Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

141–150 of 304 posts

Re: Lessons from last week’s cyberattack

#141
post #13
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

The recent cumulative rollups should include it and should be clearly labeled.

Re: Lessons from last week’s cyberattack

#142

Earlier quoted context omitted.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…

Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…

Critical systems that require long term support is what Win10 Enterprise LTSB was designed for, which you get with Software Assurance.

Re: Lessons from last week’s cyberattack

#143
post #125

Earlier quoted context omitted.

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles.

When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software for a set period of time. Afterward, it is on me.

Nobody can write perfect software, it will age and break down. Nobody can engineer a perfect car, it will age and break down. Demanding infinite warranties is ridiculous.

Re: Lessons from last week’s cyberattack

#144

Earlier quoted context omitted.

How long should Microsoft be required to support XP? They extended the original support period TWICE. Why are customers entitled to support when they were informed prior to purchasing the product that support expired on a given date?

Maybe newer OS do not have any useful features for those customers? Maybe they are even worse for them because work slower, are not compatible with old drivers, contain spyware (telemetry)?

Is a company obligated to sell a product with features that you consider useful? Intel doesn't make pre-ME CPUs anymore. Apple doesn't make Power PC iMacs anymore. And Microsoft doesn't make Windows XP anymore. In all these markets, there are consumers who would prefer to purchase the discontinued product. So what? Products get discontinued.

Consider a discontinued product from another industry, like a car or an appliance. When the product is discontinued, the manufacturer only creates replacement parts for existing machines for a limited time period. After some years, it's difficult for a consumer to maintain their copy of the discontinued product because it is difficult to find replacement parts.

The point is, mass produced engineering products have lifecycles. Microsoft clearly defined (and extended) Windows XPs lifecycle and provided patches for the entirety of that lifecycle. It's hard for me to understand how that doesn't fully meet their obligations to be fair to their customers.

Re: Lessons from last week’s cyberattack

#145
post #70

There's a lot of blame being thrown around, and I think it's all merited, but an inordinate amount needs to be on the users. I don't know how many times I've heard things like: "I don't think I'll update to Windows 10" or "That update has been nagging me for months" or even security advocates saying "Windows 10 is a privacy nightmare, I'll stay on 7". Being on the latest secure upstream isn't a nicety, it's what you…

The Microsoft Playbook:

* Predicate the commercial viability of your software on the basis of technological illiteracy

* Blame the technologically illiterate 'luser user' when things go wrong

* Try and profit from it even as you blame said 'luser user'

The best lesson for Microsoft would be if it incurs a tremendous loss to its reputation, and more importantly its bottom line, because of some issue like this.

It is strange to see people talking about how they took an exception and released a patch for Windows XP this time. Generally, such an exception is the very definition of CYA. If not, why don't they do it for all patches? Read: if the security hole can be used as a way to convince the 'luser user' to pony up more money, don't release a patch. But if the issue is so high profile (for example linking MSFT to a three letter organization), then better issue a patch and CYA.

Re: Lessons from last week’s cyberattack

#146
post #125

Earlier quoted context omitted.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

The car analogy a very poor one. Software doesn't wear out-- physical stuff does. Defects in software are present when it's created. It doesn't "age" or "break down".

(I am making no comment on the issue being discussed-- simply that this is a very poor analogy.)

Re: Lessons from last week’s cyberattack

#147
post #46

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

how much do you think it would cost Microsoft to support XP forever?

[deleted]

Re: Lessons from last week’s cyberattack

#148
post #80

Earlier quoted context omitted.

> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…

That's fine and dandy - I'm all for it, in fact, I configure my systems thus with 3rd party tools as much as I can. Android is mostly like this (with a less than perfect implementation) But when people talk of "walled gardens", they mostly refer to the guardian at the entrance. Only Apple decides what runs on iOS, only Microsoft decides whats in the App Shop. That's NOT good for anyone (except Apple and Microsoft). S…

Sandboxing and tighter security are orthogonal to app stores. The same security policy should apply to every app, regardless of whether it was installed through the official store or from another source.

What the grandparent is suggesting is akin to UAC, which received much hate when it first debuted in Vista but has now become a mostly accepted part of the Windows user experience. It has been done before, and it can be done again, with every Windows app, not just apps from the Microsoft Store.

Re: Lessons from last week’s cyberattack

#149
How to prevent an attack from internet is really a big problem. More open the system is, more dangerous the system maybe. like this attack, the macOS and Linux is safe. Maybe just because the system is not that open and malicious program cannot get some access to do something bad. And usually the update to prevent some kind of attack is later than the attack itself.

Re: Lessons from last week’s cyberattack

#150
How to prevent an attack from internet is really a big problem. More open the system is, more dangerous the system maybe. like this attack, the macOS and Linux is safe. Maybe just because the system is not that open and malicious program cannot get some access to do something bad. And usually the update to prevent some kind of attack is later than the attack itself.
Post reply on HN