15 ms·
Lessons from last week’s cyberattack
- denzil_correa 9y ago> Finally, this attack provides yet another example of why the stockpiling of vulnerabilities by governments is such a problem. This is an emerging pattern in 2017. We have seen vulnerabilities stored by the CIA show up on WikiLeaks, and now this vulnerability stolen from the NSA has affected customers around the world. Repeatedly, exploits in the hands of governments have leaked into the public domain and caused widespread damage. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen. And this most recent attack represents a completely unintended but disconcerting link between the two most serious forms of cybersecurity threats in the world today – nation-state action and organized criminal action Did the Microsoft President just confirm that NSA develop the vulnerability which led to the attacks on hospitals this weekend?!
- funnuf 9y agoI thought that the NSA itself informed Microsoft after EnternalBlue was stolen?
- rando444 9y agoThis is public knowledge at this point.
- MichaelGG 9y agoCitation please?
- laumars 9y agoThe NSA hoarding / leaking aspect of this vulnerability has been reported by most major news outlets. Even the mainstream ones. Albeit most haven't expanded on that point to the level that Microsoft did here.
- MichaelGG 9y agoSorry I misread it as the NSA was developing the holes as in backdoors, intentionally creating the vulnerability.
- dredmorbius 9y agoEffectively, that's what happened.
- detaro 9y agoThis (as far as I know) was one of hte first reports of details of the malware and clearly mentions it, and other analysts haven't said otherwise, which by now they would have if they disagreed: http://blog.talosintelligence.com/2017/05/wannacry.html http://blog.talosintelligence.com/2017/05/wannacry.html
- JumpCrisscross 9y ago> An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen This is a bad analogy. The solution to people stealing your Tomahawks is to guard your goddamn bombs. A better analogy would be the U.S. military seeing Al Qaeda has a bunch of Tomahawks and doing nothing because they might be aimed at ISIS.
- hutzlibu 9y ago"Did the Microsoft President just confirm that NSA develop the vulnerability " Where did he do that? He said they found it and kept it for themself, but not that they injected it into Windows. And about the whole thing, I would rephrase it to "many users learned the hard way about why are security-updates important". But it is nice, that microsoft advocates a " digital genvue convention" even though I doubt anything will really change.
- pquerna 9y ago> We need governments to consider the damage to civilians that comes from hoarding these vulnerabilities and the use of these exploits. This whole incident is really raising the profile of the creation of "cyber weapons". They aren't like physical weapons with physical controls -- they are digital, controls and costs to copy/distribute are more like digital music than anything a Goverment organization is used to.
- cm2187 9y agoAnother lesson learned: don't bundle your security updates with your cool new features nobody wants, Microsoft. This will aggravate the problem as more people/companies will defer updates.
- ak39 9y agoI disabled updates on my Windows 7 last September when I feared that I'd wake up to a Windows 10 machine like my wife did when her laptop updated to Windows 10. Unfortunately I can't seem to resume updates and fear that I may be vulnerable to WannaCrypt. (Some recent updates succeeded but I don't know if i patched for it)
- foxh0und 9y agoYour safest option then is to disable SMB.
- gerdesj 9y agoJust SMBv1 in this case, here is how: https://support.microsoft.com/en-gb/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012 https://support.microsoft.com/en-gb/help/2696547/how-to-enab... Also, decent AV and anti spam and don't open email attachments without some prior analysis. Backups - good backups and check them at least weekly. Actually just do all the boring stuff that IT Security have been recommending for years.
- ak39 9y agoThanks. Done it
- mobiplayer 9y agoWhy do you fear updating to Windows 10?
- mistermann 9y ago
- cm2187 9y agoOne thing that strikes me with this malware is that it hits pretty much every single country. Don't hackers try to follow the proverbial "don't shit where you eat" proverb? They have nowhere to hide if they are identified now.
- 4lch3m1st 9y agoLast time I checked, hackers used to follow the "lulz" principle. However some follow the money principle, which can be stolen from anyone.
- flukus 9y agoYou're assuming it was released on purpose and worked on the intended scale, I'm not sure either are true.
- muricula 9y agoThis malware was first released as part of a massive spam campaign, and then from there wormed its way onto other systems. It was definitely released on purpose.
- y_u_no_rust 9y agoIt's ransomware the intend target is anyone and everyone
- hugh4life 9y ago
- loteck 9y agoThe quote bombshell here, and what hasnt yet gotten much attention since sysadmins the world over are busy dealing with fallout, is that the NSA and therefore the US government is directly responsible for the current global cyber-carnage. We developed the capability, we chose to keep it unpatched, we tried to keep it secret, we lost control of it. This has similarities in type, if not in horror, to the development and subsequent spread of nuclear weapons. When we lost control of those secrets, it was a BFD [0]. [0] https://en.m.wikipedia.org/wiki/Atomic_spies https://en.m.wikipedia.org/wiki/Atomic_spies
- deleted 9y ago[deleted]
- SomeStupidPoint 9y agoMS issued a patch ahead of the usage of the lost exploit by a wide enough margin that I'm loathe to blame the government for the mere existence. The problem lies in our defensive infrastructure and our ability to roll out patches responding to incidents. It also lies in our security infrastructure: that cryptoworms are a danger speaks to a fundamental lapse in permission and process management systems.
- CydeWeys 9y agoThe margin would've been much wider still with responsible disclosure from the NSA, however. This means that fewer people would have been affected.
- mastax 9y agoUnless the NSA reported it to MS back when XP was still supported, not much would change. People can (and do) reverse-engineer exploits from windows updates, and they could still take advantage of the large number of unpatched XP machines.
- muricula 9y agoIn an unusual move, after the worm statrted spreading MS released a patch to XP for this exploit.
- DanBC 9y agoNo one in the UK seems to be tying this attack to the Conservative Party's desire for backdoors everywhere, which is a shame because it's a nice example for the public of how the government have got this very wrong.
- gruez 9y agothe public doesn't care or doesn't want to care, which is the same reason there's no widespread opposition in the first place.
- setq 9y agoReddit is all over it although it has turned into something suitably reminiscent of Alex Jones' material. Jeremy Hunt is apparently directly responsible for running XP on all NHS equipment and pulling the plug on the support contract for post-extended-support causing the deaths of thousands of people while he rolls around in the dust of the crushed skulls of all his victims. I would rather see it used to leverage an opinion against back doors and surveillance culture but alas this is merely administrative incompetence and failure to either upgrade or airgap systems which have had a clock ticking on them and plenty of notice from the vendor to sort. The buck should stop at the trust IT directors as this was entirely avoidable with a properly managed estate.
- whitefish 9y agoShould hospitals such as UK's NHS and other such organizations use dumb terminals (or chromebooks) instead of Windows? That way data is centralized on servers where it is easy to backup and harder for hackers to hold to ransom.
- cryptarch 9y agoIt'd be a good start if they just didn't use Windows. But yeah, definitely. It's pretty damned unlikely that an OpenBSD backup server would get wormed, unless an ME exploit is involved.
- phs318u 9y agoLet's be clear on this. No matter how secure the operating system initially, if it stays unpatched then over time it will become more and more vulnerable as uncovered exploits go unfixed. The reason a machine might go unpatched is because it might support some critical hardware (eg medical) for which there is only one or two vendors and only a particular combination of HW and SW are supported (eg due to a specific custom hardware driver). To lay the blame for this at a single vendor's feet is naive.
- pier25 9y agoTrue, but I'm sure there are a lot of cases where the OS wasn't updated because of the necessary investment to jump to a new Windows version.
- kijin 9y agoThere are very few free/open-source operating systems that get security patches for as long as Windows does. Major versions of OpenBSD are only supported for 5-6 years. Most Linux distributions only get 3-5 years. Red Hat promises 10 years of support, the same as Windows 7/8/10. None comes close to the 13 years that Windows XP was supported for. So you're gonna have to update anyway, at roughly the same interval if not more often, as if you had used an enterprise edition of Windows.
