5 ms·
Manchester, UK, police still relies on Windows XP
- francis-io 9y ago> The remaining XP machines are still in place due to complex technical requirements from a small number of externally provided highly specialised applications," a spokeswoman told the BBC. This is the real heart of the issue. In my (very limited) experience, software choices are made by different people than the ones that deal with them each day. My hope is that more and more applications will become web based, and big enterprises can move to a cut down linux desktop with a limited attack surface, so internal IT teams can focus more on securing servers.
- rlpb 9y agoAt a higher level, I think the problem is poor requirements specifications when the externally sourced applications were first procured. If the procurers had accurately predicted the lifetime requirement, they could have required the stack to be fully security supported for that length of time, making it the vendor's problem to update to a newer OS that has security updates. Instead, they pushed the cost back while keeping the risk themselves. Perhaps back then this wasn't so obvious. I hope it is now, and procurement teams actually do incorporate this into their requirements now.
- grecy 9y ago> If the procurers had accurately predicted the lifetime requirement, they could have required the stack to be fully security supported for that length of time, making it the vendor's problem to update to a newer OS that has security updates. Oh sure, but there are a million other reasons too. Maybe the vendor went out of business, but company is still using whatever application for edge cases. Maybe the vendor now has Version 2.0 of application that does support newer OSs, but it requires hundreds of millions in hardware upgrades. Maybe it simply takes years and tens of millions to test every application and piece of hardware used by the company to see how they handle new OS. (I worked for a large company that just recently upgraded from XP to Win 7, and the project was years and tens of millions over budget)
- stupidcar 9y agoIt's 2017, not 1997. None of these issues should be any surprise to a large organisation's IT department. It's professional negligence to allow the situation to devolve to the point that such huge, expensive projects are required to upgrade everything, or the business is relying on a single outside software vendor for an important function. IT departments should have complete visibility of all their hardware and software assets. They should have rolling programmes of upgrades for both hardware and software, and they should understand exactly how long these will take, so that they do not overrun an OS end-of-life. They should have contingency plans for deprecating or replacing software if a vendor goes out of business. Failure to do the above is equivalent to a facilities department not doing essential maintenance, or forgoing safety checks, or a compliance department ignoring legal requirements. That fact that something costs money, or involves IT, does not magically excuse incompetence, shortsightedness or ignorance.
- walshemj 9y agoThe uk police have faced massive cuts year on year so probably don't have the budget and have lost a lot of in house knowledge
- Nexxxeh 9y agoAbsolutely this. Our Prime Minister (by default), Theresa May, used to be our home secretary. She seems technically illiterate. Unfortunately the base she appeals to is also relatively... Ignorant... Of tech issues and of the real world. If it won't play well in The Daily Mail, it's not a priority. According to people in the know, there aren't enough police in the community, and there aren't enough armed police, and there's not enough money going into the police force. This has all been brought into sharp focus by the recent terror attacks. Her actions read like a bad conspiracy theory.
- dx034 9y agoEven if you have a tech literate home secretary that won't help you much. Telling the public that police presence has to be reduced because the police needs to upgrade to Windows 10/Linux can cost you the next election. Especially in times when people are very concerned about the security situation.
- vetinari 9y agoOften, the application is supported, however the procuring organization has meanwhile opted out of maintenance in order to cut costs, which takes the updated releases out of reach. Another scenario is, that the organization pays maintenance, new release supporting new OS is available, but upgrading both involves costs (in updating, migrating, documenting, testing), that the organization is not willing to take and just carries on with the old releases.
- jlebrech 9y agothey should install some VMS for those specialised applications, this would also have the additional benefit of snapshotting.
- rbanffy 9y agoIt's not always possible with specialized hardware whose drivers are not even properly documented. Of course, mandating blob-free open-source for all government purchases would have solved this mess right at the start. The only reason it's not mandated now is that some vendors would be excluded for being unable or unwilling to comply.
- dx034 9y agoThe problem is that you'd want to have desktop apps for some parts and you'd then probably end up with some Electron app which looks nice but is slower than a 20yr old programme with the same function. Esp where hardware needs to be integrated (e.g. taking fingerprints), I imagine it's not easy to create platform independent applications.
- hoodoof 9y agoFor hecks sake just put the foot down and cancel the money going to the tardy vendors. Cutting off the money supply magically fixes software issues fdast.
- osullivj 9y agoLast year I contracted for a mortgage origination system vendor supplying Virgin Money aka Northern Rock. The client preferred to run a heavily customised Windows C++ 90s version of the system, with XP desktops. All attempts to persuade them to move two generations forward to a browser GUI .Net back end were resisted. Migrating forward two generations would have been a huge project. The status quo was a heavily customised, almost bespoke, system that was booking huge volumes of business.
