Live data from Hacker News

Windows 10 in-place upgrades are a severe security risk

blog.win-fu.com

41–50 of 124 posts

Re: Windows 10 in-place upgrades are a severe security risk

#41
post #26
post #22

Earlier quoted context omitted.

Fedora 25 is best ever, you should try it. Now that then replaced X with Wayland it should become be ever more secure.

Does Fedora still recommend wipe->reinstall from scratch as the default upgrade path?

I'm not sure what they recommend, but the in-place upgrade path for Fedora works really really well.

Re: Windows 10 in-place upgrades are a severe security risk

#42
post #29

To really be considered white hat wouldn't you have to wait until the fix is deployed?

That's exactly how responsible disclosure works. You wait until after the patch, then you do the blog post. In that order. Publishing early just damages your relationship with the company, the community, and makes it more well known that you _don't_ have good intentions.

In this case the next time the vulnerability will be available is with the release of the next upgrade, expected around March.

Re: Windows 10 in-place upgrades are a severe security risk

#43
post #11

TL;DR When you do an in-place upgrade it does so in the SYSTEM authority. If you hit Shift+F10 during part of this process you get a Command Prompt running as SYSTEM. Then you can do some file system and registry changes to replace an accessibility feature exe with cmd and again run it under the SYSTEM authority pre-login and add your account to the Administrators group.

That's not the bad part. The bad part is that this process suspends the disk encryption. Without disk encryption having physical access to the machine would be enough to elevate priviledges anyway.

Re: Windows 10 in-place upgrades are a severe security risk

#44
post #21
post #19

Earlier quoted context omitted.

>i only remove csript.exe and wscript.exe. You are no longer running Windows, you are running alien3d's-special-snowflake-version. Please don't be surprised when many third party programs/games no longer run, because, some of my software certainly won't.

We are dealing with this right now with our software. Our end users on Windows 7 who haven't kept their machine up to date can't install the VC++ 2015 redistributable which is required to run our software. It's a Microsoft problem but it's still frustrating having to do basic tech support for them just because they won't let Windows do the updates that it is insistently but politely asking them to let it do. Not a pr…

With all due respect, if your software has an OS-level dependency that is less than 2 years old, you're too cutting edge and it's your fault.

You should not require an unpackaged dependency from 2015. This is a problem with your developers trying to use the latest and greatest technologies, with no respect for reality. It is neither your users', nor Microsoft's fault, that your users don't have bleeding edge 2015 upgrades.

Re: Windows 10 in-place upgrades are a severe security risk

#45
post #34

Earlier quoted context omitted.

The Windows 10 Calculator is a Store app, and Server 2016 LTSB doesn't include Store apps. Therefore, Server 2016 LTSB doesn't have Calculator. While I guess they could bundle the Windows 7/8 Calculator with Server 2016, that would make server and desktop Windows different (for a feature that both include).

They don't even include the Edge browser on Windows 10 LTSB. That's ... strange. Edge has been out for like 18 months on Windows 10. They really seem to have taken out the whole UWP platform on LTSB, so we once again see that the whole "one Windows to rule them all" spiel is nothing but a nice marketing story Microsoft likes to tell its fans, but not as real as they might like it to be. Unfortunately this just means…

LTSB was launched being stable in mind, which Edge at the time certainly wasn't. Nothing strange here.

Re: Windows 10 in-place upgrades are a severe security risk

#46
post #43
post #11

TL;DR When you do an in-place upgrade it does so in the SYSTEM authority. If you hit Shift+F10 during part of this process you get a Command Prompt running as SYSTEM. Then you can do some file system and registry changes to replace an accessibility feature exe with cmd and again run it under the SYSTEM authority pre-login and add your account to the Administrators group.

That's not the bad part. The bad part is that this process suspends the disk encryption. Without disk encryption having physical access to the machine would be enough to elevate priviledges anyway.

Yes but that is documented as part of any in-place system upgrade or firmware upgrade https://technet.microsoft.com/en-us/library/jj649830.aspx

Re: Windows 10 in-place upgrades are a severe security risk

#47
post #40
post #27

Is there not a presumption that with physical access to a machine it can be rooted if you try hard enough? I certainly make that presumption. The number of Macs I've unlocked by creating a new admin by removing the "install is finished" file in single user mode is in the teens.

> The number of Macs I've unlocked by creating a new admin by removing the "install is finished" file in single user mode is in the teens. What's the procedure, in case I need to unlock a mac someday?

http://apple.stackexchange.com/questions/164331/i-dont-have-...

Won't work on an encrypted system, of course.

Re: Windows 10 in-place upgrades are a severe security risk

#48
post #14
post #3

Earlier quoted context omitted.

Arent these kinds of updates pushed out my Central IT? Just because they can push it out, there are still a lot of employees watching the update run that probably don't have admin access.

Another common Raymond Chen reminder: "Local Administrator != Domain Administrator". If a user gains administrative privileges on their own machine as part of a corporate network, that just means they can bork their own machine and IT will have to come and take it for repair (and they'll likely be disciplined for doing stupid things against IT policy.) If becoming a local administrator on your own machine allows you…

Assuming all machines on the network do not have the same local admin password.

Re: Windows 10 in-place upgrades are a severe security risk

#50
All this and the comments assume Windows will let you upgrade at all. Google "windows 10 upgrade something happened" and then try to find the fix for that amazing piece of error reporting.

In my case it was either that the language pack was wrong: Eng UK not Eng US, neither of which actually have language pack installed... or it was the Win toobar/menubar being docked to the left of the screen and not the bottom. One of these stopped the upgrade completely, repeatedly. The greatest security risk had to be getting stuck on an old version of Windows with no good info on how to fix a 2 year old bug in the upgrade process.

Post reply on HN