Stability is a superset of security.
Printable View
Incidentally I just had to speak to technical support for some software that I use (because it was something I'd never done before). Out of curiousity at the end of the conversation because of this thread I asked for their advice regarding Windows 10, fully expecting the answer.
His advice was that while they don't know of any problems using their software with Windows 10 it hasn't been tested on it yet and he would recommend unless I need to upgrade now to hold off "for at least a month" so that if there are any problems somebody else is the one to discover it. File that under "no shit Sherlock".
Missed this reply but the two are synonyms not a downgrade. In fact if you want I will upgrade some to "most".
Ignoring Windows 10, Windows 8.1 as the most recent OS is two years old and so ought to be fully adopted if it was not true that many don't want to upgrade and so should be close to 100% market share of Windows machines.
According to this website Win 8.1 has a 13.12% market share. Considering Windows XP through to 8.1 have a combined 90.6% market share (even assuming there's no older Windows within the Others category) that means that 8.1 represent <14.5% of all Windows machines. Over 85.5% of Windows machines are not the latest OS and even nearly one in every five Win 8 machines aren't 8.1! Yes I consider the vast, vast majority "many".
Guessing I'm the latter. ;)Quote:
Yes, you two remind me of my kids. One is cocksure yet almost completely oblivious to how the real world works, and the other loves to point out how ridiculous that looks and sounds to everyone else.
There are a multitude of reasons to not update, not just security or reliability. No single OS has been "fully adopted" within 2 years, hell, they don't even reach majority of marketshare within that time. Not even XP (which had something like 35% after 2 years). Cost and hardware requirements (not so much drivers) used to be a major concern.
So two years isn't reasonable but what's being proposed is the automatic with no choice whatsoever upgrade of all home machines within a month? And within a few months for Enterprise machines. Somebody is off their rockers.
Neither cost nor hardware requirements are reasons not to update from 8 to 8.1 (and there's plenty of good reasons to as 8 was pants) yet a fifth of 8-generation machines are Win 8.
Who said anything about a month? I have no idea how Microsoft is going to roll out the updates. Only 1 of my non 10 machines has gotten additional popups about it today. This statement barely even makes sense, no one is forcing home machines to update to 10. Its the smart thing to do since 7 and earlier have exited their mainstream support window and 8/8.1 are supposedly so horrible. Once the machines are moved over to 10 keeping them up to date is the smart thing to do, no different than allowing your antivirus to auto update (which carries the same risk), or do you delay that protection a month as well?
a quick reminder that the stats you are using are from internet users visiting that network's analytical tools. Steam for example, with 9 million active users, shows 8.1 64bit at 31% and 8 at 3%. But my work has more 8 than 8.1 machines because they are single use, supplied and maintained by a 3rd party behind our firewalls. Users being ignorant and stupid as a bricks plays a big part in the updating as well. The number of people coming in with tablets and laptops complaining about the 8.1 banner across their screen... :bulb: I'm honestly surprised that 8.1 is so far ahead of 8.Quote:
Neither cost nor hardware requirements are reasons not to update from 8 to 8.1 (and there's plenty of good reasons to as 8 was pants) yet a fifth of 8-generation machines are Win 8.
When I talk about computers, I don't mean PC. PLC is also a type of computer.
Didn't came over here that way. Looked like you wrote in absolute terms
Do you need a code per transaction or is it a per session security? If it's per session, you are still vulnerable to session hijacking.Quote:
Secondly, I never dismissed security. I actually said that relying solely on the OS to do banking etc is stupid IMO, my security for my online banking is far more advanced than putting blind faith into Windows as being secure. Frankly given history and experience I have always put the least confidence in Microsoft for being secure by itself. You need to build on your own security on top.
Nailed it in one.
Please elaborate.
He's saying that if we don't raise our eyebrows at people taking two years to upgrade their OS (eg. from 8 to 10) then maybe it's a little silly to flip our shit over people who don't want to be forced to update their OS within a month of an update's release.
People have been dicking around with Windows 10 for 10 months now, its public now yes but Microsoft has flipped the table on a lot of aspects of this OS, from its extended beta to it being a free upgrade with an expected 10 year life. Besides I thought we were talking about Microsoft approved updates inside of Windows 10. I'm not aware of any program thats forcing non Windows 10 machines to update into Windows 10.
Even if he needed a code per transaction, he'd still be vulnerable. If he's using a PIN generator: Simply intercept the website, alter the contents to show him what he' supposed to see and then use the generated key to do something completely different.
If it's PIN by SMS - SIM cloning is a thing now.
Who the hell is talking about being "forced to upgrade to a new OS"?
If that computer is reachable by the general internet (or even a semi-public corporate intranet) then you're doing it wrong. Period.
Plus, you'd use a completely different OS architecture which allows you to patch anything while the processes are running. Ever heard of "No Reboot Kernel Patching"?
I was takling about PIN by SMS, as you then need to intersept the SMS as well. Possible but way more difficult.
Define reachable. Of course, physically separated from the internet would be preferable, but then you need a completely separate means to communicate if necessary.Quote:
If that computer is reachable by the general internet (or even a semi-public corporate intranet) then you're doing it wrong. Period.
I certainly wouldn't like to do live Kernel patching on a safety relevant system. That update process would be a little bit more complicated.Quote:
Plus, you'd use a completely different OS architecture which allows you to patch anything while the processes are running. Ever heard of "No Reboot Kernel Patching"?
Interesting how some people have waited for Windows 10 to become concerned about the safety of Microsoft products.
