4 ms·
You are focused too much on Microsoft and the individual user. The concepts are applicable to any device from any manufacture. The book I linked is about the ev
by 0xcoffee 4y ago
You are focused too much on Microsoft and the individual user. The concepts are applicable to any device from any manufacture. The book I linked is about the evolution and history of network spread malware such as bots. It discusses about how security was always an afterthought during the start of the millennium, and how at a certain point basically every device was running some malware. Then collectively the industry and the government finally started to understand the nature of the beast and introduced security hardening best practices.
This is continuing today, and the increased knowledge sharing has industries working together to fight the problem. Even the US government has learned from e.g. google and started to move to 0-trust network architecture: https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/ https://www.whitehouse.gov/briefing-room/presidential-action...
Automatic updates are one of the biggest enablers of stopping automatic spreading of malware. The Mirai botnet for example had a large capacity knocked out thanks to Deutsche Telekom responding and force updating their network devices which were vulnerable attack vectors. Unfortunately there are a lot of devices out there which are out of support or have no updates available (i.e. internet of shit), which remain a constant problem.
Automatic updates are the industry standard, because the days an patched or unpatched device is a threat to the internet is 0. This doesn't mean patching is futile. It still greatly reduces the available attack surface, and also helps protect other devices.
You should also be aware the when 0-day gets patched, they often happen silently. e.g. Linux will obfuscate it's commit message, because if they say 'e.g. fix really bad 0 day', then immediately that 0-day becomes public knowledge and will be exploited even more before the patch is live and propagated to the systems. Same in release notes, so people don't diff the binary to discover what the attack vector was. Just because it's not loudly announced, doesn't make it not real.
So please do your minimum part to practice network hygienic if you want to participate. It is not a 'dilemma', it is polite behavior for a greater goal.
- exodust 4y agoPlease stop selling me Microsoft automatic updates. I'm not buying. Doesn't mean I never update. It means I control the updates on my terms, not on those of commercially motivated, privacy-invading faceless tech giants with agendas far beyond the scope of network hygiene. I use a cheap smartphone. It works fine but gets no more updates. According to your position in this debate, I should abandon that unhygienic phone, and pay the protection money for a fresh plastic box of rare earth metals, for the greater good. I'm not sure why you're invested in replying to me about this topic. Most general PC users already have automatic updates on. You should be ecstatic about that. Behavior modification and reinforcement tactics used by software vendors to get people to do things, is real. Overstating the threat of security risks if people fail to update in a given time frame, is one of the tactics used to get people to install, upgrade, buy, renew, etc. I apply updates on some things without much delay, such as specific software I trust/respect. Other times I will never update, such as my e-bike where I modified the firmware for certain reasons which are my business. There are valid reasons why people delay or decline updates. It's disappointing you believe embracing automatic updates is tied to ethical use of the internet. The implication of that idea, is that update-urgency is never exploited by those pushing the updates. We're even seeing "updates for the sake of updates" coming through, as Apple will reportedly delist apps that haven't seen an update in awhile. Okay I'm done on this topic! Updates! Ugh... I turn them off and edit group policies etc to put a stop to the blatant turf-war on who gets to run the show in my house.
- josephcsible 4y ago> I use a cheap smartphone. It works fine but gets no more updates. According to your position in this debate, I should abandon that unhygienic phone, and pay the protection money for a fresh plastic box of rare earth metals, for the greater good. It's definitely not right that you have to do that, but the fact is that today, being secure means you do have to. In the ideal world, manufacturers would have to either provide security fixes for way longer, or open up their devices to the point that other people can do it for them. > It's disappointing you believe embracing automatic updates is tied to ethical use of the internet. The implication of that idea, is that update-urgency is never exploited by those pushing the updates. Do you consider it ethical for your computer to knowingly be part of a botnet? And of course Microsoft abuses automatic updates, but the solution to that isn't getting rid of automatic updates; it's getting rid of Microsoft (e.g., switching to Linux or something).