Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

271–280 of 304 posts

Re: Lessons from last week’s cyberattack

#271
post #188

Earlier quoted context omitted.

What does "evergreen style software" mean? A quick search didn't return an obvious answer.

Software that continually updates itself automatically. It's what Chrome popularized.

I think MS wanted this in Win10 (hence the big push on the consumer side by giving it away for free). The problem is that plenty of people, even people who should know better, don't want to upgrade something they think is "working well" for an advantage they can't see.

Re: Lessons from last week’s cyberattack

#272
And what about the lesson that software should be mortal, and should one day die? By what metric is, e.g. Windows XP, subject to evergreen updating to mitigate (prevent or reduce impact of) this exact scenario, forever? Does Microsoft have the right, and even the obligation, to remote detonate all Windows XP in existence on a certain date?

Perhaps EOL should be literal. The software kills itself and does not function.

The lesson I'm getting is our software can become malicious, and that malice can spread like wildfire. Is a company obligated to patch any wildfire type of bug forever? Is that a cost of proprietary software? Or is setting a date for its death the cost?

I think aging proprietary software has a much greater chance of becoming a weapon than it does becoming inconveniently obsolete. So forcing a company to release the code as free and open source software upon EOL date, I think just enhances the chances that it gets weaponized. There's a greater incentive to find exploits than to fix them, in old software.

Another lesson is most people really shouldn't be using Windows. If you can't afford to pay Microsoft to keep your software up to date, then use something that's FOSS and is up to date. (Same rule applies to Apple, if you can't afford new hardware in order to run current iOS/macOS versions that are being maintained, then don't buy stuff from Apple anymore.)

Re: Lessons from last week’s cyberattack

#273

Earlier quoted context omitted.

Disabled the SMB services yet? Win + R -> services.msc I routinely disable services (until things stop working and I have to figure where I went too far) and luckily I'd disabled this one on my Win7 gaming box, even though the updates came through as well (I just manually vet updates, and have a bunch of them blacklisted for adding telemetry).

Are you sure this is enough? At least on WinXp, port 445 is opened by a kernel driver and is still opened after stopping the SMB service.

Disabling services is good, but beware that they may be re-enabled during a software update. Once a service is disabled, you have to monitor that is remains so.

Re: Lessons from last week’s cyberattack

#274
post #251
post #222

Earlier quoted context omitted.

This comment makes my blood boil. Please ask yourself: 1. why would anybody want to keep 10.04 alive? 2. do you think the type of people who stubbornly continue to use 10.04 would know/care enough about security to seek an alternative source for security patches? edit: should maybe add why this pisses me off: just logged into a production server running 12.04, default install apache and updates _turned off_. the owne…

Whatever hardware that is running that 12.04 system can be upgraded, free of charge, for likely the next 20 years if the past 20 years of linux is anything to go by. Even if you pay money for the windows 10, it is unlikely to even start on the hardware that XP ran on. Not only will the people have to go through the budget to pay for the software, but now you need a full upgrade plan. To put this in a concrete example…

I understand the argument, but I think "just take someone internal from IT and go and fix it" is vastly oversimplifying the skills/manpower/time required for doing something like this.

Re: Lessons from last week’s cyberattack

#275
post #213

Earlier quoted context omitted.

I thought MIT wasn't free software as defined by the FSF? Open source would be the term for that. Free requires end users to receive source, open just allows you to use the source if you have a copy.

Free software is software that doesn't cost any money, hence it is free.

You're confusing free software[0] with freeware[1]

[0] https://en.wikipedia.org/wiki/Free_software

[1] https://en.wikipedia.org/wiki/Freeware

Re: Lessons from last week’s cyberattack

#276
post #142

Earlier quoted context omitted.

Critical systems should not have installed an operating system that collects metadata on virtually anything the user does: telemetry. https://arstechnica.com/information-technology/2017/04/micro... (Privacy) Especially if the company that develops the os in question shows a track like this one: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=microsoft+w... . (Security) I also wonder how long it will take before the…

Critical systems that require long term support is what Win10 Enterprise LTSB was designed for, which you get with Software Assurance.

