Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

201–210 of 304 posts

Re: Lessons from last week’s cyberattack

#201
post #125

Earlier quoted context omitted.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

software is not subject to entropy...

Re: Lessons from last week’s cyberattack

#202
post #131
post #125

Earlier quoted context omitted.

Is there some philosophical principle under which you believe that companies must "cough up money" for services that they have already ostensibly paid for? That sounds remarkably like extortion. If Windows XP is proven to be untenably insecure, anyone who bought it should receive a refund.

Microsoft's support policy says they will only provide security updates for 10 years. Any company who wants more than that can pay them extra for the privilege. That's not extortion anymore than extended warranties are extortion.

Microsoft was a monopoly when they sold that contract, which makes it subject to much stricter guidelines on what is allowable in the product they sell.

Re: Lessons from last week’s cyberattack

#203
post #95

Earlier quoted context omitted.

> Being on the latest secure upstream isn't a nicety, it's what you have to do if you want any semblance of a secure environment. Windows 7 is in extended support to 2020. So as far as I know security wise still up to date. > There's a grocery store that just went up nearby that I saw Windows XP splash screen on when one of the cashiers rebooted. The cash register may be even running with a user interface written in…

Do you really think that the machine does not handle credit cards a well? Provide a daily management report? Report inventory? Provide a Facebook interface between customers via the big blue E icon?

> Do you really think that the machine does not handle credit cards a well?

I don't know about the U.S., but as far as I know were I live these card readers have to be almost completely separate systems. The connection between these two should only exist to a) set the price to pay and b) confirm that a payment was made.

> Provide a daily management report? Report inventory?

No longer managing money directly, so the possible abuse for financial gain is quite restricted. You could argue that someone manipulates the reports in order to skim some money for himself, however that would be a rather targeted attack with someone on the inside profiting and could be detected when the physical goods no longer line up with the reported values.

> Provide a Facebook interface between customers via the big blue E icon?

Are we even talking about the same thing?

Re: Lessons from last week’s cyberattack

#204
post #168

Earlier quoted context omitted.

The CVE database or Open SSL, are good examples how much safer open source actually is.

> ... are good examples how much safer open source actually is. Sorry, open source never equals free software (most of the time). Though what you said may be true for both. And some day, we will surely know why free software is better than open source. It's only a matter of time. But by the time, it will be late, and out of control.

Free software can be closed source, which is why companies love MIT style licenses.

Re: Lessons from last week’s cyberattack

#205
It's not just a question of people not keeping their computers updated. I have bought a few second hand computers with windows 7 the last few months and they have all had problems when updating. I doubt most people even notice this and think they are updated.

Re: Lessons from last week’s cyberattack

#206
post #151

Earlier quoted context omitted.

There are very few free/open-source operating systems that get security patches for as long as Windows does. Major versions of OpenBSD are only supported for 5-6 years. Most Linux distributions only get 3-5 years. Red Hat promises 10 years of support, the same as Windows 7/8/10. None comes close to the 13 years that Windows XP was supported for. So you're gonna have to update anyway, at roughly the same interval if n…

Major versions of OpenBSD are only supported for 5-6 years. I thought that security updates are only made for -current, the current stable release, and the previous stable release. So, 1 year of support, not 5-6. A cursory look at the errata seems to confirm this.

Most of the time, upgrading from one minor version to the next is painless. If you installed OpenBSD 5.0, you are expected to keep updating all the way to 5.9. (For some reason, OpenBSD always makes exactly 9 minor versions for each major version.)

Most Linux distros don't even make any fuss about minor versions, using them only as an opportunity to build fresh installation images. New minor versions are security patches for the major version and all previous minor versions.

Re: Lessons from last week’s cyberattack

#207

Lesson 1: don't use Windows. Lesson 2: be it a web resource or your pc, make sure you can restore all your data/sw from clean/current copies. Lesson 3: test lesson 2 periodically.

Lesson 1: don't use proprietary operating systems.

If Windows were open-source, would the situation have been any different?

Would organisations with very conservative attitudes to upgrade paths or a requirement to run an older OS version have suddenly been patching nightly?

Would the exploits used have been identified and patched prior to their malicious deployment?

Would organisations with a vested interest in stockpiling exploits have elected to immediately notify projects' maintainers?

The answer to these swings wildly between 'maybe' and 'probably not', so the eventual endpoint is likely largely the same. It's a compound issue brought about by a chain of decisions made by disparate organisations, and using it as a stick to beat Microsoft or proprietary vendors in general with is missing a very important point -

Security is the responsibility of everybody involved, from vendors and the government, all the way down through to the people innocently opening infected attachments.

Re: Lessons from last week’s cyberattack

#208

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

Re: Lessons from last week’s cyberattack

#209
post #208

Earlier quoted context omitted.

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

Anyone can seek help on the open market to support Ubuntu 10.04 forever if they like. You can't go to another company if you don't like the price Microsoft sets for support for Windows XP.

Re: Lessons from last week’s cyberattack

#210

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

It wasn't about fixing, it was about upgrading/updating. It takes people and money to upgrade large infrastructures - closed source or open source, doesn't matter. Thinking that irresponsible (or budged-constrained) organizations will somehow have a completely different mindset and or set of priorities when they switch from Windows to open source software is naive.
Post reply on HN