Log in

View Full Version : Windows XP support discussion (split from MediaInfo thread)


LoRd_MuldeR
17th November 2014, 04:22
...some because they are too lazy to upgrade, and others like me because they feel that XP is better than Win7 or Win8... :)

Doesn't change the fact that any security vulnerability found in Windows XP after the end-of-support date (April 2014), like this (http://www.pcworld.com/article/2846004/microsoft-fixes-severe-19-year-old-windows-bug-found-in-everything-since-windows-95.html) recently discovered bug which effects all Windows versions since Windows 95, will remain unfixed forever.

So I'm not sure we should encourage people to continue using a system that is known to be insecure by still providing "fresh" compatible software for that system ;)

(BTW: According to "my" numbers, Windows XP has dropped to 13%, while Windows 8.1 is at 18% now and Windows 8 at 4%. Windows 7 still clearly is the most famous system with 55%. And Vista is negligible)

LoRd_MuldeR
17th November 2014, 14:05
If your software runs on XP you are not 'encouraging' users to use XP, you are enabling them to use your software, if not, then they will not use your software.

Still updating software for Windows XP gives people a false feeling of security. You cannot build a secure software stack on top of a vulnerable operating system. But if more and more software cannot be updated anymore, because the latest version won't run on Windows XP, most people will realize that it's time to move on. There'll always be a small group of Windows XP enthusiasts that will never upgrade. But you'll never convince those anyway...

Embedded XP will get the fix for linked bug and be added to the XP SP4 which is currently being worked on by a private individual.

Since Windows XP is ClosedSource only Microsoft can release patches for it. And we all know that they won't release any patches, not even security fixes, for the normal "consumer" version after April 2014. Thus any unofficial SP-4 can only bundle old patches that were released between the SP-3 and the end-of-support date. This isn't necessarily a bad thing. But it should be clear that it doesn't address any vulnerabilities discovered after April 2014.

Patches for the "embedded" version of Windows XP don't help the situation either. Neither do these patches address all the vulnerabilities in "consumer" version of Windows XP (they only address vulnerabilities relevant for "embedded" version) nor have these patches been tested to work correctly with the "consumer" version of Windows XP. But most important: All the normal Windows XP users out there will never be able to get these patches! Microsoft only gives those patches to "enterprise" users who have a payed support contract. And if any "private individual" redistributes these patches without Microsoft's consent, he or she should expect an unfriendly letter from Microsoft's legal department...

Internet Explorer was/is always going to be a security nightmare, what with all of the new ways to break-in that MS keeps inventing (then inventing ways to stop the new inventions from being used/exploited).

Many Windows applications embed IE frames, so you cannot really get around IE on Windows, even if you wanted to. But IE isn't the biggest problem here. Every software unavoidably uses services of the operating system. And if the operating system is flawed, so is your software that runs on top. Again: You cannot build a secure software stack on top of a vulnerable operating system. Furthermore, sooner or later, sticking with Windows XP will force you to use "legacy" web-browsers, PDF viewers, and so on. That's because even the alternative programs (Firefox, etc) won't support XP forever. So you will end up running "legacy" software with known vulnerabilities on a "legacy" operating system with known vulnerabilities.

I suspect that the usage numbers for XP are substantially underestimated, there are a lot of machines out there that will not be 'on-the-books', and thereis no shortage of new machines being sold that come with this ancient OS.

Don't trust any numbers that you haven't faked yourself ;)

I primarily trust on "my" own statistics. They may not accurately represent the overall situation, but they should represent "my" user base fairly well. And those numbers look like this:

http://i.imgbox.com/fqjxnEoC.png

I still use XP32SP3 (SP4 when stable), and no amount of 'encouragment' is gonna dissuade me, next step would probably be Ubuntu.

IMO, running an up-to-date Linux distribution is far better than sticking with an outdated/unsupported Windows version.

If any relatives ask for help, because their Windows XP system has been infected by some virus/trojan once again, I usually "upgrade" these old machines to Xubuntu nowadays :D

the_weirdo
17th November 2014, 14:09
Most people who are still using XP don't care about security, they also don't often care about updating softwares anyway. They can always use older versions when developers drop support for XP. And it's not like there's a great loss if they don't use your software.

