Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

261–270 of 304 posts

Re: Lessons from last week’s cyberattack

#261

Earlier quoted context omitted.

A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.

"The chaos surprised many security watchers because Microsoft issued an update in March that patched the underlying vulnerability in Windows 7 and most other supported versions of Windows. (Windows 10 was never vulnerable.)" source: https://arstechnica.co.uk/security/2017/05/wcry-microsoft-is... So I don't really know what you mean by 'hoarding the fix'. The patch was not initially released to some OS versions becaus…

I believe the "hoarding the fix" comment was in reference to the patches for Server 2003, XP, and Windows 8 that were released publicly for the first time over the weekend (but had been distributed previously to customers paying for custom support) [0].

[0] https://news.ycombinator.com/item?id=14329914

Re: Lessons from last week’s cyberattack

#262

Earlier quoted context omitted.

Is it a program written by humans and have parts that accept user input or network input? then yes.

By that definition, pretty much all software has "poor security" regardless of language. I don't think your definition of "poor security" is proportionate or useful.

> By that definition, pretty much all software has "poor security" regardless of language.

My definition of "poor" is that it must have a babysitter to maintain and patch it. Whether or not this is the case depends on the attack surface, which of course depends on the complexity of what it does. A system that has no attack surface can be very buggy without having poor security. But an internet connected machine with modern windows/posix OS that does some useful work will likely need a security patch already within the first couple of years - and that I consider pretty poor.

Re: Lessons from last week’s cyberattack

#265
post #261

Earlier quoted context omitted.

"The chaos surprised many security watchers because Microsoft issued an update in March that patched the underlying vulnerability in Windows 7 and most other supported versions of Windows. (Windows 10 was never vulnerable.)" source: https://arstechnica.co.uk/security/2017/05/wcry-microsoft-is... So I don't really know what you mean by 'hoarding the fix'. The patch was not initially released to some OS versions becaus…

I believe the "hoarding the fix" comment was in reference to the patches for Server 2003, XP, and Windows 8 that were released publicly for the first time over the weekend (but had been distributed previously to customers paying for custom support) [0]. [0] https://news.ycombinator.com/item?id=14329914

[deleted]

Re: Lessons from last week’s cyberattack

#266

Earlier quoted context omitted.

I agree completely. People can blame MS for their insecure OS, or users who don't know any better for running outdated systems (or even for running Windows at all), but the stark reality is that all OSes have vulnerabilities because they are huge and complex and it is impossible to make them 100% secure. But the NSA are - by definition - supposed to be security experts, so what are they doing letting themselves get h…

A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.

The "$$$ extended support agreements" funded the development of those fixes. Why would anyone pay the agreements if Microsoft just developed and released those fixes for free? If organisations are stupid enough to lock themselves in to 16-year-old software and create more work for Microsoft I'd say they were well within their rights to charge.

Re: Lessons from last week’s cyberattack

#267
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Sorry, but I can't agree with this. If it weren't the NSA discovering it and losing control of it, some other group would eventually get to it.

The problem is Microsoft, who wrote the exploitable software in the first place.

Re: Lessons from last week’s cyberattack

#268
post #248

Earlier quoted context omitted.

A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.

maybe they were testing them?

For three months? That says a lot about the overall testability of their stuff.

Re: Lessons from last week’s cyberattack

#269

Earlier quoted context omitted.

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

It wasn't about fixing, it was about upgrading/updating. It takes people and money to upgrade large infrastructures - closed source or open source, doesn't matter. Thinking that irresponsible (or budged-constrained) organizations will somehow have a completely different mindset and or set of priorities when they switch from Windows to open source software is naive.

No it is about fixing, a design flaw allowed this to happen. SMB1 (hopefully) wasn't built thinking EternalBlue would be a fun feature.

No one expects perfect software; but this clearly happened because Microsoft's​ software was broken, the NSA found where, and horded and then lost control of that knowledge.

edited: I understand what you mean about people not patching and leaving themselves vulnerable. A lot of pain could have been prevented at that level.

Re: Lessons from last week’s cyberattack

#270

Earlier quoted context omitted.

I'm not advocating for using Windows for critical systems that store tons of user data, but I am advocating that if you do use it, you should use versions that are still supported and make sure you patch it ASAP. But should Microsoft be expected to back port patches to old OSes in perpetuity?

Oh that's fair, if a product is unsupported, use it air-gapped or at least in a reasonably controlled environment... Again, pretending and forcing upgrades is not the solution. The practise perpetrated by Microsoft has been described again and again as an "aggressive effort to push upgrades". https://www.theguardian.com/technology/2016/mar/15/windows-1... The issue is not the upgrade per se, but the "imperfection" of…

I would personally use an enterprise Linux distro for something like health records and other critical data, but you can Windows 10 similar to how you use Windows 7, and it's a faster OS. You just need to spend some time to get your settings in place.

I was in the same camp of you as Windows 10 vs 7 until I saw how much Windows 10 sped up an old machine of mine.

Post reply on HN