Windows 7, not XP, was the reason WCry spread so widely
arstechnica.com
arstechnica.com
Instead, it now appears, the leading contributor to the virally spreading infection were Windows 7 machines that hadn't installed a critical security patch Microsoft issued in March
I'd guess a lot of those who don't install updates on 7 were greatly turned off by the aggressive Windows 10 upgrade promotions and other unwanted features Microsoft were trying to sneak by as security-related. Those still on XP didn't have to worry about that either.
I remember a memorable analogy about the nature of Windows updates: "they aren't just like vaccinations --- there's also a large chance of making you grow an extra 3 ears, lose one eye, and turn your skin bright green."
If only Microsoft had two "update channels", one for features and the other for security-only fixes...
I'm disgusted by this situation. This was supposed to be a simple email-checker. But without anybody making any serious mistakes in its administration, (terrible AV software notwithstanding) it had degraded to the point of uselessness in two years and was headed for the dumpster. (There was still plenty of space on the hard disk, and as I said, no evidence of malware.) I could only conclude that the computer was behaving exactly as it was designed to. Under Linux, this computer remains perfectly suitable for its purpose. It's quite responsive even when running a modern web browser, and I have a whole separate rant about how insane web browsers have become.
At any rate, it's quite sensible that people don't apply updates, when updates literally make the computer impossible to use. This being Windows 10, there was no avoiding updates, but I can see why Windows 7 users wouldn't bother with them.
Edit: punctuation
After doing this I can update windows normally again. Try these for starters: kb3102810, kb3138612, kb3172605
Even if that was true, it is valid only for system packages. Updating any other application means one of the three things:
1. Manual updates (and don't get me started on uninstalling).
2. Brew (which can be a hell of it's own kind).
3. Apple Store (a.k.e. the walled garden).
I'll rather stick with apt, thank you very much.MacPorts is also hell for various reasons (not the least of which being the effectively-nonexistent integration with the rest of macOS, keeping its own little silo of an OS that gets huge if you install even relatively-simple graphical applications).
2. Again, what? Brew is dead-simple. `brew install whatever` and `brew remove whatever` work like butter.
3. Triple what. Sandboxed apps that cleanly update, with a gatekeeper that makes sure no trash comes through? And I can manually sideload stuff if I absolutely need to? Hell yes.
I have a pretty strong feeling you're a Linux elitist, probably running Arch. All the stuff you point out about macOS is plain wrong, and you'd know within a day of using.
1. Oh yes, Mac has the easiest installation process. Deinstallation, not so much -- yes, you can draw your app to trashcan, but that leaves bunch of data files, configurations (depending on the app) etc on the disk. That is the reason for existence of a number of uninstallation utilities like AppCleaner or AppDelete (my tool of choice). And while Sparkle is useful, it is a third-party effort and not aprt of the OS.
2. Oh yes, brew is simple, there is no doubt about that. Except when a package becomes corrupted (e.g. while upgrading, or when there are missing dependencies, or when you accidentally install the same thing in two different ways), in which case it becomes a nightmare to untangle.
3. Oh yes, the gatekeeper is very useful -- unless you disagree with it about what represents "trash". And honestly, my strong belief is that Apple is going to restrict the other ways to install apps in favour of the Apple Store, moving towards a "desktop iOS"; which is perfectly fine if you just want to use certain apps, but isn't if you're a software developer building anything other than MacOS or iOS apps.
Edit: Just to clarify, I am giving my own opinion and pain points which have been turning me away from the Mac for quite a long time (and it's only getting worse). It is not my intention to force my opinion to anyone else or to pronounce Mac the worst and Linux (or anything else) the best choice. It's simply the case that each OS has it's own realities, and some are better fit for some purposes, and others for others.
Or you mix and match releases. I usually keep Sid sources enabled, so that I can quickly build a newer version of this or that package if necessary; 90% of the time this works flawlessly, but when it comes to complex stuff like python, the dependency graph can get a bit borked if I'm not careful. (Yeah yeah, not supported, but as I said most of the times it works just fine.)
Whereas Windows Update just screws up periodically on its own. Sometimes it sits at 0% for hours then BANG! 60 updates installed, please reboot. Once I had 100+ updates to apply and I couldn't see any progress, so I killed the wusua service and observed the download folder immediately filling up with packages, which clearly Windows was keeping somewhere else while lying about download progress. Then there are the times when it just refuses to install this or that update and doesn't tell you why...
Really? Update downloads restart once in a while for no apparent reason. Also, installing Xcode after already having the command line tools messed up everything for me last week.
But sometimes, the broken packages error is illusory. Just a few days ago, I was installing some old thing on Debian jessie, and got that it depended on openssl (0.9.8). But apt wasn't going to install that. So I get that jessie has openssl (1.0.1). Hopeless? No. It turns out that both versions can actually coexist.
Yeah.... I like the huge downloads and the regular prompts for my apple account password when installing an update best.
Justified fear. 100% of the older machines I upgraded to Windows 10 stopped working in one way or another (e.g. Wifi didn't work, video drivers crashed) after upgrading.
