5 ms·
Effectively this is done as a POC, don't expect any security on a machine running Windows 2000 nowadays. Regarding legality, I hope that Microsoft doesn't clai
by hectorm 5y ago
Effectively this is done as a POC, don't expect any security on a machine running Windows 2000 nowadays.
Regarding legality, I hope that Microsoft doesn't claim any rights, since the Windows 2000 image has been published in WinWorld for years without issues.
- grepfru_it 5y agoCareful with your claims. What is the supply chain of that win2k iso? You could be compromised before you even begin. Just because it is past EOL doesn’t mean you chuck all security best practices out the window. “Oh well it’s end of life, might as well store passwords in plaintext” Microsoft still owns copyright on Win2k, so you could be met with a cease and desist or you could be liable for infringement.
- xxpor 5y agoIf you connect windows 2000 to the internet, you're probably owned within a few minutes regardless. Similarly for xp pre-sp2.
- rustymatter 5y agoWhat? Can you elaborate? If I spin this up in a container, even though it has access to the internet, how am I owned within a few minutes, given that my firewall is in place and I don't expose any port of this container to the internet?
- hulitu 5y agoSoftware evolves. This means that new software needs new libraries. Will be interesting if someone tries new exploits on old software.
- genezeta 5y agoI'd guess that the "don't expect any security" comment above meant exactly that. Not that you should forgo security, but that you should expect this to provide no security at all. Some other comments mention browsing with IE5. You should expect that to provide no security either.
- hectorm 5y agoThe ISO is downloaded from WinWorld, which is a website dedicated to archiving old software, it's certainly community maintained but at least gets some scrutiny. I also searched the checksum and it matches with other sources, but as there is no longer an official Microsoft source you can never be entirely sure. I've done my best to confirm the legitimacy but if anyone has an original CD it would be awesome if they could confirm it.
- grepfru_it 5y agoMy suggestion is to not embed third party urls for infringing software.. that makes you a target. Inside leave that variable empty and make suggestions on where one could find the media whether it’s the original or from questionable third party websites. This is how popular emulators survived the 90s, they emulate the bios but force you to find the firmware yourself. Even if it means downloading from an unknown source without a supply chain and running unknown code on your computer. The emulator and author are in the clear