Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

191–200 of 304 posts

Re: Lessons from last week’s cyberattack

#191
post #13

Earlier quoted context omitted.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Why do you fear updating to Windows 10?

[deleted]

Re: Lessons from last week’s cyberattack

#192
post #110
post #63

Earlier quoted context omitted.

I always had auto updates turned on until Windows' malicious behaviors in recent years: https://thenextweb.com/microsoft/2015/09/11/microsoft-is-aut... This one consumes me several gigabytes on my C drive without my permission. https://www.tenforums.com/windows-updates-activation/55185-w... This one acts like malware. And this one: http://www.pcworld.com/article/3039827/windows/7-ways-window... I don't know why I'd c…

Yes, Microsoft is converting an operating system to a web page where they can track your usage. Have you tried with tweaking software like http://winaero.com ?

Not yet, thanks for the recommendation!

Re: Lessons from last week’s cyberattack

#193
post #186
post #183

Earlier quoted context omitted.

Thanks I've been searching for this but with no luck. Do you have a link? (I've disabled SMB V1 as has been suggested in this subthread. I've also run MS Defender with latest virus sigs and so far it hasn't reported anything)

for example: https://support.microsoft.com/en-us/help/4019264/windows-7-u...

Thanks Yu! I'm checking.

Have a great day.

Re: Lessons from last week’s cyberattack

#194
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

See, but you're​ making practical sense about the real world. That's not going to fly with people using this as an opportunity to push their favorite narrative.

I agree with the point on the NSA. there were surgeries cancelled in the UK. This materially impacted the lives of our allies. How is that supposed to work?

Luckily we've got a set of level heads running every branch of government these days...

Re: Lessons from last week’s cyberattack

#195
post #135

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

Why do you claim C++ relates to poor security? OSX and iOS are primarily C, C++, and assembly, (objective C at the higher levels). And linux of course is C and assembly. Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

> Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

Absolutely.

Re: Lessons from last week’s cyberattack

#196
post #125

Earlier quoted context omitted.

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

Not all markets or products are the same. You're taking about software as if it were a rotten potato. It's not. It's an incredibly complex market for incredibly complex products. I agree that there needs to be a way to value the liability that software makers should face.

In the short term we need everyone to be better net citizens. That includes the businesses using this software to create the trillions of dollars of wealth on the global economy.

Re: Lessons from last week’s cyberattack

#197
post #80
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…

Why do you think people would treat them any differently from the UAC screen of Windows 7? That is, just click OK to grant whatever permission it wants, or disable it entirely to avoid the annoyance.

Re: Lessons from last week’s cyberattack

#198
post #173

Earlier quoted context omitted.

I'm a CentOS desktop user at work and Ubuntu at home. I love my Linux. Objectively, the parent poster is correct. For all MS's faults, I've had no less problems updating Ubuntu systems than I've had or seen with MS systems. That said, CentOS is _rock solid_. The packages are old, but maintained by Redhat upstream and do not break on updates. The only thing I recall seeing break on a CentOS update, including point rel…

What type of update? Dist upgrades can be broken, but I've never had issues with general updates.

Mostly problems with the graphical stuff. More than once I've had to log in via a text console and mv ~/.kde somewhere else to start X, or move some ~/.Xfoobar file. Once some ~/.Xfoobar file filled up the entire /home/ partition due to some X error. I've also had problems with some network card driver on a new install, I can go through my posts on unix.SE if you want more detail.

I simply remember that Ubuntu should only be updated when I've got a spare day to fix any potential issues, whereas so far CentOS can be updated before each shutdown.

All this is from the perspective of a desktop user. I use both on various web servers and I've found both to be reliable. I'll use CentOS where I need absolute stability but on my cloud instances I'll happily use Ubuntu and get the latest PHP, etc.

Re: Lessons from last week’s cyberattack

#199
post #80

Earlier quoted context omitted.

> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…

That's fine and dandy - I'm all for it, in fact, I configure my systems thus with 3rd party tools as much as I can. Android is mostly like this (with a less than perfect implementation) But when people talk of "walled gardens", they mostly refer to the guardian at the entrance. Only Apple decides what runs on iOS, only Microsoft decides whats in the App Shop. That's NOT good for anyone (except Apple and Microsoft). S…

Security professionals are almost completely unanimous about how effective Apple has been with it's "walled garden". I'm not even an Apple fan, but what they have done is pretty amazing from a security perspective. Like it or not it has worked to keep people safe from many many types of attacks.

Re: Lessons from last week’s cyberattack

#200
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Another point which hasn't yet gotten much attention is the valuable role Wikileaks played as an early working system. Without Wikileaks it is likely that Microsoft wouldn't have had the chance to release a patch ahead of any attacks.
Post reply on HN