Page 4 of 8 FirstFirst ... 23456 ... LastLast
Results 91 to 120 of 216

Thread: Windows 10

  1. #91
    Quote Originally Posted by Khendraja'aro View Post
    Even if he needed a code per transaction, he'd still be vulnerable. If he's using a PIN generator: Simply intercept the website, alter the contents to show him what he' supposed to see and then use the generated key to do something completely different.

    If it's PIN by SMS - SIM cloning is a thing now.
    I was takling about PIN by SMS, as you then need to intersept the SMS as well. Possible but way more difficult.

    If that computer is reachable by the general internet (or even a semi-public corporate intranet) then you're doing it wrong. Period.
    Define reachable. Of course, physically separated from the internet would be preferable, but then you need a completely separate means to communicate if necessary.

    Plus, you'd use a completely different OS architecture which allows you to patch anything while the processes are running. Ever heard of "No Reboot Kernel Patching"?
    I certainly wouldn't like to do live Kernel patching on a safety relevant system. That update process would be a little bit more complicated.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  2. #92
    Senior Member
    Join Date
    Jan 2010
    Location
    Amsterdam/Istanbul
    Posts
    12,462
    Interesting how some people have waited for Windows 10 to become concerned about the safety of Microsoft products.

    I still don't regret my switch; interestingly enough it came about a month before my norton subscription runs out. I now learned that I may not even need that any longer.
    Congratulations America

  3. #93
    Listening to an audiobook and it said something to activate Cortona. I wonder if Cortona disables itself when other apps go fullscreen, or gaming could have some interesting moments now.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  4. #94
    Quote Originally Posted by Ominous Gamer View Post
    Who said anything about a month? I have no idea how Microsoft is going to roll out the updates. Only 1 of my non 10 machines has gotten additional popups about it today. This statement barely even makes sense, no one is forcing home machines to update to 10. Its the smart thing to do since 7 and earlier have exited their mainstream support window and 8/8.1 are supposedly so horrible. Once the machines are moved over to 10 keeping them up to date is the smart thing to do, no different than allowing your antivirus to auto update (which carries the same risk), or do you delay that protection a month as well?
    It was said above that Home users would have no choice but to automatically update (without prompting or choice) all future updates within a month. Next time Microsoft decides to do a major update you will have no option to say "no thanks" to that.
    Quote Originally Posted by earthJoker View Post
    Do you need a code per transaction or is it a per session security? If it's per session, you are still vulnerable to session hijacking.
    Per transaction. I have to enter the transaction details, it prompts me with a 9 digit code that I key into my dongle. I enter my cards PIN (the card being just for this, not a transaction card used at ATMs etc) and it gives me back a 10 digit code to confirm the transaction.
    Quote Originally Posted by Aimless View Post
    He's saying that if we don't raise our eyebrows at people taking two years to upgrade their OS (eg. from 8 to 10) then maybe it's a little silly to flip our shit over people who don't want to be forced to update their OS within a month of an update's release.
    Exactly thank you.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  5. #95
    Are you still confusing updating to Windows 10, which is a free choice for the next 364 days, with software updates pushed through to Windows 10 users?

    If you're referring to the update decision with Windows 10, I consider it no different and no riskier than allowing anti-virus to auto update. If staying secure is an honest issue and not ridiculous paranoia then maybe the most basic version of Windows meant for the sheep of humanity isn't the right version of the OS for you.
    Last edited by Ominous Gamer; 07-30-2015 at 08:52 PM.
    "In a field where an overlooked bug could cost millions, you want people who will speak their minds, even if they’re sometimes obnoxious about it."

  6. #96
    No you are. I've been consistent, updates should be at our timing and not Microsoft's.

    Staying stable is not ridiculous paranoia. Having less than 100% confidence in Microsoft's updates is not ridiculous paranoia. If the auto-update restarts the machine then not wanting the machine to restart outside your timings is not ridiculous paranoia.

    Taking responsibility for your own actions and your own machines is not ridiculous.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  7. #97
    Senior Member Flixy's Avatar
    Join Date
    Jan 2010
    Location
    The Netherlands
    Posts
    6,435
    Has there (recently) been a windows update (not upgrade) that messed with reliability or stability or anything?
    Keep on keepin' the beat alive!