- partycoder 9y agoMicrosoft is feature and sales oriented not quality oriented. Security is an aspect of quality. So if you voluntarily like to put yourself at risk, by all means use their products. Their product design doesn't emphasize security. For example, remember the extremely convenient AUTORUN.INF feature? That has probably resulted in billions of dollars lost and that number continues to grow every day. Rendering fonts on the kernel... fantastic idea! What's the next great Microsoft idea? Continue to buy their products and figure it out.
- cholantesh 9y ago>implying ransomware has only ever affected Windows
- feelix 9y agoFrom the article: >A month prior, on March 14, Microsoft had released a security update to patch this vulnerability and protect our customers. While this protected newer Windows systems and computers that had enabled Windows Update to apply this latest update, many computers remained unpatched globally. They stopped supporting Windows XP years ago, including with security updates. There are still around 100 million computers around the world running XP. It seems irresponsible to just leave them to hang out to dry when there are that many machines out there running it. A virus seems inevitable if they do. And shifting the blame onto the customers is not reasonable when there are still 100 million customers who are "doing it wrong" by not upgrading to a later version of Windows. This entire article pertains to directly shifting the blame onto their customers, and the governments of the affected countries (!) >The fact that so many computers remained vulnerable two months after the release of a patch illustrates this aspect Again, XP systems are the most affected, and there was no patch released for XP. This is extremely irresponsible of Microsoft and this article shifting the blame onto everyone but themselves is reprehensible.
- will4274 9y agoHow long should Microsoft be required to support XP? They extended the original support period TWICE. Why are customers entitled to support when they were informed prior to purchasing the product that support expired on a given date?
- idlewords 9y agoThey do support XP, they just charge a king's ransom for it. Thanks to Microsoft's policies, XP is also a kind of ransomware.
- feelix 9y agoWhile there are more than 100 million users of it they should continue to supply security updates for it. Otherwise a widespread virus like this is 100% inevitable.
- codedokode 9y agoMaybe newer OS do not have any useful features for those customers? Maybe they are even worse for them because work slower, are not compatible with old drivers, contain spyware (telemetry)?
- codedokode 9y agoOne of the reasons why such attack was possible is poor security in Windows. Port 445 that was used in an attack is opened by a kernel driver (at least that is what netstat says on WinXP) that runs in ring 0. This driver is enabled by default even if the user doesn't need SMB server and it cannot be easily disabled. Most of services in Windows are run under two privileged user accounts (LocalService or NetworkService). Many of them are enabled by default and are listening on ports on external interface so the potential attack surface is large. Microsoft uses programming languages like C++ that is very complicated and a little mistake can lead to vulnerabilities like stack overflow, use-after-free, etc. Microsoft (and most companies) prefers to patch vulnerabilities with updates rather than take measures that would reduce attack surface. Oh, and by the way Linux has similar problems. In a typical Linux distribution a program run with user privileges is able to encrypt all of the user's files, access user's cookies and saved passwords on all websites, listen to microphone and intercept kestrokes.
- muricula 9y agoThe thing is there really isn't a production ready alternative. Rust in ring 0 isn't production ready -- a lot of language features needed to run in ring 0 are nightly only. There are no widely used microkernels. Ironically, of the widely used operating systems in the world, Windows does the best job of running drivers in userland.
- aphexairlines 9y agoMicrosoft had enough resources in the 90s and 2000s to get a safe language like ocaml running at least their network services.
- muricula 9y agoOCaml in ring 0? Anything can be done if you try hard enough I guess. MS had a research project to rewrite the NT kernel in a C# derived language at one point. It worked, but they decided not to go ahead with it.
- deleted 9y ago
- z3t4 9y agostop exposing functions ment to run in private networks (LAN) to the internet. please make stuff secure by default.
