Not a problem
The CCTV thingy running XP is not a problem - provided it is on a separate network and cannot be reached from the outside. And why should it have connections to the outside world?
PWNED Welcome, once again, to PWNED, the weekly column where we show you how not to use your computer or your network. In this week’s fable of fecklessness, we talk about a teacher who had a lot to learn about security. Have a story about someone leaving a gaping hole in their network? Share it with us at pwned@sitpub.com. …
Where I work, we have a few machines that require specialist control software that requires Windows XP. (and some that require 7). These machines would need to be replaced or have major upgrades to work with newer versions of the software. In either case, the cost would start in the high five figure range, venturing into the six figure range if the machine does need replacing.
So, we opted to remove them from the network, blocklist their MAC addresses on the the network, and restrict physical access. Not saying a hacker won't get them on the network, but it'd be bloody difficult..
Oh, I have run ins with them before.. I am actually a fan of Linux, but there have been a few times on here where I've asked a question about something (for example, remote fleet management for Linux similar to System Center), and the only answers I've got have been given were downvotes and responses of "Google it"..
I'd like to see more Linux use where I work, but I've been told, to put it bluntly, that the problem with Linux (and all Open source software) is we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue. Microsoft can afford better lawyers than we can, so any legal action is likely to fail, but with Windows, at least we do have a entity we can sue.
I'd still like to see more use of Open Source..
... we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue.
Yes?
So you would sue ...
Microsoft?
Good luck filing a lawsuit against M$ for using XP on your hardware.
The terms unsupported and EOL right before software and hardware respectively would be seen in the heading to their reply.
And it would most probably be a boiler-plate one at that.
.
"I'd like to see more Linux use where I work, but I've been told, to put it bluntly, that the problem with Linux (and all Open source software) is we didn't purchase it, so have no rights if it fails to work as advertised, and we also have no one we can sue."
Read the small print of any commercial software licence. It'll pretty much say "We make no claims and offer no warranties whatsoever about the functionality of our software. You agree we have no responsibility for anything. Have a nice day." Of course you'd still be welcome to sue M$ or Oracle or Palantir or.... but that'll crash and burn - much like their software - before the case gets near a court.
Even the airline inflight entertainment apps, to download inflight media to your personal device,
.. expect you to assume all responsibility for any consequence from the software and data they are pushing onto your device.
and young people think WE are tech illiterate...
Why? If it's specialist S/W tied to a specific Windows version then that's what it needs to be. The same would apply if it were an S-100 ox running CP/M, a Linux box running a kernel in the 4 range or even a MicroVAX running VMS. Just treat it as the dedicated appliance it is, but isolate it. The real problem comes when the H/W dies, of course.
Depends how modern you want to go. I got XP SP3 running happily on a 1st gen Intel NUC (dual core Celeron 847), I think the build date on the underside is 2013 or so.
Driver support exists but is a bit limited, with only one HDMI port out of the two willing to function, however there is XP driver support for the iGPU and it will run a 1920 x 1200 display happily.
As weak as the CPU in that NUC is, It's entertainingly whizzy running XP. I should see about spinning up some late 90s / early 2000s games on it and seeing how it gets on.
I've tinkered around with a few "newer" systems but the driver support for XP falls off a cliff as you approach any hardware around intel core 4th gen.
Our CCTV system is accessible from Windows 11, but only in Edge running in Internet Explorer mode because it uses an ActiveX plugin to display the video streams.
We have to reset it to Internet Explorer mode every 90 days because Edge won't allow it to stay on the IE Mode site list longer than that (the default is 30 days but that can be extended to a maximum of 90 days with a registry hack).
why should it have connections to the outside world?
Because inevitably there will be someone or someones who want to be able to remotely access the videos. Say an alarm is triggered at the school on a weekend, unless that is routed straight to the police (which has its own risks, especially in the US) someone like a school security officer, custodian, or assistant principal will want to take a look to know if it is a real issue like intruders or if it an employee like a teacher or coach who accidentally set it off.
A CCTV system without a connection to the outside world 1) cannot be backed up or accessed via cloud which means 2) intruders can take/destroy the CCTV computer or its storage device to erase all evidence of their breakin.
I saw a MSDOS machine running a program to control which doors each access card could open in about 2005. No actual access to the Internet but I was assured that the Lemmings Christmas Edition program on it couldn't actually be there; floppy disks aren't a major access flaw once they're no longer easy to get I guess.
There are plenty of previous comments about the default passwords on VMS.
It's strange that "UETP" doesn't show up on The Register's search.
