7 ms·
Sounds like their system works. If that 486 hardware lasted 20 years already, seems like there's a pretty good chance it'll outlast most of the modern stuff it
by ColanR 6y ago
Sounds like their system works. If that 486 hardware lasted 20 years already, seems like there's a pretty good chance it'll outlast most of the modern stuff it would be replaced with.
- non-entity 6y agoI suppose its fine as long as its not connected to the internet.
- owenmarshall 6y agoDo you suspect there are any 0day/worms still targeting Windows 95 systems? I wonder if an unpatched Win95 box is actually safer than an unpatched modern Windows box.
- PopsiclePete 6y ago>Do you suspect there are any 0day/worms still targeting Windows 95 systems? You'd be surprised how much malware is "legacy" 32-bit and works without issue on WinXP. A lot of malware even shies away from Unicode API's and specifically calls out the *A Win32 API functions. Considering the Win32 API is backwards compatible to a fault, I don't see why modern malware couldn't absolutely wreck a Win9x box.
- owenmarshall 6y agoSure – once the malware lands. But I doubt anyone is going after any Win95 vulnerabilities, so how does it get on the box to start chomping?
- jasomill 6y agoLoaded from the boot sector of any floppy that happens to be present when the system is restarted, unless the boot order has been changed from factory defaults and the (possibly very old) coin cell powering NVRAM holds sufficient charge to retain these changes when (if) the system is ever powered off.
- PeterisP 6y agoIn general, attacks (e.g. most ransomware campaigns) are not automated malware spreading on its own, they involve people. If it's accessible on a network (which is the big 'if'), then it's obvious on any scan that it's a Win95 machine, and then you can try to look up a vulnerability for any exposed service. For example, if file sharing is running, then all the SMB vulnerabilities (e.g. EternalBlue and friends) apply also to Win95 systems, and I'm not sure if Windows 95 had a patch made, backported and issued for them.
- badsectoracula 6y agoYes, but Windows XP was in widespread use until recently and is still in use in a lot of places. I don't know where "netmarketshare.com" takes their user statistics (Google just used them when i searched for that) but it reports "1.26%" for Windows XP, which i think is still a large number. There are still so many users of Windows XP that Microsoft released a critical security patch last year despite XP being official EOL for years now.
- TillE 6y agoWindows XP (NT kernel) and 9x are totally different OSes, using totally different kernels. They share some API, but not really the interesting parts. I work on software that still supports XP with only a little pain. Visual Studio 2019 will still install the necessary toolchain if you ask nicely. Targeting Windows 95/98 in 2020 sounds like a nightmare.
- Snitch-Thursday 6y ago> Visual Studio 2019 will still install the necessary toolchain if you ask nicely Could I get a link to how to do this and/or web search terms? Is this just something targeting visual C runtime 20xx or older?
- anthk 6y agoEh, no. Not by a chance. I have some old as heck games which don't even work even under W2k with w9x compat mode (it's hidden, you need a command to enable it), so a total nope under XP.
- goalieca 6y agoThat floppy disk controller is the only way into the box and isn't nearly as vulnerable as a modern usb controller since there's no smarts!! The windows 95 system is going to be safer than a patched windows 10 on the network for their use case.
- vlovich123 6y agoFor the common-case en masse compromises, not a concern. For targeted attacks it can still be an issue. Stuxnet is an example of this where they compromised an air-gapped system. Stuxnet was obviously extremely sophisticated, technically and for the overall operation, but the principles still apply. Also people frequently misjudge how big of a target they may be & what their risk profile really is (not saying for this use-case specifically, just in general).
- projektfu 6y agoWin95 is running as root by default. Any process can open another's memory. It has the same registry entry as Windows NT for running a program on startup. The keylogging API is basically the same. The IShellFolder and IWebBrowser interfaces are identical, so as long as the malware didn't request specific classes or features that are outside the realm of Windows 95, it can probably do pretty well. Luckily, Internet Explorer 3 doesn't support TLS.
- anthk 6y agoExcept for the Ex functions. I wonder if a malware can be run under KernelEx.
- ajford 6y agoIIRC, the machine was on an isolated equipment network with no external access for some time, but the network drivers would often cause some kind of conflict with the ISA interface card (and custom driver) so the network interface was disabled. So yeah, should be safe (and is likely no longer hardwired to the network).
- fetbaffe 6y agoRisk is hardware related, finding replacement parts. But yes, the software part seem to work fine.
- ajford 6y agoIt works yes, but they were running out of spare parts when I left. That system's parts were on frequent Ebay searches, as it was becoming quite fragile. I think it was on a 3rd power supply and a second mobo or proc, can't quite remember. It was on a redundant on-line UPS as the last time it went completely off and was booted from cold, it ended up needing parts. So no, I'd say it's not likely to outlast modern replacements. Just had lots of support and organ transplants. Systems like that ultimately end up being a resource drain, as unlike modern hardware it's not simply wandering over to a retailer and buying standard replacement parts, but sourcing used or NOS parts and hoping they work, often requiring far more time and effort by someone who could be doing some other important task. The problem is that in open use observatories like Arecibo, a lot of equipment like that is put in place by third parties, but becomes our responsibility to maintain. But the science is important, so we maintain it as best we can.
