Live data from Hacker News

My long goodbye to Windows XP (2022)

woodfromeden.substack.com

241–250 of 323 posts

Re: My long goodbye to Windows XP (2022)

#241

Earlier quoted context omitted.

"We're going to write security updates for this OS but we won't give them to you" is such psychopathic behavior.

Writing security updates costs money-and as the software gets older, the cost generally goes up too. Is it wrong for them to decide, after a reasonable period, to stop spending that money on outdated versions? What happens then when a small subset of customers says “we need those updates so much, we’ll pay extra for them?” Is it wrong to take their money and spend it on writing the updates they request, with a reason…

> I don’t see any “psychopathy” here, just rational business decisions.

That's just a prettier word for the same thing.

And bringing up Oracle as your reference for ethical behaviour is certainly... a take that doesn't really say what you think it says.

Re: My long goodbye to Windows XP (2022)

#242
post #225

So many problems with this piece >> My computer is also not some old rubbish. It has an Intel Core2Duo CPU with 4 Gb RAM. It was top of the line in 2009. Just because you had a top of the line PC in 2009 does not disqualify it from being 'old rubbish' in 2023. A Core2Duo is ancient at this point. >> The truth is I have never been hacked once in the eight years I have had this computer. Or something has been compromis…

That's the thing. I'm an it professional. I've had a computer since I was 6 (30years ago). Couple of decades ago, I could be reasonably confident that my pc was safe.

Today? I take above average precautions but I would never claim that my system is not pwned on some level. That feels like arrogance and hubris (as well as a little bit of "I played Russian roulette several times and I'm fine! It's dangers are overblown:)

Re: My long goodbye to Windows XP (2022)

#243
post #191
post #24

Earlier quoted context omitted.

They are running a Chrome from 2016, so they are vulnerable to ~every exploit found in Chrome since then.

That's not how (modern) SW works. Ever heard of "new features and security improvements" ?

What? This is certainly how not updating Chrome works.

Re: My long goodbye to Windows XP (2022)

#244
post #225

So many problems with this piece >> My computer is also not some old rubbish. It has an Intel Core2Duo CPU with 4 Gb RAM. It was top of the line in 2009. Just because you had a top of the line PC in 2009 does not disqualify it from being 'old rubbish' in 2023. A Core2Duo is ancient at this point. >> The truth is I have never been hacked once in the eight years I have had this computer. Or something has been compromis…

>Or something has been compromised or exploited and you've had no idea because it's not something obvious like opening your CD-ROM drive automatically.

This is addressed two paragraphs after the one you've quoted.

Re: My long goodbye to Windows XP (2022)

#245

I have a Windows 7 Professional system with my startup's software in some boxes and, since now my office is functional enough, am about to get that system powered up and running again. So, here's a piece of information relevant to security and versions of Windows, I'd like to give exact and really clear references instead of working just from memory, but for such references just now I'd have to do a lot of digging. F…

I don't know what your startup's software does, but I already don't want to use it.

Re: My long goodbye to Windows XP (2022)

#246
post #225

So many problems with this piece >> My computer is also not some old rubbish. It has an Intel Core2Duo CPU with 4 Gb RAM. It was top of the line in 2009. Just because you had a top of the line PC in 2009 does not disqualify it from being 'old rubbish' in 2023. A Core2Duo is ancient at this point. >> The truth is I have never been hacked once in the eight years I have had this computer. Or something has been compromis…

>Or something has been compromised or exploited and you've had no idea because it's not something obvious like opening your CD-ROM drive automatically. This is addressed two paragraphs after the one you've quoted.

> This is addressed two paragraphs after the one you've quoted.

And it's equally an incomplete assessment based on the same "This is fine" attitude. The computer could be participating in a botnet dedicated to bring down the network in hospitals or steal their sensitive medical data, and the author would never know.

Re: My long goodbye to Windows XP (2022)

#247

Many times have I lost hours, days, or functionality that was never regained to an update/"upgrade." Never have I had my personal computer owned by some exploit that resulted in data loss/breach. Thus, undesired upgrades are a greater risk for personal computing than security. Simple as.