StainlessS
17th November 2014, 18:42
Thank you for you response m'lud although I cannot agree with all you said.
I dont think MS will want to chase XP updates being touted, might make them look real bad as the no longer support it themselves, there is no upside to it for them.
People messing with Video/Audio are on the whole much more likely to have a nice bright and sparkly new machine with gazillions of cores, and OS to boot,
perhaps your figures are reflecting that.

EDIT: I still prefer Windows 2000 Pro to XP.

manolito
17th November 2014, 22:18
I mostly agree with StainlessS, still there's some things I'd like to say in response to LoRd_MuldeR:

1. The security risks by running XP are greatly exaggerated. Most of the published content about these risks comes either from Microsoft itself or some outside parties which are highly dependent on MS.

In the real world most security risks do not come from the operating system itself. Take away the risks from email links, browsers, PDF viewers, FlashPlayer and Java, then there are not too many threats left. Use a decent AV software, and most of all use good judgement, then there will only be a minimum risk left.

And IMO it is really Microsoft who gives users a false feeling of security. They suggest that you only have to keep your OS updated and that's enough to protect you. Nothing could be more wrong. There are always 0-day exploits, there is malware which does not get detected for months, and MS sometimes takes forever to patch known security problems. Bottom line: Without a reasonable backup strategy there is no security. Depending on the importance of your files and documents you absolutely have to make regular backups, use more than one backup media and keep several generations of your backups.


2. Getting the patches for the embedded version of XP takes just one additional registry entry. It might be disputed how useful these patches are, but downloading and installing these patches is hardly illegal. (There is a software called "CacheMan" from Outertech which adds this key on installation, it is enabled by default)


3. Usage statistics always have to be taken with caution. Recently it was reported that there was a sharp drop in XP usage by more than 7% within one month. Later it turned out that NetStats had simply changed their measuring algorithm.


4. My most important concern is where desktop opereating systems are headed. Information about the upcoming Win 10 revealed that in the future the MS operating systems will be free of charge to the users. But it will be MS and only MS who decide what can run on the computer and what cannot. End users will no longer be able to reject updates to the OS (how often has MS distributed updates which made the computer non-bootable in the past?) It is heading into the Apple direction where the company can and does even push content (the U2 album) on every machine running this OS.


And my complaints about Win7 and Win8 are along this line, too. MS has the philosophy that all users are stupid and must be protected from themselves. They also believe that the real owner of the computer is not the user who has paid for it, but that they are.

For users like me who do like to get into the internals of a computer, Win8 (and even Win7) can be a nightmare. Small list of annoyances:

UAC
Virtual store
Folder, file and registry permissions.

The 64bit versions even add more illogical quirks. Who in his right mind could ever come up with the idea to name the folder for 32bit system drivers "SysWow64" ? Any normal person who sees the 64 in the folder name assumes that this folder houses 64bit drivers.

WinXP for me is the last version where an informed user like me still is in the drivers seat. I own the computer, I paid for the OS, and I am the only one who decides what I can do with a file, a folder or the registry. If I screw up, I know how to fix it, I won't call MS crying for help.

My personal outlook is that I will probably install a Linux version and run XP in a VM. A promising alternative could be ReactOS, but they still need some time (a lot of time probably).



Cheers
manolito

LoRd_MuldeR
17th November 2014, 22:55
1. The security risks by running XP are greatly exaggerated. Most of the published content about these risks comes either from Microsoft itself or some outside parties which are highly dependent on MS.

By now, there are several known security vulnerabilities in Windows XP that allow for remote code execution and that are never going to be fixed (at least not in the "consumer" version), like this one:
http://www.darkreading.com/vulnerabilities---threats/microsoft-fixes-critical-schannel-and-ole-bugs-but-no-patches-for-xp/d/d-id/1317423

So the situation is quite clear, whether you like it or not. No exaggeration needed.

In the real world most security risks do not come from the operating system itself. Take away the risks from email links, browsers, PDF viewers, FlashPlayer and Java, then there are not too many threats left.

Keeping your applications, like Bowsers, PDF Viewers, FlashPlayer and so on, up-to-date is essential, yes. However, security always depends on the complete software stack! User-space programs run on top of the operating system. They rely on services provided by operating system. Thus, if the operating system is flawed, then so is everything that runs on top. You cannot build a secure software stack on top of a flawed operating system. It's a simple as that.