I still don't regret my switch; interestingly enough it came about a month before my norton subscription runs out. I now learned that I may not even need that any longer.
Listening to an audiobook and it said something to activate Cortona. I wonder if Cortona disables itself when other apps go fullscreen, or gaming could have some interesting moments now.
It was said above that Home users would have no choice but to automatically update (without prompting or choice) all future updates within a month. Next time Microsoft decides to do a major update you will have no option to say "no thanks" to that.
Per transaction. I have to enter the transaction details, it prompts me with a 9 digit code that I key into my dongle. I enter my cards PIN (the card being just for this, not a transaction card used at ATMs etc) and it gives me back a 10 digit code to confirm the transaction.
Exactly thank you.
Are you still confusing updating to Windows 10, which is a free choice for the next 364 days, with software updates pushed through to Windows 10 users?
If you're referring to the update decision with Windows 10, I consider it no different and no riskier than allowing anti-virus to auto update. If staying secure is an honest issue and not ridiculous paranoia then maybe the most basic version of Windows meant for the sheep of humanity isn't the right version of the OS for you.
No you are. I've been consistent, updates should be at our timing and not Microsoft's.
Staying stable is not ridiculous paranoia. Having less than 100% confidence in Microsoft's updates is not ridiculous paranoia. If the auto-update restarts the machine then not wanting the machine to restart outside your timings is not ridiculous paranoia.
Taking responsibility for your own actions and your own machines is not ridiculous.
Has there (recently) been a windows update (not upgrade) that messed with reliability or stability or anything?
Yes. It happens surprisingly frequently. There's been two high-profile examples in the last week alone quoted earlier this thread. Let alone the number of ones that aren't high profile.
When you have a complicated software running into the gigabytes that interacts with literally billions of machines worldwide and who knows how much countless types of software then any patch is inherently risky.
Are you having some sort of monitor malfunction? These are the actual words I wrote and that you should be able to see right there on your screen:
The first is voluntary and many users wait a long time to upgrade. The latter will henceforth be more or less mandatory with little user control of timing etc. RB mistakenly used the terms "upgrade" and "update" interchangeably. Taking two years to upgrade or even update may be extreme (except that it's common when it comes to OS upgrading anyway) but to some forcing an update within a month of its release is also on the extreme end of things.Quote:
He's saying that if we don't raise our eyebrows at people taking two years to upgrade their OS (eg. from 8 to 10) then maybe it's a little silly to flip our shit over people who don't want to be forced to update their OS within a month of an update's release.
Thanks Minx.
No worries, I'll send you an electronic invoice or you can just paypal me I guess :o hail Ayn
Yes the webpage gives a unique code that I enter into my dongle and then code back. I trust the banks security and my browser's security more than my OS, frankly I always view Microsoft as the weakest link in the security chain.
Upgraded my Win 8 Laptop to Win 10 now. Will wait a while before I upgrade my (newer) Win 7 PC.
Well I am sorry to say Rand, the OS is part of your chain here. As soon as your browser is turning the code into plain text to present it to you, it's in the hand of the OS. Anything that goes to your screen and anything that comes from your keyboard is in the hands of the OS. Doesn't matter what browser you are using.
That's why some banks use SMS as secondary communication path, under the assumption, your Smartphone is using a different OS.
I understand that. As I've said all along, life is about balance and compromise.
Odd surprise but why the hell is Candy Crush Saga pinned to my Start Menu? I've never played that nonsense and no interest in doing so ...
What other crap has been installed?
EDIT: It seems not only was that installed and pinned but the whole viewable area of the Start Menu is clogged with adware for Minecraft or other nonsense I have no interest in at the start. Clicking tile by tile to remove all that nonsense and maybe get my actual programs to appear instead. It even has adware for "Get Microsoft Office" pinned to appear above my Microsoft Office programs which are installed already. :rolleyes:
EDIT2: All bemusement aside ... I need Microsoft to have permission to continue to install adware without notice or even requesting permission from me don't I? If MS couldn't install adware on my PC then how would I possibly cope? And again of course we all have 100% in MS and every bit of adware or other patches and updates it has to do immediately :rolleyes:
Ask Cortana :o
Edited my post above a couple of times after you replied, didn't realise you'd replied sorry.
As to the SMS interception: Not really difficult. Because it's used already.
I'm also not sure why you'd actually need to have your complicated machine accessed by the general network. Again, that's just asking for trouble. And the companies who understand this are actually doing just that: It's either completely physically separate networks or at least through VLANs.
Well, and you can't have it both ways on a "safety relevant system": Either you patch it as fast as you can or you don't, in which case it isn't really that safety relevant in the first place.
The IEC and ISO norms on safety disagree with you.
Safety relevant software according to IEC EN 61508 every change needs to go through the whole verification process. A process that easily takes months.
Then that safety software shouldn't bloody be accessible to the general internet. As I already said: If it's that exposed, you're doing it wrong.
Is that some kind of rocket science or why are you unable to comprehend this fact?
Not being accessible to the general internet doesn't render you immune to malware infections, just removes the most likely vector.
The only way to fully protect a system is to create all its software in a language spoken by Navajo-cockney hiphoppers.
How does that help? It will be translated in the the very same machine code at the end of the day.
Didn't got that reference.
I think IIRC they used Navajo as a 'secret language' during WWII for the simple reason there were too few speakers at all to suspect anybody could understand it.
So, we've reached the point in this discussion where home user security has to be of the level of weapons grade systems?
You guys realise that the 'free Windows 10' thing we're talking about isn't the same as the professionally used versions of Windows that businesses actually pay for ?