21-05-2016, 08:10 PM
I guess we'll have to agree to differ 
I fully respect other folks' views, however I spend a substantial part of my professional life at the very sharp end of the security world and I see, day to day, the evolving threat landscape. And it's not pretty...
"Security through Obscurity" (I'm only a little person on their home PC - no one is interested in me), is, at best, naïve. At worst, it's irresponsible.
Just because you seem to be OK now, does not mean that you will be in the future - some of the threats that we see are so subtle it's astonishing - you have to admire their thought processes - Edward de Bono would be proud
These are (mostly) not theoretical risks - they are "in the wild" - there are also catalogues of "zero day threats" for sale - these are exploits that are discovered, kept private, and sometimes sold to the highest bidder (malware writers, governments, vermin etc.) - a recent example (though not Windows-related) that made it to National News is the exploit that the FBI allegedly paid $1M for to access the iPhone of a terrorist - many others are never reported nationally but are well known in the InfoSec community - some known ones are available for public access on the CVE (Common Vulnerabilities and Exposures) List - most of these you'll never have heard off and many will not be directly relevant to you, but they are very real and there have been many 1000s this years with several 100 more waiting on confirmation as of today - The ZDI (Zero-Day Initiative), one of many bodies that pays (White Hat) researches to hand over exploits so that they can be fixed, has had 353 reports this year to date and 665 last year.
I hate FUD in every form, but accusing folk of spreading FUD is not an argument, not even a weak one - it doesn't address the issues - it simply attempts to deny that they exist or that they are relevent.
This is NOT a FUD issue - its a basic fact that the architecture of earlier versions of Windows was developed in a time when the current range of sophisticated threats simply did not exist and it's difficult to retrofit protection into systems that were never designed for it - their attack surface is simply too large and porous.
As we become more and more on-line dependant, the need to keep up to speed on security is vital - burying one's head in the sand is an extremely poor option. It really isn't that bad to upgrade, and once done, it's pretty painless going forward.
Do what you like - it's your life (and identity)

I fully respect other folks' views, however I spend a substantial part of my professional life at the very sharp end of the security world and I see, day to day, the evolving threat landscape. And it's not pretty...
"Security through Obscurity" (I'm only a little person on their home PC - no one is interested in me), is, at best, naïve. At worst, it's irresponsible.
Just because you seem to be OK now, does not mean that you will be in the future - some of the threats that we see are so subtle it's astonishing - you have to admire their thought processes - Edward de Bono would be proud

These are (mostly) not theoretical risks - they are "in the wild" - there are also catalogues of "zero day threats" for sale - these are exploits that are discovered, kept private, and sometimes sold to the highest bidder (malware writers, governments, vermin etc.) - a recent example (though not Windows-related) that made it to National News is the exploit that the FBI allegedly paid $1M for to access the iPhone of a terrorist - many others are never reported nationally but are well known in the InfoSec community - some known ones are available for public access on the CVE (Common Vulnerabilities and Exposures) List - most of these you'll never have heard off and many will not be directly relevant to you, but they are very real and there have been many 1000s this years with several 100 more waiting on confirmation as of today - The ZDI (Zero-Day Initiative), one of many bodies that pays (White Hat) researches to hand over exploits so that they can be fixed, has had 353 reports this year to date and 665 last year.
I hate FUD in every form, but accusing folk of spreading FUD is not an argument, not even a weak one - it doesn't address the issues - it simply attempts to deny that they exist or that they are relevent.
This is NOT a FUD issue - its a basic fact that the architecture of earlier versions of Windows was developed in a time when the current range of sophisticated threats simply did not exist and it's difficult to retrofit protection into systems that were never designed for it - their attack surface is simply too large and porous.
As we become more and more on-line dependant, the need to keep up to speed on security is vital - burying one's head in the sand is an extremely poor option. It really isn't that bad to upgrade, and once done, it's pretty painless going forward.
Do what you like - it's your life (and identity)
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
ʞɔıu







