Live data from Hacker News

Windows 10 in-place upgrades are a severe security risk

blog.win-fu.com

21–30 of 124 posts

Re: Windows 10 in-place upgrades are a severe security risk

#21
post #19
post #9

I'm disable windows update and windows background intelligent service . The most reason was windows keep re downloading broken update and cost a lot my broadband bandwidth. To secure my laptop, i only remove csript.exe and wscript.exe.

>i only remove csript.exe and wscript.exe. You are no longer running Windows, you are running alien3d's-special-snowflake-version. Please don't be surprised when many third party programs/games no longer run, because, some of my software certainly won't.

We are dealing with this right now with our software. Our end users on Windows 7 who haven't kept their machine up to date can't install the VC++ 2015 redistributable which is required to run our software. It's a Microsoft problem but it's still frustrating having to do basic tech support for them just because they won't let Windows do the updates that it is insistently but politely asking them to let it do. Not a problem with our Windows 10 end users, of course.

Re: Windows 10 in-place upgrades are a severe security risk

#22
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

In all seriousness, why is Fedora the mosts worthy Linux out of them all, in terms of privacy and security? I thought those two were kind of an inherent staple of all Linux distros? In the past I've used Debian Stable with AwesomeWM (the inspiration for Mjolnir) and it felt pretty secure?

Fedora 25 is best ever, you should try it. Now that then replaced X with Wayland it should become be ever more secure.

Re: Windows 10 in-place upgrades are a severe security risk

#23
post #2

Sounds like a case of 'already behind the airtight hatch'. If you have administrative privileges to install an OS upgrade then you have administrative privileges to disable filesystem encryption. On the other hand, if MS pushes the update to the PC and it self-launches or can be initiated by a non-administrator, then it seems like there is a real security problem here.

I think the point is that bitlocker means that a locked machine shouldn't be accessible to anyone even at the keyboard who doesn't know the password. If that machine happens to be executing an upgrade, even a scheduled upgrade, this is a bitlocker security bypass.

Re: Windows 10 in-place upgrades are a severe security risk

#24
post #21
post #19

Earlier quoted context omitted.

>i only remove csript.exe and wscript.exe. You are no longer running Windows, you are running alien3d's-special-snowflake-version. Please don't be surprised when many third party programs/games no longer run, because, some of my software certainly won't.

We are dealing with this right now with our software. Our end users on Windows 7 who haven't kept their machine up to date can't install the VC++ 2015 redistributable which is required to run our software. It's a Microsoft problem but it's still frustrating having to do basic tech support for them just because they won't let Windows do the updates that it is insistently but politely asking them to let it do. Not a pr…

These days I don't blame them. I'm guilty of it myself. After Microsoft repeatedly dropped in the Windows 10 "updates" (including nag) under new names it got to be enough of a hassle to avoid them that I've basically stopped updating. Finding the latest update names to ignore, then actually finding them in the update listing is enough of a pain to get me to continually put it off.

Re: Windows 10 in-place upgrades are a severe security risk

#25
post #23
post #2

Sounds like a case of 'already behind the airtight hatch'. If you have administrative privileges to install an OS upgrade then you have administrative privileges to disable filesystem encryption. On the other hand, if MS pushes the update to the PC and it self-launches or can be initiated by a non-administrator, then it seems like there is a real security problem here.

I think the point is that bitlocker means that a locked machine shouldn't be accessible to anyone even at the keyboard who doesn't know the password. If that machine happens to be executing an upgrade, even a scheduled upgrade, this is a bitlocker security bypass.

It sounds like a machine running the upgrade can't be screen locked, which means you can't safely, e.g., use the restroom until it's finished.

Re: Windows 10 in-place upgrades are a severe security risk

#26
post #22

Earlier quoted context omitted.

In all seriousness, why is Fedora the mosts worthy Linux out of them all, in terms of privacy and security? I thought those two were kind of an inherent staple of all Linux distros? In the past I've used Debian Stable with AwesomeWM (the inspiration for Mjolnir) and it felt pretty secure?

Fedora 25 is best ever, you should try it. Now that then replaced X with Wayland it should become be ever more secure.

Does Fedora still recommend wipe->reinstall from scratch as the default upgrade path?

Re: Windows 10 in-place upgrades are a severe security risk

#27
Is there not a presumption that with physical access to a machine it can be rooted if you try hard enough? I certainly make that presumption.

The number of Macs I've unlocked by creating a new admin by removing the "install is finished" file in single user mode is in the teens.

Re: Windows 10 in-place upgrades are a severe security risk

#28
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

If you're going to recommend a Linux for security, I would have assumed it'd be Tails. For maximum greybeard, I'd go with Gentoo. But this is hacker news, I don't think your average user here is just hearing about Linux from this thread.

Re: Windows 10 in-place upgrades are a severe security risk

#29

To really be considered white hat wouldn't you have to wait until the fix is deployed?

That's exactly how responsible disclosure works. You wait until after the patch, then you do the blog post. In that order.

Publishing early just damages your relationship with the company, the community, and makes it more well known that you _don't_ have good intentions.

Re: Windows 10 in-place upgrades are a severe security risk

#30
post #7

Come join Linux my friends. My fedora hat wearing greybeards wait for you. Only operating system left that gives semblance of privacy and security. And to those who think I am derailing... http://news.softpedia.com/news/microsoft-wants-all-linux-dev...

Call me when linus in all of his trumpiness accepts rust until then i'm #teamwindows
Post reply on HN