In addition to that: Application developers drop support for "legacy" operating systems sooner or later. Thus, sooner or later, you will be forced to use outdated applications, which means even more known vulnerabilities that will never get fixed for you. For example, try to find an up-to-date Browser for Windows 2000 today. Hopeless. For example, the last Firefox working on Windows 2000 was something around v3.6. The situation on Windows XP will be no different in the near future...

Use a decent AV software, and most of all use good judgement, then there will only be a minimum risk left.

The problem is that good judgment doesn't help against security vulnerabilities at all. That's because if you are using vulnerable software (versions), no special user actions are required to get your system infected. It could be enough to visit a certain web-site (which could be a perfectly normal web-site where somebody has "implanted" the exploit code). It could even be enough to connect your computer to the Internet. That's the whole point.

Also, Anti-Virus software that is running on top of a flawed operating system cannot provide security either. For the same reason you should be running your Anti-Virus software from a 100% clean Boot-CD when you suspect that your system might have been infected. Running the Anti-Virus software on a potentially infected operating system is pointless, because (like every software) the Anti-Virus software depends on services provided by the operating system.

And IMO it is really Microsoft who gives users a false feeling of security. They suggest that you only have to keep your OS updated and that's enough to protect you. Nothing could be more wrong. There are always 0-day exploits, there is malware which does not get detected for months, and MS sometimes takes forever to patch known security problems. Bottom line: Without a reasonable backup strategy there is no security. Depending on the importance of your files and documents you absolutely have to make regular backups, use more than one backup media and keep several generations of your backups.

The 100% bug-free software doesn't exist in the real world. And it will never exist. Especially not when it comes to operating systems, which consist of millions of lines of code. So we can safely assume that there are critical security vulnerabilities in all major operating system, including Windows, Linux and MacOS X. So the actual question is how we deal with this situation. And the only answer is: Software developers must continuously fix bugs as they are discovered and release updates as soon as possible. And users must continuously install these updates as soon as possible. There still can be so-called "0-day exploits", of course, but the job for everybody should be to keep the window of vulnerability as short as possible. Using a piece of software (or a software version) that has well-known vulnerabilities, for which there are exploits circulating on the Internet, is simply thoughtless. It's an invitation for every "script kiddie" and every criminal out there to infect your system.

hello_hello
19th November 2014, 15:20
The problem is that good judgment doesn't help against security vulnerabilities at all. That's because if you are using vulnerable software (versions), no special user actions are required to get your system infected. It could be enough to visit a certain web-site (which could be a perfectly normal web-site where somebody has "implanted" the exploit code). It could even be enough to connect your computer to the Internet. That's the whole point.

I still run XP on two computers, generally running and connected to the internet 24/7. I visit dark corners of the internet. I don't run anti-virus or anti-malware software or a software firewall (I'm behind a router). Around once a year I install an antivirus program on each (on the second hard drive with a barebones Windows installation that's hardly ever used) and run a full scan. It's yet to turn up anything nasty. Then I restore the previous image of XP and installed programs, run Windows Update, update software as required, make a new image and that's it for at least another year. Sometimes longer. The last time I ran Windows Update was April 2013 when I last went through the above process for both PCs. I guess I'm over-due.

If I'm cleaning nasties off a PC it's always someone else's PC and it's pretty much always running antivirus software. Tomorrow I've got to visit the ex and play "find the nasty" on her Win7 laptop. It mightn't be infected. It could be running really slowly for other reasons, but if it is infected, it wouldn't be the first time.

My experience tells me running an up to date browser (I run Firefox) and using good judgement is the best protection available. The young relatives, who'll happily click through anything in their way without thinking, seem the most likely to become infected, despite anti-virus software.

I know I'm going to have to upgrade Windows at some stage. I've been planning on upgrading one of these PCs (or building a new one) for a couple of years (I've even bought most of the parts now) but that'll mean at least Win7 due to a lack of XP drivers, which is also a reason I've put off upgrading for so long.

I hate upgrading the OS and software just for the sake of it. It was fun years ago, but now I just want to use the PC, not spend all my time maintaining it. If I'm going to upgrade there's got to be a real benefit to doing so. After days of work tweaking Windows, installing and configuring software, installing updates and sorting out problems, I'd really prefer the best case scenario to be something more than "everything will work just as it did before". :)

Ghitulescu
19th November 2014, 16:53
Doesn't change the fact that any security vulnerability found in Windows XP after the end-of-support date (April 2014), like this (http://www.pcworld.com/article/2846004/microsoft-fixes-severe-19-year-old-windows-bug-found-in-everything-since-windows-95.html) recently discovered bug which effects all Windows versions since Windows 95, will remain unfixed forever.

