Live data from Hacker News

Windows 10 in-place upgrades are a severe security risk

blog.win-fu.com

11–20 of 124 posts

Re: Windows 10 in-place upgrades are a severe security risk

#11
TL;DR When you do an in-place upgrade it does so in the SYSTEM authority. If you hit Shift+F10 during part of this process you get a Command Prompt running as SYSTEM. Then you can do some file system and registry changes to replace an accessibility feature exe with cmd and again run it under the SYSTEM authority pre-login and add your account to the Administrators group.

Re: Windows 10 in-place upgrades are a severe security risk

#12
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

In all seriousness, why is Fedora the mosts worthy Linux out of them all, in terms of privacy and security? I thought those two were kind of an inherent staple of all Linux distros? In the past I've used Debian Stable with AwesomeWM (the inspiration for Mjolnir) and it felt pretty secure?

I meant the hat not the distro. I use Ubuntu, I am happy with it. Before that used Debian and Slackware. Was happy with those too. Used it for 15 years. Can't complain. I don't feel my computing has been hurt by using Linux. And over time it seems as it's the only sane choice.

Re: Windows 10 in-place upgrades are a severe security risk

#13
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

I think you meant Debian.

Re: Windows 10 in-place upgrades are a severe security risk

#14
post #3
post #2

Sounds like a case of 'already behind the airtight hatch'. If you have administrative privileges to install an OS upgrade then you have administrative privileges to disable filesystem encryption. On the other hand, if MS pushes the update to the PC and it self-launches or can be initiated by a non-administrator, then it seems like there is a real security problem here.

Arent these kinds of updates pushed out my Central IT? Just because they can push it out, there are still a lot of employees watching the update run that probably don't have admin access.

Another common Raymond Chen reminder: "Local Administrator != Domain Administrator". If a user gains administrative privileges on their own machine as part of a corporate network, that just means they can bork their own machine and IT will have to come and take it for repair (and they'll likely be disciplined for doing stupid things against IT policy.) If becoming a local administrator on your own machine allows you more privileges on the network, there's something wrong with the network's security architecture. (After all, in a regular, healthy corporate network, Bring-Your-Own-Machine scenarios—where everyone is their own local administrator—are common without posing any threat.)

Re: Windows 10 in-place upgrades are a severe security risk

#15
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

Fedora is too young for Greybeards.

And there's no active VAX port of Fedora anyway.

Re: Windows 10 in-place upgrades are a severe security risk

#16
post #5

> Stick to LTSB version Good advice in general for almost any software.

Although I think it's strange what they exclude. For example, they didn't include Calculator in Windows Server 2016 LTSB:

http://www.zdnet.com/article/windows-server-2016-ltsb-whats-...

Sure, maybe you wouldn't use it that much, but it's small and useful.

Re: Windows 10 in-place upgrades are a severe security risk

#17
post #5

> Stick to LTSB version Good advice in general for almost any software.

Although I think it's strange what they exclude. For example, they didn't include Calculator in Windows Server 2016 LTSB: http://www.zdnet.com/article/windows-server-2016-ltsb-whats-... Sure, maybe you wouldn't use it that much, but it's small and useful.

The Windows 10 Calculator is a Store app, and Server 2016 LTSB doesn't include Store apps. Therefore, Server 2016 LTSB doesn't have Calculator.

While I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include).

Re: Windows 10 in-place upgrades are a severe security risk

#18
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

I think you meant Debian.

All unix graybeards wear fedoras, you're issued one once your beard is four inches or longer, everyone knows that. ;-)

Re: Windows 10 in-place upgrades are a severe security risk

#19
post #9

I'm disable windows update and windows background intelligent service . The most reason was windows keep re downloading broken update and cost a lot my broadband bandwidth. To secure my laptop, i only remove csript.exe and wscript.exe.

>i only remove csript.exe and wscript.exe.

You are no longer running Windows, you are running alien3d's-special-snowflake-version. Please don't be surprised when many third party programs/games no longer run, because, some of my software certainly won't.

Re: Windows 10 in-place upgrades are a severe security risk

#20

Earlier quoted context omitted.

Although I think it's strange what they exclude. For example, they didn't include Calculator in Windows Server 2016 LTSB: http://www.zdnet.com/article/windows-server-2016-ltsb-whats-... Sure, maybe you wouldn't use it that much, but it's small and useful.

The Windows 10 Calculator is a Store app, and Server 2016 LTSB doesn't include Store apps. Therefore, Server 2016 LTSB doesn't have Calculator. While I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include).

While I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include).

To make another guess, a lot of Server/LTSB users might actually like an even older Calculator:

https://news.ycombinator.com/item?id=10791667

Post reply on HN