It's not always that much better in business.
We had a sister company that had IT oversight for us who kept a handwritten list of all their user's passwords in their office where almost anyone could have found it - when they did "demand" my password to do something I made a point of changing it before and after. They really should have known better and were always bleating on about "Sarbanes Oxley doesn't allow..." whilst ignoring basic principles themselves.
Hopefully people have got past using such obvious things but one colleague was always talking about her horse, Oliver, guess what her password was? Everyone on the office knew that until she was persuaded to change it to something more secure.
When I joined the current employers the servers were in a locked cupboard. The clearly labelled key to the cupboard was hanging in an open keysafe in the lab office which wasn't permanently manned or locked. I fixed that when we moved - I inherited a reinforced room with a Chubb safe door (formally used as a property deeds store), there were two keys, one in my possession and one in a hidden key safe that only a couple of very senior people had the number for.
"one in a hidden key safe that only a couple of very senior people had the number for."
Sitting in the Crown Room at Crumlin Rd courthouse, waiting for the trial I was involved with to start. One of the police witnesses - photographer, mapper or whatever was also sitting there. There was a key safe lying about so to pass the time he picked it up and started trying the combination lock. After a few minutes he had it open.
Why? From the data we have, we don't know that the laptop was offline, just that you had to have it involved. One tactic I've seen used for things that only can be accessed from a old machine is to install some remote access software on said old machine so you don't have to go physically to it, like these guys did. They're not getting the best of praise in the comments over there.
Even if they hadn't done that, we still don't know if it was offline, and it frequently wouldn't be if, for example, they had to email results off it to someone else. Even if we assume it's offline, that does fix much of the security problem, after all it is unlikely someone's going to try a Stuxnet approach on a school system, but it likely still has problems of dependence on something that's more likely to break. The fact that you couldn't use another machine suggests backups either didn't exist or wouldn't work when restored to something else without doing the work that would have liberated them from reliance on that laptop. I think it sounds secure to you because you're being charitable with your assumptions.
... in places you (might) least expect it.
Part of pen testing is proving to the C*s that human stupidity knows no bounds, and that they are not immune ... I once found a comprehensive list of machine names and login/password pairs written in sharpie on the underside of the leaves of a faux ficus in the office of the secretary of a VP. They included complete access to the corporate mainframes various LPARs (including HR and R&D). Quite a few people got reamed, and I'm absolutely certain that Amdahl's internal security culture was much better by the time Fujitsu bought them ...
I wouldn't be so sure.
You can also imagine Fujitsu's culture being contaminated and degraded by Amdahl's.
I must admit writing credentials on the underside of the foliage of office potted plants is a new one for me. Pen. testers must devious minds; necessarily so I suppose.
The name or brand of the monitor, computer, keyboard or something in the office was pretty much first cab of the rank in earlier times. Given our *ix hosts all used a single NIS (yellow pages) service anyone could ypcat the passwd map and run it through John the Ripper. I ran it preemptively (once) - pretty horrible.
This post has been deleted by its author
As head teacher he might have chosen Blackbeard as his password (aka Captain Teach.)
I suspect the lack of critical thinking symptomatic of le malaise américain is augmented by an imaginatory deficit.
I have just noticed the American malady in francophone media "Paroles de scouts : Le malaise américain" — a different sort of buggery altogether.
I, being of devious mind and paranoid disposition, might have had such a password sticker on the underside of my keyboard. It would of course mainly be used to trace the times of any unathorized login attempts, not actually do anything.
Well, there is allways honeypots...
While Mr Walker's advice, essentially KISS, is evergreen advice it unfortunately doesn't combat the most persistent and stubborn of reasoning for why so many good ideas are never implemented. Things cost money, either directly in terms of licenses and/or hardware or indirectly in time needed to set them up. Usually some mix of both.
At our company we can't even get sign-off on provisioning accounts for a password manager, despite departments like Logistics needing one for each of the couriers we use and then Customer Services needing a metric shedload of passwords for various systems and webshops. Depending on what PWMan we went with, we'd could be looking at costs anywhere from £15 - £40 per seat per month. In this day and age, unfortunately that should just be the cost of doing business. I'm not going to pretend our Customer Service people are paragons of Cyber Security, but at the very least we should be using tools that would allow us to force their hands when it came to password security.
Keepass isn't multiuser though.
Only one person can be accessing the kdbx file at time. Which is fine if the team is 2 or 3 people but once it gets into the +5 then one of them is going to open Keepass to grab a PW and then forget to close it and go to lunch. Leaving the DB locked for the next poor soul who just gets a message "Retail password.kdbx is locked by another user" and has to wait until the luncheoner has returned.
