Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

51–60 of 304 posts

Re: Lessons from last week’s cyberattack

#51
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

Were people not updating to more modern OSes because they didn't want new features or because they didn't want to spend the money on new licenses and testing software compatibility? And how sure are we that they didn't install security updates out of sheer laziness or hubris? People who run systems that store sensitive information and systems should take computer seriously more serious than the people on Hacker News.…

New versions of Windows also work slower (especially on old hardware), require more disk storage, contain spyware (telemetry) and advertisement that user cannot disable. And contain no new useful features. No wonder people don't want to upgrade. I think Microsoft should have stopped developing new OS with Windows 7 and release only security and bug fixes.

Re: Lessons from last week’s cyberattack

#52
post #33

From the article: >A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. They stopped supporting Windows XP years ago, including with security updates. There are still around 100 million c…

How long should Microsoft be required to support XP? They extended the original support period TWICE. Why are customers entitled to support when they were informed prior to purchasing the product that support expired on a given date?

While there are more than 100 million users of it they should continue to supply security updates for it. Otherwise a widespread virus like this is 100% inevitable.

Re: Lessons from last week’s cyberattack

#53

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

It'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.

Let's be clear on this. No matter how secure the operating system initially, if it stays unpatched then over time it will become more and more vulnerable as uncovered exploits go unfixed.

The reason a machine might go unpatched is because it might support some critical hardware (eg medical) for which there is only one or two vendors and only a particular combination of HW and SW are supported (eg due to a specific custom hardware driver).

To lay the blame for this at a single vendor's feet is naive.

Re: Lessons from last week’s cyberattack

#54
post #13

Earlier quoted context omitted.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Why do you fear updating to Windows 10?

a) telemetry

b) I'm worried my fairly nicely working Win7 environment will not work so well after updating to 10, as much as I want to get current with some genuinely useful features.

I'm generally a Microsoft "fan", but this is one of the many reasons I hate on them as much as Linux fans.

Re: Lessons from last week’s cyberattack

#55
post #40

Earlier quoted context omitted.

I am not exactly sure what dark powers were US government using to force people to leave 3389 on public facing ips. I thought that CIA mind control experiments failed.

According to CERT [0], the original infection vector is still unclear but possibly phishing, however once a computer is infected, any vulnerable machines on the local network are targets. [0] https://www.us-cert.gov/ncas/alerts/TA17-132A

Yep, too many companies still use the Ring Fence approach to security, in a day where Mobile Devices and laptops are moving all the time this is very very very bad.

All it takes is one infected machine to get behind the permitter defenses and it is game over.

Re: Lessons from last week’s cyberattack

#56
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

No system is perfect. Remember Heartbleed? Microsoft released a patch to correct this particular issue in March, however the IT infrastructure in companies is slow, the whole process is convoluted, yada yada. The point is: the NSA caused this particular problem. Steps should be taken be everyone to ensure something like this doesn't happen ever again.

Just because the media (including Microsoft) tagged those projects (that were maintained by small groups of core develops and are free (unpaid) software) with fancy names - those problems weren't anything like the massive, global impact of just one of Microsoft's ticking timebombs due to poor software design and lack of emphasis on security in their products. OpenSSL doesn't and didn't have the PR powerhouse of Microsoft and people didn't pay for their software let alone fund its development.

Re: Lessons from last week’s cyberattack

#57
I think the lesson is to have less uniform, opaque bloatware controlled by disinterested parties whether through proprietary technologies, walled gardens, OR paternalistic update policies. Have some diversity in the network, let people really know and choose what they want on and off, and have the minimum of what is needed for the job turned on by that endowed choice, and half of these problems go away.

Re: Lessons from last week’s cyberattack

#58
post #13

Earlier quoted context omitted.

I disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)

Disabled the SMB services yet? Win + R -> services.msc I routinely disable services (until things stop working and I have to figure where I went too far) and luckily I'd disabled this one on my Win7 gaming box, even though the updates came through as well (I just manually vet updates, and have a bunch of them blacklisted for adding telemetry).

Are you sure this is enough? At least on WinXp, port 445 is opened by a kernel driver and is still opened after stopping the SMB service.

Re: Lessons from last week’s cyberattack

#59

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

IMHO, best approach is to use a (hypothetical) system where all apps are sandboxed by default.

Re: Lessons from last week’s cyberattack

#60
post #46

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

how much do you think it would cost Microsoft to support XP forever?

There's a big argument for only releasing evergreen style software, and giving the middle finger to IT orgs that want more control
Post reply on HN