The Register Home Page

* Posts by Doctor Syntax

42400 publicly visible posts • joined 16 Jun 2014

Page:

Microsoft to spooks: WannaCrypt was inevitable, quit hoarding

Doctor Syntax Silver badge

Re: Ministers need to sort out GCHQ

Not disclosing an exploit must be an exception; it must require sign-off from the highest levels in GCHQ a cabinet minister; it must be very time limited (e.g. no more than 12 months)

And after the expiry or if it all goes pear-shaped the sign-off should be made public.

Doctor Syntax Silver badge

Re: The lull before the next storm rolls in

"And (this may be controversial) how easy would it be to upgrade to a 2017 version?"

A lot of pre-compiled applications got broken at 2.4 > 2.6 although I think that was changes to libc at more or less the same time.

"I have a sneaky feeling that XP -> 10 breaks much less than Redhat 6 to RHEL 7"

I doubt it. Consider, for instance, the XP in hospitals issue: dependence on specific versions of IE because Microsoft decided to throw in a helping of non-standard stuff. Generally Linux/Unix complies with standards rather better so the temptation for developers to use that wouldn't be there. And a lot of the complaints with Windows updates seem to be broken drivers. Although you'll regularly get the anti-Windows trolls saying that Linux doesn't support this bleeding edge H/W (any more than the last version of Windows does) what they omit to say is that if you have a printer a few years old that the latest version of Windows doesn't support you'll probably find that Linux does.

Doctor Syntax Silver badge

Re: The lull before the next storm rolls in

"The last thing I read about Munich and Linux was a statement that it was a disaster and that they had to change course bad to something with main stream support."

That's Munich local government politics.

How do you say "told you so" in German?

Doctor Syntax Silver badge

"So that's 13 years (give or take a few months) in which Microsoft supported XP."

Another way of looking at it is that Microsoft had 13 years to get it right. Did they?

Doctor Syntax Silver badge

Re: Numbers

"Time to ditch windows"

In principle I agree. I don't use it myself. But in the real world, as a previous post made clear, there's a lot of core NHS applications that are not only Windows specific but XP specific. Windows can't be simply ditched. It needs to be phased out and that will take time and money.

Doctor Syntax Silver badge

Re: If you cannot patch it quarantine it

"what you're suggesting needs someone to look at what's on the network, and work out a plan for sorting it out"

And for a large and complex estate that's not trivial. There'll be a lot of special cases to analyse.

Doctor Syntax Silver badge

Re: If you cannot patch it quarantine it

You are assuming that "they" are in a position to choose what they do. In all the cases you've cited, some PHB, or committee, will have decided what projects are going on - the grunts at the coal face just get told what they are doing.

"They" applies to the PHBs and committees.

I wish more folk round here would remember that IT don't exist in isolation. They have to follow what the business wants. The best one can do is advise; strongly and in writing if necessary.

One difficulty is that the decision makers find it difficult to understand risk. They're choosing between the certainty* of a new, shiny and probably very useful development on the one hand and a list of things which you can't be certain will go wrong on the other. They'll choose the shiny almost all the time

*And ignoring any project risks.

Doctor Syntax Silver badge

Re: Let's mention Microsoft's Policy of hoarding patches unless you pay up.

Erm hold on - weren't Microsoft hoarding patches for "end of life" XP unless you paid to be part of a Enterprise service agreement? Sounds very similar to hoarding vunerabilities by the NSA/GCHQ. i.e. the fact XP Embedded (cash machines etc) still gets/got patches.

Got it in one.

It's very telling that on Friday Microsoft were suddenly able to release a patch. It's almost as if they suddenly realised they had a degree of responsibility.

Now they're trying to claim the moral high ground.

Ransomware scum have already unleashed kill-switch-free WannaCry‬pt‪ variant

Doctor Syntax Silver badge

I can't help thinking that announcing the discovery of the kill switch might not have been a good idea.

Doctor Syntax Silver badge

Re: A dish best served cold

"collateral damage amongst their allies, but that's the new normal."

When the Germans open fire the British duck

When the British open fire the Germans duck

When the Americans open fire everybody ducks.

Doctor Syntax Silver badge

If they're within reach or Russian special forces it's not their S/W being killed they should worry about.

