Rubbish! They sell systems and the OS is a minor part, a very minor part as far as costs go.
You may not be able to sell linux but you can sell systems running linux. The real question is can you sell the software built using linux. If you can't then you wont use it to make what is essentially a software product.
Didn't find your answer? Ask the community — no account required.
D
dennis
A proper firewall would prevent the spread. You need to put the XP machines on a VPN(s) and firewall it/them really well. Don't buy any more kit based on XP, it is very old and the kit must be well out of date by now.
D
dennis
If its just a file server there is no excuse for not upgrading.
Which 15 year old Linux is still being supported then? Haven't all the linux people abandoned the users of old linux systems?
T
Tim Streater
Well indeed. I'd have said disconnect the whole NHS network from the Internet. That would isolate all these older machines from infection, and not prevent those within it from having existing access to scans as you describe. If they need to email off the network, that could involve special email gateways, connected to both the Internet and the NHS network. You can then concentrate virus scanning in one place, and forbid any other access to the Internet.
M
Martin Barclay
RedHat became the first world's first $2 billion open-source company to reach that milestone. So /they/ made money out of Linux.
Also a couple of interesting reads about MS Windows in The Register Forums: wannacry ransomware worm Why isn't the true culprit being blamed? Its been interesting watching this trainwreck unfold but even more interesting reading all the comments blaming everyone but the true culprits. Microsoft.They wrote the shoddy code that the exploit used. I see that the worm uses the SMB v1 buffer overflow "bug". The buffer overflow code is not actually a bug but a piece of very shoddy coding. It seems that someone wrote some code long long ago that adds a long value offset to a short variable. So that tells me that either the code source file was compiled with warnings turned off , the type mismatch warning has been in C compilers since the mid 80's, or some bright spark typecast one or both variables to make the warning go away. I'm tempted to dig out the source code, its been in the clear and in the wild since the early 2000's, and find the guilty line of source code. Based on past experience digging though the Win32 source codebases (about
400M total) it usually does not take long to track down these type of glaring errors. Yes, MS software engineering really is that lazy and incompetent.So this very simple piece of programmer lazyness which has probably been compiled millions of times over the years and considered acceptable by MS is the real reason why all those NHS hospitals were disrupted yesterday.For all you real old timers out there if you want a really good laugh look at the Win2k/ XP WinExplorer codebase. It is easily the biggest code/project train wreck I have seen in my 30 plus years in the business. And I spent a lot of that time doing code/project turnaround in the Valley. So I've seen inside some absolutely epic disasters. WinExplorer is very much shades of Autocad R13, but with a staggeringly inept team.So if anyone wants to organize a pitchfork mob to attack and deal with the real culprits just let me know.
As I said the most amazingly amateurish junk code has been shipped in Win16/32 for decades. You should see some of the Win16 code. Which is still in there. Despite what senior MS management might say. The only part of the Win32 codebase I've seen over the years that is anyway is of professional quality is the NTKernel code.
Given the way that MS operates internally for as long as I can remember, which would be late 70's, almost all their dev teams by their very nature produce buggy ill designed code. You get promoted for shipping, something, anything, not for fixing stuff or producing stuff that works. Its a toxic work environment. You dont need any kind of conspiracy theory to explain all the security exploits in MS products, just monumental arrogance and contempt for the users. They ship version after version of a totally insecure product because they dont have to care. Never did, never will.
formatting link
B
Brian Gaff
formatting link
Especially if you have xp. Brian
B
Brian Gaff
According to the Microsoft folk the main reason windows 10 was not hit was that slight changes to the way it looks for domains on the internet saved it. It seems a lot of machines never bothered to do the march update. XP seems to have not been the main issue, it has been lax updating. Brian
D
dennis
By your logic there are lots of linux dev people responsible for any attacks on old unpatched linux machines. M$ patched the vulnerability two months before the attack and have been advising everyone to get out of really old XP systems for years.
But its to be expected form someone as bitter as you.
That must be how linux has so many bugs reintroduced and left there for months, lazy M$ developers.
It must have been a really obvious error as all those hackers waited until the NSAs leak before using that obvious exploit.
It must be wonderful to be the only person in the world that can fix all coding problems in an OS, why don't you do it for linux to start with?
