Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

221–230 of 304 posts

Re: Lessons from last week’s cyberattack

#222
post #208

Earlier quoted context omitted.

Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

Anyone can seek help on the open market to support Ubuntu 10.04 forever if they like. You can't go to another company if you don't like the price Microsoft sets for support for Windows XP.

This comment makes my blood boil. Please ask yourself:

1. why would anybody want to keep 10.04 alive?

2. do you think the type of people who stubbornly continue to use 10.04 would know/care enough about security to seek an alternative source for security patches?

edit: should maybe add why this pisses me off: just logged into a production server running 12.04, default install apache and updates _turned off_. the owner looked confused (and slightly bored) when I explained the problem to him.

Re: Lessons from last week’s cyberattack

#223
post #197
post #80

Earlier quoted context omitted.

> Instead what will happen is more tightening of the walled garden You know what? I'm starting to get excited for the walled garden to get more walls. Native desktop applications get far too many permissions by default - its crazy that any desktop application, once running can register itself at startup, see all my files (created by any application), register system-wide keyloggers, take screenshots of other applicat…

Why do you think people would treat them any differently from the UAC screen of Windows 7? That is, just click OK to grant whatever permission it wants, or disable it entirely to avoid the annoyance.

Thats probably true but you could enforce it at a corporate level with a whitelist of apps that should have access to certain permissions.

Re: Lessons from last week’s cyberattack

#224
post #208

Earlier quoted context omitted.

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

Install Debian with testing repositories and unattended upgrades and you're done for good.

Or just stick to CentOS and with their 11 years support period.

Re: Lessons from last week’s cyberattack

#225
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

I agree completely. People can blame MS for their insecure OS, or users who don't know any better for running outdated systems (or even for running Windows at all), but the stark reality is that all OSes have vulnerabilities because they are huge and complex and it is impossible to make them 100% secure.

But the NSA are - by definition - supposed to be security experts, so what are they doing letting themselves get hacked? They have effectively given away the nuclear football.

I'm shocked we're not seeing more blame in their direction on this one.

Re: Lessons from last week’s cyberattack

#226
post #224
post #208

Earlier quoted context omitted.

Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

Install Debian with testing repositories and unattended upgrades and you're done for good. Or just stick to CentOS and with their 11 years support period.

XP was supported for 12 years. It's now over 15 years since it was released.

Re: Lessons from last week’s cyberattack

#227

Earlier quoted context omitted.

My car will break down at some point due to imperfect engineering and the realities of physics. Is Ford required to repair my car indefinitely or allow a refund on a car with 250k miles? No, when I bought the car, it came with a warranty stating if they messed up they would fix it within a certain period of time or miles. When I buy Windows, I agree to a warranty of sorts. They agree to supply updates to the software…

> Is Ford required to repair my car indefinitely..? Never. But it would be wrong for Ford to stop others to fix your car by providing no information about the car, which I believe is what Microsoft is doing with their obsolete Software pieces (including OS). As that is the case here, They (Microsoft/Ford) are just lending you something, you won't ever own it. Would you agree with that?

You can either pay very expensive official Ford garages forever, or go to unofficial ones, which is basically reverse engineering. The thing is, for experienced car mechanics, 'reverse engineering' some mechanical part and replacing/repairing it is quite doable. If some CPU burns out in some system, they can't do anything but replace whole unit.

So no, you aren't getting better support from Ford, it's just not as complex system to hack yourself.

As for agreeing, yes we all did when clicking on that Agree button during installation. Already forgot that part? Why do people assume legal contracts should be normally fiercely enforceable, but when it comes to M$ they should just work forever, outside of their contract that we all agreed upon? Even though they in fact offer paid patching?

Re: Lessons from last week’s cyberattack

#228
post #135

Earlier quoted context omitted.

Why do you claim C++ relates to poor security? OSX and iOS are primarily C, C++, and assembly, (objective C at the higher levels). And linux of course is C and assembly. Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

> Are you saying all of the major operating systems have poor security because they use "vulnerable" languages? Absolutely.

Does this include OpenBSD?

Re: Lessons from last week’s cyberattack

#229
post #204

Earlier quoted context omitted.

Free software can be closed source, which is why companies love MIT style licenses.

I thought MIT wasn't free software as defined by the FSF? Open source would be the term for that. Free requires end users to receive source, open just allows you to use the source if you have a copy.

Free software is defined by the FSFs list of freedoms and MIT licence certainly provides those freedoms.

Re: Lessons from last week’s cyberattack

#230

Earlier quoted context omitted.

> Are you saying all of the major operating systems have poor security because they use "vulnerable" languages? Absolutely.

Does this include OpenBSD?

Is it a program written by humans and have parts that accept user input or network input? then yes.
Post reply on HN