Microsoft Software Assurance is something very distant from real SwA.

> https://www.microsoft.com/en-us/licensing/licensing-programs...

> https://en.wikipedia.org/wiki/Software_assurance

Users don't want to upgrade, many I know would rather use linux or macs. Microsoft should acknowledge the thing and fix what's wrong. IT departments these days are trying to convince the people they work with.

OS editions

- 10: Home [wipb + cb], Pro [wipb + cb + cbb], Education [wipb + cb + cbb], Enterprise [wipb + cb + cbb], Enterprise LTSB [ltsb], S

- 8: Core, Pro, Enterprise, RT

- 7: Starter, Home Basic, Home Premium, Professional, Ultimate, Enterprise

vs

- Debian: unstable, testing, stable, old-stable

- macOS: developers beta, public beta, released

- BSDs: current, stable, release, old-release

I am unsure if the Windows mess can be considered a "naming scheme", the single thing I have very clear is that there's something terribly broken (maybe the whole marketing fuss thing).

Re: Lessons from last week’s cyberattack

#277
post #42
post #13

Earlier quoted context omitted.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Disabling updates is the worst possible solution. Just click no on the windows 20 upgrade dialogue (or just upgrade, it's pretty good). Refusing to patch your system because of this is ridiculous (and yes some blame does lie with MS For pushing people to this)

> Disabling updates is the worst possible solution

If so, more blame lies at the feet of those that make it the only solution.

> Just click no on the windows 20 upgrade dialogue

Would that it were so simple. But Microsoft chose to mean "yes" by the "close this [annoying] window" button, with Windows 10; who knows what they'll come up with for Windows 20.

> (or just upgrade, it's pretty good)

For you, sure. Some people like to make their own choices.

> Refusing to patch

For most people that disabled updates, it wasn't a "refusal to patch", so much as a (read: the only) relief from annoyance.

Re: Lessons from last week’s cyberattack

#278
For those who think that using free software would be similar (naming ubuntu or even centos).

The real question is why a hospital is still running windows xp even though it's not supported by its own vendor.

The answer is vendor lock ins. The upgrade is not a matter of simple command. Upgrade cost involves more licenses and hardware upgrades (which is not needed as old hardware is fine, but this is how things work between microsoft and hw vendors) it's like you need a new buy watch to apply dst summer time.

Also mirosoft and old school desktop software vendors used to make sure switch or upgrade cost is really high ex by using non stanard formats.. to lock users from switching to mac or linux

If you remember active x and internet explorer specific vbscript...

If you use free software from an expensive but decent vendor like redhat you can upgrade software on same hardware

And if it software was expensive you can switch to centos, scientific linux or pay anyone to handle that for you are fair rate. There is no vendor lock in. Every thing is stardard and no vendor lock in.

Re: Lessons from last week’s cyberattack

#279

Earlier quoted context omitted.

The thing is there really isn't a production ready alternative. Rust in ring 0 isn't production ready -- a lot of language features needed to run in ring 0 are nightly only. There are no widely used microkernels. Ironically, of the widely used operating systems in the world, Windows does the best job of running drivers in userland.

Microsoft had enough resources in the 90s and 2000s to get a safe language like ocaml running at least their network services.

OCaml in ring 0? Anything can be done if you try hard enough I guess.

MS had a research project to rewrite the NT kernel in a C# derived language at one point. It worked, but they decided not to go ahead with it.

Re: Lessons from last week’s cyberattack

#280
post #26
post #11

The quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development an…

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

>Microsoft is responsible for their shit software getting exploited

This is an absurdly naive viewpoint. How are they responsible? What is their responsibility? How is it their responsibility when a state-funded group/actor targets their software and finds an exploit?

At some point you have to realize that 0days will always exist. It is an impossible task to expect software developers to ship perfect software.

Post reply on HN