  8. #98
    Yes. It happens surprisingly frequently. There's been two high-profile examples in the last week alone quoted earlier this thread. Let alone the number of ones that aren't high profile.

    When you have a complicated software running into the gigabytes that interacts with literally billions of machines worldwide and who knows how much countless types of software then any patch is inherently risky.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  9. #99
    Quote Originally Posted by Khendraja'aro View Post
    Who the hell is talking about being "forced to upgrade to a new OS"?
    Are you having some sort of monitor malfunction? These are the actual words I wrote and that you should be able to see right there on your screen:

    He's saying that if we don't raise our eyebrows at people taking two years to upgrade their OS (eg. from 8 to 10) then maybe it's a little silly to flip our shit over people who don't want to be forced to update their OS within a month of an update's release.
    The first is voluntary and many users wait a long time to upgrade. The latter will henceforth be more or less mandatory with little user control of timing etc. RB mistakenly used the terms "upgrade" and "update" interchangeably. Taking two years to upgrade or even update may be extreme (except that it's common when it comes to OS upgrading anyway) but to some forcing an update within a month of its release is also on the extreme end of things.
    "One day, we shall die. All the other days, we shall live."

  10. #100
    Thanks Minx.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  11. #101
    No worries, I'll send you an electronic invoice or you can just paypal me I guess hail Ayn
    "One day, we shall die. All the other days, we shall live."

  12. #102
    Quote Originally Posted by RandBlade View Post
    Per transaction. I have to enter the transaction details, it prompts me with a 9 digit code that I key into my dongle. I enter my cards PIN (the card being just for this, not a transaction card used at ATMs etc) and it gives me back a 10 digit code to confirm the transaction.
    What do you mean by "it"? The webpage? Because if you get the 9 digit code from the webpage and reenter it to the webpage, you are open to a man in the middle attack. Of course SSL/TSL solves that problem, but than you have to trust your OS/Browser package.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  13. #103
    Yes the webpage gives a unique code that I enter into my dongle and then code back. I trust the banks security and my browser's security more than my OS, frankly I always view Microsoft as the weakest link in the security chain.

    Upgraded my Win 8 Laptop to Win 10 now. Will wait a while before I upgrade my (newer) Win 7 PC.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  14. #104
    Quote Originally Posted by RandBlade View Post
    Yes the webpage gives a unique code that I enter into my dongle and then code back. I trust the banks security and my browser's security more than my OS, frankly I always view Microsoft as the weakest link in the security chain.
    Well I am sorry to say Rand, the OS is part of your chain here. As soon as your browser is turning the code into plain text to present it to you, it's in the hand of the OS. Anything that goes to your screen and anything that comes from your keyboard is in the hands of the OS. Doesn't matter what browser you are using.

    That's why some banks use SMS as secondary communication path, under the assumption, your Smartphone is using a different OS.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  15. #105
    I understand that. As I've said all along, life is about balance and compromise.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  16. #106
    Odd surprise but why the hell is Candy Crush Saga pinned to my Start Menu? I've never played that nonsense and no interest in doing so ...

    What other crap has been installed?

    EDIT: It seems not only was that installed and pinned but the whole viewable area of the Start Menu is clogged with adware for Minecraft or other nonsense I have no interest in at the start. Clicking tile by tile to remove all that nonsense and maybe get my actual programs to appear instead. It even has adware for "Get Microsoft Office" pinned to appear above my Microsoft Office programs which are installed already.

    EDIT2: All bemusement aside ... I need Microsoft to have permission to continue to install adware without notice or even requesting permission from me don't I? If MS couldn't install adware on my PC then how would I possibly cope? And again of course we all have 100% in MS and every bit of adware or other patches and updates it has to do immediately
    Last edited by RandBlade; 07-31-2015 at 09:24 AM.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  17. #107
    Ask Cortana
    "One day, we shall die. All the other days, we shall live."

  18. #108
    Edited my post above a couple of times after you replied, didn't realise you'd replied sorry.
    Quote Originally Posted by Ominous Gamer View Post
    ℬeing upset is understandable, but be upset at yourself for poor planning, not at the world by acting like a spoiled bitch during an interview.

