My long goodbye to Windows XP (2022)
woodfromeden.substack.com
woodfromeden.substack.com
>> My computer is also not some old rubbish. It has an Intel Core2Duo CPU with 4 Gb RAM. It was top of the line in 2009.
Just because you had a top of the line PC in 2009 does not disqualify it from being 'old rubbish' in 2023. A Core2Duo is ancient at this point.
>> The truth is I have never been hacked once in the eight years I have had this computer.
Or something has been compromised or exploited and you've had no idea because it's not something obvious like opening your CD-ROM drive automatically.
>> My belief is that computer security is highly overrated. With a decent firewall, which every router has these days, only your own activity can expose you to attack from hostile actors
This probably explains the author's mindset. An outdated belief system that the only thing you need is a firewall to stay safe on the modern Internet.
Even worse, the author's successor computer is a Windows 7 PC, which is already out of support
Today? I take above average precautions but I would never claim that my system is not pwned on some level. That feels like arrogance and hubris (as well as a little bit of "I played Russian roulette several times and I'm fine! It's dangers are overblown:)
This is addressed two paragraphs after the one you've quoted.
And it's equally an incomplete assessment based on the same "This is fine" attitude. The computer could be participating in a botnet dedicated to bring down the network in hospitals or steal their sensitive medical data, and the author would never know.
Also you're missing the obvious solution, using a long-term support system with a robust audit process and well timed security releases. Author's setup will NOT be safer than that.
Core 2 Quad was already out for a couple of years, and in 2009 Intel already had the Nehalem based i7 with quad cores and 8 threads that moved the goalposts an insane amount it became a staple CPU for the next decade till Ryzen launched.
I still have a Core 2 Quad and Duo chips kicking around the house but at around 17 years old they're long in the tooth already to be remotely useful at anything. Even a raspberry pi would be better.
A 4 year old Android flagships has more performance than those, let alone performance per watt where they're just not great to fire up at EU energy prices. At 65w-95w they make the most insane gas guzzling machines you could ever (not) want.
Unless you get your energy for free, best sunset and scrap them for something more power efficient.
Used one myself until 2018, was a great piece of tech.
In very broad terms the idea should be to profile what the outdated thing is actually needed for and restrict all possible requests to this narrow allowlist and put it behind a gateway that handles the actual connections from the rest of the network and rewrites the requests it forwards.
This guy is talking about arbitrary usage by a human which is far more risky and all he thinks is needed is to block off some unused ports and protocols.
Speaking of the CD-ROM drive, Windows XP is vulnerable to malicious CD-ROM discs thanks to AutoRun [1] and can be compromised just by inserting a CD, from which Windows XP will happily execute code automatically. Firewalls don't protect against that.
[1] https://en.wikipedia.org/wiki/AutoRun#Issues_and_security
If Microsoft cared more about security, they would keep releasing such shovelware at modern editions of Windows.
Why? Well, I really like the screen and it happens to be setup in the nicest spot I have in my home to work. In particular, it is the best place to video conference ( Zoom, Teams, or GoToMeeting ). The real answer though is because I when I sit down at it to get things done, I rarely run into a limitation that makes me want to move something more powerful to that spot. I am lazy, and it works. The machine is fast and responsive. Mostly I just forget that it is old. When I am thinking about it, I guess I also get a kick out of it. So, it adds a bit of fun.
I do email and office work ( documents, spreadsheets, presentations ) and browse the web of course. I author and run a few containers ( Podman ) to verify stuff engineering is creating for a key project. I am using it to teach myself Kubernetes and a bit of DevOps. A lot of the “heavy processing” I do it “in the cloud” anyway. Obviously I am not gaming or editing hi-res video. That said, I do so a fair bit of audio processing on this machine. It is my “work from home” computer.
I originally put Arch Linux on this machine to “get through a few days” when my laptop got damaged. “A few days” has been a couple of years now because it has worked so well. MacOS was really slow on the few apps I tried. Worse, like the author, I found that none of the modern software I want to use worked. With Arch though, everything is up to the minute. For browsers, I have Firefox, Microsoft Edge, and Slimjet ( all the very latest versions ). All my compilers are right up to date ( Clang, GCC ). I am even running .NET 7 on this machine. As Arch is a rolling release and I update every day, I have the very latest security patches for everything.
I am not advocating we all use old computers. I guess my point is that, for most of my day to day professional life, a machine much like the one the author had has been just fine. It surprised me too.
I use the 2009 iMac more than my 2023 M2 Pro Mini, although the latter machine is IMPRESSIVE (to say the least).
You are not gaining much by doing this, and are assuming significant risk. Even if specific portions can be quantified away, it's the unknown unknowns that should scare you.
Try a Linux distro again maybe? With some non-default themes and Wine, it really should make a better WinXP than WinXP.
Or at least use something like https://github.com/kirb/LegacyUpdate or the pirated ISOs that get updates from the Windows Embedded POSReady channel -- Win7 POSReady is supported until late 2024, and XP was until 2019.
There are safe ways to do this, but I worry the author may not be aware of them.
This doesn’t just happen for operating systems. Many vendors of on-promise proprietary software do the same-databases, middleware, ERP suites, etc-most of them have a special program for customers who want to stay on really old versions, in which they pay extra $$$ for updates compared to customers willing to move to a more current one. If you accept proprietary software as ethical, I can’t see how this practice can reasonably be accused of being unethical.
I use them anyway but only for gaming to limit my exposure.
> Many vendors of on-promise proprietary software do the same-databases, middleware, ERP suites, etc-most of them have a special program for customers who want to stay on really old versions
You can't really compare enterprise class software with something that is sold directly to consumers.
Enterprise, Server and Education licenses support "Diagnostic Data Off" telemetry level. I think they'll sell Server to anyone, and even though Enterprise is only sold to "businesses", it doesn't cost much to set up a corporation, and now you are a business customer.