- mrmondo 9y agoPretty sure this is a highly targeted piece of PR designed to shift the blame from Microsofts appallingly poor operating system design especially when it comes to security. Are the NSA a deceptive, anti-humanist organisation that performs atrocious acts against people - yes - I absolutely believe so and they play a HUGE part in this, but Microsoft - they are the irresponsible software vendor here and do they reimburse people that have PAID for their software? No.
- pishpash 9y agoI think the lesson is to have less uniform, opaque bloatware controlled by disinterested parties whether through proprietary technologies, walled gardens, OR paternalistic update policies. Have some diversity in the network, let people really know and choose what they want on and off, and have the minimum of what is needed for the job turned on by that endowed choice, and half of these problems go away.
- dominhhai 9y agoWhy not use Linux or MacOS?
- azangru 9y agoYeah, I am surprised how many people here complain of their experience with Windows, yet keep using it.
- peterkelly 9y agoBecause they have a long history of vulnerabilities too.
- ladzoppelin 9y agoBut what does that solve? Nothing. Why offer a bad solution to a real problem? "MacOS" really?
- Cole_Jontrane 9y agoBecause we want to run real software?
- devrandomguy 9y agoBecause fear of the unknown is stronger than fear of the beast.
- carlosrg 9y agoYou have to be pretty delusional if you think macOS or Linux don't have security problems.
- pmlnr 9y agoOf course they do, yet we still haven't seen an outage like this, even though most of the web world is running on some kind of linux. Most probably it's due to the high variety in kernels, versions and the subtle differences in linux distributions.
- deleted 9y ago[deleted]
- ssdfe 9y agoThere's a lot of blame being thrown around, and I think it's all merited, but an inordinate amount needs to be on the users. I don't know how many times I've heard things like: "I don't think I'll update to Windows 10" or "That update has been nagging me for months" or even security advocates saying "Windows 10 is a privacy nightmare, I'll stay on 7". Being on the latest secure upstream isn't a nicety, it's what you have to do if you want any semblance of a secure environment. If you don't like upstream, jump to another. It's definitely not end-users either. There's a grocery store that just went up nearby that I saw Windows XP splash screen on when one of the cashiers rebooted. No joke, new store, Windows XP computers that handle money. Microsoft may have cultivated this nightmare, but it seems everyone wants to live in it.
- josefx 9y ago> Being on the latest secure upstream isn't a nicety, it's what you have to do if you want any semblance of a secure environment. Windows 7 is in extended support to 2020. So as far as I know security wise still up to date. > There's a grocery store that just went up nearby that I saw Windows XP splash screen on when one of the cashiers rebooted. The cash register may be even running with a user interface written in VB6. Don't attach it to an external network and it will work just fine. No need to invest in new hardware/software when you can get it old, working and cheap. > Windows XP computers that handle money. In what way do they handle money? A computer virus isn't going to steal paper money and the device operating the card reader should have been sufficiently separated to begin with.
- dotancohen 9y agoDo you really think that the machine does not handle credit cards a well? Provide a daily management report? Report inventory? Provide a Facebook interface between customers via the big blue E icon?
- josefx 9y ago> Do you really think that the machine does not handle credit cards a well? I don't know about the U.S., but as far as I know were I live these card readers have to be almost completely separate systems. The connection between these two should only exist to a) set the price to pay and b) confirm that a payment was made. > Provide a daily management report? Report inventory? No longer managing money directly, so the possible abuse for financial gain is quite restricted. You could argue that someone manipulates the reports in order to skim some money for himself, however that would be a rather targeted attack with someone on the inside profiting and could be detected when the physical goods no longer line up with the reported values. > Provide a Facebook interface between customers via the big blue E icon? Are we even talking about the same thing?
- yuhong 9y agoSide note, I posted https://news.ycombinator.com/item?id=14334776 https://news.ycombinator.com/item?id=14334776 on custom support and MS quarterly earnings.
