Slashdot Mirror


WinXP SP2 Sacrifices Compatibility for Security

goldragon writes "TechRepublic is reporting that "Microsoft is pulling out all the stops to improve security. So much so, in fact, that it will cause many problems because SP2 will de-emphasize backward compatibility with legacy systems and code for the sake of security." One small step forward for Microsoft, one giant leap backwards for mankind?"

30 of 773 comments (clear)

  1. Compatibility Woes? by Oculus+Habent · · Score: 5, Insightful

    Giant leap backwards?

    Let's face it, you can't remain compatible with old software forever. It causes, well, Windows XP. XP is trying so hard to be everything to everyone, that it can't even pop up a delete confirmation fast enough to not make me wait for it (On an Athlon XP 2700+ with 1GB of DDR333, fresh from boot).

    Compatibility is an important issue, but at some point shouldn't the ten-year-old programs run in a virtual environment separate from the OS?

    --
    That what was all this school was for... to teach us how to solve our own problems. -- janeowit
    1. Re:Compatibility Woes? by Ubergrendle · · Score: 5, Insightful

      I think this is a realistic perspective. SP2 will have numerous enhancements and functionality changes, and will fix some long-standing bugs. For those programs that are 'broken' by SP2, businesses always have the opportunity to continue to run @ SP1 for a period of time while the kinks are worked out. I doubt MS will stop providing hotfixes for major problems under SP1 for a period of time.

      I'm not a big fan of MS, but some of the criticism they receive is unfair -- damned if they do, damned if they don't. I'd rather have SP2 with some pain and be more stable and secure, vs running indefinitely under SP1.

      --
      John Maynard Keynes: "When the facts change, I change my mind. What do you do?"
    2. Re:Compatibility Woes? by Anonymous Coward · · Score: 5, Insightful

      if it didn't start any services by default

      Try launching Linux with NOTHING RUNNING and see how productive you are. No cron, no logs, no fucking getty or login. Some services are necessary. Some of Microsoft's need to be fixed. Very few truly need to be disabled.

    3. Re:Compatibility Woes? by Anonymous Coward · · Score: 5, Funny

      aren't ten year old programs the only thing DOSEMU and WINE capable of running? *ducks*

    4. Re:Compatibility Woes? by Mr.+Neutron · · Score: 5, Informative
      Very few truly need to be disabled.

      WinXP by default starts 36 services. I doubt any one user needs more than 10 of those.

      http://www.winnetmag.com/Windows/Article/Article ID/40722/Windows_40722.html

      --
      dinner: it's what's for beer
    5. Re:Compatibility Woes? by Xeleema · · Score: 5, Insightful

      True, but how many of those services that you mentioned even know what a network adaptor is? login doesn't have any sort of interaction with a NIC, (by default) neither does cron. I don't think I've even seen a way to configure login to do anything over the network. The only major thing in my experience with most Linux distros is that the X server keeps port 6000 open and waits for requests. However, that lil' nuance can be taken care of by changing a line in the appropriate config file. For Example; if you're running XFree86, find the file(s) "Xaccess" and change the "#*" and "#* CHOOSER BROADCAST" to "!*". This will reject any requests for a logon window (which is maybe where you get the assumption that the login service is exploitable via the network).

      P.S: I know I'm feeding the Troll, but I just want to calm any worrried n00bs before they fall for this kind of FUD.

      --
      "When I am king, you will be first against the wall..."
    6. Re:Compatibility Woes? by MoonBuggy · · Score: 5, Insightful

      Quite right - the blurb of this article was bordering on being a troll, it's the kind of thing that makes us as the OSS community look bad and as usual is caused by the vocal minority.

      I am a multi-OS user, I spend time on open source projects and I strongly support the EFF. I hate MS as a company for their evil business practices and destruction of competitors, they create FUD and use weasel tactics in their advertising. I do not, however, go around screaming about them to anybody who will listen - I will point out open source solutions when possible but I do not moronically bash MS simply for being who they are.

      I hold a certain amount of mistrust simply because of their past record, but that does not mean I can't see a positive thing when it comes along, and enhanced Windows security is most definitely a positive thing. I don't like them, but this time they're in the right.

