All this, and still WannaCry hit the main evening news, which at least around here is somewhat high bar. Not sure what to think about that.
All this, and still WannaCry hit the main evening news, which at least around here is somewhat high bar. Not sure what to think about that.
2 months ago, March 17th, and many organizations do not patch as often as they should, Many have even started delaying longer since MS patches of late have been causing more problems for people breaking Office, Breaking WiFi and breaking other critical systems with MS normal response of "opps our bad, well fix it in another month until then get fucked"
> Additionally W10
Win10 has about a 12% Market share, about the same as Windows XP still does.
Win10 has not been widely adopted outside the consumer market.
>All this, and still WannaCry hit the main evening news,
Made the news because of the numbers of systems, and number of high profile systems like Hostipols that were infected not because it was a Technical marvel of malware engineering
It also made the news because the NSA is indirectly responsible for not disclosing these vulnerabilities when they were discovered until they weaponized them for their own gain. While I do not blame the NSA for this infaction, I believe they should be forced, today, to disclose to all software vendors any other vulnerabilities they want to play Hacker with....
It's not just Office that's an issue, it's Windows Update itself. In late 2016 both a Vista and a Windows 7 machine stopped updating. The windows update service on both just hung at 100% cpu time, not updating anything. I didn't actually realise for a few months. Apparently it's a common problem, and the only solution is to manually download and install all the updates. Even after doing that, the problem kept occurring.
I've now upgraded everything to windows 10, and so far no problems.
And, shouldn't a workplace be setup for re-imaging if updates go wrong? I know its easy to just store files in C:\user\name\documents, but then it makes it just as easy to be forced to pay $300 for each computer in the network
That said, yes in a perfect world everyone would have perfect backups, and perfect imaging systems that makes ransomeware a non-event, we do not live in a perfect world and it is easy to monday morning QB the IT Staff.
Most IT depts are understaffed and corners are cut because you have to keep your head above water, business do not want to pay for proper staff or proper infrastructure,
IT is a "cost center" that should be cut every year in perpetuity, after all everything is working so why do I need to pay you to sit there all day
On an OS where even the biggest geek advocates insist on running outdated versions (7) + "Common Sense 2017" virus protection and institutions don't want to foot the bill for an XP system upgrade.
I think the longterm solution is delayed execution. Meaning everything entering such a old, but functional system - no matter what port, will have to get through a VM that simulates a near similar working computer, and checks for data availability. Once the safety of the arriving chunk is confirmed, the data is mirrored up.