back
175 comments
This seems like a nice altruistic useful thing, but (given some overly-trusting security practices we still often see) it'd still be good practice to keep some ideas in mind...

DECREASING LEVELS OF SECURITY:

1. Running Microsoft Windows.

2. Running out-of-support Microsoft Windows.

3. Running out-of-support Microsoft Windows and having it report itself to a server of unclear provenance and security (which could be efficiently indexing such insecure machines, and possibly even exploiting vulnerabilities during this simple interaction).

4. Running out-of-support Microsoft Windows and updating its system software from a server of unclear provenance and security (which could install malware, possibly even defeating any outdated vendor signing).

SUGGESTIONS:

* If your important science/medical/industrial/etc. equipment is stuck on ancient Microsoft Windows, probably you want to keep it airgapped and treat it gingerly, while planning to upgrade to more sustainable equipment (and hopefully it doesn't fail abruptly before convenient).

* If you're playing with Microsoft Windows for personal use, that's fine, but maybe consider whether you'd prefer to spend your time and energy instead learning and creating atop an open source software platform.

* For many business and personal purposes, Debian Stable is a good OS platform, and this is one installer for it: https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/

I hate windows, like I'm trying to get off it because of the ads/ragebait news. I hate edge. Microsoft is basically a never buy anymore, but according to this:

https://zerodium.com/program.html

Getting a Windows exploit is higher value than any linux exploit. Given how many servers use Linux, it makes me wonder if Linux 0 click are easier than windows.

There are a bunch of counters like 'there are too many distros', or 'a personal computer of a VIP is higher value than some corporations'. But I'm not sure its fair to include your point number 1.

I like to give people credit where its due, I imagine it took lots of work to make windows as secure as it is. (Giving Android OS the most credit for their 2.5M payout)

Compared to Windows, I find that most linux desktop distros have what I would call ‘stability vulnerabilities’ where the user has to tread carefully when doing something basic like updating graphics drivers or applying other updates, or changing resolution. Otherwise they end up with an OS that wont start or will just show a blank screen. I wouldn’t recommend linux for general business or personal use unless this kind of tinkering is enjoyable or you have sufficient IT staff.
That's pure fearmongering FUD.

Recommending Debian to the retrocomputing community is possibly the most tone-deaf thing I've seen today.

People always say this but

1) doesn't even a domestic router block all inbound connections?

2) is there any evidence of unpatched remote vulnerabilities for windows 98?

> Running Microsoft Windows.

Is Windows 11 with all of the default security settings really that insecure? Like Windows Defender, Windows Firewall, anything that needs admin needed you to click "yes, elevate to admin" through UAC

I'll never accuse old Windows of being bulletproof, but I've gotten some considerable reliability out of old appliances by adding SSDs, a passively cooled chassis, and a weekly reboot scheduled task. Basically, just get rid of the moving parts and plan for state drift.

Old OT is actually pretty easy to take care of aside from sourcing replacements for some secret sauce PCI card that is no longer made. New OT blurs the line with IT in a really difficult way however, you can no longer rely on a dead simple airgap to solve your security concerns because everything and its mother wants to be on the internet.

I'm glad somebody brought this up. I was waiting for the follow-up article to post on HN about the "Botnet of Windows 98 Machines"
"Be very careful connecting to some random server and running code from people you've never met, with whom you have no contract or legal comeback, just because other people are doing it. Also, download Debian!"
>* If you're playing with Microsoft Windows for personal use, that's fine, but maybe consider whether you'd prefer to spend your time and energy instead learning and creating atop an open source software platform.

Open source does not address my need or desire for Windows, regardless outdatedness.

Seriously, it's annoying that fReE and oPeN sOuRcE are thrown around like they will solve all the problems in the world. Spoiler alert, they don't. Especially if that problem involves a practical need that most libertarian neckbeards wouldn't care about.

Yes I run Windows, and yes I happily run EOL Windows because they are required to run something reliably. And yes, I happily run unpatched Windows because updates break shit and waste my time compared to the dangers posed by hypothetical threats outside my practical threat model.

Something being free or open source does not in any way fundamentally address my needs and desires. No, Wine is not a panacea (unless we're talking about the drink). No, I'm not going to waste even more time getting Linux to work just so I can get on with life.

What about retro gaming?
What I'd love is a project for Windows 11 that gives me back full control of which updates I download and when I reboot. I've been living with vague registry hacks and the "pause for 5 weeks" button but they're getting less effective.
The genuine answer is that you won't get this functionality unless you use windows enterprise. Which of course you can't purchase.. This functionality is locked to just the enterprise and will likely never change..
This should go without saying but this flagrant disregard for what users want is going to continue and get worse as long as people keep buying and using Windows. I wonder pretty often why people put themselves through this crap to use Windows.
I'm solving this for myself with Windows 10 LTSC, which I keep activated with an activation emulator I host. For a professional, it was super easy to setup, virtually zero maintenance, and I get a pass on at least a good chunk of the bullshit that goes on in the MS-verse. Functionality doesn't seem to be lost, but I just use it to play my multiplayer games because of their Windows-only rootkit, I mean, anti-cheat.
You are the beta tester. While you're using "your" windows, you're performing a task as an unofficial employee. If something is free for you, you are the product that is sold.
Windows pro managed through intune should give you that control, though it is a bit of an awkward path for a single user.
Just buy a pro/enterprise version, they support the GPOs to block updates
Windows Update Blocker works as a nuclear option to disable all updates.
Use registry editor to export And then delete wupdsvc and waasMedicSvc services. (HKLM/system/currentControlSet/Services) Reboot. Enjoy. Whenever you want updates, double click exported “reg” file and reboot. Allow updates to install. Delete services again.
Lookup Windows 10 LTSC
Not sure if this is because I run the Pro version but I've never ever ever once had Windows 10 or 11 reboot to install updates on it's own.
PSA: Security updates for 2000 and XP are still available from Microsoft at https://www.catalog.update.microsoft.com/
Windows Update did a better job over the years selling me on the Mac platform than Apple ever could
Funny enough, windows updates are infinitely better than macOS updates, which takes 30-60 mins each time.
The sad thing is that IMO, Windows users brought the shitty Windows Update implementation on themselves.

