Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

281–290 of 304 posts

Re: Lessons from last week’s cyberattack

#281
post #142

Earlier quoted context omitted.

Critical systems that require long term support is what Win10 Enterprise LTSB was designed for, which you get with Software Assurance.

Microsoft Software Assurance is something very distant from real SwA. > https://www.microsoft.com/en-us/licensing/licensing-programs... > https://en.wikipedia.org/wiki/Software_assurance Users don't want to upgrade, many I know would rather use linux or macs. Microsoft should acknowledge the thing and fix what's wrong. IT departments these days are trying to convince the people they work with. OS editions - 10: Home…

Win10 also has an insider program too.

Re: Lessons from last week’s cyberattack

#282

Earlier quoted context omitted.

It wasn't about fixing, it was about upgrading/updating. It takes people and money to upgrade large infrastructures - closed source or open source, doesn't matter. Thinking that irresponsible (or budged-constrained) organizations will somehow have a completely different mindset and or set of priorities when they switch from Windows to open source software is naive.

No it is about fixing, a design flaw allowed this to happen. SMB1 (hopefully) wasn't built thinking EternalBlue would be a fun feature. No one expects perfect software; but this clearly happened because Microsoft's​ software was broken, the NSA found where, and horded and then lost control of that knowledge. edited: I understand what you mean about people not patching and leaving themselves vulnerable. A lot of pain…

So let's assume this was in Ubuntu, lets say, version Ubuntu 10.04.4 LTS (5 years of support), and the NHS decided that it didn't want to upgrade beyond 10.04.4 because some of their stuff broken...

Long term support ended in May 2013 for desktop. But Ubuntu patched the bug in March 2017 for all current supported versions of Ubuntu.

Then the NHS got his with the bug.

How does free / non-microsoft software protect against a shitty decision to not update / upgrade?

Re: Lessons from last week’s cyberattack

#283
post #281

Earlier quoted context omitted.

Microsoft Software Assurance is something very distant from real SwA. > https://www.microsoft.com/en-us/licensing/licensing-programs... > https://en.wikipedia.org/wiki/Software_assurance Users don't want to upgrade, many I know would rather use linux or macs. Microsoft should acknowledge the thing and fix what's wrong. IT departments these days are trying to convince the people they work with. OS editions - 10: Home…

Win10 also has an insider program too.

And that's even more bewildering ... Needless complexity over needless complexity.

Re: Lessons from last week’s cyberattack

#284
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…

I suggest some reading:

* http://www.telegraph.co.uk/technology/microsoft/7898033/Micr...

* https://www.gov.uk/government/uploads/system/uploads/attachm...

* http://www.bbc.co.uk/news/uk-politics-24130684

* https://www.theguardian.com/society/2013/sep/18/nhs-records-...

* https://blog.venngroup.com/august-1st-marked-the-launch-of-m...

* https://www.gov.uk/government/publications/nhs-foundation-tr...

* https://www.theguardian.com/technology/2010/jan/22/internet-...

* http://www.cio.co.uk/it-applications/uks-largest-nhs-trust-d...

Yes, this is a large and complex subject.

Re: Lessons from last week’s cyberattack

#285
post #249

Earlier quoted context omitted.

XP was supported for 12 years. It's now over 15 years since it was released.

XP is still in use for 2 reasons: cost and backwards compatibility. For cost, CentOS, on it's own, is free. Support costs you of course, but the updates are coming down from RedHat for which there is enough money flowing in already, so support in this case means a sysadmin who understands CentOS and those are not that rare, not even that expensive. Backwards compability is another topic, especially with the rise of s…

> Backwards compability is another topic, especially with the rise of systemd.

User level ABI has had no important incompatibility since the glibc released with the kernel 2.6 (don't remember the version). That was some 15 years ago. Most applications didn't even break at that time, and core libraries promise more stability now.

That's nothing similar to the compatibility break between Windows XP and Vista. That transition broke most of the older applications, at the kernel level.

Re: Lessons from last week’s cyberattack

#286

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

> Port 445 that was used in an attack is opened by a kernel driver that runs in ring 0.

You know, not too long ago, Linux used to run NFS on ring 0 too.

There was a good reason for those things, you can find them on the performance comparatives between CPU and network at the time.

Re: Lessons from last week’s cyberattack

#287
post #261

Earlier quoted context omitted.

"The chaos surprised many security watchers because Microsoft issued an update in March that patched the underlying vulnerability in Windows 7 and most other supported versions of Windows. (Windows 10 was never vulnerable.)" source: https://arstechnica.co.uk/security/2017/05/wcry-microsoft-is... So I don't really know what you mean by 'hoarding the fix'. The patch was not initially released to some OS versions becaus…

I believe the "hoarding the fix" comment was in reference to the patches for Server 2003, XP, and Windows 8 that were released publicly for the first time over the weekend (but had been distributed previously to customers paying for custom support) [0]. [0] https://news.ycombinator.com/item?id=14329914

I guess I don't see it that way. Extended support (which includes security patches) are only for paying customers.

Re: Lessons from last week’s cyberattack

#288
post #251

Earlier quoted context omitted.

Whatever hardware that is running that 12.04 system can be upgraded, free of charge, for likely the next 20 years if the past 20 years of linux is anything to go by. Even if you pay money for the windows 10, it is unlikely to even start on the hardware that XP ran on. Not only will the people have to go through the budget to pay for the software, but now you need a full upgrade plan. To put this in a concrete example…

I understand the argument, but I think "just take someone internal from IT and go and fix it" is vastly oversimplifying the skills/manpower/time required for doing something like this.

I can only speak of my own experience as a sysadmin, but the more isolated the system is and the less critical it is for operation, the easier it is to delegate the job of doing a software update to coworkers and new hire. Especially if all the issues from doing an update has already been established on several other machines, in which case the update is more or less mechanical in nature.

It reminds me of the story about a thirty year old Commodore Amiga running the AC system for a school district. The district finally decided to modernize the AC for $2 million, but until then it was just cheaper and easier to continue paying a person to run it every year. Replacing hardware systems is expensive and political complicated, while continuing paying an employee is just status quo.

Re: Lessons from last week’s cyberattack

#289
post #207

Earlier quoted context omitted.

Lesson 1: don't use proprietary operating systems.

If Windows were open-source, would the situation have been any different? Would organisations with very conservative attitudes to upgrade paths or a requirement to run an older OS version have suddenly been patching nightly? Would the exploits used have been identified and patched prior to their malicious deployment? Would organisations with a vested interest in stockpiling exploits have elected to immediately notify…

Windows update is, put simply, a pain in the ass.

That has been the case for over a decade, and it has been getting worse over time.

The reason I recommend a free operating system is not because you are allowed to read the source (although that is a bonus), it is because you have the freedom to control your operating system.

The problem with Windows is that "updates" are done in the most inconvenient way possible, and with no control by the user. They often include changes that the user does not want bundled in with security patches. To contrast, a free operating system gives you options (liberty). If I just want an old stable version of Debian with security patches, I can get it.

The issue here stems from using proprietary software in the first place. Proprietary software is controlled by the company, not the user.

Re: Lessons from last week’s cyberattack

#290

Earlier quoted context omitted.

No it is about fixing, a design flaw allowed this to happen. SMB1 (hopefully) wasn't built thinking EternalBlue would be a fun feature. No one expects perfect software; but this clearly happened because Microsoft's​ software was broken, the NSA found where, and horded and then lost control of that knowledge. edited: I understand what you mean about people not patching and leaving themselves vulnerable. A lot of pain…

So let's assume this was in Ubuntu, lets say, version Ubuntu 10.04.4 LTS (5 years of support), and the NHS decided that it didn't want to upgrade beyond 10.04.4 because some of their stuff broken... Long term support ended in May 2013 for desktop. But Ubuntu patched the bug in March 2017 for all current supported versions of Ubuntu. Then the NHS got his with the bug. How does free / non-microsoft software protect aga…

> How does free / non-microsoft software protect against a shitty decision to not update / upgrade?

By not bundling upgrades with what is essentially malware, and making them as inconvenient as possible.

If I am running Ubuntu 10.04.4, and I hear about serious malware that relies on a security hole that is patched upstream, I have the opportunity to patch it myself, and keep running Ubuntu 10.04.4 as long as I want.

That being said, it's disingenuous to compare unpatched Windows 10 with unpatched Ubuntu 10.04. It is totally unreasonable to think you are secure using an unsupported OS, but it is a lot more reasonable to think you are secure running Windows 10 just a couple months out of date.

Post reply on HN