Japanese researchers spin up toilet paper gyroscopes for science

Doctor Syntax Silver badge

Obligatory youtube

https://www.youtube.com/watch?v=MkrKkBhsMiA

Doctor Syntax Silver badge

"The paper was put together for a Pervasive Smart Living Spaces workshop"

That's an odd way to spell "invasive".

74 countries hit by NSA-powered WannaCrypt ransomware backdoor: Emergency fixes emitted by Microsoft for WinXP+

Doctor Syntax Silver badge

Re: Risk Management

"The applicable software for controlling stuff like an MRI scanner isn't desktop Windows XP, it's one of the Windows Embedded family, the XP-derived ones of which can be supported (including patches) till 2019"

OK, let's deal with the specific: XP-embedded, support ending in 2019. If, in 2019 you were in a position I outlined in my question what would you do?

And go back to the more general point of which the scanner was an example: something, H/W, information system, whatever, which is still essential, but depends on XP, either the already EoLed version or not yet EoLed version makes no difference in principle. There's no point in calling out those who find themselves responsible for stuff which had a planned life in excess of what turns out to be that of its components. They are faced with real problems - if they choose to invest in a replacement then something new that was planned has to be foregone.

The original post to which I was replying was over-simplistic. So was your response. You do not solve problems by telling them, or those who remind you of the, to go away.

Doctor Syntax Silver badge

Re: Risk Management

"The rest goes on wages. That's a political failure."

?

Doctor Syntax Silver badge

Re: Risk Management

"What if such systems had been based on open standards for device control, document interchange, etc?"

You are, of course, correct. But note the past perfect tense in your sentence. We're not where we'd like to be or ought to be. We're where we are.

Doctor Syntax Silver badge

Re: Risk Management

"Can you explain to me, with consideration for any contractual terms one might agree to in the EULA, how that proposal would work?"

It transpires that MS were very quickly able to knock out a patch for this vulnerability. They must finally have realised that they had responsibilities. So they question arises - was this EoLed because it wasn't feasible to continue maintenance or because they wanted to herd those who could be herded into upgrading?

Doctor Syntax Silver badge

Re: Solution

"True, but that implies you can sue a previous administration which is AFAIK not possible."

No such implication. I said sue the NSA. Even given the political nature of top USA appointments institutions like that are apt to run on unchecked.

Doctor Syntax Silver badge

"Yeah, Microsoft only supported XP for 13 years (2001-2014)."

Is it too unreasonable to hope that in 13 years they'd be able to get it right?

Yes, it is.

Doctor Syntax Silver badge

Re: on the upside....

"The good thing about this episode is that it is so high profile that no CTO or even IT manager is going to want to be caught out by it again and can not refuse to address the problem of running obsolete OS´s and maintaining a policy of never patching anything again."

I'd like to think you're right. Cynicism says that there'll be a subset of bean counters* for whom it confirms their belief that IT is a net very good cost centre.

*Bean counters are, of course, a cost centre but they lack self-awareness.

Doctor Syntax Silver badge

Re: Windows XP

"Why are people still using it again?"

Why is this question being asked again?

Go and read through comments in many MS-related threads including this one. You'll find it explained time after time.

Doctor Syntax Silver badge

Re: From North of the Border

"Part of the blame goes to the regulators who drag their feet on approvals."

And if they move faster and let something through without thorough testing how does that work out?

Doctor Syntax Silver badge

Re: From North of the Border

"Enterprise licences don't do this. It's only Home and Professional et al. that spy on you."

Neither my dentist nor optician are large enough to qualify. They're professionals but don't get treated as such by Microsoft.

Doctor Syntax Silver badge

Re: From North of the Border

"knee jerks are for jerks."

Nice one.

Doctor Syntax Silver badge

Re: From North of the Border

Interesting calculation. But you've omitted the cost of testing the ability of the existing applications to run on W10 and remediation or replacement of those that won't. An OS exists to run applications. These are the very arguments used against FOSS in such circumstances.

There's no silver bullet.

Doctor Syntax Silver badge

Re: Kill switch

They knew the code had been stolen. But they chose not to activate the "kill switch".

Not activating it immediately it was stolen was reasonable. If they had the malware operators would have noticed it because they'd have had to debug it to get it to work. However they should have been watching for a release and thrown the switch as soon as they discovered it in the wild.

