Microsoft says RIP Windows XP AutoRun
Microsoft has finally decided to push out a Windows update that should stop attempts to exploit AutoRun - a feature of its operating system that fires up any program once a USB or CD is inserted into a computer.
In recent years hackers have increasingly turned to AutoRun, which permits programmers to deliver instructions via Autorun.inf files to run programs without first gaining user permission.
The problem for Microsoft was that while the obvious solution was to disable AutoRun, it was considered a legitimate feature, which happened to be exploited by the Conficker worm, Rimecud and Taterf. "AutoRun isn't an accident -- it's by design, and as I mentioned we care about the very real positive uses of the feature. In other words, in a very real sense, it's not a bug, it's a feature," said Adam Shostack, a Microsoft security program manager.