Live data from Hacker News

Windows 10 in-place upgrades are a severe security risk

blog.win-fu.com

121–124 of 124 posts

Re: Windows 10 in-place upgrades are a severe security risk

#121
post #48

Earlier quoted context omitted.

Assuming all machines on the network do not have the same local admin password.

This is a privilege escalation bug that lets you reset the admin password, but it doesn't give you the old password.

I want to block my young teen-aged son from hacking into his time-locked win 7 (soon win 10). He already searched the web and found some kind of system restore scheme to reset his password. Next step was to encrypt the hard drive to block rebooting without password.

Re: Windows 10 in-place upgrades are a severe security risk

#122

Earlier quoted context omitted.

> As I said a semblance of security and privacy Unless you happened to install Ubuntu, which used to send all your local file searches to the cloud to find Amazon deals

And does not any more?

no.

Re: Windows 10 in-place upgrades are a severe security risk

#123
post #66

Earlier quoted context omitted.

> can read keystrokes, read mouse events, and make screen grabs of any other applic As compared to Windows in which an app can't do that? > The operating system where no apps are sandboxed by default? As compared to Windows or Mac where apps are sandboxed by default? > The operating system where once you find a local root exploit, which are not rare, you can embed a root kit deep in the operating system? As a desktop…

> As I said a semblance of security and privacy Unless you happened to install Ubuntu, which used to send all your local file searches to the cloud to find Amazon deals

True. Though we knew about it immediately and could apt-get remove that stuff quite easily too.

Re: Windows 10 in-place upgrades are a severe security risk

#124
post #42

Earlier quoted context omitted.

In this case the next time the vulnerability will be available is with the release of the next upgrade, expected around March.

Insiders see this style of Upgrade on a regular basis (with each new major Insider Build). Microsoft just made a big blog post about a new system for this style of Upgrade (the "Universal Patch Platform") and has asked Insiders to keep an eye out on it. A White Hat attempting responsible disclosure could at least check on Insider Builds and attempt to provide feedback on the new platform through official channels.

The last Insider Fast build was 2 weeks ago. Maybe MSFT is holding the net one back until they fix this...?
Post reply on HN