    7. Re:Compatibility Woes? by YouAreCorrect · · Score: 5, Insightful

      Almost all comments below stories are trolls. If story X is submitted 100 times by 100 different people, the one that will invoke the most responses is the one that will be chosen by the editors. Because this site is driven by responses (More ads viewed when people go to read the comments, etc, etc).

      If someone submitted this story as "Microsoft toughens up Win XP with SP2" and wrote thoughtful, balanced comments to go along with it, it would be rejected in favour of the current one because it would not generate as many responses/page views/ad views.

      So if you want to get a story accepted, write a flaimbait/troll comment with it. It rewarded when it's part of a story submission, just not when part of the discussion.

      And besides.. it wouldn't be as much fun without the flaimbait/troll articles.

  2. One small step for M$? by boarder8925 · · Score: 5, Insightful
    One small step forward for Microsoft
    Actually, any security step taken by Microsoft is an enormous step.
  3. Can we save the MS Bashing... by kevin_conaway · · Score: 5, Insightful

    ...for the comments? I know this is slashdot and all, but that really has no place in the article summary.

  4. Might this encourage by foidulus · · Score: 5, Insightful

    less people to patch? I can bet it is going to drive IT managers crazy because now they will have to do hardcore tests of all their software to make sure it still works after the patch.
    This might just make things less secure overall because nobody is going to want to bork their software. Will it be possible to roll back the patch quickly if someone finds they cannot run program X anymore?
    But then again, who knows, it might "accidentally" break Office 97 so people think they need to upgrade to Office 2003.

    1. Re:Might this encourage by BlueNexus · · Score: 5, Insightful

      I agree with you. We're going to have to spend months testing compatibility with the software our company uses. Even with the "promise" of better security management will allow us to install something that breaks critical software.

      Then there are the home users who will hear "SP2 breaks 'Product X'" from the mass media and will be afraid to install it. We already have a hard enough time getting them to install normal patches that are supposed to be "safe". Image how eager people will be to isntall it when they hear it might break their favorite software!

  5. What? by TheMadRedHatter · · Score: 5, Insightful

    I wouldn't call this a small step forward. I'd call it a huge leap. It shows that Microsoft actually cares about security. You can't keep an API exactly the same forever. It'll get crufty eventually.

    Hopefully, there'll be more breaking for the sake of security.

    TheMadRedHatter

    --

    while(1)
    {

    }

    Ah, the story of life.
  6. Sacrifice? Windows Users are used to it by Gunfighter · · Score: 5, Interesting

    Aren't all Windows users already sacrificing security for compatibility just by using Windows? Perhaps this is just meant to level the playing field.

    I'm sure Microsoft will be releasing an update full of application compatibility fixes shortly after the SP2 release. Even in vanilla XP, you can run applications in Win95/98 compatibility mode. I don't see any reason to change it now.

    --
    -- Stu

    /. ID under 2,000. I feel old now.
  7. Seems deceptive by stanmann · · Score: 5, Interesting

    The article indicates that most of the things being broken will be viruses and trojans.

    And that the only other major change will be to Finally honor the NX(Non-executable) memory designation, IOW if you want self-modifying code, you can still have it, but you can't place a call to an area that has been marked as Data-only or NX.

    Seems to be all good to me...

    --
    Food not Bombs is a nice platitude but it breaks down when you notice that the Bombees are usually well fed
  8. Part of the design... by LostCluster · · Score: 5, Insightful

    SP2 represents a big change in Microsoft's security vs. ease-of-use stance.

    In the past, Windows shipped with many unlikely-to-be-useful services such as the NetBIOS Messenger service turned on by default installations, meaning that a user who wanted to use the service just needs to start using it and it'll already be there ready to work. Of course, we all know how this has been exploited by spammers.

    Now, such non-essential services will default to the "off" position, and the user will have to take a step to affirmatively activate the services they want to use. This makes plug-and-play operation a little harder to accomplish, but Microsoft has finally decided that the security gained is worth more than the ease lost.

  9. Compatibility is Overrated. by PhxBlue · · Score: 5, Interesting

    It was overrated when Apple told its users, "deal with it." And it's overrated now. If you want backwards compatibility, use a Win2k emulator.

    --
    !#@%*)anks for hanging up the phone, dear.
  10. To Be Fair by sabat · · Score: 5, Insightful


    Hey, given the choice between the two, I think MS is right to choose security. You're often forced to lean toward security at the expense of some convenience, or vica-versa. And in this case, given the recent (past 10 years) track record, security is more important right now.