D
Dave Plowman (News)
I'm told MRI scanners use software which runs on XP. (No idea if this is so, though) My recent scan was done at a facility outside the NHS. So I assume they have to send the files somewhere - like to my GP?
D
Dave Plowman (News)
You think saving money by not keeping an IT system secure a 'petty prejudice'? Be interesting to know the final bill for sorting out this mess - let alone the inconvenience to patients, etc. Will likely turn out that a stitch in time would have saved money in the long run.
Another deluded one who thinks Linux 100% secure...
D
Dave Plowman (News)
Yet another nonsensical 'solution'.
D
Dave Plowman (News)
MS ceased supporting XP some time ago. No different to any other maker of anything. Try getting off the shelf parts for anything after it is obsolete. You might be lucky - you might not.
The NHS did the equivalent of having spare parts specially made - they paid MS for support after it had officially ceased. But then cancelled that agreement as too costly.
Most of the upgrades you get to a current MS OS are actually security patches.
It's the very fact that MS is the most popular OS that hackers go for it.
R
Robin
I'd welcome reference to anything about what the *NHS* did - for England as a whole or Trust by Trust. The only general deal I know of was the central government (Cabinet Office) contract for 2014-15 for the public sector which they made clear was a one-off.
I note too that Scotland and Wales were also affected, despite health being devolved.
T
T i m
So, what are the alternatives, specifically for the desktop machines then?
How long have we had Linux out there now, 'Free' (of cost, should be a big draw) and 'Free' (as in Open Source, few seem to care)?
The first hurdle for Linux has been hardware support, something Linus himself has admitted has been difficult for Linux:
formatting link
formatting link
And then, 'what disto?':
formatting link
And then it's a matter of a broad range of application support (and lack thereof with Linux).
I'm not saying it couldn't be done with Linux of course as I'm aware several organisations have, but if you have a unpredictable range of apps and hardware that *may* need to be run on these workstations (as may be the case in say a hospital) and with little support from many of the hardware manufacturers and software developers re Linux, you can see why it hasn't made a big impact (on the desktop) yet:
formatting link
It's a similar story with OSX (BSD?) in that whilst it works and would be considered more 'refined' by most people, it (still) only represents 10% of the desktop OS market and again, you are still tied in with a single supplier (and even more so with their hardware).
I think part of the problem (apart from the above etc) re why Linux (specifically) hasn't taken off after ~15 years is because of the 'attitude' of many of the geeks. It's not only those who may not have good interpersonal skills (often for clinically testable reasons, so are unable to understand .. therefore aren't willing to help those who might be interested) who put people off but the rigid 'you do it the Linux way or take the highway'.
Desktop OS's are used by 'people' and 'people' want what they want and really DGAF about what goes on under the hood .. *as long as they can do what they want to do*.
As soon as you can't use the hardware you have or run the app you want (that you could on the current version of Windows or OSX etc), it doesn't matter how 'better' an alternative may be designed or how much more secure it may be, most would consider it useless. [1]
Cheers, T i m
[1] I have installed Linux for many people (foc) and mostly 'dual boot' with Windows because from the getgo there are apps that the users simply 'must have' (MS Office or iTunes etc). It's very rare that any of them are still using it at all, after the initial introduction (two or 3 are though). Linux could be the answer to the question few ask (security) but it's still unable to able to fill that role for many.
A
Andy Burns
Look into what N3 is, the code of connection for it, and NHSmail ...
T
Tim Lamb
In message , "Dave Plowman (News)" writes
I ask for copies of my MRI scans. Not distrust of NHS but convenience if private healthcare involved. Usually cost ?10.00/ disc.
>
T
TimW
The NSA of the USA developed a 'cyber-weapon' and failed to keep it safe. Then after they lost it they can't even protect their best allies.
I know who I blame
Tim W
G
GB
That also recommends turning off SMB v1.
D
dennis
I blame the IT experts that don't patch their systems.
They were told about the problem with XP years ago and the problem with this exploit two months ago and they did nothing.
M$ could have made it a compulsory update but then everyone would be up in arms.
D
Dave Plowman (News)
Right. Thanks for confirming it was actually this Tory government's fault.
Only seen the BBC news, but they specifically excluded Wales from the map they showed of effected areas.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.