- accountyaccount 9y agoLESSON: UPDATE YOUR SHIT
- Cole_Jontrane 9y agoCue the Apple and Linux astroturfers who say that _their_ OS is secure!
- bikamonki 9y agoLesson 1: don't use Windows. Lesson 2: be it a web resource or your pc, make sure you can restore all your data/sw from clean/current copies. Lesson 3: test lesson 2 periodically.
- thomastjeffery 9y agoLesson 1: don't use proprietary operating systems.
- ry_ry 9y agoIf Windows were open-source, would the situation have been any different? Would organisations with very conservative attitudes to upgrade paths or a requirement to run an older OS version have suddenly been patching nightly? Would the exploits used have been identified and patched prior to their malicious deployment? Would organisations with a vested interest in stockpiling exploits have elected to immediately notify projects' maintainers? The answer to these swings wildly between 'maybe' and 'probably not', so the eventual endpoint is likely largely the same. It's a compound issue brought about by a chain of decisions made by disparate organisations, and using it as a stick to beat Microsoft or proprietary vendors in general with is missing a very important point - Security is the responsibility of everybody involved, from vendors and the government, all the way down through to the people innocently opening infected attachments.
- thomastjeffery 9y agoWindows update is, put simply, a pain in the ass. That has been the case for over a decade, and it has been getting worse over time. The reason I recommend a free operating system is not because you are allowed to read the source (although that is a bonus), it is because you have the freedom to control your operating system. The problem with Windows is that "updates" are done in the most inconvenient way possible, and with no control by the user. They often include changes that the user does not want bundled in with security patches. To contrast, a free operating system gives you options (liberty). If I just want an old stable version of Debian with security patches, I can get it. The issue here stems from using proprietary software in the first place. Proprietary software is controlled by the company, not the user.
- fiatpandas 9y agoHow did MS know to patch a month before the exploits leaked? Did they get advanced notice as a courtesy from NSA, or someone else, that the exploits leaked?
- amaterasu 9y agoI'm assuming this was contained in the vault7 leak: https://en.wikipedia.org/wiki/Vault_7 https://en.wikipedia.org/wiki/Vault_7
- spydum 9y agoa lot of people kicking sand in MSFT's eyes for having such a vulnerability.. but come on, the code base for windows is enormous. The feat of engineering that is microsoft windows (and its many iterations) is pretty amazing when you really look at it. Yes, plenty of flaws, but show me some other software which has endured? Further, all of the major infections are based on Windows XP. Windows XP mainstream support ended a full year before the first gen iPhone was out! It's seriously ancient and there are very few excuses for people to have this crap on a network in 2017. For the folks who dont run XP, but got infected because they didn't patch? No excuses. If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009.
- merlincorey 9y ago> If I booted a RedHat (5.2 came out in 2009ish) or FreeBSD machine from 2009 without patches, and put it on the internet, I'm pretty sure it'd be hosed just as bad (shellshock, heartbleed, ?). the difference is, everyone would tell me I'm an idiot for putting a machine online from 2009. As a tongue in cheek (but totally true) correction, FreeBSD from 2009 would NOT be vulnerable to the shellshock vulnerability unless you explicitly install `bash` and make it the shell used by apache-cgi. By default, FreeBSD lacks bash.
- alex_anglin 9y agoTrue, but FreeBSD can't guarantee perpetual security for releases. It also doesn't provide warranties, like the majority of software out there. FWIW, I do hold FreeBSD in high regard. It's just that expecting perfection security-wise from complex systems is a fools errand.
- asdfgadsfgasfdg 9y ago> It's just that expecting perfection security-wise from complex systems is a fools errand. I think that may have been the OP's point. Bash is more complex than sh has to be hence because FreeBSD choose the simpler option they avoid the inherent security implications of complex systems. (I use bash myself and don't use FreeBSD.)