- tixocloud 9y agoI totally hear you. Any transformation to push forward new technology in financial services requires multiyear projects and thousands if not millions of dependency checks, testing and upgrades that may or may not bring in the additional revenue that would make the effort worthwhile. Factor in the fact that systems knowledge might also be scarce and you can see why no one wants to go through the pain.
- stupidcar 9y ago> The UK's biggest force - London's Metropolitan Police Service - was among those that refused to share an up-to-date figure. > But in June it said about 10,000 of its desktop computers were still running XP. > "Disclosing further information would reveal potential weaknesses and vulnerability," the force's information manager, Paul Mayger, said. So they're concerned enough about security not to disclose the number of XP machines, but not so concerned as to actually fix the problem.
- dx034 9y agoPublic services in the UK have faced severe budget cuts in recent years. Spending money for new software could very well have meant to have less police on the street. That's not an excuse to use unsafe systems but it can be an explanation. Public services don't work like companies, especially if they're forced to reduce their budget by 30% over a few years without neglecting their duty.
- guitarbill 9y agoOn the other hand, public services don't have a great track record for effectively spending IT budgets, and the managers who oversee all this barely have any accountability. So it's not too different from companies.
- dx034 9y agoI'd argue all large organisations have a bad track record for IT budgets. It's shocking to see the amounts large companies spend on outdated and ineffective IT systems, just because the vendor is large or the consultant likes it.
- dTal 9y ago"We can't tell you because it would reflect badly on us." You hear this sort of thing a lot from secretive bureaucracies.
- xvilka 9y agoThey should try ReactOS.
- squarefoot 9y agoThey could be using the POS version which IIRC will get regular updates until 2019. Probably illegal, unless they have some special license, but surely not a bad thing given the huge boost in performance compared to newer OSes and the shrinking number of compatible malware around.
- petepete 9y agoYes, my hometown is on the front page on HN! Oh, damn.
- Nexxxeh 9y agoMine is front page of BBC News this morning. Seems like it's never good news at the moment.
- peterburkimsher 9y agoI work for a tech company in Taiwan. The factory downstairs is making microSD cards. I write some driver software to talk to the machines, sending commands using SECS-II and getting the machines to log data to a SQL server. The testing machines still run Windows 2000. There is no SQL library for Visual C++ 5. I couldn't use the .NET framework, or any other libraries - everything running on the testing machine had to be bundled into a single .exe file. Why not update? The testing machine was built by another company, and sold with a 20-year warranty. Updating Windows, or even installing software would void the warranty. My program was designed to be easily deleted in case of an audit. These machines were on their own LAN with no Internet access, thankfully. I've realised that for my software to endure, I should write it standalone, without needing libraries, and in a very common language that is likely to still be around for a while (C, JavaScript, Bash). The code is more verbose, but that puts the burden on the developer (me) instead of the user, who is more likely to make really dodgy workarounds than file a bug report.
- Dayshine 9y ago>My program was designed to be easily deleted in case of an audit. Errr what?
- Phil987 9y agoHe's running his program on the testing machine, which would void the warranty.
- Unknoob 9y agoI'd guess a simple .exe file that doesn't create additional files or registry entries. Since installing additional softwares would void the warranty, they can simple delete a single .exe to get the computer back to it's factory state.
- kennydude 9y agoLast I heard Northumbria Police still use COBOL...
- sjmulder 9y agoCOBOL is old and increasingly rare but not necessarily unsupported. That makes it a different kind of issue.
- dx034 9y agoOnce you're language is old enough you're probably much safer. Finding a hacker who understands how to find weaknesses in a system from the 70s will be harder than someone who knows how to exploit Win XP.
- jaclaz 9y agoFrom the article: "So, if the [police's] Windows XP computers are exposed to the public internet, then that would be a serious concern. "If they are isolated, that would be less of a worry - but the problem is still that if something gets into a secure network, it might then spread. That is what happened in the NHS with the recent Wannacry outbreak." Only problem being that KryptosLogic tests confirmed that WannCry did not infect "properly"[1] Windows XP machines on the network (while if the malware is executed locally XP is vulnerable): https://blog.kryptoslogic.com/malware/2017/05/29/two-weeks-later.html https://blog.kryptoslogic.com/malware/2017/05/29/two-weeks-l... [1] if SP3 the infected machine would blue screen without encrypting anything and without having the possibility to spread the malware to other machines, if SP2 (improbable) the machine would not be infected.