So I'm not sure we should encourage people to continue using a system that is known to be insecure by still providing "fresh" compatible software for that system ;)

I said it and I maintain

Why on hell one would have to be worried about internet security issues, when that damn computer is not supposed to be connected to internet?

A video computer has to process videos, videos that enter via whatever media (capturing card including DVB, FireWire, DVD/BD-ripper, MemoryCards (eg from camcorder or SmartPhones) and USB-media), and exits again on virus-free media (DVDR, BDR, USB-media).

Those that connect their PC to the internet either haven't paid for their software, since a virus cleaning might require the reinstallation of many payware, or are "innocent victims".

LoRd_MuldeR
19th November 2014, 17:40
I said it and I maintain

Why on hell one would have to be worried about internet security issues, when that damn computer is not supposed to be connected to internet?

Well, if your computer is not connected to any network (Internet, home network, company Intranet, etc.) and if you never process any files that came from an "external" source (downloaded from the WWW, received by E-Mail, handed over from a colleague/fried, etc.) you are pretty much on the safe side. All the vulnerabilities will still be there, of course. But, by isolating your computer completely from the "outer world", you don't give the attacker any attack vector.

BUT: How realistic is this scenario? How useful is a computer that can only be operated safely under such harsh restrictions? Not that much!

A video computer has to process videos, videos that enter via whatever media (capturing card including DVB, FireWire, DVD/BD-ripper, MemoryCards (eg from camcorder or SmartPhones) and USB-media), and exits again on virus-free media (DVDR, BDR, USB-media).

A malicious file can get onto your computer in many ways. The Internet is one way. But optical media and especially USB-media can work just as well.

The problem with security vulnerabilities in outdated/unmaintained software is that no special user interaction is needed to exploit these vulnerabilities. Just imagine you got a malicious video file from a fried on USB stick (maybe even without your friend being aware of this). Just opening the USB stick in Windows Explorer might be enough to get your computer infected! That's because at this point Windows Explorer will generate a preview image for the video using some Shell Extension. And, if there's some security vulnerability in that Shell Extension (not that uncommon!), which is being exploited by the malicious file, this is enough for remote code execution on your computer. Of course this is only one example of how it might happen!

The same could happen in a zillion of different but similar ways. For example with pictures files that you view in some image viewer applications, PDF files that you view in a PDF reader, and so on, and so on... (the list is infinite)

clsid
19th November 2014, 20:22
You can easily prevent most exploits from working by installing EMET. It even works on unknown/unpatched holes.

Microsoft still makes patches for XP for companies/governments that are paying for extended support. It is very likely that those are the same patches as the ones distributed for the WEPOS version of XP, which you can get by using the registry hack.

Then also just use a restricted user account for daily use and run your webbrowser in a sandbox (like sandboxie). With these easy steps you can make an XP install even more secure than a vanilla up-to-date Win7 box.

manolito
19th November 2014, 20:54
My usage pattern is very similar to the one of hello_hello, and in many years of using computers (visiting questionable sites frequently) my machine got infected just twice. And the only reason was that I deliberately ignored ThreatFire's warnings, because I was in the mood to analyze the infection. :p

OTOH I did loose quite some time solving problems with borked MS updates. Especially the updates for the .NET framework were a major PITA on several occasions. Incidentally just a few days ago MS screwed up their SChannel Patch, fixing it took them several days.

From the ReactOS FAQ:
Why ReactOS? Why clone Microsoft Windows?

ReactOS is not technically a clone of Microsoft Windows. ReactOS is an operating system that implements the NT architecture and is compatible with Microsoft Windows applications and drivers. The developers involved believe that the NT architecture itself is robust and powerful but are often frustrated by some of Microsoft's business decisions in restricting Windows. As such, they elected to write an NT operating system of their own. For end users, ReactOS' ability to run both Windows programs and drivers provides people with another alternative should they need to replace a Windows installation.


I really look forward to a stable version, and I hope that there will be enough software developers who are willing to make their software compatible with it.