It was common in the Windows XP days for many users to never install updates and it really contributed to Windows's reputation for being incredibly insecure. Forcing updates became the only option to ensure Windows users remain secure.

Last time I tried to tinker with Windows XP few years ago: you couldn't just update it after installation, but if you let it work for a few days, eventually it'd download and install updates automatically. And after those updates are installed, you can actually use Windows Update UI to install optional updates and other things.

It definitely was after 2011.

DOS is easy to emulate - and dosbox does a great job of it, even in a web browser.

Windows 3.1, 95, 98, Me are less easy to emulate.

Note that that seems to have impacted the preservation of old games and programs. Plenty of dos games are all over the web and still quite popular, yet most stuff from the Win 9x era has almost entirely vanished due to the difficulty of running it on modern hardware.

Archivists take note - if you want something to live for a long time, it needs to be easy to emulate. And in turn, that means it needs to be both very common, and have simple API's so someone in the future can be bothered to make and maintain an emulator.

> most stuff from the Win 9x era has almost entirely vanished due to the difficulty of running it on modern hardware.

The tricky part is that this applies even if you're using a VM. I learned the hard way that Windows 98 isn't compatible with Ryzen CPUs, even through VirtualBox. I had to try again on another PC with an older Intel CPU.

DOS may be easy to emulate and re-implement because it's a single task operating system that does not do much. Most of hardware is accessed directly, and needs to be emulated instead. We enjoy great compatibility because of the enormous leap in performance since then (the slower the system the easier it is to simulate correctly on a modern one), and the combined knowledge of all the ins and outs collected during the PC boom by software authors and hardware makers implementing and re-implementing compatible devices.
I've had great success running Win 95 games on modern hardware. I just had to do it in Wine, amusingly enough.
I wanted to play certain games from that era (Spiderweb's Exile series), and the best solution I found was to just play the MacOS versions with SheepShaver.

You can technically get Windows 9x software running in a VM, but not without laggy video/audio in my experience.

> Archivists take note - if you want something to live for a long time, it needs to be easy to emulate

how do archivists have a say in this?

I looked up the last update for Windows XP - KB4500331[1] from May 2019. Eighteen years after the OS was released. Gotta give credit for that.

[1]: https://www.catalog.update.microsoft.com/Search.aspx?q=SP3+X...

Huh, I never realized that 95/98/ME ever had online updates in the first place.
It all started in Windows 98 with the launch of Windows Update; they then released the Critical Update Notification Tool (later renamed to Utility, for obvious reasons) which would query the website and just tell you when a critical update was available to go check the site.

Otherwise, in the 95 era, I believe you'd likely be finding out through a software vendor or otherwise that a certain fixpack from Microsoft might fix an issue and you should go grab an update then.

Me neither.

Wikipedia:

> Windows Update was introduced as a web app with the launch of Windows 98 and offered additional desktop themes, games, device driver updates, and optional components such as NetMeeting. Windows 95 and Windows NT 4.0 were retroactively given the ability to access the Windows Update website and download updates designed for those operating systems, starting with the release of Internet Explorer 4.

Seems like a centralized repository for a collection of updates issued by MS to windows computers. Does this bring additional security updates not issued by MS?
What’s the advantage over Legacy Update which seems to work pretty well.
This is exactly what I was looking for. Thanks.

(Sent from a ThinkPad x41 running Windows XP)

So I may have missed it, are they hosting old updates to make them available still or are they actually patching old SW with new builds. For example say the last update for XP was SP3.5, they got the tooling to build and release 3.6 which was never released by Microsoft but is from this organization? Is it one or both?
Is ReactOS stable enough to replace an old Windows 95 installation?
I saw an ATM reboot into XP kiosk mode the other week.

Struck me as a bit unsafe?

BTW this also exists or did exist for "Fix Windows Update on Windows XP, Vista, Server 2008, 2003, and 2000"

https://github.com/kirb/LegacyUpdate

What is the meaningful purpose of "Windows Update" for versions no longer recieving active patches. (I imagine there's some bigcorp or biggov that will pay whatever price is necessary to get a patch for XP, but anything earlier?)

Couldn't they collect and systematically 'slipstream' every patch and fix that would exist on Windows Update into a "Final Edition" ISO?

Or is the scope broader than a naive reading of the headline, and non-OS packages (drivers, third party software) were also relayed through WU?

I have to say this is awesome

> This website requires a minimum of Internet Explorer 5.0 or above, but we recommend Internet Explorer 5.5. To download Internet Explorer 5.5, Click Here

My most recent use-case for XP (in VMs) is to deploy IE as a remote app, to access old DVRs that require ActiveX for web view.
Does anyone have any experience with 0patch? I use it to keep a couple of old Win7 systems patched but it makes me nervous…
How about adding some instructions on how to use it? Just saying...
why no https on this site?