Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

211–220 of 304 posts

Re: Lessons from last week’s cyberattack

#211
post #204

Earlier quoted context omitted.

> ... are good examples how much safer open source actually is. Sorry, open source never equals free software (most of the time). Though what you said may be true for both. And some day, we will surely know why free software is better than open source. It's only a matter of time. But by the time, it will be late, and out of control.

Free software can be closed source, which is why companies love MIT style licenses.

I thought MIT wasn't free software as defined by the FSF?

Open source would be the term for that. Free requires end users to receive source, open just allows you to use the source if you have a copy.

Re: Lessons from last week’s cyberattack

#212
post #46

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

how much do you think it would cost Microsoft to support XP forever?

Microsoft still are supporting XP. Just not for the the general public.

Organisations with high value software that relies on XP still receive ongoing support from Microsoft (such as the US Navy and anyone else who wants to pay big bucks for it). The difference is none of these patches usually make it to the public.

For Microsoft to patch this current issue, there would have already been a pre-existing team working on XP patches, the only difference is this one was released publicly due to it's impact.

http://bgr.com/2015/06/24/windows-xp-support-us-navy-million...

Re: Lessons from last week’s cyberattack

#213
post #204

Earlier quoted context omitted.

Free software can be closed source, which is why companies love MIT style licenses.

I thought MIT wasn't free software as defined by the FSF? Open source would be the term for that. Free requires end users to receive source, open just allows you to use the source if you have a copy.

Free software is software that doesn't cost any money, hence it is free.

Re: Lessons from last week’s cyberattack

#215
post #213

Earlier quoted context omitted.

I thought MIT wasn't free software as defined by the FSF? Open source would be the term for that. Free requires end users to receive source, open just allows you to use the source if you have a copy.

Free software is software that doesn't cost any money, hence it is free.

Although it is often the case that free software (or libre software, or whatever you want to call it) is available at no cost, the term "free software" generally does not refer to the price but to the given freedoms.

Re: Lessons from last week’s cyberattack

#216
post #46

Earlier quoted context omitted.

how much do you think it would cost Microsoft to support XP forever?

Allowing XP to exist forever is not a good thing for security either. There are security architectures in place within Windows 10 for example that do significantly improve security. At some point companies need to cough up the money and upgrade their technology.

Yeah, I'm hoping that, if nothing else, WannaCry will prove to be the incentive required for a lot of places to stop putting the upgrade off.

Re: Lessons from last week’s cyberattack

#217

Earlier quoted context omitted.

The car analogy a very poor one. Software doesn't wear out-- physical stuff does. Defects in software are present when it's created. It doesn't "age" or "break down". (I am making no comment on the issue being discussed-- simply that this is a very poor analogy.)

I think the car analogy isn't that bad. New classes of security issues get discovered over time. Development processes which are considered "state of the art" at one point can become unacceptable 10 years down the road. A decade in software engineering is a significant amount of time!

For the car analogy, what will happen when self-driving cars become the norm and the contained software becomes so important?

I'm going to be annoyed if my car becomes useless after 10 years because they dont have to patch it after that period. On the other hand though, can we realistically enforce lifetime guarantees? What is a car company goes out of business?

Re: Lessons from last week’s cyberattack

#218
post #204

Earlier quoted context omitted.

> ... are good examples how much safer open source actually is. Sorry, open source never equals free software (most of the time). Though what you said may be true for both. And some day, we will surely know why free software is better than open source. It's only a matter of time. But by the time, it will be late, and out of control.

Free software can be closed source, which is why companies love MIT style licenses.

> Free software can be closed source...

Eh, Never. Not even for open source. Once the source is closed, it is no longer open source (and neither free software).

For a software to be open source, the user should have a way to obtain the source code legally (That is, a stolen source code won't make a software open source).

For the software to be free software, the user should have the freedom to (modify and) replace the software with the user's version of the software (of course, source code availability is pre-requisite for this).

Say for example, your router, Android phone, TV, Car, or your espresso machine could be running Linux which is open source. You get the source code of those over the Internet or from the vendor on request. But you may not be allowed to change it. So you are always on the mercy of the vendor if something happen (like the one happening now). They are open source, but they are not free software. (GNU [A]GPLv3 enforces this freedom. Some like it, some don't).

A software can be free or non-free based on where the code is run, not just whether you get the source or not.

This is freedom 1 by free software definition:

The freedom to study how the program works, and change it so it does your computing as you wish.

See https://www.gnu.org/philosophy/free-sw.html for more details.

Re: Lessons from last week’s cyberattack

#220
post #204

Earlier quoted context omitted.

Free software can be closed source, which is why companies love MIT style licenses.

> Free software can be closed source... Eh, Never. Not even for open source. Once the source is closed, it is no longer open source (and neither free software). For a software to be open source, the user should have a way to obtain the source code legally (That is, a stolen source code won't make a software open source). For the software to be free software, the user should have the freedom to (modify and) replace th…

One can make word games to what the word free should mean in English, but to the regular man and woman without technical background, or references like the Cambridge Dictionary, free software is software that doesn't cost any money.
Post reply on HN