In the meantime it is not too hard to make an XP installation at least as secure as a Win7 or Win8 installation (like clsid pointed out).

Another method I tried a while ago goes like this:
Use a clean XP installation (I used SP2 because all the software I use does not require SP3). Move all data folders to a separate partition (there are dozens of howto's on the web). Disable auto update, disable system recovery, disable auto defrag and all other automatic housekeeping. Do not install a virus scanner.

Then install all the software you will be using and set it up to store their data on the data partition. Once you are satisfied make an image backup of the system partition as a reference.

Now install one of the (free) time freeze applications. There is RebootRestore RX or Toolwiz TimeFreeze. From now on you will be back to the reference system partition after every reboot. You will need to make file based backups of your data partition, but you don't have to touch the system partition as long as you don't install new software.

I was amazed how fast and responsive my computer felt with this setup compared to the other installation with all the MS updates plus a resident AV scanner. (BTW I also tried to achieve the same thing with a VM snapshot, but this was way too slow on my machine.)


Cheers
manolito

StainlessS
19th November 2014, 23:45
This is turning into a rather interesting thread.

@ manolito, I'm with you on ReactOS, I hope that they can pull in a few more developers.

I've never been a big fan of M$ but they do do a reasonable job at making things easy for people.
I'm all for the linux non proprietary model but have a bit of a problem with some things Linux, eg
I like a word processor to have a name like 'Word', Giraffe or Duck-Billed-Platypus or similar, just dont make any sense to me as a name,
especially when installing some Linux package for a program called eg Giraffe, description says something like "Installs the Giraffe package",
what I want to know is 'WHAT DOES IT DO', the slightest clue would be good, goddam infuriating.

An operating system should be reasonably static, its purpose is to provide basic interaction with the hardware, ie avoid having to include your
own routines to eg send a character to the printer, or file storage device. Proprietary systems want you to keep purchasing the latest greatest
version with some added extras that do things that really are not in the domain of the operating system.
Operating systems should have bug fixes and of course improvements in operation made but should really not be to dissimilar from previous
versions. Some parts of the MCSE (and more recent named versions of same) have questions like "What is the new name for 'Add or remove Programs'",
It seems like M$ just wanna change things so they can justify charging for a new OS, and also charge again for new MCSE quals, just for changing
the name of something, or 'where is the new place to find xxxx config'.

Even if you do buy a nice sparkly new machine with MUCH faster processor and new OS, you tend to find that it dont go any faster than what you
had already (given that your old system was given a spring clean or reinstall), nice new fast machine and the OS grinds it back to about the same speed again.
I'm running as my No 1 M/C (I have 3 m/c's, + two or three in pieces and 1 Laptop + couple of non-functional ones) a 2.4Ghz Duel core Core Duo,
cost me £10 at Wimbledon Stadium car boot sale. It's not the fastest in the world, but does me and cost almost nothing. I like to pick up machines in the
street and make use of bits and pieces, would be nice to have a nice 32 core m/c but I dont really need one for what I do.

A few years ago, I was having a drink with a woman, she told me that she had been having problems with her machine, was REALLY slow and so she
had somone take a look at it. The guy installed an anti-virus package and it showed that she had 2,400 active virus's, I'm was surprised it managed to run at all.

Anyway, I'll stick with XP for the mo, if only I could find an OS that was more recent but also felt more like Windows 2000
(Sounds like ReactOS might do).

EDIT: How come my 2.4GHz XP machine seems slower than my Commodore Amiga 1200(10MB, 14MHz, I think, not included in above m/c's,
nor is my Atari ST[4MB 8MHz] that also still have, got rid of about 7 Pentium III's about 12 months ago).

Most of this is OT, Slap me if you want to.

Ghitulescu
20th November 2014, 09:39
Well, if your computer is not connected to any network (Internet, home network, company Intranet, etc.) and if you never process any files that came from an "external" source (downloaded from the WWW, received by E-Mail, handed over from a colleague/fried, etc.) you are pretty much on the safe side. All the vulnerabilities will still be there, of course. But, by isolating your computer completely from the "outer world", you don't give the attacker any attack vector.

BUT: How realistic is this scenario? How useful is a computer that can only be operated safely under such harsh restrictions? Not that much!



