Updates for older platforms to protect against potential nation-state activity
blogs.technet.microsoft.com
blogs.technet.microsoft.com
People never learn when disaster is narrowly averted. People learn when their decisions mean everything is on fire.
Perhaps there exists an easier middle ground solution such as somehow putting a safe proxy machine in between the unsafe machine and the internet using a very simple controlled communication to the unsafe machine?
Should they be scrapped? Maybe not. But not just left as they are either.
Most importantly: don't BUY that next MRI if it's approved only for a certain OS version and it's a general purpose OS such as Windows, and it will be connected to the internet. If you DO buy it - calculate with writing it off within the support window for the OS. That will show its true cost.
Further, equipment using general purpose OS'es should stop being approved for one version and automatically qualify for newer versions. Alternatively the approval should not be valid beyond the support window unless the machine is air gapped.
I wonder if it would be feasible to protect them with some dedicated firewall/proxy boxes or plug-in modules which could be cheaply updated (compared to the cost of updating and revalidating the whole machine), supplied by multiple vendors, etc.
Of cause not, but the hospital knew that the Windows XP running their multi-million dollar scanners would be end-of-life before the scanner it self. They should have required that the software be placed in escrow for the life time of the scanner, so that other parties could do any needed updates, if the supplier failed to do so.
I'm sorry, I get that you can't throw away expensive hardware, just because Microsoft no longer patch that version of Windows required to run the software but: EVERYONE knew that the hardware would be in use beyond end of life date for the operating system. So why isn't that included in contracts and support plans? Do banks and hospitals even care enough to ask how the supplier plans to deal with an EOL operating system?
Well, maybe there's more to a complex organization like a bank or hospital than software licensing. Maybe their service contracts had these exact contingencies but they've run into other problems that nobody could have predicted when XP was new, like:
* That there would be a Great Recession that would wipe out a lot of firms, including banks, hospitals and medical device manufacturers.
* That there would be a massive new piece of legislation that would tax medical devices heavily, thus changing the way that market works.
* That the same piece of legislation would encourage hospitals to merge into each other through various incentives that were intended to limit the cost of healthcare.
* That Microsoft would decide to break backward compatibility sharply compared to what they did before. Don't laugh at this one; they were business for nearly 30 years when XP came out and never broke backwards compatibility as much as they did in the past 10.
I suddenly feel less good about my next dentist appointment.
Plot twist: this has already been going on for decades.
The fact that people are trapped on XP is Microsoft's fault. Because some manager in Microsoft decided that getting the upgrade numbers up by breaking hardware drivers was a good idea, you have a security nightmare decades on.
People do that?
And "if company ceases to maintain and release updates to product, we will receive the source code for our use" doesn't sound like too poison of a pill for Sales to push through.
The medical device was validated with a certain version of the OS and any special configuration placed on it. If you change the OS/configuration setup in anyway, you (the manufacturer) have to analyze it for impact and potentially re-validate it. The user cannot make this change This would be a violation of FDA regulation.
Now, the hospital can say that they're going to stop using your equipment until you "fix" it --- many such products are leased, not purchased and they may use the lack of security to break the lease. But that presumes they can get a replacement that works as well, train personnel in it, update the supply chain, storage, incoming inspection, etc. for this new product and any supplies it needs...
It's not as simple as running down to MicroCenter and installing a copy of Windows 10!
(Bit of a moot point in agreement, but thought I'd share my 2c)
The fault lies entirely with the manufacturer for not providing a system fit for use/sale.
It would still cost money, but at least there's a legal path forward.
Better still would be having a device that operates on some commodity connectivity using standard protocols (APIs/etc) which can be soft-gaped by a firewall / guard that only lets well formed (or at least expressly authorized) requests in.
The open source OSes do go extremely out of their way to provide and keep userland APIs stable, in many cases modern hardware that would be completely unsupported in XP or some other proprietary OS, and again, if something that used to be depended on somehow falls out of support you're at least actually free to pay someone to add in the support you need.