>can you even get an LTSB release for the latest Windows 10 1703 Creators Update? Why get ltsb if you're going to get the latest version anyways? You might as well use regular enterprise and defer feature updates.
That's not the issue because even if there aren't feature updates to apply, there are still security updates that triggers a restart. They extended the working (no restart) hours to 18 hours, which should be enough to prevent surprise auto updates from happening.
>And getting security updates quickly without having to buy-in to new features at the same time.
Then get LTSB. But if you're going to be using the latest version anyways (as indicated by you wanting the creators update) use CBB + defer feature updates, which buys you at least 8 months of extra time.
I don't know whether earlier versions of Windows offer this level of control as I've got Win10 on all my machines. I just leave them on automatic update and yet I still only have two ears.
https://support.microsoft.com/en-us/help/3080351/how-to-mana...
Also, for the record, I never saw any attempt at a forced upgrade across three different machines... even though I made no attempt to block them. This makes me doubtful about "forced upgrade" stories.
Hoever, even if someone correctly claimed that they were forced to upgrade and didn't, along the way, accept the Windows 10 terms and conditions, it was dead easy to roll back to the previous OS. Far easier, in fact, than coping with a ransomware attack.
If we're adding personal anecdotes, then I'd like to file my own experience. A lab colleague's computer upgraded to Windows 10 in front of my own eyes. All she did was leave it alone long enough for her to go and drink some water. It was the only computer in our group which had the 3D modelling software we needed, and the update managed to break that. (I think we tried the roll-back too and that failed). Anyway, this was a few hours before our assignment was due. That is not a time to be left without one's tools.
I talked about this before here on Hacker News. Many others did. Some journalists also covered it.
Even I couldn't believe the shady tricks everyone was accusing Microsoft of until I saw it with my own eyes. But then again, I should also have realized that if so many people feel tricked, then it doesn't really matter if it was technically a trick or not.
If it wasn't technically a trick, then it sure was designed to fool users, evidenced by the sheer number of people fooled into it.
I did a few roll-backs to test the system and they worked perfectly. However, if you're upgrading 400 million PCs, there will inevitably be some errors.
This is why we have backups ;-)
> evidenced by the sheer number of people fooled into it.
How many do you think there were, and what's the percentage error over 400 million or more upgrades?
A free upgrade?
Is that more or less shady than Microsoft charging for upgrades?
From who's perspective? Microsoft? This was already fixed, just that people didn't update, because like I said, people just disabled updates. That trust was broken by Microsoft. Even if you are doubtful of 'forced upgrades', you can research for all the evidence yourself. I've had it happen to plenty of machines, and the free utilities, like I said, were negated multiple times as Microsoft kept changing how their win10 update service could be blocked. Sure, there were months where it would be perfectly stable, but if you needed to be sure, you turned off windows update.
The fact that people claim -- or journalists report -- forced updates doesn't make their claims true. Everybody who deals with real users knows how unaware they are.
Having said that, I agree that the "dark patterns" were a really bad idea. Microsoft actually does know how unaware real users are, and its upgrade offers should have reflected that.
Whether it was worth turning off security updates is another matter, and would depend on the circumstances. For most users, my opinion is that it was stupid.
Apple does this too; that's why I haven't bought a Mac in many years.
And they haven't done anything bad since? That sounds like Apple has it nailed.
In contrast to Microsoft?
Something tells me that people that still run XP aren't exactly the Kaspersky clientelle, so the sample is severely biased. Unless Kaspersky pro-rated the infection rates to accommodate for that, but it doesn't sound like they did.
However, you might be able turn off SMB1 support is if you still have machines with Windows XP or 2003. This is a similar situation to SSLv3 when POODLE was discovered, in that the difficulty of getting rid of old protocols, is that of getting rid of the last ones (Though I realise WCry exploits an implementation bug).
SMB1 will be disabled by default in the Fall Creators Update [1] and removed completely in a future release of Windows 10 [2]. It should have probably happened a lot sooner, but the protocol is still used quite a bit [3] despite Windows itself not requiring SMB1 for the past 10 years [4].
[1] https://twitter.com/NerdPyle/status/863297941930246145
[2] https://twitter.com/NerdPyle/status/863519752429293568
This wizard should fix it now: https://answers.microsoft.com/en-us/windows/wiki/windows_7-u...
If it wasn't for the WannaCry problem, I wouldn't even have bothered!
Blame for the whole "deactivated" Updates affair should be upon the CEOs and marketing guys who tried to shanghai-shovel consumers and customercompanys Win10.
Yes, they might have saved microsoft in the short turn burning consumer trust, but if that consumer trust is part of the world wide infrastructure- they should be called liable for burning this resource.
Small nitpick- though the worm aspect of WCry does have a lot of issues with targeting WinXP, the meterpreter part of that sentence is a widespread myth that originated from poor wording in a slide. Source, w/ a reply that has a link to correction from the original author: https://twitter.com/riskybusiness/status/864293475981729793
I'm still amazed so many PCs are directly online, and not trapped behind NAT or at least a firewall. Does this mean that the NHS, etc had DMZed machines on their LAN?
edit: Shodan shows over 1 million machines with SMB open