Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

151–160 of 304 posts

Re: Lessons from last week’s cyberattack

#151
post #78
post #53

Earlier quoted context omitted.

Let's be clear on this. No matter how secure the operating system initially, if it stays unpatched then over time it will become more and more vulnerable as uncovered exploits go unfixed. The reason a machine might go unpatched is because it might support some critical hardware (eg medical) for which there is only one or two vendors and only a particular combination of HW and SW are supported (eg due to a specific cu…

True, but I'm sure there are a lot of cases where the OS wasn't updated because of the necessary investment to jump to a new Windows version.

There are very few free/open-source operating systems that get security patches for as long as Windows does.

Major versions of OpenBSD are only supported for 5-6 years. Most Linux distributions only get 3-5 years. Red Hat promises 10 years of support, the same as Windows 7/8/10. None comes close to the 13 years that Windows XP was supported for.

So you're gonna have to update anyway, at roughly the same interval if not more often, as if you had used an enterprise edition of Windows.

Re: Lessons from last week’s cyberattack

#152

Earlier quoted context omitted.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

The car analogy a very poor one. Software doesn't wear out-- physical stuff does. Defects in software are present when it's created. It doesn't "age" or "break down". (I am making no comment on the issue being discussed-- simply that this is a very poor analogy.)

> Software doesn't wear out

Software does wear out. New languages/frameworks are developed which makes it difficult to patch older stuff. New threats are developed, and it may be impossible to patch older stuff.

Re: Lessons from last week’s cyberattack

#153
The real question should be: Can Microsoft write an OS that does not have to be constantly patched, month after month?

We know they have written such things as part of research. But still they continue to release software that is unfinished.

They have trained their users that failure to update is fatal. No doubt, if they are using Windows.

They also like to conflate "update" with "upgrade". They use these security problems in Windows to scare people into upgrading.

Windows 10, whether they like it or not. As others have noted, by design the new versions are not safer than the old ones.

Retroactively fixing reported issues does not make a new version more secure by design. They could just as easily fix the issues in the older version.

Can this company get anything right the first time? Will they ever design a system that is secure?

Do they have any interest in doing so?

Are they incapable?

There is nothing wrong with releasing something simple, secure and finished.

Does MS believe Windows users are not worthy of a secure OS?

I think Microsoft Research have contributed to development of L4 systems that run on baseband.

Do these systems have the same vulnerabilities as Windows?

Fixing problems after they occur (past problems) is admirable but other free opens source OS written by volunteers accomplish the same thing. The question is whether the design of the system is such that future problems are avoided.

Does Microsoft believe Windows users deserve more security? Can Microsoft deliver it?

All indications suggest the answer to both questions is no.

With no viable alternatives, no one can blame Windows users for sticking with it despite red flag after red flag, but it makes no sense to defend the Microsoft approach to security for Windows users. The company has no respect for Windows users.

Being responsive to a constant stream of reported vulnerabilities is an improvement from 1995 but as we can see it is not enough. Their software is still full of mistakes. They need to prove they can make something that is secure by design and that they are willing to do so for users.

(Truthfully, they probably do not need to do anything.

Quotes of 80% of Windows installations being tied to purchases of hardware are probably not far off the mark.

There is no selection of OS by most computer users.

A majority of users still get Windows pre-installed on the computers they purchase.

Microsoft could completely ignore users and it would not hurt their business, as long as they continue to maintain relationships with hardware manufacturers.)

Re: Lessons from last week’s cyberattack

#154

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

Yes, they really should. Some important facility should not use window anymore because it is too open to the public to hold an attack. Or the hospital's computer should not be connected to the internet. Most of the time the computers within a hospital are just doing local task.

Re: Lessons from last week’s cyberattack

#155

Earlier quoted context omitted.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

The car analogy a very poor one. Software doesn't wear out-- physical stuff does. Defects in software are present when it's created. It doesn't "age" or "break down". (I am making no comment on the issue being discussed-- simply that this is a very poor analogy.)

Nearly all complex software will have problems and weaknesses not known at creation, much like nearly every car will have some kind of weakness that will wear out. While there are differences between the physical world and the digital one, I think my critique of the concept of demanding infinite warranties is still valid.

And yes, I do think software can "wear out", not in the same sense as belts get worn and spark plugs physically wear away, but in the sense of threat landscapes changing over time and our understanding of how these systems are used in the world. This is why we do maintenance on our software and systems, much like we perform maintenance on things in our physical world. When you fail to perform this maintenance, bad things happen. Computers get hacked, cars have brakes fail.

Software can indeed age. Go run Windows 95 on the public internet or an early version of Android.

Re: Lessons from last week’s cyberattack

#156
post #135

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

Why do you claim C++ relates to poor security? OSX and iOS are primarily C, C++, and assembly, (objective C at the higher levels). And linux of course is C and assembly. Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

They are not secure. They are locked down.

Re: Lessons from last week’s cyberattack

#157
post #137

Earlier quoted context omitted.

The NSA did not cause this particular problem. The NSA may have identified the vulnerability, however there is certainly an argument that their other responsibilities outweigh any responsibility that they might have to act as a free security investigation team and report a security vulnerability to an outside corporation. If Russian government intelligence agency security researchers found that bug first would you sa…

> however there is certainly an argument that their other responsibilities outweigh any responsibility that they might have to act as a free security investigation team and report a security vulnerability to an outside corporation. Yeah, a shitty one. Free? No they're funded by tax payer dollars. I do think we need to argue about priority of responsibilities. Was this exploit used to spy on allies?

> Was this exploit used to spy on allies?

Don't know, and unlikely to ever find out. If so, it was likely very targeted to avoid detection on modern systems. Was it ever used to spy on Iran's nuclear enrichment program?

> I do think we need to argue about priority of responsibilities.

Ok. What responsibilities does a US government agency have to disclose vulnerabilities? Should they be required to disclose all vulnerabilities found in software and equipment from US companies? Since a lot of that technology is used around the world, are you on with the corollary of it being harder for the US to spy on anyone using modern equipment?

How about disclosing problems found in tech products used by US companies? Should the NSA do that as well to keep those companies safe?

The US provides a fair amount of funding to organizations focused on finding and responsibly disclosing security problems, notably CERT[1] and US-CERT [2]. The NSA is a completely separate thing.

1: http://cert.org/about/ 2: https://www.us-cert.gov/

Edit: removed snark

Re: Lessons from last week’s cyberattack

#158
post #135

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

Why do you claim C++ relates to poor security? OSX and iOS are primarily C, C++, and assembly, (objective C at the higher levels). And linux of course is C and assembly. Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

Memory corruption is the most common error that leads to vulnerabilities.

Re: Lessons from last week’s cyberattack

#159

Earlier quoted context omitted.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

The car analogy a very poor one. Software doesn't wear out-- physical stuff does. Defects in software are present when it's created. It doesn't "age" or "break down". (I am making no comment on the issue being discussed-- simply that this is a very poor analogy.)

I think the car analogy isn't that bad. New classes of security issues get discovered over time. Development processes which are considered "state of the art" at one point can become unacceptable 10 years down the road.

A decade in software engineering is a significant amount of time!

Re: Lessons from last week’s cyberattack

#160

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

[deleted]
Post reply on HN