- drbojingle 6y agoEventually, yes, it becomes a resource drain. If you want to know when, ask the finance people.
- outworlder 6y ago> If that 486 hardware lasted 20 years already, seems like there's a pretty good chance it'll outlast most of the modern stuff it would be replaced with. Unlikely. Good quality 'modern stuff' has far better quality than what was available back then. Power supplies have gotten much better (and have more protections), as did motherboards with solid state capacitors. Older motherboards loved their electrolytic capacitors. Processors had less protections. Thermal monitoring was at its infancy. Memory sticks back then were very unreliable. As were hard drives. Then there's just a matter of age. If it has lasted 20 years, chances are it won't last much longer. It has probably lasted 20 years because it wasn't being powered on and off constantly. It most likely had stable power sources and - most important - a climate controlled environment with low amounts of dust.
- phendrenad2 6y agoTrue, but people have backported modern hardware to that era. You can take a modern power supply and drop it into that PC, I'm almost sure.
- toast0 6y agoA 486 system was built before the capacitor plague. Quality electrolytics may not last forever, but can last a long time. Also, built before RoHS and the reduced longevity of poorly formulated or poorly applied lead-free solders that were common for many years. Processors had less protections, and thermal monitoring was at its infancy because almost all the 486s wouldn't use enough power to cook themselves to death, even with passive heatsinks. I don't know about memory sticks and hard drives from that period. It's quite possible they've replaced the hard drive with compact flash or something too, which should be pretty reliable given they apparently only make a floppy disk's worth of data every day.
- brundolf 6y agoI'd love to hear more about what "the capacitor plague" is
- devenblake 6y ago
- liability 6y agoAfter 20 years, might they be in territory beyond the far side of the 'bathtub curve'?
- tartoran 6y ago> Sounds like their system works. If that 486 hardware lasted 20 years already, seems like there's a pretty good chance it'll outlast most of the modern stuff it would be replaced with. Surely it does make some sense, but think about the hardware suddenly breaking down and not finding what to replace it with. Even with spare parts it could be a pain as the old generation retires
- LargoLasskhyfv 6y agoJust get an industrial board which provides ISA-slots and has something like http://www.vortex86.com/ http://www.vortex86.com/ on it.
- non-entity 6y agoI actually was surprised to see these are made, as I considered getting one for a few projects. The ones I saw were pretty expensive with some being resold on ebay for just under a thousand dollars. Reading some reviews though it seems yoy have to be careful as not all the boards may support what you want. Apparently a good many don't support DMA.
- LargoLasskhyfv 6y agoI thought about this, but let it stand. It can be tricky. I had to work with something like this a few years ago and managed. As I remember I had to get Scitech Display Doctor/Univbe from some abandonware sites to make use of the weird onboard VGA under Windown95. The ISA-card for the CNC-machine worked, it used DMA, among other things. It all worked, and was even more fluid to operate/program. The cost was just over 400EUR. (for the board) Anyways, it's industrial, the formfactor often does not fit existing cases and backpanels, but it's doable. More so than hunting ebay or similar for spares of dubious provenance. Only exception would be if the "App" and the board/card were designed so sloppily that they really only run on exactly that same hardware.
- unixhero 6y agoThis is due to the rule of antifragility. https://en.wikipedia.org/wiki/Antifragility https://en.wikipedia.org/wiki/Antifragility
- Jtsummers 6y agoI worked in an office with a similar setup that "worked", but it was very fragile. When the HDD started failing on the old 486 machine we scrambled to migrate as much as possible (including a few rewrites and ports of utility programs). We were lucky that our problem was the software not running on modern systems (for reasons), not a dependency on the hardware. Mostly we communicated with hardware systems via serial, so any computer with a serial port (or a USB-to-serial adapter, which are often unreliable) could be made to work if the software existed.
- boogies 6y agoThere’s a word for this concept, the ‘Lindy’ effect. https://en.wikipedia.org/wiki/Lindy_effect https://en.wikipedia.org/wiki/Lindy_effect https://www.urbandictionary.com/define.php?term=Lindy https://www.urbandictionary.com/define.php?term=Lindy
- DanBC 6y agoHow are they doing backups of the software and data?
- ajford 6y agoThe entire disk (all 10s of GBs of it) was cloned and backed up as a disk image, and can be re-imaged whenever necessary. The data is copied off daily via floppy (don't get me started...) and is backed up on local network shares. The specifics of that weren't in my need-to-know and was managed by the IT group. The system was essentially stateless, so spinning it up from the image wasn't an issue, but the PC itself is essentially part of the "equipment", as it ran the custom drivers and it was specifically designed for that PC and a one-of-a-kind ISA card.
- giancarlostoro 6y agoI wonder if it's even just as easy to just run some of that on VirtualBox / some hypervisor running Windows 95, that way they have access to modern replacement hardware.
- tinus_hn 6y agoBut there’s also a fair chance something will break and you can’t buy spare parts for museum pieces like this.