Not saying I'm a fan of Microsoft's telemetry policies–but it is not like people are forced to buy Windows, especially nowadays, there are other options: macOS, Linux, Chromebooks. Don't have to worry about telemetry on my Linux box, and Apple is a much more privacy-friendly company than Microsoft. If people don't like Microsoft's policies, they can vote with their feet.
> You can't really compare enterprise class software with something that is sold directly to consumers.
Microsoft no longer supports Windows 7 for consumers, only for certain enterprise use cases. So in the context in which it is still supported, it is enterprise class software, and other enterprise class software is a valid comparison.
I'm not in agreement here. Apple likes to paint themselves as more privacy-friendly, yes. Whether they actually are is another story.
They have a lot better PR that prevents them from doing stupid skullduggery like unwanted news and "special offers" and "payment plans" in edge. But a Mac calls home a lot even when you are turning telemetry "off".
I'll try the enterprise version (I have MDSN) but last time I checked it I am pretty sure it gave the same options.
That's just a prettier word for the same thing.
And bringing up Oracle as your reference for ethical behaviour is certainly... a take that doesn't really say what you think it says.
Did we always agree with the decisions of Oracle executive management? Nope. Of course, so long as you work there, you can't say that publicly. But, even though there's quite a few things that Oracle did while I was there that I strongly disagreed with – I can't see the problem with charging extra for supporting really old versions. It is just common sense, and it is part of the package the customer signed up to at the start – the collateral given to the customer as part of every deal explained it. Many other vendors do it too. A consumer might legitimately claim they didn't understand what they'd signed up to, but that's not believable when a billion dollar company signs a million dollar deal.
Oracle has over 100,000 employees today. I have no idea how many ex-employees there are – I've met so many over the years, we are everywhere – but I guess it must be well over 1 million by now.
Of course because they are profit driven entities and they can’t charge for security patches, they just stop writing them.
Personally, I don't know what they're talking about, but I've always had a smoother/faster (albeit a bit clunky/glitchy sometimes) with Linux than Windows. Even when I dual booted Win7 and Ubuntu, Linux was always faster. Currently, I'm using XFCE w/ Arch on a 6 year old laptop. Programs open very fast, I get regular sw updates, and I've been running it for work for four years.
I am regularly using a 14 year-old MacBook on plain X and it is surprisingly fast.
And that's why Linux will stay in the server for majority of people, not on their desktop.
"You just need to enable something with some parameters and you're all set!"
Seriously?
Seriously.
You can either have a system where somebody else is deciding on your behalf how your system is going to be configured, or you can have a system where it's up to you to opt-in to the stuff you want. You can't have both.
The past week we have had two major Linux discussions and in each thread there is a semi flame war that starts because some had to voice yet another "this is why Linux is so hard for nan to use", as if it was a novel or constructive observation. It's not.
Yes, if it is a reply to a problem where someone "Tried linux and it was slow, so didn't use". If system configuration debugging were in their taste, they would have done so. So it's the "Just configure parameters <x>" which is the pointless rehashing.
If it is too complicated for a HN reader it is going to be too complicated for 99% of people in the world. Get off your high horse.
I know how to enable something with parameters.
if others don't - that's fine. They can learn or they can deal with other operating systems.
I really don't care.
I don't think that this sort of attitude will result in an environment that's encouraging for more people to use Linux distros. A better approach might be going straight into suggesting whatever information helped you in the past.
For example, the Arch Wiki typically has useful information on many topics: https://wiki.archlinux.org/title/Nouveau
When dealing with other distros, there can be more specific sites too, like: https://askubuntu.com/questions/1032357/how-to-switch-from-n...
Not all of those are always up to date, though, so some digging around might be needed. Many will just give up or not even try, if they're faced with a dismissive attitude. Dialogue around what is the most helpful, accurate and up to date guide would be better!
Linux crowd, seems have not made their mind on what they want to reach as a product for end user. Or even do they want to have end user, not another cool kid to hang on with in IRC and dig inside OS. Some say - I wanna Linux be used by everyone! Other say - works for me and I don't care on the rest [of the loosers who cannot read hex dumps, ha ha ha]. Somehow the success of Chromebooks being ignored and not learnt from.
Thus, without clear goal, mission, product vision and focused team of product managers it's kept being amorphous [as I see it]. Definitely something to learn from WSL project made by Microsoft. They found the need - they did it. You may even see it as cathedral vs bazaar issue.
The only distant focused effort I'm aware about is Canonical/Ubuntu here ( I'm not sure on RH/Suse efforts ) - they are working on MDM with Intune, they have at least some telemetry ( not totally blind on real user cases ), they have Pro edition and even cooperated to be the first WSL distro, naturally paying back in brand awareness, common approaches and so on.
Make your mind, Linux.
Ubuntu is great, but it would be nice if there was some Ubuntu+ addon subscription service where I could pay to make the bullshit go away. I've got other stuff to do than still trying to get peripherals to work, in 2023.
There should be official compatibility list for laptops of all price ranges and whoever buys something not from the list needs to deal with issues themselves.
"just use linux instead of windows!"
at the same time as
"you can't expect linux to work on everything! do your research!"
So which one is it? Is Linux an OS that you can just replace Windows with straight away, or is it not? Most people don't care about the underlying reasoning why their printer doesn't work on linux - they just know it would have worked on windows fine.
Even something as simple as setting up a sound card with recent drivers required going to weird, slow-loading taiwanese websites with no english text to get the current drivers right from the manufacturer of the sound chip.
Even worse, with XP you had no GPU accelerated desktop at all. Sure, lower latency, but the PC noticeably struggled even moving windows if something happened in the background.
And if you do so, Linux works just fine as well. But you were comparing Windows XP to people trying to install linux on old, specialty hardware bought for use with Windows, so we’ll have to keep the same circumstances as well.
The minute windows update would automatically load the Nvidia driver in the background, the screen would go fully black with no going around.
Searching online, the combination was unsupported by Nvidia and there was nothing you could do.
Linux with nouveau worked flawlessly. No kernel parameter, just boot using a live usb and everything works.
Yes, sometimes you can hit a weird hardware issue and need to revert a firmware blob or add a kernel parameter to disable something. These are rare occurrences, not the norm.
Every platform has its quirks. It's just not true that windows or macos is perfect, you are simply used to all the weird quirks.
It has to be said that llvmpipe seems usable even with Firefox, but not as good as reverting to mesa-21.3.5 so accelerated graphics actually works.
(17 years is a good run and I have my eye on a nice clean X201)
The laptop was something like $300 back in 2012.
It is not purely irrational, in fact it is spelled right out in the article why the author does so: he finds the Windows XP interface much better as a user than any other OS.
I can't say i fully agree personally, but the core of the problem and really the reason i don't see any of this as irrational is that people do get used to the interfaces of the OSes and programs they use and updates pretty much always tend to come with changes to those interfaces that are seen as degradation.
Though i do disagree with his assessment of Linux: while perhaps whatever he tried was slower than Windows XP (i remember reading that Lubuntu doesn't focus on low end systems anymore), Linux can be much faster. And also it is the only mainstream OS where you can have the latest and greatest underlying kernel and libraries without being forced to change your desktop interface (though depending on your choices, some DE can take more works than others).
As mentioned in another reply IceWM would also be very close - at least compared to classic Windows - but that only gives you the taskbar and window themes.
Updates for the sake of updates is not a passive, neutral status quo. It benefits certain participants (both the ones on top of the power hierarchy capable of rotating the hamster wheel faster and faster, and the ones on the bottom, who, in accordance with this or that fashion, slap together something that is not supposed to work at all unless you update everything) while others pay the price. And it's the path of least resistance that people choose.
In the end, it's just marketing. If you can add a couple of commas here and there to make the whole thing crumble, which allows you to announce “newer better version with support for new technology, etc.”, it's way easier than explaining what you change, and why, to the inquiring public. The IT public, as we can see, is pathetically neutered, and acts like careless kids in the free-for-all amusement park.
Also, the author can totally get Linux with the leanest DE he can still stomach, and have all the fresh software. Core 2 Duo with 4 GB of memory is still a decent system, especially with an SSD. However, his problem is NOT the software, his problem is that the websites he uses stop working.
Anyway, I was talking about being inquiring. When you look at that list, surely, some questions do rise. “Why should I worry about all of that to read three paragraphs of text on some webpage?” “Which actions have made it so?” “What should be done to fix it?” Right?
Yes, a 3 months old release of chrome is not suited to use day to day. I link all the known and published CVE on chrome, but if you want to nickpick you could "just" check those which start with 2023-*.
Why does displaying a piece of information that would fit onto a single 80×25 text mode screen absolutely require exposing to a third party a potentially (and, as mentioned, effectively) vulnerable WebHID functionality (which is non-standard, and seemingly only exists to make ChromeOS less mediocre operating system), various WebGL libraries and wrappers, ever-growing Javascript and CSS engines, and thousands of other entities? Someone who grants the whole internet access to local service ports by not using a firewall is considered a fool, but at the same time “non-foolish” “security conscious” people start their browsers, and see no problem in all the services embedded in them.
Isn't relying on a constant (and never ending) stream of updates from white knights in the holy castle in the manner you describe just a subscription model without a defined price?
Who controls the Web? Is controlling the web client enough for that? What benefits the endless rat race might give to them?
How come there's a hidden dependence on corporate products and their support cycles even in the process of using seemingly “open” technologies, say, for government sites and services? Is “I have no idea, my code absolutely requires latest libraries” a valid excuse?
Can mindless acceptance and circular finger-pointing between web developers, library authors, browser developers, and users solve these problems? What needs to be done?
My assumption is they like the UX of Windows XP better than later versions of Windows. I sympathize, because I think that flat software UI design has made computers less fun to use, but I just use theming software at the expense of the stability of my explorer.exe
Clever! Security by running an OS which none of the exploit authors are targeting anymore.
Now I have the mental image of some intelligence guy working on a “get into our geopolitical rivals’ grid in case there’s a war and we need to cause a blackout” discovering the author of the post.
Maybe he will meet up with some friends in “assorted fraud” industry at the local after work watering hole and they can nostalgically steal the post author’s bitcoins together. Hacking an XP machine might trigger a midlife crisis though.
Just the other day I found myself capturing a Vista machine into a VM just to preserve some perpetually-licensed software that we can't ever install again because the activation server's gone away
This is very common, and these vulnerabilities are sold for a lot of money and the buyers make sure to protect their investment as long as possible. Of course that also means they go exclusively for high-value targets which means end users are most likely fine (see Pegasus as an example). But that's not the same as being actually secure.
I'm not ignoring them, I'm just assuming that vulnerabilities discovered by bad actors will follow more or less the same distribution as those found by security researchers.
If we're talking zero-days, then XP offers no more or less protection than any other version of Windows on that front.
Someone looking to hack the last remaining XP machines would just scroll down the list of new exploits and test them out.
The hacker does, GPZ does not need to know.
- a windows 2000 laptop that I only stopped using (a while) after win2k stopped getting security updates, and the linux i put on it didn't work very well.
- a flip phone that was gloriously good at doing the only two things it knew how to do (calls and sms) that I had to stop using because it literally stopped having compatible towers to talk to.
- a 2013 macbook with a keyboard that still works, but it can't get the latest OS updates anymore, much like OP's XP machine.
I feel like there's a willful blindness -- it's very profitable for companies to keep everyone upgrading all the time, but it creates a lot of trash and there's really no need. There's a huge swath of the population who doesn't mind having 20 year old appliances or cars, and who views their digital tools as just another appliance to be replaced as infrequently as possible.
Those of us in tech need to consider the moral prerogative of slowing the trash cycle and the frugality enabled by letting things work for decades. And to stop pretending there isn't a user base out there who will insist on using things for decades even if we tell them it's not advisable.
If a lack of web browsers is the problem: https://github.com/blueboxd/chromium-legacy
That was the situation that finally prompted me to buy an iPhone.
My understanding is project zero is about finding new zero days, not cataloging known vulnerabilities.
As for why the mouse is fast in Windows the interrupts are handled by the kernel in a very special way to perform almost mind reading levels of speed even over the bloated USB stack.
I suspect it to be a nightmare to maintain as USB upgrades happen but who knows.
I used Windows 7 until my SSD corrupted pretty much 5 years on the day after I installed it on the 400GB Intel drive. It started with games crashing and then after one such crash (black screen, not blue screen) it just refused to boot because some important file was unreadable.
Choosing your SSD will be the most important choice you make in the future, as I said previously I have 2x Windows 7 and 2x linux machines on older drives that have lasted 10+ years 24/7. So something is wrong with modern SSDs, no doubt about it.
About sites deprecating browsers, you might be more lucky with really old browsers now a days. My bank refused to work on a 3 months old Firefox, but a 6 year old Firefox (installed to run Java Applets which BTW where WAAAAY better than .js + WASM, and no; they where not insecure like all the naysayers pretend) ran fine with some layout glitches.
People miss how much of a security risk using w10/11 is because microsoft is constantly pushing updates that break your install like an xp era virus used to, or just straight up doing malicious things adware and other malware used to do. these are not "security minded" operating systems. You are not "better" for using win10 in terms of security.
Yeah but it's not like they are all guaranteed to fail. I still use an OCZ Agility 3 in one of my PCs to this very day, it runs 24/7. And that was probably one of the worst "early" SSDs for failure rates.
The only issue I've had was a few months ago Google Chrome now gives a small nag-bar on startup - supposedly dismissisable with a -flag, but the flag itself is either no longer functioning for some smirk sanctimonious reason, or more likely, hilariously not tested, and has since ironically regressed.
The only gripe from XP->Vista->7 is the respective mediocre, to amazing, to abysmal local search functionality.
Regarding 0-days: back when I had virtual valuables and wasn't a complete random, I had been specifically targeted and smitten with a TeamViewer 0-day. But, like the author notes, that would had happened regardless of my subscription to any one of the myriad of dubious AV products of the era.
win7, with its incredible native and specific backward compatibility mode, supports more apps than any other virtual ecosystem. 25+ years of great software - some of which runs smoother than their great descendent counterpart. Shame to not at least have a box sitting around for the occasional sporadic encounter with an inane, archaic file type, needing to be fandangled into a newer format.
[0] https://help.steampowered.com/en/faqs/view/4784-4F2B-1321-80...
Grab a copy of FileLocator Pro and wire it up to Ctrl+F in Explorer. It's fantastic.
But, surprisingly, most of the time I find what I need with built-in search in the Win10 Start Menu. Although I had to slap her hands not to show me web results.
Ok, I was also slipstreaming my installation CD-Rs and really putting time into it. Yet. The things that used the most memory and power were probably flash player and counterstrike. Those were not bad times!
I seriously never got malware, and always wondered what everyone else was doing differently than I.
Never have I had my personal computer owned by some exploit that resulted in data loss/breach.
Thus, undesired upgrades are a greater risk for personal computing than security. Simple as.
Almost nobody who makes a big deal out of this has ever actually been affected by it, they're just parroting what they're told.
Either that or they're paid to come and clean up the mess after a company has been hacked due to one or two random servers not being updated in the last few years.
Your point may or may not be true, but it doesn't follow from your logic.
I've had more e-ink devices fail by being knocked into the river while fishing than I have from any other cause of accident, does that mean fishing is the most common cause of e-ink device death because it's my personal anecdotal experience? I doubt it.
From a personal end user standpoint, most people will never be the direct target of a attack (and if you are, you are probably in a situation where being 100% up to date won't save you). If they get owned, it will be by a drive-by exploit or because they directly executed malware.
Drive-by exploits tend to target the most popular systems.
In the last 10 years all my updates on Mac and Windows alike have been a matter of clicking OK and waiting 30-60 minutes.
On Linux and BSD I've had some more issues at times but that's been more because of my own messing around.
It gets even better there as well, until somewhat recently after Microsoft would release a Visual Studio update, older versions would be removed from their site, and there was no way to roll back. So if you chose to update, and it broke stuff, then you were in a fun spot. Fortunately that is no longer the case, but ugh - bad memories. This is one of the big reasons I'd like to move over to Linux, but games + work make it difficult to pack up and move. For all my bitching about Microsoft's practices in general, I don't see myself moving away from Visual Studio any time soon, and it's Windows only.
[1] - https://www.howtogeek.com/fyi/bug-in-windows-10s-latest-upda...
I don't like the way VS went from a package to software as a service though :( But Microsoft just love their subscriptions.
Hell, I'd do this for all updates if Firefox didn't require an immediate browser restart every time its upgraded.
Of course Linux has this live patching thing to the kernel which is pretty cool. But I thought you needed an Ubuntu One subscription to access that on Ubuntu?
Cannot comment anything on Mac, have no experience.
On Windows side, your statement is simply waaay overestimated and honestly speaking is not true. Using your words - Hell, it's even can update video/networking drivers _online_, without restart, not even mentioning smaller things like Defender definitions updates.
Those apps installed from Store, do autoupdate without requiring restart as well.
Firefox, shows a tip on update is available and patiently waits, nothing "require an immediate browser restart".
Heck, you can even configure to use devices in your local network to act like caching of downloaded data and to not redownload the same stuff from internet to each workstatation in your network.
You either stuck in the past of WinXP era or producing defamation on purpose.
Coming back to Ubuntu, question regarding
> In Ubuntu, there is a setting to have all security updates happen automatically every day in the background
will it honor you are on metered connection like WiFi hotspot shared from phone?
In the last 10 years my updates on Windows and Android:
- have decided to hide the scrollbar (Windows and Android)
- have decided that i don't need a menu (Windows and Android)
- have decided that they can do whatever they want with the titlebar. (windows)
- Have decided to hide the keyboard cursor (Windows)
- have decided to change the default alarm sound (Android)
- general changing of behavior after updates (Are there people paid to change the UI continously ?) (Windows and Android)
- disabling accesibility settings (fonts, colors chosing) (Windows and Android)
... and so on, and so fort.
Not saying your point isn't valid but it goes for Apple too.
I'm on FreeBSD now myself (with KDE, which has a ton of options so I can finally set things up the way I like again).
Apple was actually pretty much aligned with how I liked things, but in the past years things have become much worse. I hated the flat redesign, I hated mission control and its multiple desktops in a row instead of a grid, and many more changes that were forced on me without having a choice.
Once upon a time updates were something I'd get excited for. Now it's a dread of what will break next, what new advertising will assault my eyeballs and waste my attention, and what telemetry will subvert my privacy or deteriorate my control over my device.
This is why I've "just said no" to Windows ≥ 10. I really want it, but these anti-features need a reliable off switch.
This is a ridiculous thing to say. The reason that there are so few misleading ads, so few zero days being exploited, and in general a much less tricky landscape today is because the unyielding and unrelenting efforts of people improving computer security.
I can open youtube on my phone right now and find an ad saying "everyone who clicks here will get $1000", misleading ads are still everywhere even if they might not be malware. And I doubt ads exploiting browser 0-days were actually that common back in the day, ads in general weren't nearly as common.
It remembered me when I installed Ubuntu on my mom's 2009 laptop because Windows 10 was unbearable slow, and it worked much better.
Also the title remembered me the movie The Long Goodbye, what a movie, love Altman.
By failing to reproduce that success, Microsoft has ceded most of the moral market share to Apple. Though, as a Linux user, every time I see a Mac desktop I can't resist noticing how often would it lock up and display that rotating "busy" mouse cursor in place of what the proud Mac owner actually wanted to do at that moment.
Seems Microsoft has to squeeze in at least one bad version between good ones.
But never has a new Windows version been made available where people didn't initially hate them at first, XP, 7, and 10 included. It's not until the version after gets released when people really start appreciating what once was.
95 Good, 98 Bad, 98 SE Good, ME Bad, XP Good, Vista Bad, 7 Good, 8 Bad, 10 Good.
Counting 98 SE as a separate release does seem like cherry-picking in order to make the pattern work. Then again, you could also say the cycle started with Windows 98 (putting the whole of that release into the good pile), and you'd still have a remarkably consistent pattern across two decades and seven versions of Windows. Honestly makes you wonder if there's some deeper cause related to Microsoft's organizational structure or something.
I use 10 at work and 11 at home and after changing the taskbar settings to put the start button back on the left I don't even notice switching.
Same here by the way, I don't use it for anything but gaming and work for the tracking reason.
That's because it isn't, Windows 10 and 11 both identify internally as NT10.0.
For some context: Windows Vista, 7, 8, and 8.1 identified as NT6.0, 6.1, 6.2, and 6.3 respectively; Windows 2000 and XP identified as NT5.0 and 5.1 respectively.
Windows 2000 was no-nonsense, but all good stuff. The good bones that Windows XP got came straight from Win2k.
The only real problem it had was a narrower hardware compatibility profile, but it still wasn’t that bad.
What made XP great was how reliable it was compared to previous Windows versions.
Some people claim this was mostly due to bad 3rd party drivers and not the OS itself. But even if that's true, from the user perspective it's very hard to tell the difference.
11 has all the same problems 10 has, but brings many significant improvements both in the backend and frontend. Hardly trash.
>never has a new Windows version been made available where people didn't initially hate them at first
Windows 95 and 98 were both received to applause and fanfare, 95's stellar reception in particular is probably still unmatched to this day.
The only shift in user experience that I can equate it to is maybe the jump from candy bar and flip phones to the iPhone and Android. In addition to the UI, it brought real multitasking to a consumer OS.
If you think 10 is "gold" and 11 is "trash" I assume you're suffering from some sort of stockholm syndrome from using 10 too long and haven't actually tried 11 yet because it's just a reskinned 10 (and visually, it looks a lot better).
Periodic reminder that “Stockholm Syndrome” was a complete fabrication based on no clinical evidence invented on the spot to discredit an ex-hostage who was making legitimate criticism of an unnecessarily violent police intervention by one of the architects of that intervention, because they had no rational defense.
Its invocations in debates are also typically as an attempt at a thought-terminating trope to evoke an emotional response that covers the lack of actual argument, which fits the history of the term well.
I've been on 11 since it was released and I find it to be objectively a worse experience. On Win 10, I could game on one screen and stream a video in a browser on the other. On Win 11, I get stuttering on the streamed video.
It's also failed to update twice now. I invested hours into debugging the issue the first time. This time it's been days and I'm about to just do a fresh Win 10 install over this nightmare.
My current 11 install has never failed to update, but I have experienced various update failures before on 10. This sort of issue is present in both versions, it's just random whether you'll experience it or not, and I wouldn't be surprised if the stuttering issue is just some random driver incompatibility too.
No, it's not random, which I know because I stumbled upon the solution. The problem was that it was using an old 100MB partition as the EFI boot partition. Nowhere in any of the system logs did it mention this. No error message said anything about it. Ridiculous.
and I wouldn't be surprised if the stuttering issue is just some random driver incompatibility too.
Why? My system is the same hardware after the update. In fact, the only thing that's changed (and this happened awhile after the Win 11 'upgrade') was a video card that's 3 - 5x faster than the old one.
And as others have observed, 2000 was an immediate hit with everyone who tried it.
Yes, you read that right: DirectX 3.0a.
Windows 2000 by contrast supported DirectX all the way through DirectX 9.0c, same as Windows XP, 98, and ME.
This is why Windows 2000 could run games properly.
Win2k was a huge improvement in every respect. My 2c.
(1) Win2k Home was much cheaper than Win2k Pro. Possibly an upgrade version was cheaper still.
(2) I had a bootleg version
(3) I started working for real money in 1999 so didn't care that much
(4) An OEM CD came with the computer hardware kit.
https://www.cnet.com/tech/tech-industry/microsoft-outlines-w...
> When it debuts in February, Windows 2000 Professional will sell for an estimated retail price of $319, the same as its predecessor, Windows NT 4 Workstation.
Note that there was no "home" edition of Windows 2000. https://en.wikipedia.org/wiki/Windows_2000
So it's one of 2, 3, or 4.
Another option was student bookstore. Microsoft sold its wares at universities at steep discounts.
Edit: a sister comment jogged my memory. I bet it was either a giveaway by an EECS dept or a heavily discounted disc from the university bookstore. Which is why I do not remember paying a noticeable sum for it.
I still wonder how they would have thought this was better in any kind of way. A windows 2000 home release could not possibly have had as many problems as ME.
When Windows XP came out, Microsoft unfortunately made them report every key given out, and the free ride was over.
They would have to put up with Windows ME, at least in Microsoft's eyes. Which was the first version you could play games on and leave it running for hours between crashes, lol.
I also used Win 2k Pro and it was an amazing leap coming from 98, yes. My laptop came with ME but it sucked so bad I changed it after a week.
It depended on the definition of "hours" but sometimes the "hours" were very short.
Huh? XP added nothing to 2000 except useless bling.
I remember being gifted Shattered Horizon (a DX10 launch title) and thinking "it really doesn't look that great"
Halo 2 for Vista also required DX10 even though the original Xbox was hardware DX 8.1 only
I stuck with 2000 as long as I could before gaming (and maybe.. a certain version of Visual Studio?) eventually forced a switch to XP (with the "classic" theme).
I have had my fair share of crashes though.
If I am being maximally charitable, the benefits that come afterwards are drivers, gaming-related (DirectX) or security-related (which is not a user-facing feature). All of them are nice, but not at the cost that the end user perceives; a slow, painful experience, with an OS that crashes randomly and has weird inconsistencies everywhere.
I have mostly stuck to Ubuntu for desktops (since 8.04) and MacOS for laptops (since Snow Leopard).
(Unrelated, I also notice the busy cursor, which is why I went back to Ubuntu once I was able to get a desktop)
I think Windows peaked with XP and macOS with Snow Leopard, with the caveats that Spotlight-like searching in both was primitive/nonexistent at that time and would have been a great improvement, and XP didn't have virtual desktops.
That 2001-2006 era featured systems that had learned a bunch of lessons from 10-20 years of mainstream GUI computing, but hadn't been consumed by feature bloat and a bunch of Internet connectivity and convergence stuff that I'm not interested in.
XP's design was apparently polarizing but I loved it. I was in a modding phase at that point and loved making my own themes.
Their DE is just such a horrible POS. I had one extension/addon (?), which, due to some JS problem (all those extensions/addons are written in js), was slowly, over hours, hogging more ram, until eventually OOMimg the entire DE.
Sure, this is just a one-off bug, but please just read that to yourself out loud. Addons are JS. They can OOM the machine. Their interface runs over so many different abstractions that there is a whole web browser in there.
So yes, the author may have had a horribly slow experience with Ubuntu, and I believe that. Try LXDE or LXQt or MATE or anything a little more lightweight, and you may have a very different experience.
I've had my fair share of OOMs and crashes because of shell customization on Windows and they were all far harder to deal with.
I wish our industry would realize you don't need to move everyone's cheese around and slap on new lipstick every few years. Each time you do it throws away all the muscle memory your users have built up.
Sometimes I lament that pixels are so cheap to repaint. Imagine if someone reorganized where you keep your dishes on a regular basis.
The real dealbreaker is evergreen browsers and websites updating from whatever is available on Github, making up-to-date browsers a requirement. The newest browser you can run on this is Firefox 78.15.0esr, which, funny enough, tells you that it's up to date. I also second that security by out-of-date obscurity may be a concept. (The vectors available just don't scale, if you're not a target prominent enough to make this a sensible investment. Moreover, old hardware gives you things like ECC memory, which is also immune to rowhammer attacks, as it's slow and not that tightly integrated. Having no privileged network connections to any cloud services may help, as well.)
(However, I'm writing this on a rather fresh Apple Silicon MBA, because, well, the Web…)
This made me wonder if there are still working dev kits/tools with browser components available in such a way as to provide a fairly simple pathway from basic dev skills (or just "web browser example" code) --> up-to-date browser engine, running on 10.9.5?
Thinking of somewhat more obscure dev tools too, e.g. PureBasic, etc.
(That said, Firefox 78.15.0esr works still fine in most cases, but I doubt that this will be the case much longer, mostly because of CSS feature adoption.)
I'll guess you'll be happy to see this: https://github.com/blueboxd/chromium-legacy :)
https://github.com/blueboxd/chromium-legacy
I daily-drive this browser on a 10.9 Mavericks Hackintosh. It's great.
That is because MyPal is a fork of Pale Moon which forked from Firefox back when Firefox was still Firefox (before removing extension user freedoms, adopting Chrome's extension over it's own, and the heavy ram-bloat of multi-process, etc). Pale Moon only implemented "web components" last week. Sites that use web components features like custom html elements (defined by javascript) would just be blank spaces.
I wish Pale Moon hadn't added support but it should filter back in to MyPal eventually.
Backwards compatibility with Windows/AD has always caused issues with Active Directory becoming such a juicy target in the way system-to-systems interacted.
Just this year I moved my T420 from a phenomenal Xubuntu 18.04 install that was _just_ great, to PCLOS. I'm happy with the result after a lot of work, but I know there are still a ton of things that aren't what they should be.
Hundreds of keyboard shortcuts yet to migrate, hundreds of little add-ons skipped, like "did I grab whatever the equivalent of gimp-addons is, since I couldn't use apt-clone", hundreds of little scripts un-integrated from my desktop, including genmon scripts that do valuable things, which don't even have an equivalent for porting to KDE.
