Live data from Hacker News

Lessons from last week’s cyberattack

blogs.microsoft.com

61–70 of 304 posts

Re: Lessons from last week’s cyberattack

#61
post #46

Earlier quoted context omitted.

Uh, except Microsoft had already patched the vulnerability, just not for XP that was still being run. Of course you can punish them and force them to support all legacy OSes forever, until that strangles the life out of them at which point large institutions still have to run the old OS because they have too much investment in computer controlled hardware with no forward migration. Now they are locked into an insecur…

how much do you think it would cost Microsoft to support XP forever?

[deleted]

Re: Lessons from last week’s cyberattack

#62
post #33

From the article: >A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. They stopped supporting Windows XP years ago, including with security updates. There are still around 100 million c…

I'm generally much in favor of holding vendors accountable when they abandon users, but Microsoft always had clearly communicated timelines for support, and in the case of XP even extended them later (due to Vista being crap). Windows 7 was out for 5 years or so when XP supported ended, as everyone knew beforehand. It's known you wont get support, it's known Windows XP is going to have security issues, what do you expect to happen when you don't take appropriate measures?(options include: replacing it, increased network isolation, virtualization, ..., depending on why you're still running it. Even just a really good backup strategy makes a difference right now).

Customers like this is why we now have Windows 10 where you're force-fed updates and the OS will change under you instead of the change being an upgrade to a new major version that you can delay for years. (Which I'm not happy about, but I can see its benefits on that scale)

The best argument for Microsoft doing wrong here might be that they limit their (expensive) super-extended support to large organizations. Since they do the work, keeping a few boxes with special hardware patched should be an option for smaller shops as well (and is IMHO easier to defend than keeping a large network full of XP desktops running because ?)

Re: Lessons from last week’s cyberattack

#63
post #9

Another lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.

I always had auto updates turned on until Windows' malicious behaviors in recent years:

https://thenextweb.com/microsoft/2015/09/11/microsoft-is-aut...

This one consumes me several gigabytes on my C drive without my permission.

https://www.tenforums.com/windows-updates-activation/55185-w...

This one acts like malware.

And this one: http://www.pcworld.com/article/3039827/windows/7-ways-window...

I don't know why I'd choose a operating system does that.

It pushed some telemetry updates, which arouses some privacy concerns (only after Microsoft's aggressive attitudes about Windows 10 promotion, before that I was OK with its telemetry updates. I'm aware sometimes telemetry tracking means good.)

And much more.

All of these behaviors make me think that I'd rather lose my data than suffer from these "features".

Re: Lessons from last week’s cyberattack

#64

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

Maybe they should not have connected all of the computers across the country into a single network.

Re: Lessons from last week’s cyberattack

#65
post #26

Earlier quoted context omitted.

Complete BS. This is what happens when you have top class PR at your disposal to define the narrative. Microsoft is responsible for their shit software getting exploited first and foremost. Seriously fine Microsoft and by day after tomorrow that 3500 security engineer number will jump to something realistic. Instead what will happen is more tightening of the walled garden, overcharging of support/security contracts a…

No system is perfect. Remember Heartbleed? Microsoft released a patch to correct this particular issue in March, however the IT infrastructure in companies is slow, the whole process is convoluted, yada yada. The point is: the NSA caused this particular problem. Steps should be taken be everyone to ensure something like this doesn't happen ever again.

The NSA did not cause this particular problem. The NSA may have identified the vulnerability, however there is certainly an argument that their other responsibilities outweigh any responsibility that they might have to act as a free security investigation team and report a security vulnerability to an outside corporation.

If Russian government intelligence agency security researchers found that bug first would you say that they have a responsibility to disclose it to Microsoft (notably a United States company)? Would you be surprised if they felt and acted differently?

Re: Lessons from last week’s cyberattack

#67

Should hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.

It'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.

[deleted]

Re: Lessons from last week’s cyberattack

#69

Earlier quoted context omitted.

Why do you fear updating to Windows 10?

a) telemetry b) I'm worried my fairly nicely working Win7 environment will not work so well after updating to 10, as much as I want to get current with some genuinely useful features. I'm generally a Microsoft "fan", but this is one of the many reasons I hate on them as much as Linux fans.

Sounds reasonable, thanks for replying!

Re: Lessons from last week’s cyberattack

#70
There's a lot of blame being thrown around, and I think it's all merited, but an inordinate amount needs to be on the users. I don't know how many times I've heard things like: "I don't think I'll update to Windows 10" or "That update has been nagging me for months" or even security advocates saying "Windows 10 is a privacy nightmare, I'll stay on 7". Being on the latest secure upstream isn't a nicety, it's what you have to do if you want any semblance of a secure environment. If you don't like upstream, jump to another.

It's definitely not end-users either. There's a grocery store that just went up nearby that I saw Windows XP splash screen on when one of the cashiers rebooted. No joke, new store, Windows XP computers that handle money. Microsoft may have cultivated this nightmare, but it seems everyone wants to live in it.

Post reply on HN