    --
    I, for one, welcome our new Antichrist overlord.
  11. Funny how that works by thefatz · · Score: 5, Insightful

    The reason Windows is in such a hurt is compatibility with everything. Even most Linux distros dont offer the level of backwards compatibility that windows xp or less does. You can still to this day run Win16 apps under windows and still print and save, as if it were no big deal. Thats just not possible with Linux. Try downloading or running a binary from 1994 that was compiled for linux and see if it works, im sure libc and glibc and aout and elf will make things fun.

    Its kinda sad how things are around here for Microsoft, Damned of they do, Damned of they dont. Somebody shows progress and they get pounced.

    "...one giant leap backwards for mankind?"...And recreating an OS from the 70's isnt? Thats pretty narrow thinking.

    --
    http://www.freebsd.org
  12. Games... by sqlrob · · Score: 5, Insightful

    I wonder how much of the copy protection on software this is going to break. Gamers are probably going to be the loudest yelling demographic when this hits.

  13. Typical /. hypocracy by Stevyn · · Score: 5, Insightful

    Blame microsoft for the problems brought on by bad programs made by other companies. Then bitch because windows is insecure. Then bitch because they're trying to fix the situation and remove backwards compatibility to lessen the problems. Then say how microsoft is only doing this so people have to buy updated software. Well sometimes you have to bite the bullet and upgrade. If you're using some ten year old word processor on top for windows XP, then you better have a good reason of doing so. If you don't want to spend the money, switch to open office.

    I can't understand how microsoft gets bashed for having the security holes and then again for trying to fix them. Besides, how many people on here still use windows? I'm always under the impressions that everyone on /. uses linux and other 1337 shit.

  14. Hmmm by C_Kode · · Score: 5, Insightful

    One small step forward for Microsoft, one giant leap backwards for mankind?

    Spoken like a true zealot. I'm an OOS advocate, but I disagree with this type of statement. It's a damned if you do/damned if you don't situation when someone makes comments like this. Hey, security is important here, and I'm sure Microsoft gauged this responce carefully before making these changes. Sure it's going to break some systems, but sometimes something has to give to move forward. I don't know about you, but security is very important to me. If the patch breaks your system, don't install it untill you're ready for the change. No one is forcing the service pack down your throat.

    1. Re:Hmmm by fzammett · · Score: 5, Informative

      I agree completely. It's the supid-ass comments posted with the headlines that reveals Slashdot for what it is: Anti-MS Zealots Central.

      I don't care if comments like that are posted, but they should be kept off the front page in my opinion. If your trying to be a semi-serious news site, then do it, which means keeping crap like that out of the headlines. If you just want to be a community of Microsft haters, that's fine, but get rid of your grandiose tagline because it doesn't apply.

      About the news itself... Geez people, hate Microsoft all you want, there's plenty of good reason. But even they deserve SOME level of fairness applied, and as the parent here posted, they are damned if they do, damned it they don't, in the eyes of this community anyway. That's unfair, and even THEY deserve some degree of fairness.

      --
      If a pion (n-) collides with a proton in the woods & noone is there to hear it, does lamdba decay into the source pa
  15. Firewall by Oculus+Habent · · Score: 5, Insightful
    Actually, yes. The first listed security change is turning on the firewall by default. Before the network stack loads, even, to prevent a gap between network availability and firewall protection.

    Other things that I find good include port management that both handle the opening and closing of ports, but also allows some applications to run as a regular user instead of administrator.

    There first complaint with SP2 was the NX command - which isn't available on most current processors. The second sounds like a benefit, not a complaint:

    there are literally scores of RPC-based services running, all of which provide a window for attack. That changes dramatically with SP2.
    Then they go on to complain about not offering to pirated copies, but forget to mention it's only the ten most pirated product keys. It's still a large number, I imagine, but not the whole picture.
    --
    That what was all this school was for... to teach us how to solve our own problems. -- janeowit
  16. Check the dates-- both articles are old news. by phillymjs · · Score: 5, Informative

    The WinXP article is dated June 7. The link points to a Silicon.com article about a security flaw in OS X, and that article is dated May 26.

    It was on June 7, the same day, that Apple released a second Security Update that fixed the remaining vulnerabilities.