1. Well, maybe you could do that with your abundance of skill and time, but not everyone running a hospital/bank/other-large-organization has the time or budget to slap together and maintain that kind of amateur hour rope-and-tin cans proxy shit.
2. Not everything people use a computer for happens over a network. Some people write software because they need to communicate directly with hardware devices. You can’t intercept network traffic when there is no network traffic to intercept.
2. I believe we're talking about network accessible devices here. Otherwise why would parent make comment about air-gapping infeasible?
2. The parent mentioned networking, but networking is not the only threat vector that must be accounted for. Malware can spread through removable media, and most organizations outside of the military or federal government simply don't have the sort of security policies in place to prevent that. So the unpatched vulnerabilities people are talking about can still be exploited even without the network stack doing anything.
Honestly, the cost of it getting broken into seems to be significantly higher than the cost of upgrading the systems.
We don't necessarily know what the costs of "getting broken into" are. It depends on who you are and what the breakin does. It could only cost the time it takes for IT to restore a backup and plug the hole. I mean, yeah, if you suffer a spectacular ransomware attack and are screwed so badly that you must pay the ransom and everyone finds out, that's probably more expensive than updating. But that's not the only threat or even the most likely threat your organization may contend with.
We also don't necessarily know what the costs of updating are. If you're just doing boring office stuff, the costs are low and you should just fork over the money to Microsoft and get it over with. If you need to update a bunch of custom drivers for some devices that are important to your business because the device manufacturer went out of business, that could be a vastly expensive software development project that your organization can't afford to do. Certainly that costs a lot more than having Bob in IT rewind the tapes when Russian hackers get ransomware past the firewall.
They can (sometimes) put in intermediary proxies and the like, but that's not a cheap process.
It's the only way that large institutions will come to properly value the security trade-offs of their decision to buy closed-source, proprietary systems.
Why should the VA get to externalize part of their purchasing decision on to Microsoft?
These devices run embedded Windows because they all always have. There's almost no competitive advantage in changing OS vendors in the space, because it doesn't differentiate the product. Even if a device ran CentOS or whatever, you wouldn't be able to update it significantly without going back to the FDA.
Lobby to change the market instead of externalizing costs; pool money to change the market instead of externalizing costs; etc.
I'm sick of people defending poor long-term decisions by saying they're short-term efficient. The providers aren't helpless entities these things are just happening to: they chose to go down a route that was expensive long-term, but cheap short-term and now are asking to not have to face the consequences of that. I can guarantee that every single institution facing this concern received a technical report pointing out exactly this issue -- and chose to ignore it so a manager could have a bigger bonus.
Instead of addressing the problem, they're asking to be let off the hook of their poor decision making and laying the groundwork for the same mistake. Continually bailing out such poor decision making isn't prudent.
Why would they ever change if there's no consequence?
This isn't a long-term strategy we can afford to support, so we're obligated to let it blow up in their face.
>I'm sick of people defending poor long-term decisions by saying they're short-term efficient
I'm not defending poor long term decisions, I'm simply describing the reality of a complex set of intersecting political and business systems. Sure, maybe it would be good to lobby the FDA to change rules about updating embedded software, but what should the new rules look like? How do you make sure new linux drivers for an x-ray machine won't have a buffer overflow or off by 1 error that kills people? It has happened.
I'm not even sure that Linux is definitively the right answer for embedded operating systems for safety critical systems. Do you have any evidence to support that claim, which you seem to be making? I'll be happily persuaded if you can clarify why open source is intrinsically better for long lived embedded systems like this.
Private organisations/companies? Less likely. Would they even have the ability to do a build from the source code?
Thanks for that one, I didn't put those together before.
One objection is that these systems may have been the only ones on offer that met requirements. I think one has to consider collective effects, though: were people prepared to 'irrationally' say "I'm still not buying it, because it's not open source", we would end up with open source MRI machines. Of course that's unlikely to happen at present simply because there is NOT a consensus that open source software is important or even a good thing in this context -- but this argument addresses THIS objection.
That kind of stance happens in some situations, and not currently in this one. I don't think that's an immutable state of affairs. Also, I don't think it's because of the high direct costs of saying "no": refusing to pay kidnappers also has a high direct cost and an analogous collective benefit (I'm not aiming for a hyperbolic moral comparison there, I just picked that because, as an extreme case, it makes the point clear).
I get what you're saying, it's nice that they're doing this, but it's not really so much a goodness of the heart thing as it is that there is a super critical bug to many versions of Windows and there happen to be enough XP machines around that they're a significant threat. The bugs are big enough and the threat great enough that there's probably less cost in patching than there is in dealing with any of the potential fallout.
I would gladly give them credit by name, if I could just remember who they are...
Dunno for sure because I'm not familiar with their practices here. But it's a thing.
Nobody is maintaining Linux 2.4, which was released in 2001. Its support only lasted until in 2010 as far as I can tell.
On the other hand, many oss projects have rolling releases, so trying to compare like this is futile, expect for the fact they have been maintained for a very long time.
LaTeX 2e has been around since 1994 and is still the current, maintained version.
From their announcement on 2017-05-15 [1]:
> In February Microsoft is missing patch Tuesday. TheShadowBrokers is knowing, Microsoft is missing to be making patches for Eternal exploits.
[..]
In March Microsoft is releasing patch for SMB vulnerabilities. TheShadowBrokers is knowing this is being for Eternal exploits. TheShadowBrokers is still waiting and not releasing.
[..]
In April, 90 days from theequationgroup show and tell, 30 days from Microsoft patch, theshadowbrokers dumps old Linux (auction file) and windows ops disks.
[..]
Eternal exploits is not being ZeroDays. [..] patch was being available for 30 days before theshadowbrokers is releasing dump to public.
[..]
TheShadowBrokers Monthly Data Dump could be being:
web browser, router, handset exploits and tools
select items from newer Ops Disks, including newer exploits for Windows 10
compromised network data from more SWIFT providers and Central banks
compromised network data from Russian, Chinese, Iranian, or North Korean nukes and missile programs
More details in June.
Their latest message is from 2017-05-29 [2]:
> Q: What is going to be in the next dump?
> TheShadowBrokers is not deciding yet. Something of value to someone. See theshadowbrokers’ previous posts. The time for “I’ll show you mine if you show me yours first” is being over. Peoples is seeing what happenings when theshadowbrokers is showing theshadowbrokers’ first. This is being wrong question. Question to be asking “Can my organization afford not to be first to get access to theshadowbrokers dumps?”
[1] https://steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy...
[2] https://steemit.com/shadowbrokers/@theshadowbrokers/theshado...
And computer security benefits from herd immunity tactics, so it's best to get virus updates in as many hands as possible. It's why Microsoft has never really prevented pirated copies of Windows from getting security updates. They benefit from not having old machines potentially causing problems for newer ones, and even just avoiding the bad PR from massive malware attacks.
Microsoft built this mess for profit, and continue to profit off of taxpayers indefinitely as hobbled state institutions are forced to pay permanent support contracts for old OSes because the states themselves mandated they use this shit by law. I'd love to see how many campaign contributions MS made to representatives pushing laws standardizing on Word or other bullshit MS only tech in state institutions and even worse, in schools.
Public education is infested with Microsoft giving away / heavily subsidizing their locked in products so children are hooked on them for life, and nobody is outraged about it.
Hell, the whole war for the classroom from all parties involved is disgusting. Microsoft, Apple, and Google all push free access to their proprietary services and products to lock kids into their ecosystems. And while Google's platform, Chromebooks, are much more open than their competitors, they offset that by also having the ulterior motive of farming these kids for their big data research (not to say MS and Apple aren't doing it too, just saying Google is far from innocent here).
