Windows 10 bricks

Aug 05, 2025 Last reply: 10 months ago 26 Replies

A while ago I started a thread about what to do about my old Windows 10 machines when support ends. I have my newsreader set to expire old posts after a few days and I can't find it now so I apologise for starting a new thread.



My solution, which I think will do is:


1) I have bought a new cheapish laptop with Windows 11 which will satisfy my Windows needs.


2) The old Windows 10 desktop which was getting pretty flakey is now working well with Ubuntu 22.04 LTS (couldn't get the 24.04 installer to work on it). But I haven't yet got it to talk to the Epson scanner or Canon printer.


3) I'll keep the Windows 10 laptop pro tem to drive the printer and scanner and keep it off network, using USB drives to move files from/to it.

Is there is risk with an old Windows 10 even off network with USB drives going back and forth from it to other on network machines? That was a virus vector in the old days, is i such a problem now?



nib



You could leave it connected to the LAN, but don't give it a default gateway. That way it can act as a network server for the printer (other PCs can print directly with no need for sneaker net), and access other PCs on the lan, but will not be able to access the internet, which should keep it reasonably safe.

You will be able to get Windows Defender definition files for a while, after October 2025. You can see windows 7 is in the list (scroll down).

formatting link
What you won't be getting after Oct.2025, is Patch Tuesday patches for CVE exploits. Signature analysis via Windows Defender, is only part of the story. A new exploit, where a signature is not available, if you had a patch for the CVE, you might be "inherently protected". Whereas every announced CVE that is not patched, someone can repeatedly package up attacks for it. Not that I huddle in the corner in the fetal position, thinking about it. I'm just attempting to describe the "threat surface". Only people offering some "value" to a BlackHat (phishing attack candidates) will see more attacks than others might.

For example, say I buy a domain for my business.

formatting link

When I register that, I associate an email with it. Now, say a BlackHat looks at my nice web site and says "I bet I could get some ransomware onto that guys computer". He would shoot off an email, claiming the web site registration was coming due, and the attached form was for the renewal of the domain. If I absentmindly double click the attachment, I could get ransomware.

Why was I selected ? It's assumed I am a businessman, and someone of sufficient means to pay a ransom to recover my computers.

If you are a relative unknown, have no obvious displays of wealth, then perhaps you will never receive an email like that. Consequently, your "risk" of using an unpatched OS, is slightly different than me and my corncobpipe business.

One of the weakest parts of any consumer computer, is the web browser. a lot of infections over the years, got into the computer via the browser. This is why the browser is compartmentalized. The movie player can crash and you hardly notice. If you use an old browser, the risk is there that some day, an exploit crafted for it, will be sampled by you.

Windows Defender, I don't think it has any real heuristic detection. It cannot be counted on, for "noticing weird behavior and doing something about it". It was claimed at one time, that the OS had a "jiggler" and the OS could shut down in 10usec or so, upon discovering adverse properties or behaviors. Like the last time one of these claims was made, there has been no confirmation in the wild of such.

I have personally had my computer rendered useless, without a BSOD, the +5VSB power to the keyboard and mouse and USB ports is turned off. No record is kept in EventVwr.msc of the event. I suspect this is some sort of driver behavior, but I have been unable to find a name for this. It is not a jiggler, because with one of those, the PC power goes off instantly. And the PC power remains on, just one rail is selectively (cleverly!) switched off. You cannot type ctrl-alt-delete, if the keyboard no longer has power.

I occasionally boot up a Win7 setup here, on the other machine, and I do not feel any particular "fear" it is going to tip over. The machine functions just fine, from a hardware perspective. Whereas this newer machine I am typing on, is not as "solid" a performance. Whether it is Oct.2025 or the date is something else. I have lost more than a bit of faith in the computer industry, just for the record. This is why buying a laptop with Win11 on it, would have "no positive aspect to it whatsoever", the hardware could be just as shaky as this box. And I do not get a warm and fuzzy feeling from UEFI/TPM/GPT, as that's just as exploitable or more exploitable than a legacy BIOS with a Trend Chipaway protection.

