The IE Bug That Made Microsoft Break Its Own Rule

The IE Bug That Made Microsoft Break Its Own Rule

Tech News internet explorer microsoft security windows-xp

So last week Microsoft did something I honestly did not expect them to ever do again: they shipped a security patch for Windows XP. Not a "sorry, you're on your own" blog post. An actual patch, MS14-021, that landed on May 1st, three and a half weeks after they'd officially told the entire planet that XP support was over and done with.

The reason was that ugly Internet Explorer zero-day that FireEye found being actively exploited in the wild (they're calling the campaign "Operation Clandestine Fox," which sounds like a bad spy movie but whatever). It hit basically every version of IE, 6 through 11, and it got bad enough that the US government's own security folks put out an advisory telling people to just stop using Internet Explorer until there was a fix. The UK did something similar. When your own government is telling citizens to switch browsers, thats not a great week for you.

I only really paid attention to this because my aunt called me on Wednesday convinced her computer was broken because Firefox popped up a message telling her to update. She's still running XP. I know, I know. I've been telling her to upgrade for two years now and the answer is always some version of "it still works fine for email and solitaire, why would I pay for a new one." And you know what, she's not wrong that it still runs. That's kind of the whole problem with XP honestly, it was good enough for long enough that a huge number of ordinary people never had a reason to leave it, and now theyre stuck out past the support cliff with a browser that was actively being used to hand attackers a way into peoples machines.

What got me was how obviously reluctant Microsoft was about the whole thing. They made a point of calling it a "special case," basically going out of their way to say this does not mean XP is back on the patch train, don't get used to it. Which, fair, I guess, you cant support an OS forever. But it also felt like they knew exactly how bad the optics would be if a vulnerability this public, with this much press attached to it, ended up getting blamed for a wave of XP machines getting owned three weeks after they pulled the plug. I dont think this was generosity so much as damage control.

Anyway, if youre reading this on IE, on any version, go grab the update or just switch browsers for a while. Its 2014, there is genuinely no excuse to still be running IE8 as your daily browser and I will die on this hill. I moved my own machines to Chrome years ago and the only time I open IE anymore is to download a different browser on a fresh Windows install, which is a joke that's older than this blog at this point.

The bigger thing this whole episode made me think about is how much stuff out there is quietly still running XP that nobody thinks about day to day. Not just your uncle's home PC. ATMs. Point of sale systems at random stores. I read that a huge chunk of ATMs worldwide were still on XP as of a few months ago because the embedded versions have longer support timelines than consumer XP does, but plenty of that infrastructure genuinely never got upgraded and just runs XP straight, patches or not. Nobody budgets to replace hardware that "isnt broken," until suddenly it very much is.

I dont have a tidy fix for any of this. Getting my aunt off XP is basically a two hour job of backing up her photos, buying a $250 machine, and reinstalling the three programs she actually uses, and I'll probably do it this weekend since I'm already annoyed about it. But multiply that by however many millions of machines are still out there and it stops being a weekend project and starts being a genuinely hard problem that a single patch, emergency or not, doesnt actually solve. It just buys everyone a little more time to not deal with it.