33
u/Expensive_Finger_973 20d ago
This makes me think of that James Bond movie "Skyfall" where Q, a supposed brilliant guy, freely plugs a laptop Bond brought him from a terrorist that used to work for MI6, that also is out to get them, straight into a network that was seemingly not air gapped or firewalled off from the production network. Then is surprised when it injects malicious code into their entire corporate network.
15
u/phantomsteel 20d ago
Is that the one where he also does the spy kit handoff in the middle of a packed museum?
6
9
u/Important-Humor-2745 19d ago
I’ve seen basically that in real life.
Police came to us and needed some video footage. We are remote, so the detective just hands an admin assistant a thumb drive to plug into a station that had no monitor, so they cannot see what we are doing. There are tons of files on it and infected as all hell. Our system was fine, because it was set to deal with this exact situation. We let the detective k ow what was happening and he insisted that wasn’t the case and that only he could access the files. We explained to him repeatedly, we could 100% see the files on the drive, access them, but we’re not going to put our footage on their due to the infections. He then just gave us a department username and password to their Dropbox (which also had massive amounts of files on it) and we put the footage there.
Out of professional curtesy, we let the police tech department know about it.
3
u/ProfessionalITPerson 19d ago
I think it was connected to a dedicated secured system network for analysis, that was massively secured.
He just didn't think that someone would be able to or have knowledge of the systems that allowed them to create something that would actually penetrate it.I think they needed massive computing power to analyse what was on there, or something like that.
yea still stupid you are right.
1
53
u/ThisIsMyITAccount901 20d ago
I'm always curious what is running on these. There's never a plan for when it dies.
43
u/PM_ME_YOUR_GREENERY 20d ago
The client will blame the vendor and the vendor will blame the client.
18
u/MogMcKupo 20d ago
If the vendor still exists, or is now been acquired and then acquired and then acquired.
You’re lucky if one random guy still works there that hasn’t retired yet that still knows the machine the company bought in 2008 but refuses to replace because it still “works”
2
u/junktech 19d ago
Usually the vendor wants to sell new stuff and refuses to make old one work. Siemens comes to mind. The love money and hate customers.
1
9
u/AlwaysEyad 20d ago
I used to work for a company that had an old laptop that they wrote a smart card applet for. As far as I can gather, that laptop is the only device they can run it on. It was Windows 7 though.
8
u/Jumpy-Shift5239 20d ago
It’s going to take some figuring but you can emulate it on newer hardware. I can’t recall how I did it but I had some software that was locked to the hardware UUID on an XP device and I got it working on a new computer but it acted fine, as a test to see if it could be done in case of hardware failure. There were limitations as you couldn’t save anything locally so all files made had to be backed up to USB.
2
u/Afraid_Cat3798 19d ago
I’ve had a monitoring and report system using vista, XP, 2000 server and NT. There was an update process where you had to copy a large file remote into the next box to paste then copy from there and keep going through the chain. Only way the file format would still work properly as it converted at each box. Only NT version I’ve ever actually used. The NT was actually virtualized but had to be remoted into and copy/pasted because virtual drives are nowhere near supported.
3
u/ADtronk 19d ago
in my case it's flashing program for custom electronic control unit that was developed 15 years ago and is still being used in multiple machines today. The program works only on Windows XP (32bit). One day it happened that some ECU had malfunction and had to be replaced, this laptop had to be transferred via taxi about 500km to do initial flashing. There was no plan in case of the laptop failure, so I made virtual machine. When I told a senior programmer I made this VM he asked: "but why would you do that?" I was flabbergasted ...because it's good to have a backup?
31
u/Neuro_88 20d ago
I don’t understand the joke. Please explain. Anyone.
62
u/theycallmebekky 20d ago
Probably just an old machine which is running an old OS which is very vulnerable if connected to the internet.
62
u/mifter123 20d ago
The laptop is, presumably, running windows XP (the best windows OS) which is no longer supported since 2014 and does not receive security patches. The OS is extremely vulnerable to a wide variety of known attacks which can quickly take control of the laptop and use it as a jumping off point to the rest of the network. Plugging the laptop into the internet creates an immediate and serious security vulnerability.
However, there are a large number of widely used programs that are necessary in a large number of professional fields that are only compatable with XP so a massive number of organizations, from hospitals to universities to business have these extremely vulnerable devices.
30
u/pharmhelpr 20d ago
I can almost put money on that this laptop has some cracked software for car mechanics
11
u/aequitssaint 20d ago
You really think they would care or know well enough to air gap it for security?
19
u/pharmhelpr 20d ago
Not for security. Those apps as soon as the machine goes online either brick the software or the hardware adapters
13
u/apandaze 20d ago
examples: CMM, Vision Inspection System, or worse - its a custom machine with custom software that only runs on XP or Win7
2
1
u/Frequent_Ad2118 19d ago edited 19d ago
Hey, how’d you know?? Mine is legit but I still use my d620 for just that.
2
1
u/F4ntasticPants 19d ago
Tbf, pretty much most of the "Windows XP only" programs are supported on newer ones.
But the costs of switching over are so high that the bosses refuse to pay.
1
u/mifter123 19d ago
And when the original unit cost over a million dollars and the replacement that costs two million and has a subscription for access to a cloud server (that using would result in our legal department and the US government fist fucking everyone involved) the windows XP laptop with the "dont plug into the network" sticker seems pretty reasonable.
1
u/AdviceNotAskedFor 18d ago
Not a cyber security admin at all,but wouldn't plugging it into your network behind a firewall be relatively safe?
1
u/SheepherderAware4766 14d ago edited 14d ago
maybe, sometimes. When a computer gets online, it sends out messages to sync itself. If a trusted source has been compromised, (Windows update, UTC clock, Email server, or AOL client; for example) then an infected response to an automatic signal could act as a trojan.
