4 ms·
> "Operating system" is a pretty broad description That's the problem, and the concern. I've given several concrete examples (both of actual exploitable surfa
by jdiff 3y ago
> "Operating system" is a pretty broad description
That's the problem, and the concern.
I've given several concrete examples (both of actual exploitable surface area and more abstract kinds of exploitable surface areas) in this thread already, feel free to refer back to them.
A lot of what you're complaining about as handwavy is just common knowledge. Ask questions if you're interested, but out-of-date OSes are factually insecure in known-unfixable and unknown-unfixable ways.
- Wowfunhappy 3y agoWith all possible respect, I don't think you have given concrete examples. You have given general examples, and hnlmorg and I have explained why we don't think there are concrete problems to be found there. The exception is font rendering. I haven't used Supermium specifically and I don't know enough about how it works, but if Supermium is passing remote web fonts directly to the OS for rendering, that needs to stop immediately, and until it does all Supermium users should disable webfonts! As an aside, if there is in fact something like an exploitable buffer overflow in Windows XP's TCP/IP stack, that is something enthusiasts could probably patch.
- hnlmorg 3y ago> That's the problem, and the concern. But the point you keep missing is that browser do not interface with the entirety of the OS. Just because code exists, it doesn't mean the browser calls that code. For example notepad.exe was used as a UAC bypass in early versions of Vista. But there isn't any way a website running in Supermium can elevate itself to run as Administrator, let alone use notepad.exe to bypass the UAC, without exploiting a serious zero-day in Chromium. And if attackers have a zero-day that serious in Chromium, then they're not going to burn it on infecting the 10 people who run Supermium. > I've given several concrete examples (both of actual exploitable surface area and more abstract kinds of exploitable surface areas) in this thread already, feel free to refer back to them. You've given one and even that was impossibly vague. > A lot of what you're complaining about as handwavy is just common knowledge. Nobody is disputing that you should keep your OS fully patched. But what's being said here is that the age of the system ironically actually works in its benefit: it's now a small enough market share that it isn't worth burning a Chromium zero day on. That all said, advise of not running XP / Vista for work is wise. And not connecting them to untrusted networks is wise too. Nobody is disputing that either. What is being said is that having an XP / Vista machine at home (likely for retro gaming or other niche use case) isn't automatically catastrophic. Things don't have to be boolean :) > Ask questions if you're interested, but out-of-date OSes are factually insecure in known-unfixable and unknown-unfixable ways. I have quite a lot of experience hacking Windows and even wrote my own hobby browser a while back. I'm pretty well versed on the topic. The one question I asked is examples of how you would exploit "the OS" from the browser. So maybe it's better we agree to disagree