Earlier quoted context omitted.
A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.
"The chaos surprised many security watchers because Microsoft issued an update in March that patched the underlying vulnerability in Windows 7 and most other supported versions of Windows. (Windows 10 was never vulnerable.)" source: https://arstechnica.co.uk/security/2017/05/wcry-microsoft-is... So I don't really know what you mean by 'hoarding the fix'. The patch was not initially released to some OS versions becaus…
Lessons from last week’s cyberattack
261–270 of 304 posts
Re: Lessons from last week’s cyberattack
#262Earlier quoted context omitted.
Is it a program written by humans and have parts that accept user input or network input? then yes.
By that definition, pretty much all software has "poor security" regardless of language. I don't think your definition of "poor security" is proportionate or useful.
My definition of "poor" is that it must have a babysitter to maintain and patch it. Whether or not this is the case depends on the attack surface, which of course depends on the complexity of what it does. A system that has no attack surface can be very buggy without having poor security. But an internet connected machine with modern windows/posix OS that does some useful work will likely need a security patch already within the first couple of years - and that I consider pretty poor.
Re: Lessons from last week’s cyberattack
#263I think the lesson here is to disband all spy agencies when not at war with another nation state.
Re: Lessons from last week’s cyberattack
#264Re: Lessons from last week’s cyberattack
#265Earlier quoted context omitted.
"The chaos surprised many security watchers because Microsoft issued an update in March that patched the underlying vulnerability in Windows 7 and most other supported versions of Windows. (Windows 10 was never vulnerable.)" source: https://arstechnica.co.uk/security/2017/05/wcry-microsoft-is... So I don't really know what you mean by 'hoarding the fix'. The patch was not initially released to some OS versions becaus…
I believe the "hoarding the fix" comment was in reference to the patches for Server 2003, XP, and Windows 8 that were released publicly for the first time over the weekend (but had been distributed previously to customers paying for custom support) [0]. [0] https://news.ycombinator.com/item?id=14329914
Re: Lessons from last week’s cyberattack
#266Earlier quoted context omitted.
I agree completely. People can blame MS for their insecure OS, or users who don't know any better for running outdated systems (or even for running Windows at all), but the stark reality is that all OSes have vulnerabilities because they are huge and complex and it is impossible to make them 100% secure. But the NSA are - by definition - supposed to be security experts, so what are they doing letting themselves get h…
A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.
Re: Lessons from last week’s cyberattack
#267The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…
The problem is Microsoft, who wrote the exploitable software in the first place.
Re: Lessons from last week’s cyberattack
#268Earlier quoted context omitted.
A bit rich from Microsoft to talk about hoarding when the patches they released over the weekend were all signed back in February... i.e. they are hoarding fixes to their own shit for their $$$ extended support agreements.
maybe they were testing them?
Re: Lessons from last week’s cyberattack
#269Earlier quoted context omitted.
This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.
It wasn't about fixing, it was about upgrading/updating. It takes people and money to upgrade large infrastructures - closed source or open source, doesn't matter. Thinking that irresponsible (or budged-constrained) organizations will somehow have a completely different mindset and or set of priorities when they switch from Windows to open source software is naive.
No one expects perfect software; but this clearly happened because Microsoft's software was broken, the NSA found where, and horded and then lost control of that knowledge.
edited: I understand what you mean about people not patching and leaving themselves vulnerable. A lot of pain could have been prevented at that level.
Re: Lessons from last week’s cyberattack
#270Earlier quoted context omitted.
I'm not advocating for using Windows for critical systems that store tons of user data, but I am advocating that if you do use it, you should use versions that are still supported and make sure you patch it ASAP. But should Microsoft be expected to back port patches to old OSes in perpetuity?
Oh that's fair, if a product is unsupported, use it air-gapped or at least in a reasonably controlled environment... Again, pretending and forcing upgrades is not the solution. The practise perpetrated by Microsoft has been described again and again as an "aggressive effort to push upgrades". https://www.theguardian.com/technology/2016/mar/15/windows-1... The issue is not the upgrade per se, but the "imperfection" of…
I was in the same camp of you as Windows 10 vs 7 until I saw how much Windows 10 sped up an old machine of mine.