  19. #109
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Quote Originally Posted by earthJoker View Post
    I was takling about PIN by SMS, as you then need to intersept the SMS as well. Possible but way more difficult.


    Define reachable. Of course, physically separated from the internet would be preferable, but then you need a completely separate means to communicate if necessary.


    I certainly wouldn't like to do live Kernel patching on a safety relevant system. That update process would be a little bit more complicated.
    As to the SMS interception: Not really difficult. Because it's used already.

    I'm also not sure why you'd actually need to have your complicated machine accessed by the general network. Again, that's just asking for trouble. And the companies who understand this are actually doing just that: It's either completely physically separate networks or at least through VLANs.

    Well, and you can't have it both ways on a "safety relevant system": Either you patch it as fast as you can or you don't, in which case it isn't really that safety relevant in the first place.
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  20. #110
    The IEC and ISO norms on safety disagree with you.

    Safety relevant software according to IEC EN 61508 every change needs to go through the whole verification process. A process that easily takes months.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  21. #111
    Let sleeping tigers lie Khendraja'aro's Avatar
    Join Date
    Jan 2010
    Location
    In the forests of the night
    Posts
    6,239
    Then that safety software shouldn't bloody be accessible to the general internet. As I already said: If it's that exposed, you're doing it wrong.

    Is that some kind of rocket science or why are you unable to comprehend this fact?
    When the stars threw down their spears
    And watered heaven with their tears:
    Did he smile his work to see?
    Did he who made the lamb make thee?

  22. #112
    Not being accessible to the general internet doesn't render you immune to malware infections, just removes the most likely vector.
    The light that once I thought compassion still casting shadows in your action
    The words you shared were cold transactions that bring me to curse what you've done
    When you're up there absorbed in greatness with such success you've grown complacent
    I hope you scorch your many faces when you fly too close to the sun

  23. #113
    Quote Originally Posted by Khendraja'aro View Post
    Then that safety software shouldn't bloody be accessible to the general internet. As I already said: If it's that exposed, you're doing it wrong.

    Is that some kind of rocket science or why are you unable to comprehend this fact?
    Do you remember what my profession is?

    This is fucking rocket science, development of a safety relevant system getting it certified and and keeping it maintained and running is not a simple thing, especially if it needs to communicate.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  24. #114
    Senior Member Flixy's Avatar
    Join Date
    Jan 2010
    Location
    The Netherlands
    Posts
    6,435
    Quote Originally Posted by Steely Glint View Post
    Not being accessible to the general internet doesn't render you immune to malware infections, just removes the most likely vector.
    Exactly. IIRC stuxnet infected offline systems through usb sticks.
    Keep on keepin' the beat alive!

  25. #115
    The only way to fully protect a system is to create all its software in a language spoken by Navajo-cockney hiphoppers.
    "One day, we shall die. All the other days, we shall live."

  26. #116
    How does that help? It will be translated in the the very same machine code at the end of the day.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  27. #117
    Quote Originally Posted by Flixy View Post
    Exactly. IIRC stuxnet infected offline systems through usb sticks.
    Also, infection through compromised firmware is I believe possible.
    The light that once I thought compassion still casting shadows in your action
    The words you shared were cold transactions that bring me to curse what you've done
    When you're up there absorbed in greatness with such success you've grown complacent
    I hope you scorch your many faces when you fly too close to the sun

  28. #118
    Quote Originally Posted by earthJoker View Post
    How does that help? It will be translated in the the very same machine code at the end of the day.
    "One day, we shall die. All the other days, we shall live."

  29. #119
    Didn't got that reference.
    "Wer Visionen hat, sollte zum Arzt gehen." - Helmut Schmidt

  30. #120
    Senior Member
    Join Date
    Jan 2010
    Location
    Amsterdam/Istanbul
    Posts
    12,462
    Quote Originally Posted by earthJoker View Post
    Didn't got that reference.
    I think IIRC they used Navajo as a 'secret language' during WWII for the simple reason there were too few speakers at all to suspect anybody could understand it.

    So, we've reached the point in this discussion where home user security has to be of the level of weapons grade systems?

    You guys realise that the 'free Windows 10' thing we're talking about isn't the same as the professionally used versions of Windows that businesses actually pay for ?
    Congratulations America

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •