There's a lot of blame being thrown around, and I think it's all merited, but an inordinate amount needs to be on the users. I don't know how many times I've heard things like: "I don't think I'll update to Windows 10" or "That update has been nagging me for months" or even security advocates saying "Windows 10 is a privacy nightmare, I'll stay on 7". Being on the latest secure upstream isn't a nicety, it's what you…
> Being on the latest secure upstream isn't a nicety, it's what you have to do if you want any semblance of a secure environment. Windows 7 is in extended support to 2020. So as far as I know security wise still up to date. > There's a grocery store that just went up nearby that I saw Windows XP splash screen on when one of the cashiers rebooted. The cash register may be even running with a user interface written in…
Lessons from last week’s cyberattack
181–190 of 304 posts
Re: Lessons from last week’s cyberattack
#182Earlier quoted context omitted.
Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.
My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…
Never. But it would be wrong for Ford to stop others to fix your car by providing no information about the car, which I believe is what Microsoft is doing with their obsolete Software pieces (including OS).
As that is the case here, They (Microsoft/Ford) are just lending you something, you won't ever own it. Would you agree with that?
Re: Lessons from last week’s cyberattack
#183Earlier quoted context omitted.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
The recent cumulative rollups should include it and should be clearly labeled.
(I've disabled SMB V1 as has been suggested in this subthread. I've also run MS Defender with latest virus sigs and so far it hasn't reported anything)
Re: Lessons from last week’s cyberattack
#184Earlier quoted context omitted.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
Your safest option then is to disable SMB.
Re: Lessons from last week’s cyberattack
#185Earlier quoted context omitted.
This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.
Maybe the law should say 'security patches or open source'?
Re: Lessons from last week’s cyberattack
#186Earlier quoted context omitted.
The recent cumulative rollups should include it and should be clearly labeled.
Thanks I've been searching for this but with no luck. Do you have a link? (I've disabled SMB V1 as has been suggested in this subthread. I've also run MS Defender with latest virus sigs and so far it hasn't reported anything)
Re: Lessons from last week’s cyberattack
#187The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…
They ostensibly maintain their capability to protect us, but this is a clear example of them failing to protect us. The focus on offensive posture is all macho and typical military industrial bluster. My point is that the offensive cyber capability is more about dick length than keeping the country safer.
Nevermind that the internet is a global shared resource that works best when we work together.
Also, MS haters are doing some pretty fantastic replays of the hits in this thread. I get that you don't like them, but "kill Microsoft" isn't the answer. Maybe there needs to be a model for assigning cost to vulnerabilities like this...to Microsoft and the NSA. Make them account for this in monetary terms and you will see change.
Re: Lessons from last week’s cyberattack
#188Earlier quoted context omitted.
There's a big argument for only releasing evergreen style software, and giving the middle finger to IT orgs that want more control
What does "evergreen style software" mean? A quick search didn't return an obvious answer.
Re: Lessons from last week’s cyberattack
#189There are at least 50 different releases of Windows 10 alone, and it's hard enough to find which is actually used.
The "System" dialog Shows "Windows 10 2015 LTSB". "Winver" on the command line shows "Windows 10 2015 LTSB build 10240" - but there are several releases of that and only the latest ones, e.g. from 10240.17236 and up have the patch - But I can't seem to find which one I have.
I don't doubt I have a patched version, but out of curiosity I'd just like to double check.
Re: Lessons from last week’s cyberattack
#190Earlier quoted context omitted.
I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
Why do you fear updating to Windows 10?
Unfortunatelh I've been so busy with project deadlines that I haven't had a weekend I could dedicate to the new install and set up.
I guess I'm forced to now.