3 ms·
At this point, it's probably safe to assume that every feature in Windows that hasn't been touched for the last decade has severe security problems. And it's no
by codeflo 8y ago
At this point, it's probably safe to assume that every feature in Windows that hasn't been touched for the last decade has severe security problems. And it's not only Microsoft -- maybe their approach to backwards compatibility makes them especially vulnerable, but similar things have happened in the free software ecosystem as well. It's basically a very insidious form of bitrot.
So what's the lesson here? Aggressively remove old features, as you suggest? Rewrite everything every few years? Software has become way too complex to closely audit everything forever...
- giancarlostoro 8y ago> but similar things have happened in the free software ecosystem as well. Shellshock comes to mind. https://en.wikipedia.org/wiki/Shellshock_(software_bug) https://en.wikipedia.org/wiki/Shellshock_(software_bug)
- pjmlp 8y agoSecurity only works properly when applied to all layers. It is very educative to read about security models on Multitics, ClearPath, System 360/370, OS/400 among many other similar systems, their attack vectors, and what we ended up getting by having winner takes it all with UNIX based systems. This year we celebrated 30 years of Morris worm.
- watersb 8y ago> This year we celebrated 30 years of Morris worm. Wow. That was one hell of a night. Melted down our university computer labs, packed with desperate undergrads trying to complete and turn in their projects before midnight deadline...
- fujimotos 8y ago> Melted down our university computer labs How did admins manage to disinfect servers? It should have been a hell of fun for them, provided it was the first pandemic ever.
- watersb 8y agohttps://news.ycombinator.com/item?id=5302924 https://news.ycombinator.com/item?id=5302924 Hard reboot with email server disabled.