Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It concerns me more that the UK's healthcare system runs on a no longer supported operating system. Something that important should be kept up to date.

The UK's NHS computers were running Windows XP (which was EOL). http://www.telegraph.co.uk/news/2017/05/12/nhs-hit-major-cyb...

Otherwise, the patch to fix the security flaw was released back in March before it was a real problem. There will always be holes in software, it's important to have a system in place to patch them in a timely manner.



"only" 5% of the computers are running XP, which is an improvement driven through after a report given to Hunt last year about the risks of old IT.

It wasn't just affecting XP machines, it was affecting other machines if they hadn't been patched.

http://www.bbc.co.uk/news/uk-39918426

> We know there have been warnings before about IT security in the NHS - last summer a review said it needed looking at.

> But the problem is that over the last three years the capital budget - which is a ring-fenced fund used to pay for buildings and equipment - has been raided by the government to bail out day-to-day services, such as A&E.

> Last year a fifth of the capital budget was diverted.

> That, of course, makes it more difficult for trusts to keep their systems up to date.

EDIT: Here's a better post https://www.instituteforgovernment.org.uk/blog/nhs-cyber-att...

> One of the problems with digital government is reforming the technology infrastructure which underpins its services (‘legacy’). There has been much speculation about how the continued use of Windows XP operating systems within the NHS contributed to the cyber-attack. Although only 4.7% of NHS devices use Windows XP, these are spread across 90% of trusts. Computers that have not been updated with Microsoft’s latest software were susceptible to the ransomware. Meanwhile, NHS legacies are further complicated by the patchwork of contracts across trusts. This digital fragmentation is in keeping with the scale of fragmentation within the NHS itself.


> it was affecting other machines if they hadn't been patched.

My point is mission critical software should always be up to date. To go months without installing the update on important systems is unacceptable. It doesn't matter who originally released this exploit, exploits routinely become available. It's about fixing them in a timely manner when they appear.


> It concerns me more that the UK's healthcare system runs on a no longer supported operating system. Something that important should be kept up to date.

I was recently thinking that software producers wishing to discontinue support for a software product should have to open source that product version (or at least, disclose the source to to paying customers). That way others can continue to support it and backport patches if it's truly necessary.


Most software is based on previous renditions of the same software. This would never work in practice without giving up trade secrets.


And? Trade secrets have and deserve little legal protection. This will have one of two effects: either software products will gain longer term support because companies want to retain their secrets, or supporting old versions becomes so costly for them that they are willing to let the source go.

Either outcome seems better for customers. In fact, it's significant incentive for better development practices and good software design so these companies can maintain older versions more easily. Sounds pretty good all around, so where's the downside?


Call me crazy, but I don't think any government should be running closed source software for anything where there exists an open source alternative.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: