Live data from Hacker News

Deleting System32\curl.exe

daniel.haxx.se

91–100 of 136 posts

Re: Deleting System32\curl.exe

#91
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

> I don't even know who else to blame for this. Microsoft. It's their binary shipped in their system, and their customers are being directed to break their own systems. It's on them to remediate the situation.

Not really. They aren't the ones directing customers to break their systems. They could ban anti-virus software and get slammed for being anti-competitive I suppose. Or they could try to track down all the vendors who are being stupid and ask them to please stop but that probably won't remediate it. They don't have a lot of moves here nor does the curl project.

Re: Deleting System32\curl.exe

#92
post #73
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

As mentioned in the article: >Many Windows users are even contractually “forced” to fix (all) such security warnings within a certain time period or risk bad consequences and penalties. So the blame would be on managers who think checking boxes is how every single job works.

Many times those managers are not responsible for the contractual obligation either. It's one of those comedy of errors type situations where no one single group is fully responsible but put all the decisions together and bad things result.

Re: Deleting System32\curl.exe

#93

Earlier quoted context omitted.

Good thing there is no shake shack in the UK.

And yet there is a town called Scunthorpe - I wonder if the inhabitants have trouble getting things delivered?

At one time, a lot of email spam filters would barf on that town's name.

Re: Deleting System32\curl.exe

#94

Earlier quoted context omitted.

> I don't even know who else to blame for this. The people who told them that deleting system binaries would fix their problems? > I have been pointed to responses on the Microsoft site answers.microsoft.com done by “helpful volunteers” that specifically recommend removing the curl.exe executable as a fix. Don't trust strangers on the internet with advice you don't understand the implications of. Even if they are sin…

The problem here is that if they understand the implications they probably would not be on awnsers.microsoft.com in the first place

But that's the problem, the people doing this do not understand what curl is/does so want it gone because its got a CVE and some outlet somewhere has said its worse than what it is.

if that's the case we should just delete the entire OS as there are vulns all over it.

Re: Deleting System32\curl.exe

#95
post #46

CMD > run as admin > enter "sfc /scannow" without quotes then update should work again. Next time anyone runs into a similar problem you might just want to zip the file before deleting it put a password if you AV still reports it. Or just get rid of your AV software it clearly su*ks if it reports legit system files.

The article doesn't mention an AV software, but a vulnerability assessment solution. Its purpose is to report known vulnerabilities and it would suck, if it did not report known vulnerabilities in system files out of fear of a downstream PEBKAC.

Re: Deleting System32\curl.exe

#96
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

> I don't even know who else to blame for this. Microsoft. It's their binary shipped in their system, and their customers are being directed to break their own systems. It's on them to remediate the situation.

But Microsoft are not advising them to remove curl AFAIK, in that case Microsoft should fix every issue ever within Windows, even if its self inflicted.

End of the day this as Daniel says is scare mongering by others who don't know what they are doing.

The phrase, if someone told you to jump off a cliff, would you?, and, Your scientists were so preoccupied with whether or not they could, they didn't stop to think if they should...

Re: Deleting System32\curl.exe

#98
post #8

Vodaphone blocks this site for being “18+ content”, I guess because of “hacking” or something? There’s no explanation or option to report a false positive and they want you to put in credit card details to confirm your age to unlock it (I don’t need tips to get around this or anything, I can just connect to another network or use a VPN)

Vodafone... https://daniel.haxx.se/blog/2022/05/02/considered-18/

Oh, and Microsoft includes that adult software in their operating system. Can someone report to Vodafone that all Windows PCs must be blocked because they run adult content. Except for those who have deleted curl.exe of course...

Re: Deleting System32\curl.exe

#100

Vodaphone blocks this site for being “18+ content”, I guess because of “hacking” or something? There’s no explanation or option to report a false positive and they want you to put in credit card details to confirm your age to unlock it (I don’t need tips to get around this or anything, I can just connect to another network or use a VPN)

[deleted]
Post reply on HN