The NSA have a lot to answer for here and I hope govts. around the world let the US know that.

Doctor Syntax Silver badge

Re: Stupidity

"But it's TRAINING."

And counter-training unfortunately. You train people to use email safely. Outside of your training session marketers everywhere are counter-training them to accept HTML mail as normal. Banks and others are counter-training them to click on URLs in their HTML mail. Social networks are counter-training them to throw complex files around. Gmail and the like are training them to view their mail through a browser, described here the other day as not a single point of failure but a whole three-dimensional space of failure.

Doctor Syntax Silver badge

Re: Mitigation against ransomware:

"11. Update the antivirus version on regular basis and keep the definitions updated on a daily basis."

Today's definitions won't protect against yesterday's infection. And if that infection is also an aggressive worm as this was that's not going to be much use.

"12. Keep the computers and servers up to date with Windows updates and security patches."

In 15a you go on to explain why this isn't always possible.

Doctor Syntax Silver badge

Re: What the I don't even

"MSNet ports out there waving in the breeze of the general Internet"

Assumes a fact not in evidence. If you have a system with substantial internal SMB linkages than all it takes is one person to open an email booby trapped with a worm. The externally exposed port is your email port and that isn't going to work without being open externally.

Doctor Syntax Silver badge

Re: 'They've already been copied a dozen times for further use.'

"They weren't released before Shadow Brokers failed auction"

And what's that got to do with anything? Shadow Brokers would have sold you a copy. What guarantee would you have had that there wasn't another?

Doctor Syntax Silver badge

Re: Solution

you tell me what the "most basic principles of security" are that Microsoft have missed in current Windows and we'll see if your GNU/Linux distribution of choice has or has not also missed them.

OK. MS have always been a bit obscure about what any given fix does. Given that, in the real world, fixing one problem sometimes causes another. Recently they've taken to rolling multiple patches into one so it will take longer for sysadmins* to test and roll out.

My chosen distro is Debian LTS, ie systemd-free. Over to you.

*A good sysadmin is paranoid about everything.

Doctor Syntax Silver badge

Re: Solution

"does this mean we can now collectively sue the Trump administration"

Downvoted for gratuitous Trump insertion. Clearly this goes back some way beyond the current administration. There may well be good reasons for suing the NSA, assuming they're not legally protected. There are also good reasons for being critical of Trump but conflating the two issues when they don't belong together weakens your argument. Learn to stay focussed.

Doctor Syntax Silver badge

"Either Microsoft were coerced into deliberately introducing this for the NSA's pleasure, or the NSA had it inserted somehow."

Or it was a genuine bug which the NSA found and didn't bother to warn anyone until it was too late.

Doctor Syntax Silver badge

Re: Risk Management

"Simple."

The word you're looking for is "simplistic".

As has already been pointed out all unpatched versions of Windows are vulnerable. Patching itself introduces risks - patches have been known to break things and now that MS are rolling multiple patches together those risks are increased. So patching also involves testing and testing takes time.

The specific risk for XP is that it doesn't get patches. But, again, the issues with XP aren't simple. In many cases it will have been retained because something mission-critical depends on it and replacing whatever that is may require major expenditure and further risks. If your MRI scanner, for instance, relies on a no-longer maintained piece of XP-only software do you simply put your hand in your pocket for a few million to replace it, commission a rewrite and take the risk that it may fail in some respect to emulate the existing product or do you keep using XP?

These sorts of issues are not easily solved. Of course they only exist in the real world so please feel free to keep helping with your advice.

Doctor Syntax Silver badge

Re: worthy of mention

"On stand-alone PC's, ensure you have an adequate AV solution"

The problem with this is that the signature for any new malware won't be available until the target has been released, infected systems and been reported. When something spreads as fast as this has done that will be much too late.

Amazon's Alexa is worst receptionist ever: Crazy exes, stalkers' calls put through automatically

Doctor Syntax Silver badge

"Surely the device should be designed to make using it easy for the user."

It is. You just need to remember who's the user. They've made it easier to remember because the name of the service, Alexa, starts with the same letter...

PC repair chap lets tech support scammer log on to his PC. His Linux PC

Doctor Syntax Silver badge

Re: For the phone scammers ...