- natch 9y agoMicrosoft's version: I see three areas where this event provides an opportunity for Microsoft and the industry to improve. Fixed version: I see three areas where this event provides an opportunity for Microsoft, the industry, and government to improve. To be fair, he does go on to point out how this is partly the fault of poorly conceived government policies, namely the NSA's foolish practice of stockpiling exploits. But Microsoft and the industry should keep the heat on the government about this at every opportunity, because the horrifically bad and analogous idea of having government master keys is still being pushed forward.
- justinzollars 9y agostackoverflow nazis; this should not be a closed question
- linjian 9y agoHow to prevent an attack from internet is really a big problem. More open the system is, more dangerous the system maybe. like this attack, the macOS and Linux is safe. Maybe just because the system is not that open and malicious program cannot get some access to do something bad. And usually the update to prevent some kind of attack is later than the attack itself.
- linjian 9y agoHow to prevent an attack from internet is really a big problem. More open the system is, more dangerous the system maybe. like this attack, the macOS and Linux is safe. Maybe just because the system is not that open and malicious program cannot get some access to do something bad. And usually the update to prevent some kind of attack is later than the attack itself.
- 10165 9y agoThe real question should be: Can Microsoft write an OS that does not have to be constantly patched, month after month? We know they have written such things as part of research. But still they continue to release software that is unfinished. They have trained their users that failure to update is fatal. No doubt, if they are using Windows. They also like to conflate "update" with "upgrade". They use these security problems in Windows to scare people into upgrading. Windows 10, whether they like it or not. As others have noted, by design the new versions are not safer than the old ones. Retroactively fixing reported issues does not make a new version more secure by design. They could just as easily fix the issues in the older version. Can this company get anything right the first time? Will they ever design a system that is secure? Do they have any interest in doing so? Are they incapable? There is nothing wrong with releasing something simple, secure and finished. Does MS believe Windows users are not worthy of a secure OS? I think Microsoft Research have contributed to development of L4 systems that run on baseband. Do these systems have the same vulnerabilities as Windows? Fixing problems after they occur (past problems) is admirable but other free opens source OS written by volunteers accomplish the same thing. The question is whether the design of the system is such that future problems are avoided. Does Microsoft believe Windows users deserve more security? Can Microsoft deliver it? All indications suggest the answer to both questions is no. With no viable alternatives, no one can blame Windows users for sticking with it despite red flag after red flag, but it makes no sense to defend the Microsoft approach to security for Windows users. The company has no respect for Windows users. Being responsive to a constant stream of reported vulnerabilities is an improvement from 1995 but as we can see it is not enough. Their software is still full of mistakes. They need to prove they can make something that is secure by design and that they are willing to do so for users. (Truthfully, they probably do not need to do anything. Quotes of 80% of Windows installations being tied to purchases of hardware are probably not far off the mark. There is no selection of OS by most computer users. A majority of users still get Windows pre-installed on the computers they purchase. Microsoft could completely ignore users and it would not hurt their business, as long as they continue to maintain relationships with hardware manufacturers.)
- thr0waway1239 9y agoMost of these fit into a tweet. You could have asked Tay if it was still around :-)
- WalterBright 9y agoI'm curious what kind of vulnerability it was. A buffer overflow? Stack corruption? A memory safety issue at all, or something else?
- setq 9y agoOverflow on a cast between a 16/32 bit value I think.
- alkonaut 9y agoOne scary thing about these security holes is that it's almost impossible to check if your system is affected. There are at least 50 different releases of Windows 10 alone, and it's hard enough to find which is actually used. The "System" dialog Shows "Windows 10 2015 LTSB". "Winver" on the command line shows "Windows 10 2015 LTSB build 10240" - but there are several releases of that and only the latest ones, e.g. from 10240.17236 and up have the patch - But I can't seem to find which one I have. I don't doubt I have a patched version, but out of curiosity I'd just like to double check.
- kaoD 9y agoGo to your Windows Update History and check if you have KB4013429 installed. https://support.microsoft.com/en-us/help/4013429/windows-10-update-kb4013429 https://support.microsoft.com/en-us/help/4013429/windows-10-... EDIT: Or KB4012606 / KB4013198 for older Windows builds.