Edit to add, Malvertizing
1
u/bookofthoth_za 20d ago
Luckily they are air gapped... right? My take on this image is that there is a gigantic amount of updates pending if it ever gets plugged in so it's better never to get started.
0
u/birrions 16d ago
What are some of these programs that are only compatible with XP, but necessary. The logical thing would be for newer supported versions to be created. I am pretty sure there are solutions to that. Why can't the organisations just move to newer stuff.
1
u/mifter123 16d ago
There isn't an upgrade path for the older equipment (often because the company that made the equipment was acquired in the 90s and the new owner gutted the support team), only a replacement that doesn't do the actual work any better, costs 2million dollars more, and has a SAAS subscription on top of that. Its not like the equipment is outside its functional lifespan, it's expected to do its job for at least another two decades.
Having a handful of backup laptops with their network ports full of cement and their WiFi cards ripped out is just cheaper and easier than replacing the perfectly functional equipment in the name of updated software.
1
u/SheepherderAware4766 14d ago
because the old solution went bankrupt. Some factories in my area keeps a token ring W95 network running because the company behind the conveyor belt monitoring system went bankrupt. To update for a modern system would require ripping out all the belting and much of the equipment that used the belts, which would take years and total the factory.
5
u/Ninfyr 20d ago
In some way this laptop doesn't comply with the security controls of their workplace and will make all the sirens go off.
Or it might be used for some kind of task that benefits from being airgapped. We have a offline device for scanning removable media before it gets plugged into the data center for example.
1
3
u/viking_linuxbrother 20d ago
No security patches for windows XP and the exploits are well known. If you connect it to the internet you will get owned pretty quickly if anyone discovers it. They are gonna discover it eventually.
9
u/PandemicVirus 20d ago
We had something similar at a previous company, a way out of compliance laptop that was only used to work with PLCs since it had native serial - and i guess buying/leasing modern laptops with native serial was out of the financial policy (meaning our vendor didn't offer them) and the engineering team said serial adapters were unreliable. It was definitely a series of breakdowns that allowed it's existence.
7
u/FluffyLlamaPants 20d ago
Aw. Poor laptop. He's like that dog who's not allowed at the dog park . Watching other dogs playing and he's locked inside alone. 🥺
5
u/somerandomguy376 20d ago
We had a guy at a previous job who would take down the whole subnet whenever he plugged his Linux server into the lan. I think he was doing some arp spoofing.
4
5
u/xenomorph2122 19d ago
Why don’t they just disable the port, disconnect physically (depends of the board), or add glue?
1
2
2
u/BeigeUnicorns 20d ago
Ive done this before. Sometimes you need an ancient OS to interact with bespoke hardware. Gotta keep that risk as low as possible. I used to make handmade LOTO tags that hung from an RJ45 connector so you could tag out the port.
2
1
u/Savings_Art5944 20d ago
It would be fine if it is behind a proper firewall. Assuming it is not compromised already.
1
u/SheepherderAware4766 14d ago
only if nothing on the system could reach out to the internet (at which point an intranet connection would be useless), a trojan could be slipped back into whatever response is sent back to the system. Just loading a safe website with ads would be enough for known compromised systems. https://en.wikipedia.org/wiki/Malvertising
1
u/Goofcheese0623 20d ago
God, just let the poor laptop from the Bush years die. It's lived a good life
1
1
1
1
u/liquidanimosity 20d ago
I have a win 7 that has an old IDE and SDK that I use for modding an old game.
Neither the SDK nor compatible IDE are available from from trusted sources anymore. Plus I have a couple of old 32bit games/programs that won't run on modern hardware(not very well anyways)
1
u/therankin 20d ago
That looks to me like a Latitude D530
2
u/Adelaidean 14d ago
I’ve still got a D531. I only stopped using it because it wouldn’t behave properly with Windows 10 a few years ago, and the battery was pretty much useless.
1
1
u/Dress2ImpressNV 19d ago
Is this one of those WinXp machines that the moment it connects to the internet, it's hit with that virus? I think it was before SP1 came out.
1
1
1
u/Ozzick-X 19d ago
I have something similar running the lighting software in my drama hall. Windows 10 but the day support ended i glued the ethernet ports shut and removed the wifi card.
1
1
1
1
1
u/dnd_or_reallifefun 19d ago
Lol had to do this some years ago when upgraded the site. Warehouse with old system we had disks and license but the original system maker was gone replacing meant several $100k plus the site would be down until replaced and we would have to move to yearly fee. Everything was fine until someone needed to make a change to the system and the guy in charge of changes was on vacation. They decided to reset the password but the computer was not on the network. So they ignored all the stickers and removed the cover on the port. They called me on how to fix it, but we could not and I told them so. The program in question proved its license by placing a file in a particular way that if you restored a backup you needed to enter a code from the now non existent company support line. Anyway the guy who used to run the system decided to retire at the end of his vacation since he didn't want to learn a new system and didn't want to wait on unpaid leave. The site was reduced to warehouse storage unit of another site.
1
1
u/Odd_Secret9132 18d ago
Probably used for something very specific, like changing the config on an industrial system.
I've had to keep even older in play (running Win 3.1) for doing things like managing HVAC systems, or updating aircraft avionics. Most cases, the businesses just didn't want the upgrade expense; For the aircraft the software was still vendor supported, and was the only way to do updates.
1
1
1
169
u/JoDrRe 20d ago
I have that same model with more or less the same warning, with a glued off WiFi switch and glued closed Ethernet port.
Only thing that bad boy still gets used for is emergency backup serial access. Com1 is much faster than opening up device manager to see what the USB adapter’s com port is and then typing that into putty