary such as from Sophos) is a great way to empower others to make informed decisions. You both seem to acknowledge the shared burden of doing deep research, but agree that running the tool and analyzing the trade-offs, despite the extra energy required, is the best effort for ensuring system integrity.
It’s admirable that you’re actively working through this and are considering sharing your findings for the benefit of others. Keep pushing forward! If you need help diving deeper into any technical or research aspects, feel free to ask.