Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

121–130 of 304 posts

Re: Lessons from last week’s cyberattack

#122
a lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured?

Further, all of the major infections are based on Windows XP. Windows XP mainstream support ended a full year before the first gen iPhone was out! It's seriously ancient and there are very few excuses for people to have this crap on a network in 2017. For the folks who dont run XP, but got infected because they didn't patch? No excuses.

If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009.

Re: Lessons from last week’s cyberattack

#123
post #122

a lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured? Further, all of the major infections are based on Windows XP. Windows XP mainstream support end…

> If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009.

As a tongue in cheek (but totally true) correction, FreeBSD from 2009 would NOT be vulnerable to the shellshock vulnerability unless you explicitly install `bash` and make it the shell used by apache-cgi.

By default, FreeBSD lacks bash.

Re: Lessons from last week’s cyberattack

#124

Earlier quoted context omitted.

Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…

I'm not advocating for using Windows for critical systems that store tons of user data, but I am advocating that if you do use it, you should use versions that are still supported and make sure you patch it ASAP. But should Microsoft be expected to back port patches to old OSes in perpetuity?

Oh that's fair, if a product is unsupported, use it air-gapped or at least in a reasonably controlled environment...

Again, pretending and forcing upgrades is not the solution. The practise perpetrated by Microsoft has been described again and again as an "aggressive effort to push upgrades". https://www.theguardian.com/technology/2016/mar/15/windows-1...

The issue is not the upgrade per se, but the "imperfection" of the upgrade process (wanted euphemism) and the fact that many consider W10 a worse os if compared to W7.

Otherwise nobody would complain.

Re: Lessons from last week’s cyberattack

#125
post #46

Earlier quoted context omitted.

how much do you think it would cost Microsoft to support XP forever?

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion.

If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

Re: Lessons from last week’s cyberattack

#126
post #122

a lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured? Further, all of the major infections are based on Windows XP. Windows XP mainstream support end…

> If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009. As a tongue in cheek (but totally true) correction, FreeBSD from 2009 would NOT be vulnerable to the shellshock vulnerability unles…

True, but FreeBSD can't guarantee perpetual security for releases. It also doesn't provide warranties, like the majority of software out there.

FWIW, I do hold FreeBSD in high regard. It's just that expecting perfection security-wise from complex systems is a fools errand.

Re: Lessons from last week’s cyberattack

#127
post #125

Earlier quoted context omitted.

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

Assuming we class XP as a defective product, at what point do we stop requiring recalls? If there is a safety defect in a 2001 model car, will it be required to have a recall?

Given that MS even made a patch (which is generally equivalent to a recall), I'm not sure that your suggestion will be given that much credence. I mean, if we say that XP is an unsafe product, the government could stop them from selling it and to remove it from the shelves, but MS stopped selling the product in 2008 (nearly 10 years ago) and has repeated urged its customers to stop using it because it is insecure. This is all that the government generally requires in this situation as far as I can tell.

Edit: grammar

Re: Lessons from last week’s cyberattack

#128
post #87
post #44

Earlier quoted context omitted.

I'd be happy enough to go with "you fine whoever wrote the invoice or cashed the cheque". You wanna sell it? Take responsibility for it. You scratch your own itch and give it away for free? Good on you.

It doesn't quite work like that. If I give away "free lemonade", but people get sick because I've made it in dirty conditions, I will not get away just because it's free.

Maybe...

What's your alternative? Are you suggesting we _do_ fine all the OpenSSL contributors? Or that we do not hold anyone except end users responsible for software/hardware security?

I'm not sure metaphors or comparisons between software and lemonade are entirely helpful - although they do push the discussion along, which is at least interesting... (So if I didn't _make_ the lemonade, but published my "4 lemons pulped, 1/2 a cup of sugar, and 2 teaspoons of rat poison" lemonade recipe on github - then you made it and got sick... Who's in the firing line then? What if the README says "this recipe is satire"?)

Re: Lessons from last week’s cyberattack

#129
post #125

Earlier quoted context omitted.

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

I think the discovery of new types of exploits could be considered akin to wear-and-tear of physical things you buy. At the point of sale the software was safe, but over time problems were discovered.

When you buy a house you have a whole battery of inspections performed to make sure that you're buying somewhere safe, but over time the small things that got overlooked (like a small crack in a roof joint) or were considered safe at the point of sale become worn, or are discovered to be unsafe (locks susceptible to bumplocking for instance).

It's a tenuous analogy to be sure, but I don't think it's reasonable to think that Microsoft should refund people who bought XP. Are there any Linux distributions that back port all fixes to version 0.1?

Re: Lessons from last week’s cyberattack

#130
post #103

Earlier quoted context omitted.

This malware was first released as part of a massive spam campaign, and then from there wormed its way onto other systems. It was definitely released on purpose.

Has any of that been confirmed? I thought patient zero's were still mostly speculation.

I don't have a citation I can point you towards, just the word of a coworker who's a malware researcher, sorry.
Post reply on HN