"Never had a call back."

I had once. The salesdroid's supervisor rung back to say the call must have been cut off.

Doctor Syntax Silver badge

But surely the DoB should have been 1/4 not 1/1.

Doctor Syntax Silver badge

Re: I've done the Linux thing

"he woman at the other end had just tried to tell me Linux runs under Windows."

Well they do have a Ubuntu subsystem in W10 - although I doubt the average scammer would know that.

Doctor Syntax Silver badge

Re: Ideas for a new game

Final plans for the invasion of India with a special unit to be dedicated to liquidation of phone scammers.

Doctor Syntax Silver badge

Re: I'm missing out

"Take out service with TalkTalk."

There are limits. Now go and scrub your keyboard with soap and water.

Doctor Syntax Silver badge

Re: professional scammers

"He/she/it/they said "Hello Mr. Shaw" in perfect English to which I replied in Italian, for the lulz."

I'd have thought linguistic skills ought to be able to earn them a better legitimate income than scamming. Or maybe the scamming's just a sideline.

WannaCrypt ransomware snatches NSA exploit, fscks over Telefónica, other orgs in Spain

Doctor Syntax Silver badge

Re: Antivirus?

"Do these things do anything useful?"

The updates you get today should protect you against stuff that's been known for x* days. That means that some people will be infected in the period between release and the discovery and distribution of the AV update. In the normal state of affairs this will be a small proportion of vulnerable systems. When the virus spreads as rapidly as this today's updates are already too late.

*where x is however long it takes for the vendor to confirm reports and put together their update.

Doctor Syntax Silver badge

Re: Cost (not just of cleanup)?

"Which stovepipe's budget is going to be picking up the cost of cancelled appointments, wasted time, etc?"

How about the NSA? They sat on this for a long time and then failed to prevent it leaking out.

UK hospital meltdown after ransomware worm uses NSA vuln to raid IT

Doctor Syntax Silver badge

Re: >You might not now but in medieval times it was the best way of becoming rich.

"yeah, I know it's not necessarily the sysadmins' fault, but somewhere, some people, either incompetent IT or managers, decided it was acceptable to connect an OS that is now 2 yrs out of even extended security support to wider networks."

You may have to look a little further back than that. Maybe at some business that was writing current applications but has now been bought and re-bought by some bigger business and somewhere along the chain the application development has been discontinued, maybe the source lost and runs on nothing newer than XP.

There's no silver bullet.

Doctor Syntax Silver badge

Re: Backup

"then my friend, you deserve all you get."

But your users and those they serve don't.

Doctor Syntax Silver badge

Re: Alternatives?

"1: You do not normally have to use Windows. There are more secure alternatives."

As others have said there's a lot of specialist kit for which only Windows drivers and/or applciations exists (which version of Windows is another worry). So it's not as simple as that. However there should be proper network segmentation to protect these.

OTOH plain vanilla desktop office/mail/web machines could well be shifted to other platforms. However this would buy time, not complete protection. A booby-trapped email will inevitably find a supply of boobies if it's widely spammed.

What's needed is a better architecture that doesn't allow some random application to save or update whatever file it wants.

Doctor Syntax Silver badge

Re: something or nothing....

"ever tried deleting/moving/modifying a file on a network share that you only have "read" permissions to?"

Those file you only have read permission to - how did they get there? Could it be that someone has to have write permission?

On a more practical, albeit longer term scale alternatives to simple shared folder need to be looked at. As one approach I'm currently setting up Nextcloud at home. I have several alternative ways to share files with a client. One is to use the webdav client to sync a specific desktop folder with the server. That means that even if I had a ransomware program running wild on the client PC it could only (a) affect files on the synced folder and (b) the contents of the folder on the server are versioned so that the last good version can be restored.

Microsoft's Windows 10 ARM-twist comes closer with first demonstration

Doctor Syntax Silver badge

"Windows has had ARM support for quite some time too... there's even a distribution for Pi's"

Presumably you mean the W10 Core? That's the one aimed at IoT. Another reason to reject it.

O2 continues to splash out on 4G ahead of rumoured IPO

Doctor Syntax Silver badge

What a pity BT bought EE. They could have had O2 flogged back to them.

Page: