Government computers running Windows XP will be vulnerable after April 8
washingtonpost.com
washingtonpost.com
2. Everyone has known about this for more than 6 years.
3. Microsoft already extended it once.
4. To the person who said this: "For all the money we collectively give Microsoft, they were not too receptive to extending the deadline. There was some grumbling that they were not willing to extend." ... A) See 1 through 3. B) You suck at your job.
Tangentially, this is why in every project I've been at I always push for upgrading to the latest browser. Initially there is some resistance, but once in a while you meet with a gov manager, that has some pull, and will push back on IT. That's been the case at CBP. A year ago we were all supporting IE8 and cursing every minute of it. Now we're happily developing to IE11 and latest FF. Sadly it takes an adamant developer to push repeatedly for this when it should be IT itself forcing users and all developers to upgrade, if for nothing else than plain old security. I think they're "getting it" now though...
https://www.microsoft.com/windowsembedded/en-us/product-life...
The equivalent end-of-support date for XP Embedded appears to be January 12, 2016 (though I don't understand the end-of-license date about a year later). And I'd have to think that that banks using XP Embedded for ATMs would be extremely likely to pay for ongoing security fixes if they still depended on it in 2016.
The big chunk of pain though is really windows 2003 server which is EOL July 2015. People seem to have missed that one coming!
“Nobody is going to be promoted on the back of moving from XP to Windows 7,” said Christopher Soghoian, a computer security expert and principal technologist for the American Civil Liberties Union. “It’s so mundane but so important.”
---
Sad, but true...you'd think if there would be one sector of society in which the mundane-but-important work could be rewarded, it'd be in the government sector, where the force of law and regulation would make it a political priority, even if it will never become a glamorous role.
Working in government this is exactly what is happening. The XP to Win 7 transition is being run by contractors where I work.
If you wonder where older tech workers go, think 'Enterprise' in government or large non-tech companies.
The key issue is that the economy exploded in 2008 and the PC refresh cycle ended. The other issue is that Microsoft shipped a stinker with Vista, and took the liberty of breaking lots of legacy Microsoft tech in 7.
Few big organizations actually upgrade zone rating systems... They replace the devices. Because the upgrade cycles of PCs were stopped like 5-6 years ago, getting the budget for PC replacement was very difficult. Government bean-counters like slow growth in budget lines. Going from $10M/year to $0 to $30M for a bug refresh results in poor results.
Great idea.
If you are outsourcing the process, you're easily looking at $250-400 of labor per unit for an asset that is worth < $100. As an added issue, you're going to have quality issues that are even more expensive to deal with.
I used it for several years after that, and never got infected. Ditto for my XP installation, which is approaching 8 years old.
If 98SE was any indication (Google "kernelex"), with XP's popularity and persistence being much greater, I think once again a whole "cottage industry" will form and continue to provide various bugfixes/patches and enhancements to XP for another decade or more...
And people wonder how "easy" it is for those darn hackers to "steal info." It's easy to steal from a house with the door wide open.
Rumors have it that hackers are detecting and cataloging vulnerabilities that they're holding in reserve for the day Microsoft stops support for XP, after which they'll have a field day exploiting known vulnerabilities, secure in the knowledge that the errors will remain in place until the victims finally dump XP.
For example, Vista has a substantially-rewritten networking stack. A networking exploit in Vista would not necessarily translate over to XP.
On the other hand, there's a lot of legacy code around in GDI+ for decoding graphics formats. A file format exploit would be highly likely to carry over to XP.
That makes me curious as to just how much legacy code still exists in Vista/7/8/8.1, and where. I guess it's time for me to do some more research.
...or until someone else patches them; remember the WMF exploit at the end of '05? There was an "unofficial", but just as effective, patch released before Microsoft released theirs.
Also, if someone is still running Windows XP in 2014, he probably doesn't use the newest updates and antivirus anyway, so his security is weak in other respects too.
Yes, but until April 8th Microsoft will patch any uncovered vulnerabilities. After April 8th, hackers can have a field day because no one will patch any detected flaws. That's a big difference.
> Also, if someone is still running Windows XP in 2014, he probably doesn't use the newest updates and antivirus anyway ...
Not true, not true at all. It's too easy for a user to turn on automatic updates and run an antivirus program. My point is that one of these features will disappear 22 days from today, and hackers are going to exploit that fact to the fullest. There are even rumors that hackers are saving discovered XP vulnerabilities for use after April 8th, because they'll never be fixed and can therefore be exploited over and over.
People might even be ready to start hijacking automatic updates. XP uses the very old way of a custom site and some activeX to launch the update methods. MS probably wants to stop supporting that crazy old site a soon as possible.
Yes, very true. This is something most people don't understand about hacking -- it's just a business, much like any other. What was once an entertainment for a bright, bored youngster is now a trade, with tools and goals.
> People might even be ready to start hijacking automatic updates.
It's my hope that Microsoft will think of a way to prevent automatic updates from being taken over by just anyone after they close down the "real thing".
Ubuntu/RedHat/SUSE abandoned the distro? Well, hire devs to support it. You have the code.
They are too incompetent to switch from xp to vista or 7. What makes you think they could survive the transition to linux, let alone maintain a distribution?