My router has a pretty descent firewall so i feel like it should be safe? Maybe. Obviously I won’t be signing into any online accounts or anything like that on the XP machine. Is this a bad ideas? Obviously using Windows in general is a bad idea but I’m sort of limited by the hardware here.

  • BananaTrifleViolin@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    23 小时前

    The XP device is a major security risk because its got known security vulnerabilities that are not patched and actively targetted. Its targetted because hackefs know there are bad businesses and users still running xp.

    The issue is less your firewall and instead your whole network. If XP has internet access and is on your home network, it gives hackers and malware a route through to your other devices.

    If you want to connect XP to the internet then there are two realistic options.

    One is give the XP machine its own isolated network alongside your home network - a VLAN (virtual local area network) - i.e. a second physical network if your router supports it. One easy way of doing that is to see if your router has a Guest Wifi set up, and if so ensure that is configured to be entirely separate from your main network. But this is still risky because if you dont know what youre doing you could accidentally leave your network exposed. Also if you already use the guest network - for guests for example - then you’ll put those devices at risk, and should make a whole dedocated vlan instead.

    The other option is get a second router, create a wifi with that (or ethernet connection ideally) and connect that router to the internet via an always on VPN (virtual private network). The second router and network would completely physically isolates the XP machine from your home network, even though it needs to connect through your first router to reach fhe internet. The VPN is key there, but if you dont want to use a VPN you could also isolate the second in a VLAN on your main router. This is similar to option one but would allow a totally separate dedicated wifi connection without losing your guest wifi or compromising your home wifi.

    The XP machine itself will always be vulnerable whatever you do. Obviously configure a firewall and antivirus on it, and be safe in how you use it, to minimize the risk.

    Whatever you do, do not connect rhe XP machine directly to your home network if you’re giving it access out onto the internet.

    Edit: I may have misubderstood the question. If the device is not being allowed internet access at all, its safe to be on your network as long as you are careful what you load onto it. Malware on the XP device would still have access to your network. But yes if its contained behind your firewall and locked in, its not a problem in itself. I’d question why it needs to be on the network at all if you’re not giving it internet access though.

    • Rhaedas@fedia.io
      link
      fedilink
      arrow-up
      5
      ·
      23 小时前

      Haven’t there been videos showing either XP or 98 or both connected as fresh installs and within minutes having all sorts of issues?

      • fuckwit_mcbumcrumble@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        3
        ·
        21 小时前

        Nobody is targeting XP these days, and you have to be trying to get infected within minutes. Can it happen? Yes.

        But behind your firewall with NAT it cannot magically get infected from the internet unless you do something.

        • Zwuzelmaus@feddit.org
          link
          fedilink
          arrow-up
          5
          ·
          18 小时前

          Nobody is targeting XP these days

          The bots out there do.

          it cannot magically get infected from the internet unless you do something.

          That’s too theoretical!

          XP itself will “do something” and expose itself.