We used Keepass at our org for years, but eventually we had to go with a multi-user solution.
Keepass is excellent though if it fits your use case.
"We used Keepass at our org for years, but eventually we had to go with a multi-user solution.
Keepass is excellent though if it fits your use case.”
Which is a very good point - yes FOSS solutions do exist, but not always geared for multiuser access, aimed at a single user, ‘can’ be made to work in a multiuser environment, but only if everyone behaves properly - which they won’t.
I'm torn between coming up with free ways to get around a situation like this and complete disdain for any organisation that can have a team of more than a couple of IT spods and not spend a few quid a month on a password solution.
TBH, if none of those spods can make a business case for it that management finds acceptable, my disdain lies with them. But... when Keepass becomes unwieldy, couldn't they have a Firefox or Chrome account that they all sign into and store passwords there? If that won't work and none of them have the chops to write something that does, I'm starting to think they're a significant part of the problem.
'Leaving the DB locked for the next poor soul who just gets a message "Retail password.kdbx is locked by another user"'
Keepass is a many-headed beast these days. I use KeePassX. If it accidentally gets closed without saving it asks if I want to open it read-only which would fit your use case.
Also I use NextCloud to sync it between devices. I'm not sure what would happen if it synced in locked condition but I haven't seen an issue with it.
Re "“A headteacher’s laptop is not just a laptop; it's an entry point to the most sensitive information a school holds,” Walker told us. If a cybercriminal got access, they could effectively break into the school without ever setting foot in the building. "
This is something people forget..
Whie a senior management user may assume that hackers would have little interest in their day to day responsbilities (and, tbf, hackers probably do have little interest in the day to day responsibilites of the manager), they forget that they often have a lot of rights to access a lot of company systems. Even assuming that company has compartmentalized it's security, that compartmentalization often doesn't apply to management. Sometimes because they need access to everything, and sometimes because they shouted when they found they didn't have access to something they didn't really need access to.
Precisely.
In fact, I think in this story, as journalists put it, they've buried the lede in the last graf, to wit, “Make the safe thing the easy thing,” Walker said. “Give staff password managers. Use multi-factor authentication. Review accounts properly. Test backups. Remove shared admin logins. Keep systems updated. . . ."
As I said in the comments in another of this series, "Getting work done interprets security as damage and works around it."
I remember working on a multi-campus project with a couple of other universities that as part of what it was fashionable at the time to call a collaboratory, implemented among other things a shared file system across campuses.
Security was so unimaginably onerous that it literally took an all day seminar to learn all the ins and outs of credentials and authentication and keys to just use the blasted thing. And when I say literally, i mean literally, as in an entire wasted day.
As an applications programmer who just needed to work with it, I found myself completely bewildered, and I had a few decades of experience working in the business. Most of the actual scientists who just wanted to share and access data were left glassy-eyed in confusion.
And these were not stupid people (okay, with one possible, nay, definite, exception, me), they had advanced degrees in subjects that make my head hurt and a facility with mathematics that just leaves me gasping like a guppy out of water.
The safe thing was not the easy thing and I suspect that's one major reason why the project slowly slipped into obscurity and disuse.
"There was also a machine with a “Do Not Turn Off” note posted to it sitting in a corner that everyone was afraid to touch.”
Ah yes the 'mystery machine’ - not uncommon, I tend to slightly pull the network cable out and wait a few days/weeks and see who screams! If challenged, the cable is old and must have come loose, (bonus points for snapping off the latch on the RJ-45 plug) I’ll replace it with a new cable so this doesn’t happen again!
"dear facilities management team, DO NOT even think of turning this cabinet off" - notice on the cabinet housing the alarm/door entry system for the building!
The building had few offices in use due to remote working (after a move to "centres of excellence", not just WFH), so they had a habit of just powering down stuff and waiting for complaints... or in this case, the ability for them to get out of the building
I'd expect the local fire officer to come round periodically to check the fire readiness of the school: working alarms, fire doors not blocked or locked, etc.
It's a pity there isn't a similar inspection routine for school IT security -all that personal information held on youngsters. This is one instance where "think of the children" might actually get meaningful results.
The fire dept in my area comes around every few months to open all the fire hydrants and check pressure I guess. Not sure. I just wish they'd water my (or anyone's) lawn with the massive water flush instead of down the curb drains. As you say, I expect they do that more often than any sort of security IT checks in the city or schools.