Paul

Sorry if the context is lost/important - but what caused the above?

I still don't know. A theory is that it is address map related, because making some hardware changes (adding a PCIe NIC, changing GPU config), reduced the frequency of these events to zero. For a while. It could be a GPU driver, or related to something in the Hypervisor that manages I/O devices. The OSes are now, practically speaking, three dimensional underneath (inverted hypervisor, W11 is a Guest, Bash shell is a Guest, various other silly stuff), which makes analysis rather difficult. If the OS refuses to keep records, you're rather screwed.

Paul

MS is continuing security updates for W10 for at least an extra year, to October 2026. And, who knows what will happen then?

So, there's no really good reason to retire the W10 machines or keep them off the internet.

You need to enrol for the Extended Security Updates, but for most people that's dead easy.

formatting link

Have you looked at hplip ?

Sound plan.

As far as the epson scanner goes there should be a linux driver for that - its all a bit proprietary and isn't that great, but it does scan

I think this is what you need,

formatting link
Most printers are supported in CUPS these days.

Canon should be supported by modern CUPS installations But its not hard to install and modify Printer description files for a sklightly extended command set if something like double side printing doesnt work

Why? Scanner should work OK with the right drivers and the Canon should 'just work'

Not really. You are behind a firewall. Installing stuff using a USB from an untrusted third party source is not what you are going to be doing

Set up SAMBA on the Ubuntu box and network Win10 to it.

That's for HPs.. Epson have their own drivers for scanners.

Canon printer should be plug'n'play

I doubt that there is any danger to continue to use a Win10 machine without support. At least Microsoft won't be able to mess it up with updates, which appears to be happening with Win11.

I am still running XP., in a virtual machine...it still works and I am afraid to touch it.

Well of course. I had a very vague memory that hplip could be pointed to a .something file for other drivers. Possibly false.

Is that a real "should" or a "the marketing bs says it should" ?

Eh...no marketing in Linux...I mean that PPDs have been created for MOST printers, these days