Wish I could upvote this a hundred times. Once upon a time updates were something I'd get excited for. Now it's a dread of what will break next, what new advertising will assault my eyeballs and waste my attention, and what telemetry will subvert my privacy or deteriorate my control over my device. This is why I've "just said no" to Windows ≥ 10. I really want it, but these anti-features need a reliable off switch.

To be fair, most of those are uniquely Windows problems. If you pick a halfway decent Linux distribution, you will never see advertising, telemetry, or lack of control, and updates are a mostly positive experience. I switched from Windows 7 to Linux around 10 years ago and it's been an improvement in ~99% of my use cases. The only thing Windows really does better is games and the occasional (rare) piece of software which doesn't have a good equivalent for Linux. In those 10 years I've only found myself running a Windows VM a handful of times to get at some critical functionality I needed from Windows-only software. Switching was one of the best IT decisions I ever made.

Re: My long goodbye to Windows XP (2022)

#248
post #192

Earlier quoted context omitted.

I honestly have no idea whether you are supporting what was said with that link, or objecting to it. Anyway, I was talking about being inquiring. When you look at that list, surely, some questions do rise. “Why should I worry about all of that to read three paragraphs of text on some webpage?” “Which actions have made it so?” “What should be done to fix it?” Right?

I am objecting to what you are saying. It's terrible advice and an obtuse vision of the complexity of software nowadays, especially web browser. Yes, a 3 months old release of chrome is not suited to use day to day. I link all the known and published CVE on chrome, but if you want to nickpick you could "just" check those which start with 2023-*.

OK. Shouldn't we ask questions about real or perceived “complexity of software nowadays”?

Why does displaying a piece of information that would fit onto a single 80×25 text mode screen absolutely require exposing to a third party a potentially (and, as mentioned, effectively) vulnerable WebHID functionality (which is non-standard, and seemingly only exists to make ChromeOS less mediocre operating system), various WebGL libraries and wrappers, ever-growing Javascript and CSS engines, and thousands of other entities? Someone who grants the whole internet access to local service ports by not using a firewall is considered a fool, but at the same time “non-foolish” “security conscious” people start their browsers, and see no problem in all the services embedded in them.

Isn't relying on a constant (and never ending) stream of updates from white knights in the holy castle in the manner you describe just a subscription model without a defined price?

Who controls the Web? Is controlling the web client enough for that? What benefits the endless rat race might give to them?

How come there's a hidden dependence on corporate products and their support cycles even in the process of using seemingly “open” technologies, say, for government sites and services? Is “I have no idea, my code absolutely requires latest libraries” a valid excuse?

Can mindless acceptance and circular finger-pointing between web developers, library authors, browser developers, and users solve these problems? What needs to be done?

Re: My long goodbye to Windows XP (2022)

#249

Many times have I lost hours, days, or functionality that was never regained to an update/"upgrade." Never have I had my personal computer owned by some exploit that resulted in data loss/breach. Thus, undesired upgrades are a greater risk for personal computing than security. Simple as.

That's not sound logic. Your point may or may not be true, but it doesn't follow from your logic. I've had more e-ink devices fail by being knocked into the river while fishing than I have from any other cause of accident, does that mean fishing is the most common cause of e-ink device death because it's my personal anecdotal experience? I doubt it.

That's a bad analogy. It would be more applicable if there were a nebulous group of people dedicated to killing the largest number of e-ink devices by any means necessary so they focus on the most popular ones because it is easier to do so.

From a personal end user standpoint, most people will never be the direct target of a attack (and if you are, you are probably in a situation where being 100% up to date won't save you). If they get owned, it will be by a drive-by exploit or because they directly executed malware.

Drive-by exploits tend to target the most popular systems.

Re: My long goodbye to Windows XP (2022)

#250

Ubuntu has always been this weird OS for me. Its not free enough or fast enough to be linux, it feels like a knockoff of something, but i cant put my finger on it. Their DE is just such a horrible POS. I had one extension/addon (?), which, due to some JS problem (all those extensions/addons are written in js), was slowly, over hours, hogging more ram, until eventually OOMimg the entire DE. Sure, this is just a one-of…

It seems strange to blame a distribution for a problem you had with a DE. Just change the DE. Or download one of the many Ubuntu flavours which has your preferred DE preinstalled.
Post reply on HN