Story image

It’s time to finally say goodbye to Windows XP. And Vista. Again.

10 Apr 2017

On April 8 it was three years since Microsoft ended its extended support for Windows XP. Despite the fact that no one is patching its vulnerabilities, almost 8% of desktop users worldwide still run the operating system.

Somewhat paradoxically, XPs are still very much alive and kicking compared to some of its successors. Windows Vista – which will be abandoned by Microsoft next week on April 11 – only runs on less than 1% of desktops and figures for Windows 8 and Windows 8.1 combined are comparable to XP’s current stats.

You might ask, what is the reason for people to keep such old software on their desktops, even beyond its ‘use by date’ (which was April 2014)?

There are several reasons:

  • The computer was used to run a key application(s), which only worked under Windows XP.
  • The computer was used to operate a piece of hardware, which only worked with Microsoft Windows XP. This was mostly in cases of industrial, medical or scientific equipment where the operating system acted as a kind of embedded controller, and the cost of upgrading the system to support newer versions – or replacing – was possibly cost-prohibitive.
  • The computer was used to perform a specific set of functions familiar to the user and comfortable to use.
  • Or users simply don’t want to pay for another license and security doesn’t concern them as they only use it for very specific activities – such as browsing their favorite news websites or writing up recipes (which can be done even if offline).

However, with every additional year after the end of extended support, the likelihood of security issues and incidents increases. So unless you are using XPs in an air-gapped setting or only for non-crucial activities, you should consider moving on to a newer version offering a more secure experience.

Without patches and updates, your PC becomes an easier target for malicious code that can steal or damage your data. The same goes for many XP-specific applications that have become unsupported in the past three years and open additional attack surface for the attackers.

Although, there are also a few exceptions to this rule, like Firefox, which announced it will be automatically moving all Windows XP and Vista users to the extended support release.

So what should you do if you still want to run Windows XP?

  1. If you don’t want to part from your XPs, install all available updates (Service Pack 3 is a good start) for the OS. Also update all the software you are using to the latest possible version supported for the XPs.
  2. If possible, run the XPs in an air-gapped setting – so without internet connection. As an alternative, you can always cut the connection when you don’t need it.
  3. Use a reliable, updated and multilayered security software (if the computer is air-gapped, it will only update at the moment you connect to the internet).
  4. Use a separate administrator and user account(s) – based on how many people are using the desktop. This helps to limit the possible malicious use of the elevated rights by the attackers, even if they achieve to control your computer.
  5. Disable AutoPlay and AutoRun features, as these were often misused by malware or its writers to install or download malicious code to the victim’s machine.

We need to emphasise that none of these steps will keep your desktop completely safe; they will merely reduce the attack surface. The best option is to move on to a newer operating system offering updates and patches as well as updated applications and install a security solution as an additional layer of protection.

Article by Ondrej Kubovič, welivesecurity evangelist.

NVIDIA announces Jetson Nano: A US$99 tiny, yet mighty AI computer 
“Jetson Nano makes AI more accessible to everyone, and is supported by the same underlying architecture and software that powers the world's supercomputers.”
Slack doubles down on enterprise key management
EKM adds an extra layer of protection so customers can share conversations, files, and data while still meeting their own risk mitigation requirements.
NVIDIA introduces a new breed of high-performance workstations
“Data science is one of the fastest growing fields of computer science and impacts every industry."
Apple says its new iMacs are "pretty freaking powerful"
The company has chosen the tagline “Pretty. Freaking powerful” as the tagline – and it’s not too hard to see why.
NZ ISPs issue open letter to social media giants to discuss censorship
Content sharing platforms have a duty of care to proactively monitor for harmful content, act expeditiously to remove content which is flagged to them as illegal.
Partnership brings AI maths tutor to NZ schools
“AMY can understand why students make a mistake, and then teach them what they need straight away so they don't get stuck."
Polycom & Plantronics rebrand to Poly, a new UC powerhouse
The name change comes after last year’s Plantronics acquisition of Polycom, a deal that was worth US $2 billion.
Unencrypted Gearbest database leaves over 1.5mil shoppers’ records exposed
Depending on the countries and information requirements, the data could give hackers access to online government portals, banking apps, and health insurance records.