Before that it was...Ubuntu Netbook Edition (UNE). Tiny screen but wow it worked amazingly well on my Linux-reseller MSI Wind Netbook. I could hardly bear the upgrades away from that, to different distros, since everything worked super well.
It's hard to feel torn between such UserLand concerns (my stuff is how I like it!) and regular ol' userland concerns (my software does what I need, with the following somewhat clever workarounds).
> Exactly why even very light-weight Linux versions like Lubuntu feels slow on my computers I do not know. Maybe they lack the drivers for hardware optimization compared to Windows.
I remember this EXACT feeling coming from Windows XP, lol. I never did figure out what the difference was, but it definitely went away for me starting around Windows 8 IIRC. Today I can't discern a difference except that occasionally it seems like Linux is faster by default.
It also felt incredibly unjust back then, to a lot of us happy Creative Labs users, to migrate to Linux and learn that our slick cards & low latency didn't work that way anymore, or at all.
Fun read! Thanks for sharing it.
For malware developers those old boxes are uninteresting. To slow, to few, not worth the effort. They are the sloths of the predator and prey ecosystem of software security.
You do you, you’ll be fine until you aren’t.. I feel bad for anyone you convince that this is okay.
It seems that the major reason why XP worked for him was how dead simple it was. The fact is that there's no modern "simple" OS. I know. I've looked. The point-and-click simplicity of the 90s is quite plainly no longer out there. Even macOS, championed for its supposed simplicity, has grown a large amount of extraneous features and an outright hostility to those who try to use it in a nonstandard way.
Coming to think of it, it wouldn't even matter. All of the OSes I've suggested struggle with the same issue as WinXP, which is that there's no modern browser support. SerenityOS seems to be the only one which is making any actual strides to fixing that with its Ladybug browser (which theoretically could be ported to the other OSes), but even that is a work-in-progress.
This author doesn't believe that security is important because their crypto currency hasn't been stolen yet.
I don't know how one could possibly do a better job of conveying that they don't care and are just coming up with nonsense reasons to justify their bad computing habits.
They're free to do whatever they want, just like us all.. but I still cringe at the idea that somebody who doesn't know better could read this article and think running Windows 7 now is a good idea.
Recent example: in Fedora the firewall in default configuration blocks DHCP packets when you try to share Internet via bluetooth. In Windows traditions no message is displayed on screen nor printed to logs. Wireshark also doesn't show that packets are dropped by firewall. Takes a lot of time to figure out why the client sends DHCP requests and never gets a reply. Why do they enable firewall by default? And if they enable it, why didn't they configure all necessary services properly? I am not running a server in a datacenter, it is more an osbtacle for me. By the way, Windows XP had no such problem.
But Linux is better than Windows. For example, Windows 11 doesn't allow to use a computer until you configure a network connection. It has data collection without opt-out, advertisement and involuntary updates.
And Linux is better than MacOS because it doesn't make you pay three times more for hardware and get a laptop with soldered RAM and SSD. It is surprising that they have premium prices and at the same time try to save several cents on sockets.
If only Linux didn't have those tiny bugs everywhere it could be a viable alternative for people not familiar with console.
The RAM on M1/M2 has 200 GB/sec bandwidth. Hence must be soldered. Impossible with sockets at this level of power consumption.
Adding sockets significantly reduces efficiency and performance at the high end. Laws of physics.
Commodore 64 - stuck with 64k soldered RAM.
Amstrad CPC 6128 - stuck with 128k soldered RAM
No one bitched or moaned about it.
I prefer soldered RAM and SSD on my Macbook for the performance boost.
The act of entering some specific text into a field in a computer is something many people experience with the URL bar, or even (for most users) the Google bar. The act of following a tutorial somewhere to achieve a thing is also something that is nowadays practiced in society. Maybe even moreso that earlier, even if people expect the tutorial to be video for some reason.
This makes me think the gap between Linux having a more approachable knowledge ecosystem and people willing to acquire a little more computer competence should be kind of realistic to close.
I was going to comment that many Linux projects can have questionable hyper-"safe" defaults, another example being KDE forcing you to reboot on GUI update at some point. (I'm aware that apparently people were reporting bugs that would go away after rebooting, and they couldn't figure out a better mitigation.) But on the other hand, there are probably distros other than Fedora willing to forego security and ideological purity for more hassle-free start for the average user. So there's choice.
Lots of people laud Mint but I found Cinnamon to be ugly under the hood when going of the beaten path. I've enjoyed Plasma a lot more but found Kubuntu to have it with a myriad of bad configurations and defaults whilst my experience with manjaro KDE has been great.
On one I often had to rely on command to deal with stuff or use the commandline to get rare packages and to get em working. On the other there's UI for everything and I flip some checkboxes to have access to the default repositories, the AUR, snap store, flatpaks, etc so that i'm rarely lacking if i'm not opinionated about the source.
Someone can come up with a washlist of complaints and someone else will have experienced none due to different hardware, distro or wm and this becomes evident when discussing with opponents and detractors.
You would think that if there was one place where the dangers of not having the possibility of patches when the next “heartbleed” comes was obvious and understood by all (read: major software vulnerability affecting critical libraries) — it would be a forum mostly composed of software engineers.
If you want to go full old windows it's an easy next step to run this theme's setup script: https://github.com/grassmunk/Chicago95
But, it's hard to give up the real terminal, now that you've used it, isn't it? Modern Firefox, Python, tons of software just doesn't support it any longer.
A shame really. I'd love a modern Windows 2000. ReactOS not quite there yet.
https://github.com/tumagonx/xompie/ https://i430vx.net/files/win32/ https://github.com/Skulltrail192/One-Core-API-Binaries/issue... https://github.com/Skulltrail192/One-Core-API-Binaries/issue...
Well that's an interesting idea for detecting certain classes of hackers.
The author is much more likely to be targeted by automated botnets than a dedicated attacker who will actually manually look at his machine.
The author obviously likes security updates. He isnt running zero day windows xp (which is a hoot to expose to the internet btw) he is running fully patched windows xp.