Her is waht Canons CUPS supports

*Perfectly* BJ-100 BJ-10e BJ-10v BJ-15v BJ-20 BJ-200 BJ-30 BJ-330 BJ-35v BJ-5 BJC-210 BJC-250 BJC-250ex BJC-255SP BJC-265SP BJC-4000 BJC-4100 BJC-4200 BJC-4300 BJC-4400 BJC-4550 BJC-600 BJC-610 BJC-620 BJC-680J BJC-70 BJC-800 BJC-880J GP 335 GP 405 imageRunner C5800 imageRunner C5870U imageRunner C6800 imageRunner C6870U iPR C600 iPR C650 PPD iPR C700/800 iPR C750/850 PPD iR-ADV 400/500 iR-ADV 4025/4035 iR-ADV 4045/4051 iR-ADV 4225/4235 iR-ADV 4245/4251 iR-ADV 6055/6065 iR-ADV 6075 iR-ADV 6255/6265 iR-ADV 6275 iR-ADV 8085/8095 iR-ADV 8105 iR-ADV 8205 iR-ADV 8285/8295 iR-ADV C2020/2030 iR-ADV C2020i/2030i iR-ADV C2025 iR-ADV C2220/2230 iR-ADV C2225 iR-ADV C250/350 iR-ADV C3320 iR-ADV C3320L iR-ADV C3325/3330 iR-ADV C351 iR-ADV C5030/5035 iR-ADV C5045/5051 iR-ADV C5235/5240 iR-ADV C5250/5255 iR-ADV C7055/7065 iR-ADV C7260/7270 iR-ADV C7280 iR-ADV C9060/9070 iR-ADV C9065/9075 iR-ADV C9270/9280 LBP-1000 LBP-1260 LBP-1760 LBP-310 LBP-320 Pro LBP-3360 LBP-350 LBP-4+ LBP-430 LBP-470 LBP-4U LBP-8A1 LBP6670 LBP6680/3480 LBP6780/3580 LBP710C PPD LBP712C PPD LBP7660C LBP7680C/5280 LBP7780C/5480 LBP8780 LIPS-II+ LIPS-III LIPS-IV LIPS-IVv *Mostly* BJC-1000 BJC-2000 BJC-2010 BJC-2100 BJC-2110 BJC-240 BJC-3000 BJC-4310SP BJC-50 BJC-55 BJC-6000 BJC-7004 BJC-80 BJC-8200 BJC-85 CP-100 CP-200 CP-220 CP-300 CP-330 imageRunner 1023 imageRunner 1023iF imageRunner 1023N imageRunner 2016 imageRunner 2016i imageRunner 2018 imageRunner 2020 imageRunner 2020i imageRunner 2022 imageRunner 2200 imageRunner 2230 imageRunner 2270 imageRunner 3025 imageRunner 3225 imageRunner 330s imageRunner 3570 imageRunner 4570 imageRunner 5000 imageRunner 5570 imageRunner 6000 imageRunner 6570 imageRunner 7086 imageRunner 7095 imageRunner 7105 imageRunner 8070 imageRunner 8500 imageRunner C2550 imageRunner C2570 imageRunner C2570i imageRunner C2620N imageRunner C3100 imageRunner C3170 imageRunner C3170i imageRunner C3200 imageRunner C5058 imageRunner C5068 imageRunner C5180 imageRunner C5185 imageRunner C5185i iP4000 LBP-1120 LBP-3460 LBP-460 LBP-4sx LBP-5360 LBP-5960 LBP-5970 LBP-5975 LBP-660 LBP-800 LBP-810 S100 S330 Photo S400 SELPHY-CP-400 SELPHY-CP-500 SELPHY-CP-510 SELPHY-CP-600 SELPHY-CP-710 *Partially* BJ-300 BJC-210SP BJC-6100 BJC-6200 BJC-6500 BJC-7000 BJC-7100 i450 imageRunner 2800 imageRunner 3300 MultiPASS C2500 MultiPASS C3000 MultiPASS C3500 MultiPASS C5000 MultiPASS C5500 S300 S450 S4500 S500 S600 S630 S800 *Paperweight* BJC-5000 BJC-5100 BJC-8500 LBP-600 Multipass L6000 S200

Ah - it was CUPS I was remembering, not hplip :)

Considering I setup a series of machines to use it last year (to replace some Win10 boxes that were unstable) I should have remembered quicker.

The marketing comment was about printer vendors ("It *should* work with Linux" ....)

That was MY comment.

Most printer people say 'Linux? WTF is that?'

The warehouse packers never got a chance :) It booted into Chrome and everything was driven from that. However at the back end we now had SSH into the boxes saving a trip into the warehouse when the Windows boxes jammed up from lack of SSD (they were fanless sealed boxes you couldn't upgrade).

Ta for that, though so far I've followed the instructions and not found the link to enrol in ESU - it says it'll be there if I'm eligible. I use a local a/c on W10, it says it might ask me to log in to my M$ a/c but I haven't found out where yet!

nib

The link is in settings. I think in windows update. But it's not being rolled out until later in August. I enrolled in the Windows Insider programme, so as to get an early release (and just out of interest), and that already had the link in.

I bought a used HP tower without hard drive, installed a brand new hard drive having first initialised it using Windows, and then installed Linux Mint (which is mostly Ubuntu based). I did then manage to find and download a package which successfully worked my ancient Epson scanner. (Really ancient - it was first used on a Win98 system, there is a Windows driver for XP but nothing newer, yet the scanner was too good to throw away which is why I was hunting a Linux possibility)

If you are prepared to change horses to Linux Mint (I am running version

20.3 which has just tipped into the "no longer supported" list and I think Versions 21.x have the same pedigree - try
formatting link
.Then you need to find and download: iscan-bundle-2.30.4.x64.deb.tar.gz

No guarantees, but it did drive my Epson scanner. Mint also seems to have most Canon printers in its catalogue. Certainly it just found and installed mine automatically when I turned it on.

Good luck! Jim

Iscan is still maintained by Epson I am using it

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required