Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

291–300 of 304 posts

Re: Lessons from last week’s cyberattack

#291
post #222

Earlier quoted context omitted.

Anyone can seek help on the open market to support Ubuntu 10.04 forever if they like. You can't go to another company if you don't like the price Microsoft sets for support for Windows XP.

This comment makes my blood boil. Please ask yourself: 1. why would anybody want to keep 10.04 alive? 2. do you think the type of people who stubbornly continue to use 10.04 would know/care enough about security to seek an alternative source for security patches? edit: should maybe add why this pisses me off: just logged into a production server running 12.04, default install apache and updates _turned off_. the owne…

> why would anybody want to keep 10.04 alive?

> Assuming these hospitals keep updating and do not get stuck at Ubuntu 10.04.

It's that simple.

If someone wants to continue using outdated software, they will want to keep supporting it. Free software lets them do that. Proprietary software specifically forbids it.

Re: Lessons from last week’s cyberattack

#292

Earlier quoted context omitted.

This is why free software is necessary. Proprietary software makes you rely on a company to fix everything . It's like driving a car without being able to replace a flat tire.

Maybe the law should say 'security patches or open source'?

Why do you want the law involved?

What we have is a cultural issue, not a legal issue.

Re: Lessons from last week’s cyberattack

#293

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

The thing is there really isn't a production ready alternative. Rust in ring 0 isn't production ready -- a lot of language features needed to run in ring 0 are nightly only. There are no widely used microkernels. Ironically, of the widely used operating systems in the world, Windows does the best job of running drivers in userland.

SMB server doesn't need to run at ring 0. It doesn't need direct access to hardware or physical memory. The most safe option would be to run a copy of SMB server under user's account (but it still would allow to encrypt all of the files).

Re: Lessons from last week’s cyberattack

#294
post #135

One of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService…

Why do you claim C++ relates to poor security? OSX and iOS are primarily C, C++, and assembly, (objective C at the higher levels). And linux of course is C and assembly. Are you saying all of the major operating systems have poor security because they use "vulnerable" languages?

I think C++ is very compicated, it is difficult to write memory-, thread- and exception-safe program in it and it is easy to make a mistake that can be exploited.

Re: Lessons from last week’s cyberattack

#295

Earlier quoted context omitted.

Maybe newer OS do not have any useful features for those customers? Maybe they are even worse for them because work slower, are not compatible with old drivers, contain spyware (telemetry)?

Is a company obligated to sell a product with features that you consider useful? Intel doesn't make pre-ME CPUs anymore. Apple doesn't make Power PC iMacs anymore. And Microsoft doesn't make Windows XP anymore. In all these markets, there are consumers who would prefer to purchase the discontinued product. So what? Products get discontinued. Consider a discontinued product from another industry, like a car or an appl…

While you are right, there is a difference that you can drive a 20-30-year old (if repaired) car on modern roads but you once you connect a PC with 20-year old OS to the internet, it will get infected. And 20-year old browser will not be able to display modern websites.

Maybe when cars will become more computerized(?) and connected, they will become unusable faster.

Re: Lessons from last week’s cyberattack

#296
post #256

Earlier quoted context omitted.

How do I know that's the one? I'm was curious about the process of knowing how to find out if my system is patched against vulnerability X.

Here's the complete process I followed: 1. Search for "windows smb server vuln" in Google. 2. "Microsoft Security Bulletin MS17-010 - Critical"[0] is the link I'm looking for. 3. Search for your version in the list. Mine is "Windows 10 Version 1607", listed in the table with 4013429 (right next to the Windows version, not in "Updates replaced"). That's my update number. [0] https://technet.microsoft.com/en-us/library…

I think a lot of the confusion here is what constitutes a "version" of windows 10.

Re: Lessons from last week’s cyberattack

#297
post #256

Earlier quoted context omitted.

Here's the complete process I followed: 1. Search for "windows smb server vuln" in Google. 2. "Microsoft Security Bulletin MS17-010 - Critical"[0] is the link I'm looking for. 3. Search for your version in the list. Mine is "Windows 10 Version 1607", listed in the table with 4013429 (right next to the Windows version, not in "Updates replaced"). That's my update number. [0] https://technet.microsoft.com/en-us/library…

I think a lot of the confusion here is what constitutes a "version" of windows 10.

Indeed. As far as I can tell they are like what used to be Service Packs?

E.g.: I didn't install the so-called Creators Update so I'm not in the latest Windows 10 version.

I'm no Windows sysadmin though so I'm not really sure.

Re: Lessons from last week’s cyberattack

#298

Earlier quoted context omitted.

Are you sure this is enough? At least on WinXp, port 445 is opened by a kernel driver and is still opened after stopping the SMB service.

Disabling services is good, but beware that they may be re-enabled during a software update. Once a service is disabled, you have to monitor that is remains so.

Wouldn't it be a great feature of Windows update to warn its users that once manually disabled services are now being forced to be active?

Re: Lessons from last week’s cyberattack

#299

Microsoft is feature and sales oriented not quality oriented. Security is an aspect of quality. So if you voluntarily like to put yourself at risk, by all means use their products. Their product design doesn't emphasize security. For example, remember the extremely convenient AUTORUN.INF feature? That has probably resulted in billions of dollars lost and that number continues to grow every day. Rendering fonts on the…

>implying ransomware has only ever affected Windows

Re: Lessons from last week’s cyberattack

#300
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

Why would you pay to change something that works fine ? And pay more to have your software redone, and pay more to have the employees retrained.

Microsoft wants more money and push newer revisions of the same crap instead of actually improving the existing one.

Until win10 that is, win10 is now the only windows version and offers more spying, a worse UI and UX while also including ads.

Post reply on HN