The issue he says is productivity. With maybe some amount of trying to squeeze more time out of old computers. I can empathise with the first point but not the second.
Productivity isnt a function of just the OS, its also hardware and user skill related. I feel like he could be just as productive on either flavour of 22H2 as Windows 7.
I have a Win7 machine, for gaming, not directly connected to the internet. I hate it so much it's never going to be my main OS.
I'm forced to use Win10 at work, and I hate it even more.
I'm slowly switching to Linux (in a VM in WinXP64). From linux, currently I'm only using Firefox without a desktop environment; anything else is too difficult, too incompatible, too slow or too bloated. To me, Linux desktops really look and feel a lot like Win10, execept with a lot more bugs and lacking Windows' Control Panel (what's left of it, anyway...).
Anyone focusing on constant updates must be really young in my opinion. I understand your point of view. I was like that too. When you grow older you will start to notice how the OS you grew up with could do 90% of what your current OS does, using just 1% of memory, 1% disk space and maybe 10% CPU. At some point you will want to stop all this constant fight to get minimally better features (or even less features) at the cost of ever-faster new hardware and, at the same time, ever-slower UI.
Only then you will be able to understand my point of view.
I hope to never ever be that person, but you do you.
Using crypto as a canary for hacker intrusions, brilliant!
Be not the first by whom the new are tried,
Nor yet the last to lay the old aside.
- Alexander Pope.This sounds like many I talk to in that they refuse to learn or make any changes in their life. I don't think this is a positive attitude to have. He also sounds like a major cheapskate and my country is full of people like this very hard to argue why spending your money is a good thing (within reason).
HN uses might be young, but C# malware will run everywhere. Also, remember Blaster/Sasser? Good times.
https://github.com/nothings/stb
> Why not C99? stdint.h, declare-anywhere, etc.
> I still use MSVC 6 (1998) as my IDE because it has better human factors for me than later versions of MSVC.
EDIT: Found it - https://zorin.com/os/
Not 48 hours ago, I spoke highly of the benefits of Windows 7[1], as a user myself.
It is absolutely possible to use Windows 7 reasonably securely, if you take the appropriate precautions(again, see my comment)
> I can use the latest versions of Google Chrome
Firefox? Yes. Chrome? No.
Chromium 109 is the last version to support Windows 7. Here's the last working ungoogled variant [2].
Switch to LibreWolf[3] Firefox based browser with user.js modifications[3] pre-installed. Or if you don't trust librewolf, use Firefox and manually add the same user.js[4]
It's better for security than Chrome could ever hope to be.
Your web browser's javascript continues to be the predominant way for malware to make its entry. So just make sure to take the appropriate security precautions elsewhere, as mentioned in my comment [1].
> When Firefox stopped receiving upgrades I switched to Mypal browser, an open source browser specially made for Windows XP. It is cruder than Google Chrome but does the job most of the time.
Have you tried K-Meleon on Windows XP[5]? It's Old Firefox(pre-Australis) based, and still gets updates.
-----------
Windows 7 is the last legit good Microsoft Operating System.
It truly is a wonder and a delight to use and modify.
Anyway, all the very best on your Windows 7 journey. May it serve you well.
Cheers!
[1] https://news.ycombinator.com/item?id=35431587
[2] https://github.com/macchrome/winchrome/releases/tag/v109.541...
[3] https://librewolf.net/installation/windows/
better try New Moon 28 which is XP compatible fork of Pale Moon.
If so, thank you so much for your work! Also please get https://piped.video working in k-meleon somehow.
If you're not that RoyTam, I rescind the previous thank you, and the request.
[1] http://kmeleonbrowser.org/forum/read.php?19,154431,157231,pa...
So, here's a piece of information relevant to security and versions of Windows, I'd like to give exact and really clear references instead of working just from memory, but for such references just now I'd have to do a lot of digging.
From memory, I discovered that one of the security updates to Windows 7 Professional, as I recall, the last one, was the same as for a version of Windows Server.
So I guess: Since that version of Windows Server was intended for some of the most serious business computing on the planet, that security update should be pretty good, maybe good enough to be pretty good now!
I've been intending to use Windows 7 Professional as my server for my startup, but ... I'm also considering some version of Windows Server. I do notice that it appears that the versions of Windows Server go much longer, years longer, before "end of life" or "end of support" than the versions of Windows not Windows Server.
So, I'm considering getting a version of Windows Server 2019. I've done the shopping and am intending to buy.
Also I'm thinking of using my computer with Windows 7 Professional as my general purpose and software development computer (it is where I wrote the 100,000 lines of code for my startup) and plug together a new computer for the server for the Web site, etc. That computer would run Windows Server 2019.
I would like to know more about Windows Server, e.g., version 2019, as in
No disrespect, if I was still a windows user I would be on win7 too, however I can’t help but think about how naive this was with regard to security while I read it. I personally don’t know how XP could make a person more productive, but I really can’t understand throwing all caution to the wind and doing mental gymnastics to rationalize it.
I admit it’s possible that being on XP has some obscurity benefit, just like if you only used DOS. Having a firewall is de rigueur as noted in TFA, but far from foolproof. No single layer of security is airtight.
Probably the OP has heard of defense in depth, maybe not. Security of any system is porous. It’s like layers of Swiss cheese and so long as all the holes don’t line up, you don’t get owned. Being that windows exploits often affect versions all the way back to 3.11, XP might be more holes than cheese.
Short of booting directly into the browser, you’ll still need some minimal UI, at least for switching between VS Code and your browser of choice. That’s the part where the modern OS should not get in the way, but often does.
Is this an option for individuals?
How can you be that sure and are you confident to connect this computer to any random public network? That's just a demonstration of ignorance.
> Maybe I have been hacked but simply have not noticed. That is also a possibility. But I store some crypto currency on my computer and I make crypto transactions from time to time. If my computer had been compromised by an invisible attacker I figure that attacker would have had an interest in crypto assets.
Then set your default apps as you want
Its fine imo