A malicious file can get onto your computer in many ways. The Internet is one way. But optical media and especially USB-media can work just as well.

The problem with security vulnerabilities in outdated/unmaintained software is that no special user interaction is needed to exploit these vulnerabilities. Just imagine you got a malicious video file from a fried on USB stick (maybe even without your friend being aware of this). Just opening the USB stick in Windows Explorer might be enough to get your computer infected! That's because at this point Windows Explorer will generate a preview image for the video using some Shell Extension. And, if there's some security vulnerability in that Shell Extension (not that uncommon!), which is being exploited by the malicious file, this is enough for remote code execution on your computer. Of course this is only one example of how it might happen!

The same could happen in a zillion of different but similar ways. For example with pictures files that you view in some image viewer applications, PDF files that you view in a PDF reader, and so on, and so on... (the list is infinite)

Realistic or not, this scenario is employed on all employers I've worked for so far :) and I believe the number of computers in corporates and agencies, organisations, etc are at least equal to those in private hands.

Secondly, getting untested media is a fault of the user of that computer. It may also indicate a copyright violation :). It is not that hard to have a testing computer that runs a diag software.

Thirdly, I disabled all shell extensions and various autoruns. I don't need things to be carried out without my knowledge. If I do a mistake, then it's my voluntary fault, and I, and only I, am to blame.

Fourthly, I did a mirror on a clean, freshly installed system, with all patches and installed software. It may help if the computer becomes somehow (see #3) ...

Finally, there are things that cannot be upgraded. Or the upgrade costs a lot, maybe in 5 figures. Imagine someone paid a hell lotta money for a state-of-the art videocapturing card (or audio, or acquisition), and there are no drivers for the next OS, since the manufacturer wants to sell the new product, equally expensive, and to drop the support for the old ones. Imagine some of these older products being better than newer ones, for reasons everyone should know (costs cuts, optimisations only for the newer codecs/formats etc). Even if I wouldn't do any of the prevention measures #1-4 above I still won't pay another 100€ (or 250€) to force me fork another 4000€ for a similar quality card (old one unsupported), or similar money for unsupported software (that won't run even in compatibility modus).

I can't stop this mas hysteria :) but I least I can stop me :) :)

Ghitulescu
20th November 2014, 09:42
Microsoft still makes patches for XP for companies/governments that are paying for extended support. It is very likely that those are the same patches as the ones distributed for the WEPOS version of XP, which you can get by using the registry hack.

I don't think so, we had extended support and this ended, truly later than the others but it ended.

manolito
12th December 2014, 15:51
that thread has some exceptionally low quality argumentation, even by doom9's already low standards

just drop XP support already, it will never disappear if people don't stop supporting it and there's absolutely no reason to keep using it on an encoding box other than pure obstinacy

Here's another "exceptionally low quality" post... :p

On last Tuesday MicroSloth screwed up big time (again) with their latest updates for Windows and Office. See here:
http://www.infoworld.com/blog/infoworld-tech-watch/

Problems with M$ updates have become so frequent lately that the current advice for users can only be to disable automatic updates and wait at least for a couple of days until the word is out about these updates. Looks like the smarter people have been withdrawn from the update team and the rookies took over.

For my part I am almost glad that the support for my Win XP has ended so I am not affected by these problems. And BTW since the end of XP support I did not encounter any infection of my OS...


Cheers
manolito

LoRd_MuldeR
12th December 2014, 16:19
Software being vulnerable, because it has reached its end-of-life, and thus known vulnerabilities will never get fixed, is one thing. Regressions introduced into supported software via "faulty" updates, is a completely different and unrelated problem. But is the (rather small) chance, that an update might "break" something in the supported software, a reason to revert to an old unsupported software with known vulnerabilities? Probably not! Furthermore, while the introduction of "regressions" via updates is always possible, such regressions not only are rare, they usually will be fixed quickly. At the same time, the situation for software that has reached its end-of-life is beyond remedy, since there never will be any fixes for the known vulnerabilities or bugs. Last but not least, while the manufacturer is still working on the fix, you can simply revert that one "faulty" patch, which gives a working system with zillions of fixes that will never make it into the old/unsupported software...

(Note: I totally agree that Microsoft needs to improve their quality management, with respect to the latest regressions. But I strictly disagree to abuse that argument as a justification for using unsupported/vulnerable software)