no, not running windows in a decade is still the better way.
only sort of joking. I run windows 7 and haven't upgraded.
no, not running windows in a decade is still the better way.
only sort of joking. I run windows 7 and haven't upgraded.
I'm going to wait this whole windows thing out.
Nevermind the fact that everyone is almost always behind a NAT and are basically unreachable for attackers to exploit remotely.
If anything, the newer versions of Windows are "horribly inescure" because they contain so many "unknown unknowns". But that wouldn't fit the narrative MS wants to propagate...
Have they? We just had printernightmare (CVE-2021-34527) a few months ago. In certain configurations you can even get RCE.
That's a remote authenticated code execution...
...which is how this fucking corporatoracy will try to maintain its power. You can point out the very clear and visible truth, but they'll just deny it. Fortunately, the number of people who realise they're being fleeced is slowly rising.
Of course, we can play the asterisk game and expressly state that if the machine is not connected to the internet and not used to browse the web, then it's probably safe. Or if you like browse the web in a VM. I still have to wonder if the patches for these kinds of issues[1] get backported to Windows 7.
As to the appeal for age, I think software ages like seafood in terms of security. Just because it's been deployed for years doesn't mean that there aren't vulnerabilities lurking in that code. Although I will concede that as Windows 7 loses users, the payoff for finding a vulnerability will decrease too.
[1]: https://www.sentinelone.com/labs/cve-2021-3438-16-years-in-h...
What if you just browse the web in an up-to-date web browser? In both cases, the browser has a sandbox that should keep you safe.
Multiple layers of defense are of course better—but in both cases, someone would need a zero day to escape the sandbox, right?
Excuse me while I die of laughter.
People are still finding bugs which existed in XP. Which was supported for 12 years and was released 20 years ago.
7 was supported for 11 years and was released 12 years ago.
> Nevermind the fact that everyone is almost always behind a NAT and are basically unreachable for attackers to exploit remotely.
Sure, except that the vast majority of malware doesn't come from a remote attack.
Ones which existed only in XP and not later? I doubt it. On the other hand, as for the bugs which exist only in the later versions...
Sure, except that the vast majority of malware doesn't come from a remote attack.
...then where does it come from? Don't say "users installing it", because that's nothing more than an authoritarian excuse to take away freedom --- and as the saying goes, "Those who give up freedom for security deserve neither."
When did I say that? Finding a bug in Win10 which has existed since XP is just as dangerous as finding a bug only in XP, given that the patch Microsoft releases for Win10 will not be released for XP.
> ...then where does it come from?
Vulnerabilities in locally installed software? Supply-chain attacks, drive-by attacks, clickjacking attacks? Or, you know, users installing it? Believe it or not, users frequently install malware; otherwise, there wouldn't be such a proliferation of fake "driver" sites on the internet. I'm not sure how you reached the conclusion that facts are an authoritarian excuse to take away freedom, particularly since I have never and would never advocate for disallowing people to install whatever software they like.
Which security issues are worse?
A built-in cloud command logger is quite bad if you don't know it's there, and is a security risk even if you know.
Some people occasionally enter things like private URLs, tokens, UUIDs, pathnames and query value onto the command line. Which is fine if they're the sort of thing that's ok in your local, private command history. Not so much if it's sent upstream.
But like I said, you do you. You'll figure it out eventually, probably at great cost.
Obviously the correct answer is "neither," but if you're deciding between Windows 7 or 11, that isn't an option you seem to be considering. Random people on the internet in countries with lower costs of living than yours will happily install malware on your computer to drain your bank account or cryptolocker you for a couple thousand bucks. Microsoft makes way more money than that (as does every single Microsoft engineer) and doesn't care about attacking you, at least not in that way.
(Also keep in mind that Microsoft surely has a bug tracker with a pile of WONTFIX'd security vulnerabilities in Windows 7 that they just didn't get around to fixing before EOL, and almost certainly that bug tracker is less locked down internally than raw telemetry data, so if you assume Microsoft or its engineers do care about attacking you, that's probably easier on Windows 7.)