- alkonaut 9y agoHow do I know that's the one? I'm was curious about the process of knowing how to find out if my system is patched against vulnerability X.
- kaoD 9y agoHere's the complete process I followed: 1. Search for "windows smb server vuln" in Google. 2. "Microsoft Security Bulletin MS17-010 - Critical"[0] is the link I'm looking for. 3. Search for your version in the list. Mine is "Windows 10 Version 1607", listed in the table with 4013429 (right next to the Windows version, not in "Updates replaced"). That's my update number. [0] https://technet.microsoft.com/en-us/library/security/ms17-010.aspx https://technet.microsoft.com/en-us/library/security/ms17-01...
- alkonaut 9y agoI think a lot of the confusion here is what constitutes a "version" of windows 10.
- Moru 9y agoIt's not just a question of people not keeping their computers updated. I have bought a few second hand computers with windows 7 the last few months and they have all had problems when updating. I doubt most people even notice this and think they are updated.
- a_imho 9y agoSecond, this attack demonstrates the degree to which cybersecurity has become a shared responsibility between tech companies and customers. Victim blaming at its finest.
- Findeton 9y agoLesson 1: don't use Windows.
- LoonyBalloony 9y agoI think the lesson here is to disband all spy agencies when not at war with another nation state.
- deleted 9y ago[deleted]
- dandare 9y agoWhy can't Microsoft or NSA or whatever good samaritan use the same vulnerability and attack vector to force-spread the update or at least a patch of some kind?
- shanavasm 9y ago95% of ATM machines still run Windows XP [0](a little outdated though). Can't imagine what happens if the got affected sigh :( [0] http://info.rippleshot.com/blog/windows-xp-still-running-95-percent-atms-world http://info.rippleshot.com/blog/windows-xp-still-running-95-...
- cmurf 9y agoAnd what about the lesson that software should be mortal, and should one day die? By what metric is, e.g. Windows XP, subject to evergreen updating to mitigate (prevent or reduce impact of) this exact scenario, forever? Does Microsoft have the right, and even the obligation, to remote detonate all Windows XP in existence on a certain date? Perhaps EOL should be literal. The software kills itself and does not function. The lesson I'm getting is our software can become malicious, and that malice can spread like wildfire. Is a company obligated to patch any wildfire type of bug forever? Is that a cost of proprietary software? Or is setting a date for its death the cost? I think aging proprietary software has a much greater chance of becoming a weapon than it does becoming inconveniently obsolete. So forcing a company to release the code as free and open source software upon EOL date, I think just enhances the chances that it gets weaponized. There's a greater incentive to find exploits than to fix them, in old software. Another lesson is most people really shouldn't be using Windows. If you can't afford to pay Microsoft to keep your software up to date, then use something that's FOSS and is up to date. (Same rule applies to Apple, if you can't afford new hardware in order to run current iOS/macOS versions that are being maintained, then don't buy stuff from Apple anymore.)
- alsadi 9y agoFor those who think that using free software would be similar (naming ubuntu or even centos). The real question is why a hospital is still running windows xp even though it's not supported by its own vendor. The answer is vendor lock ins. The upgrade is not a matter of simple command. Upgrade cost involves more licenses and hardware upgrades (which is not needed as old hardware is fine, but this is how things work between microsoft and hw vendors) it's like you need a new buy watch to apply dst summer time. Also mirosoft and old school desktop software vendors used to make sure switch or upgrade cost is really high ex by using non stanard formats.. to lock users from switching to mac or linux If you remember active x and internet explorer specific vbscript... If you use free software from an expensive but decent vendor like redhat you can upgrade software on same hardware And if it software was expensive you can switch to centos, scientific linux or pay anyone to handle that for you are fair rate. There is no vendor lock in. Every thing is stardard and no vendor lock in.