The whole intersection of state and software globally is a giant mess of corruption. There is way too much profit to be made off taxpayers money for anything close to good intentions to win the day.
I keep hearing it will be the Year Of The Linux Desktop and it keeps never happening. That's why. No need for any wacky conspiracy theories, for the average user who just wants their computer to be a tool to get work done, the choices are Windows or Mac, and for large organisations who want to centrally manage machines, the choice is... Windows.
And yet Chromebook and iPad sales are booming at the expense of the PC. My sample size is ~20 family members. Those with Chromebooks love them and those with Windows 8/10 despise them. From a support perspective, it's considerably less for Chromebooks vs multiple issues with malware on the Windows devices.
Caveat emptor, YMMV etc.
We only got rid of the VMS controlled CNC lathe a couple of years ago - it ran off a VAXstation something-or-the-other. A 2100, methinks.
Granted, these machines didn't pose much of a problem besides scarcity of spare parts - neither of them had any need for a network, anyway.
Some industries are still full of Unix boxes from the 90's RS/6000 vintage. I've heard oil and gas industry is pretty bad for this sort of stuff especially in industrial control systems.
Problems arise when some bright spark figures out that it would be much easier to collect data via a network, directly from $Expensive_Device - or when another bright spark in accounting figures one can do without spare parts; after all, OEMs are supposed to keep stock of spares, right? No. Not years - decades - after sending out the EoL notice.
As an aside, I probably have one of the largest concentrations of Motorola pSOS hardware in the world in my shed (that is, the office next door) - my employer used a LOT of pSOS kit in the nineties, and as the platform became obsolete, noone thought to preserve a supply of spare parts; I quite literally dumpster-dived to reclaim whatever I could which warehouse staff had been told to get rid of.
Still happens every now and then that a customer asks for pSOS thingies. I really should get myself a stuffed dodo to put on the shelf next to the Motorola boxes...
I just saw a system that used Java applets. Java applets are outdated so they rewrote it in ...drumroll... Flash.
I can imagine there are plenty of systems still on DOS.
What makes this harder is that people bought into a platform that doesn't given them access to the code they run. The business that originally created it isn't interested in supporting it further (well, they are, i.e., "Windows 10", but I presume that that's not acceptable to our hypothetical "vote with there [sic] feet" person), and I don't really see that the business should be forced to support it, either. (It's not like MS didn't support it for quite a while, and don't still offer a solution.)
Software evolves. Ideally we're finding more secure and better ways of doing stuff, and shedding the old stuff, though I acknowledge the debatability of that. I acknowledge that it's also unfortunate that UI changes, and bloat, often seem tightly coupled with that. But if people also persist in choosing non-free, non-open source software…
Of course, security vulnerabilities do still become more known over time, and if you patch for them, you end up rotting code.
To handle both code rot and security vulnerabilities, you need software that is persistently maintained and upgraded, which means having a software team permanently on the job instead of what a lot of government software came from: One-time projects where a contractor comes in and does something.
Because the nation-states involved are legally immune, because of sovereignty and sovereign immunity, and rather resistant to other forms of coercion because of substantial economic power, conventional military forces, and nuclear weapons.
"Nation" is really the people, not the country or the state, and the reason it's mixed up to the point of having reached the dictionaries, is the strong nation-states that have been founded in Europe the last few hundred years.
"State" is the organisation that governs a country or region, and in extension all it's concerns.
Activity means hacking.
So... a government organisation from a country of ethnically and culturally distinct people are hacking shit.
It's state sponsored hacking or hoarding of vulnerabilities.
That looks hard enough to understand, but additionally it is "potential".
Is that a new way of saying "NSA"?
All joking aside... this is likely the tail-end result of the Shadow Brokers leak coupled with the recently-used exploits in the failed crypto-locker variant "Wanna Cry".