Live data from Hacker News

Why Microsoft really patched XP

nothingjustworks.com

1–10 of 59 posts

Re: Why Microsoft really patched XP

#2
Interesting idea, yet it doesn't quite line up with the facts, IMNSHO: IE on XP only goes up to 8, yet this CVE goes up to 11, and it's what, two weeks old? http://www.symantec.com/connect/blogs/emerging-threat-micros... - and guess what, the recommendation is "Do not use IE, at all, not even the new versions." Both the browser and its brand are broken beyond any repair.

Re: Why Microsoft really patched XP

#5

Looks like their WP DB borked...

HN effect, I suppose. Reposting here (let me know if I'm stepping on anyone's toes):

Why Microsoft really patched XP

Long story short, it hurt their IE brand. MS no longer has to worry about reputation management for the XP brand, but they sure do for IE.

Can you imagine the conventional wisdom for IE being, “Don’t use it, ever. It has known holes that MS refuses to fix.” Even with the qualifier, “Only on XP,” it would be a PR nightmare for a browser that isn’t exactly well loved.

So where does this leave MS now? Arguably, they’re going to continue to patch XP for non-paying extended support customers depending on the severity of the exploit and especially if it affects IE. We probably won’t see anything patched outside of serious IE vulnerabilities or maybe a conficker-type vulnerability that can be exploited remotely. Serious vulnerabilities like privilege escalation that crop occasionally will remain unpatched.

What does this extended support mean for web developers? IE8 on XP is alive and well apparently. This is a five year old browser with a poor feature set compared to modern browsers. I remember watching my remaining IE6 traffic disappear almost completely in a 12 month span about three years ago only to be replaced with IE8. Is IE8 the new IE6? Maybe, but whats for certain is that this kind of extended support is just going to make the problem worse.

Of course, the larger question is why aren’t we all using EMET, which thwarts this, and other, vulnerabilities without patching? I tested it in my environment, and Sophos refused to let IE run when EMET was running. Sophos support had no resolution. If third-party AV companies can’t work with first-party utilities, what hope is there of Joe User or Joe Corporate Admin rolling this stuff out and expecting it to work without major issues?

The protections EMET offers are pretty impressive. I wonder why these protections aren’t enabled by default. This would be a good differentiator for Windows9. I could see a business friendly version of Windows with less focus on the Modern mobile-like UI and a return to the full features of the Start menu. Now, imagine it with EMET on by default with an option for admins to disable it via a whitelist. One can dream.

Re: Why Microsoft really patched XP

#8
It's actually much simpler than you think. Microsoft have some big customers that pay them to maintain XP. Microsoft like making money, so they maintain XP for them. If these patches make it to general availability is up to Microsoft however, and it looks like they are still doing that.

Re: Why Microsoft really patched XP

#10

Interesting idea, yet it doesn't quite line up with the facts, IMNSHO: IE on XP only goes up to 8, yet this CVE goes up to 11, and it's what, two weeks old? http://www.symantec.com/connect/blogs/emerging-threat-micros... - and guess what, the recommendation is "Do not use IE, at all, not even the new versions." Both the browser and its brand are broken beyond any repair.

Sure it does. The moment I saw headlines like "US government recommends against using Internet Explorer" because of that bug, I thought "Chrome and Mozilla guys must be over-joyous with this". Google already promised enterprises that they'd support XP a year longer than Microsoft, for Chrome. This made it even easier to convince them to switch to Chrome. And I don't think Mozilla plans on ending XP support anytime soon either. I think they only ended Windows 98 support a few years ago.
Post reply on HN