Lesson 1: don't use Windows. Lesson 2: be it a web resource or your pc, make sure you can restore all your data/sw from clean/current copies. Lesson 3: test lesson 2 periodically.
Lessons from last week’s cyberattack
121–130 of 304 posts
Re: Lessons from last week’s cyberattack
#122Further, all of the major infections are based on Windows XP. Windows XP mainstream support ended a full year before the first gen iPhone was out! It's seriously ancient and there are very few excuses for people to have this crap on a network in 2017. For the folks who dont run XP, but got infected because they didn't patch? No excuses.
If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009.
Re: Lessons from last week’s cyberattack
#123a lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured? Further, all of the major infections are based on Windows XP. Windows XP mainstream support end…
As a tongue in cheek (but totally true) correction, FreeBSD from 2009 would NOT be vulnerable to the shellshock vulnerability unless you explicitly install `bash` and make it the shell used by apache-cgi.
By default, FreeBSD lacks bash.
Re: Lessons from last week’s cyberattack
#124Earlier quoted context omitted.
Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…
I'm not advocating for using Windows for critical systems that store tons of user data, but I am advocating that if you do use it, you should use versions that are still supported and make sure you patch it ASAP. But should Microsoft be expected to back port patches to old OSes in perpetuity?
Again, pretending and forcing upgrades is not the solution. The practise perpetrated by Microsoft has been described again and again as an "aggressive effort to push upgrades". https://www.theguardian.com/technology/2016/mar/15/windows-1...
The issue is not the upgrade per se, but the "imperfection" of the upgrade process (wanted euphemism) and the fact that many consider W10 a worse os if compared to W7.
Otherwise nobody would complain.
Re: Lessons from last week’s cyberattack
#125Earlier quoted context omitted.
how much do you think it would cost Microsoft to support XP forever?
Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.
If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.
Re: Lessons from last week’s cyberattack
#126a lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured? Further, all of the major infections are based on Windows XP. Windows XP mainstream support end…
> If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009. As a tongue in cheek (but totally true) correction, FreeBSD from 2009 would NOT be vulnerable to the shellshock vulnerability unles…
FWIW, I do hold FreeBSD in high regard. It's just that expecting perfection security-wise from complex systems is a fools errand.
Re: Lessons from last week’s cyberattack
#127Earlier quoted context omitted.
Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.
Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.
Given that MS even made a patch (which is generally equivalent to a recall), I'm not sure that your suggestion will be given that much credence. I mean, if we say that XP is an unsafe product, the government could stop them from selling it and to remove it from the shelves, but MS stopped selling the product in 2008 (nearly 10 years ago) and has repeated urged its customers to stop using it because it is insecure. This is all that the government generally requires in this situation as far as I can tell.
Edit: grammar
Re: Lessons from last week’s cyberattack
#128Earlier quoted context omitted.
I'd be happy enough to go with "you fine whoever wrote the invoice or cashed the cheque". You wanna sell it? Take responsibility for it. You scratch your own itch and give it away for free? Good on you.
It doesn't quite work like that. If I give away "free lemonade", but people get sick because I've made it in dirty conditions, I will not get away just because it's free.
What's your alternative? Are you suggesting we _do_ fine all the OpenSSL contributors? Or that we do not hold anyone except end users responsible for software/hardware security?
I'm not sure metaphors or comparisons between software and lemonade are entirely helpful - although they do push the discussion along, which is at least interesting... (So if I didn't _make_ the lemonade, but published my "4 lemons pulped, 1/2 a cup of sugar, and 2 teaspoons of rat poison" lemonade recipe on github - then you made it and got sick... Who's in the firing line then? What if the README says "this recipe is satire"?)
Re: Lessons from last week’s cyberattack
#129Earlier quoted context omitted.
Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.
Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.
When you buy a house you have a whole battery of inspections performed to make sure that you're buying somewhere safe, but over time the small things that got overlooked (like a small crack in a roof joint) or were considered safe at the point of sale become worn, or are discovered to be unsafe (locks susceptible to bumplocking for instance).
It's a tenuous analogy to be sure, but I don't think it's reasonable to think that Microsoft should refund people who bought XP. Are there any Linux distributions that back port all fixes to version 0.1?
Re: Lessons from last week’s cyberattack
#130Earlier quoted context omitted.
This malware was first released as part of a massive spam campaign, and then from there wormed its way onto other systems. It was definitely released on purpose.
Has any of that been confirmed? I thought patient zero's were still mostly speculation.