As I've heard it, it's to flush the crud out of the lines. Often accompanied by warnings not to wash light colored clothes on the days they are doing it.
And you might want to only drink bottled or filtered on those days?
Sorry, sorry, you’ve lost me - just what sort of oddball fresh water supply do you have in your neck of the woods?
Working in a school is a great training ground for a career in infosec.
Basically the kids are all bad actors / terrorists but provided with physical and logical access to the network, the staff are all hostile as well and will attempt to block most changes to prevent the hostile actions of the kids or are so stupid the kids aged 6 can social engineer them.
At the same time all the data is sensitive, much of it critical and you're expected to be an expert in networking, firewalls, proxies, websites, webdev, system admin, Data Protection, photocopier maintenance, union negotiations, psychology, child protection law and provide 99.9% uptime on a budget of 50p. All delivered by your crack team; consisting of you and only you.
If you can manage that for a few years everything else is easy.
Couldn't agree more - after 20 years in corporate, I thought I knew about computers...and then I started work in a school after an unexpected redundancy - what a shock!
I had a group of teachers who liked to reward "good" students by giving them their passwords and letting them fill in the register, thus giving them access to lots of sensitive data on their classmates. I couldn't get SMT to order them to stop doing it (they were TEACHERS by god and would not take orders from ancillary staff!) and restricting their access got me put on a charge - so I just went into CYA mode and emailed everyone concerned with each breach as it happened until I got out
I found schools very "officers and other ranks" and teachers were clearly the only officers, after repeatedly being told that I ought to break the system for them, or it was essential that they had full admin access because they had "qualifications", my assistant (a very clever chap with in a stop gap job) and myself (degrees and a bunch of post nominals) had name plaques made to go on our office door, showing these off as a bit of a laugh - we were ordered to remove them straight away as it was affecting staff morale :D
Why not NOT make primary schools responsible for their computer systems?
Perhaps have some sort of education authority locally responsible for hiring IT staff, purchasing hardware and software and administering it ? A Local Education Authority if you would.
I know we spun off every aspect of public service into some sort of independent anarcho-syndicalist commune, in order to be hyper-dynamic and not at all as a precursor to privatisation, but perhaps it's better to make someone king.
We don't make every train driver responsible for building their bit of HS2
This is a great idea!
The LEA could then force the worst MIS system in human memory onto schools and make it ridiculously expense and difficult to get out of contracts! Then, they could probably ask the same company to do all of the network backbone.
After spending 10 years working in education support, if I had a pound for every time a teacher told me their password was...teacher... I'd have enough money to retire to the Seychelles or the Maldives, or even enough for a punnet of popcorn at the local Odeon cinema.
In theory, yes you are right a centralised system should be best. But, of course, in theory Communism is the best form of government because everyone is equal, everything is resolved by consensus and everyone looks out for everyone else.
Or not.
A centralised system tends to fossilise, one single system, supplier, model is chosen and has to work for everyone. Except, the outliers, where it doesn’t work. But the knee-jerk reaction is to try to force them to conform to ’the system’ rather than allow ‘dissidents’.
There is no easy or perfect answer or solution.
Once upon a time I had conversation with the university's safety officer. The biggest concern by far on campus was the fish tank in the foyer of the accountancy department. Where the head of department kept a shoal(?) of piranha.
Sorry - no IT angle.
Many years ago, I was responsible for maintaining some in-house, password protected software. The password was only valid for a month and the boss was very paranoid, so only gave out 3 months passwords in advance. The users immediately wrote them down on a Post-It Note and stuck it to their monitors.
Honestly as a naive measure, the best thing we could do to improve the security at our company is go around with a black bin bag and grab all the sticky notes we find used or unused and then lock down the stationery ordering such they are never ordered again. Mind our staff would just start writing passwords on entire A4s instead.
It’s less stupid than ignorance, and the latter is not a derogatory term. Yes I have an honours degree in Physics, but I am an incompetent brain surgeon.
They simply don’t know or understand the risks. Hopefully you pointed this out to them, and ideally they took steps. And if not, then yes that is stupid.
As anyone who has ever used a Microsoft network with mandatory password changes will know, passwords are a pointless pain.
You write down your new password and put it on a post-it note somewhere, and it will be variant of the old password anyway.
If you actually have some data to protect - most use-cases don't - then a security access device with 2FA makes most sense.
Another easy alternative is an Authenticator system with or without 2FA.
Personally I have all my master passwords printed out and stuck on my monitor. It allows access for others if I am unavailable and also provides a degree of plausible deniability