    ~Philly

  17. Re:OS X did it with Classic mode - works great by Anonymous Coward · · Score: 5, Insightful

    Interesting how the Classic layer is "brilliant" when it comes to bashing Windows. But if when read the Mac boards, Classic is totally unusable and every vendor was under extreme pressure to produce a native version of their app immediately. Using mainstay apps like Quark or Outlook was apparently impossible under Classic.

    Classic is fine for what it is (us old OS/2 users used to call the VM the "Penalty Box"), but lets not pretend it's the compatibility solution for the ages. Frankly it's slow and the redraw is buggy and one only uses it when there is abosolutely no other choice.

    Besides, the article is about MS breaking modern Win32 applications, not legacy apps running inside a VM.

  18. Re:Pah. by MoonBuggy · · Score: 5, Interesting

    Spam zombie/pwned newbie machines will be running dog slow. The owners of said machines will either pay a techie to "fix AOL for them" at which point the techie removes viruses and spyware and installs the latest Windows updates (i.e. SP2) or the machines will simply be considered 'broken' by the owners (you'd be suprised how many people think they need to upgrade their hardware because they broke the software by installing crap) at which point Dell/PC World/Emachines will ship them a shiny new box complete with a patched up version of SP2. It might take a year or two, but assuming SP2 is as secure as MS is making out its proliferation will be very good for the internet at large.

  19. Re:OS X did it with Classic mode - works great by LightningBolt! · · Score: 5, Insightful

    > OS X did this brilliantly with the Classic compatibility layer.

    It's not an OS transition. The "compatibility" problems will come from the enabling of no-execute memory regions on the few processors that support that feature. This will cause problems for the rare old program which contains self-modifying code. I imagine it will also require Sun and others to modify their JIT compilers to declare runtime-compiled code as executable.

    In any case, there isn't really an analogy to OS9/OSX differences.

    --
    Old people fall. Young people spring. Rich people summer and winter.
  20. Backwards? by MasterVidBoi · · Score: 5, Insightful

    From a linux user, I see backwards compatability as the biggest nightmare of linux today. There is just too much of it, and it's holding back progress. Many of the points I'm about to address come from OS X, as I'm also a happy user of that system, and think it's a model for what can be improved about operating systems if you're willing to sacrifice some backwards compatability.

    Over 4 years ago slashdot was full of posts about how it would take the OOS community a couple weeks, months at most, to match Apple's nifty new compositing window system. Well, today 99% of us are still using X, and it really hasn't changed significantly. Even the extensions being worked on at FreeDesktop aren't in wide use, and it doesn't look like they will be soon.

    We're still stuck with an ancient standard directory hierarcy, and multiple search paths meant to find the same thing (what? I still have to have a huge autoconf macro in order to find both the LDFLAGS and CFLAGS necessary to include library foo?). This obviously isn't the best it could be, and yet no one even considers trying to change, because 'that's the way it was always done'. Again, look towards OS X. Headers, libraries, resources, documentation, XML files with library metadata, everything associated with libfoo is contained in a single directory 'foo.framework', not scattered in /usr/include, /usr/lib, /usr/share. This conventional *nix approach practically requires a package manager to keep things straight. Then, all that is required to compile against it, both finding includes and library search path, is a simple '-framework foo' argument to gcc, which follows a single search path. Easier to write makefiles, without wasting your time in autoconf.

    A lot of lessons have been learned since these systems have been designed. If you insist on supporting everything ever made, you're never going to get anywhere.

  21. They're Too Early by krmt · · Score: 5, Insightful

    While I fully applaud what MS is doing, it seems like the wrong time to be breaking legacy apps. Put out an actual new Windows release, rather than just a point update. People will be far less surprised when old software breaks with a full release, but with an update to the old system you shouldn't be breaking compatibility.

    This isn't a damned if you do, damned if you don't situation in reality, it just needs to be managed properly. By jumping the gun on this, they'll likely piss off users, but if it were longhorn or some interim release then some breakages are simply to be expected.

    That said, since I don't run Windows on my own machines, I get to be one of those that benefits by not having as much email or log spam due to 0wn3d winboxes (less spam please indeed!) so I can't complain. This is a distinct advantage of the Free software model, since Mozilla, OpenOffice, etc can be updated for no cost if this release happens to break them.

    --

    "I may not have morals, but I have standards."