7 ms·
Ask HN: Are Windows 10 and 11 considerably more secure than the old versions?
Is it enough to avoid opening unverified executables and emails to stay safe? or I'm being oblivious
- eimrine 4y agoIf you are behind a NAT then you may consider your any OS safe. But I have no idea about state-of-the-art of NAT hacking, maybe some of them are flawed.
- anderiv 4y agoThere are innumerable ways vulnerabilities can be exercised that do not involve having to “hack” NAT. I would not be comfortable staying so simply that NAT will protect in all situations. It’s one layer of defense, yes, but is inadequate without others like malware avoidance.
- eimrine 4y ago> There are innumerable ways vulnerabilities can be exercised that do not involve having to “hack” NAT. Any examples? Suppose we have a Windows computer connected to a NAT with an access to an Internets, but the computer doesn't download anything. I am not a sysadmin but from my understanding this is almost safe.
- anderiv 4y agoA couple examples: 1) You’re browsing the web from the old machine. Your HTTPS connection gets MITM’d due to a TLS vulnerability, and the attacker is able to gain control of your email account. 2) Unbeknownst to you, another machine on the network is infected with some virus. That machine uses a CIFS vulnerability to remotely infect and root your old computer.
- postalrat 4y agoNumber one the OS is still secure. Number two is doesn't involve the NAT.
- eimrine 4y ago1. I do not believe this is possible. Old device (example - any Blackberry and may be Windows XP) can not connect to any site on the Internets except of HN, maybe because websites like mail provider use to not give any content via HTTP. Any working HTTPS connection just can not be MitMed except of if you are a person of interest of somebody extremely powerful. 2. Great example.
- rbanffy 4y agoThere are tons and tons of attack vectors that are not deterred by NAT. And with so many routers around that are vulnerable and not updatable, or that still have their default admin passphrases, you shouldn't consider your NAT network a safe place.
- eimrine 4y agoMy router has a default admin password but this password invite is not available from the Internets. There is a way of doing it available - press and hold some button and connect to router via wire using telnet. Here is what I know about default password vector, am I missing something?
- nicolaslem 4y agoThat is obviously not true. NAT has been pretty much the default way of accessing the Internet for the vast majority of computers for the last 15 years. The proliferation of ransomware and zero-click exploits clearly shows that NAT did not turn any boxes behind it into something secure.
- deleted 4y ago[deleted]
- rbanffy 4y agoMost of the time, the problem lays with the users. Once (a long time ago) I RDP'ed into a Windows Server 2003 (or so) for some checking and saw it running a eDonkey or some other P2P download utility, as Administrator.
- cpach 4y agoThey’re fine, but with any desktop operating system (including macOS and Linux) there’s always some risks involved, depending mostly on user behaviour. For something more foolproof and secure, consider iPadOS or a Chromebook. Here’s a useful resource: https://techsolidarity.org/resources/basic_security.htm https://techsolidarity.org/resources/basic_security.htm
- runjake 4y agoThey (especially Windows 11 on supported hardware) are far more secure than older versions of Windows. That said, I don't really consider Windows "secure", when it's still filled with legacy cruft that was written before Microsoft's focus on secure coding. We are still seeing font exploits in 2022, FFS. The track Windows 11 is headed seems like a decent approach given realities. For whatever reasons, Microsoft's efforts to eliminate legacy cruft has proved unsuccessful/untenable, so the next best compromise is to harden the OS against itself and everything else.
- Kukumber 4y agoWindows is not secure, it doesn't have any proper permission system, any process can read/write files, send network requests to anyone without the user noticing anything It can even change system settings without you noticing You should feel naked when you manipulate sensitive data with Windows, because you are indeed naked Hence why most companies forbid their employees to use windows with public internet access for work
- iLoveOncall 4y ago> Hence why most companies forbid their employees to use windows with public internet access for work I have literally never heard of a single company doing that.
- Kukumber 4y agoMost companies that care about security will only offer a windows device with just a VPN/Intranet access
- iLoveOncall 4y agoName one other than Kukumber LLC.
- Kukumber 4y agoDon't just trust me, a random internet user, check by yourself Call your bank, and ask them if their employees PCs have access to the public internet Same for your local hospital, call them Bonus: https://www.hipaajournal.com/internet-access-control-for-hospitals/ https://www.hipaajournal.com/internet-access-control-for-hos...
- P5fRxh5kUvp2th 4y agoyou said most, your bank with extreme regulatory compliance needs, is not most.
- hulitu 4y agoLooking at the number of processes run with administrative priviledges, i would say, no.
- type0 4y agoIt isn't secure from MS pushing updates that will revert some settings to default. I don't remember older versions doing that.