this post was submitted on 11 Aug 2026
27 points (96.6% liked)

No Stupid Questions

49377 readers
817 users here now

No such thing. Ask away!

!nostupidquestions is a community dedicated to being helpful and answering each others' questions on various topics.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must be legitimate questions. All post titles must include a question.

All posts must be legitimate questions, and all post titles must include a question. Questions that are joke or trolling questions, memes, song lyrics as title, etc. are not allowed here. See Rule 6 for all exceptions.



Rule 2- Your question subject cannot be illegal or NSFW material.

Your question subject cannot be illegal or NSFW material. You will be warned first, banned second.



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Questions which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding META posts and joke questions.

Provided it is about the community itself, you may post non-question posts using the [META] tag on your post title.

On fridays, you are allowed to post meme and troll questions, on the condition that it's in text format only, and conforms with our other rules. These posts MUST include the [NSQ Friday] tag in their title.

If you post a serious question on friday and are looking only for legitimate answers, then please include the [Serious] tag on your post. Irrelevant replies will then be removed by moderators.



Rule 7- You can't intentionally annoy, mock, or harass other members.

If you intentionally annoy, mock, harass, or discriminate against any individual member, you will be removed.

Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.



Rule 8- All comments should try to stay relevant to their parent content.



Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- Majority of bots aren't allowed to participate here. This includes using AI responses and summaries.



Credits

Our breathtaking icon was bestowed upon us by @Cevilia!

The greatest banner of all time: by @TheOneWithTheHair!

founded 3 years ago
MODERATORS
 

My router has a pretty descent firewall so i feel like it should be safe? Maybe. Obviously I won't be signing into any online accounts or anything like that on the XP machine. Is this a bad ideas? Obviously using Windows in general is a bad idea but I'm sort of limited by the hardware here.

top 37 comments
sorted by: hot top controversial new old
[–] Soulinyx@piefed.world 2 points 2 hours ago

Even if we say you won't get infected the first moment you put XP online in the open web. Consider this, the internet itself has advanced beyond what WinXP could handle in its time. It would struggle to load modern day web design and functionality, as dogshit as they've been implemented. Firefox, Chrome, Edge have all long moved on from WinXP so don't get your hopes up for them.

You're left to third party browsers and even then, what's the point?

[–] alternategait@lemmy.world 2 points 5 hours ago (1 children)

Since this is an already open topic. How would anyone suggest getting files of an XP machine to anything else (but preferably to a modern mac)?

[–] daggermoon@piefed.world 1 points 3 hours ago

USB floppy drive, DVD-ROM, or a Flash drive.

[–] hexagonwin@lemmy.today 2 points 5 hours ago

well realistically its not dangerous unless you have some very open/unrestricted network setup

[–] ZkhqrD5o@lemmy.world 3 points 10 hours ago
[–] VitoRobles@lemmy.today 6 points 1 day ago (1 children)

You probably wouldn't even be able to visit websites/have them work correctly, because the browser is so outdated.

[–] Scrollone@feddit.it 1 points 1 minute ago

There are forks of Firefox that work with XP

[–] PP_BOY_@lemmy.world 18 points 1 day ago (1 children)
[–] daggermoon@piefed.world 6 points 1 day ago (2 children)

Wouldn't any attackers need to penetrate the firewall first though?

[–] CameronDev@programming.dev 10 points 1 day ago (1 children)

Yeah, its pretty safe. XP on the open internet is bad, but behind a NAT is mostly fine. Just be very careful not to port forward or UPnP any ports to the XP box. The other concern would be ie6 reaching out to the internet, ideally you'd want to restrict that, as there are probably ie6 exploits around, but even this is fairly low risk.

What do plan on doing with the box? That may increase your risk level.

[–] fyzzlefry@retrolemmy.com 2 points 1 day ago (1 children)

Ehhhh, bots are constantly crawling for vulns these days. I wouldn't trust in security through obscurity anymore.

[–] CameronDev@programming.dev 7 points 1 day ago (1 children)

A NAT/Firewall isn't obscurity, its actual protection. Any scanning bot would need to breach the firewall/NAT first before it could ever see the XP box. And if the bot can do that, it doesn't need the XP box.

Making sure the XP box doesn't poke holes in the NAT is important, so depends what OP is planning on doing.

[–] black0ut@pawb.social 3 points 1 day ago (1 children)

XP has background services that automatically connect to the outside for stuff. Most of those remain inside your network, but not all. It only takes a hardcoded expired domain to get instant infection without any user action.

I would never consider connecting a winXP machine to the internet safe.

[–] CameronDev@programming.dev 2 points 1 day ago

Other than windows update, what other background services call out?

[–] WolfLink@sh.itjust.works 5 points 1 day ago

The risk is your computer reaching out to something on the internet (either by you browsing, or some automatic background activity) and whatever it finds infects it.

This could be something like an ad on an otherwise trustworthy website.

I would avoid giving it internet access. You could probably get away with network access, but id still mainly restrict it to a disconnected network and just download anything you need for it from a modern machine. (Probably a shared nas for transfer.) If you've got a good router (ie not a isp or home router) you could give it access to specific items on a whitelisting basis.

[–] Toes@ani.social 14 points 1 day ago (1 children)

Any particular reason it needs to be XP?

Last time I checked there was over 40 open exploits that are fairly easy to trigger. (Mostly related to web browsing or gpu acceleration)

I'd imagine something like Debian or Alpine would run on it?

[–] daggermoon@piefed.world 7 points 1 day ago (1 children)

I wanted XP to play old games but now i'm thinking that's a waste of time. I might try AntiX on it. This thing has 512MB or RAM and 32MB of VRAM I think. It can't even run Windows 7 lol. I gotta wait for the laptop charger to come though as I haven't even been able to verify the thing will power on. Let's hope for the best. Also, the CPU is 32 bit and Debian is dropping support for it. We'll see how that affects AntiX.

[–] IWW4@lemmy.zip 9 points 1 day ago

If all you are going to do is play old stand alone games why are you attaching it to a network?

Just sneakernet the install.

I would not attach an XP machine to a network.

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com 8 points 1 day ago (1 children)

Are you starting fresh with XP or using an old crusty install. If you start fresh you should be fine. Just don’t browse the internet on it, or run sketchy ass software on it. And turn it off when you’re done. Behind NAT the only way for your device to get infected is for something else on the network infect it.

Also FYI it’s probably not going to work with your WiFi. You’re probably going to need to be hard wired. Most built in network cards from windows XP era machines don’t understand WPA2, and WPA3 is allegedly backwards compatible, but it REALLY hates older devices that barely speak WPA 2.

I have an old router that I installed DD-WRT on that I use for my old devices. I have the WiFi power dropped down to the bare minimum, and it barely leaves the room. Then I have an open WiFi network with MAC address filtering, that automatically turns off after a few hours of no devices. I can turn it on with the WPS button. That gets me a relatively not entirely insecure wireless network that I can use on devices all the way back on my iBook G3 or earlier.

Just remember, you are the biggest threat to your network.

[–] LedgeDrop@lemmy.zip 5 points 1 day ago (1 children)

If you start fresh you should be fine. Just don’t browse the internet on it, or run sketchy ass software on it. And turn it off when you’re done. Behind NAT the only way for your device to get infected is for something else on the network infect it.

There is a lot of wisdom here, but be cautious...

"Back in the day" (when xp was still relevant), I installed a VM with xp on the cooperate LAN. ...as it took eons to install all the patches and updates, this turned into a multi-day task. I didn't browse the internet or do anything (because the patches were still installing/rebooting/ect).

When I came back to the office, the next day, the networking on the VM was disabled and I got a message from the local IT guy saying that my VM was part of a botnet and was spreading worms, so they had to quarantine it (by disabling the networking).

I literally did nothing with it, other than install updates. I assume someone in the office had a worm and it infected my VM during the night.

...so if you're playing with xp (or any unsupported version of windows) - be careful.

[–] Blemgo@lemmy.world 2 points 6 hours ago (1 children)

My guess was that it was the updates that did the thing. I think I remember there being an issue up to Win 7 where malicious parties could advertise malware as available updates (under win7 this was only a problem if you didn't let it select and download manually).

[–] LedgeDrop@lemmy.zip 1 points 29 minutes ago

.…classic Microsoft :facepalm:

[–] Janx@piefed.social 7 points 1 day ago

Unless it's built into something and can't be changed, what possible benefit could there be to connecting an old, unsupported OS to the internet!?

[–] BananaTrifleViolin@lemmy.world 6 points 1 day ago* (last edited 1 day ago) (1 children)

The XP device is a major security risk because its got known security vulnerabilities that are not patched and actively targetted. Its targetted because hackefs know there are bad businesses and users still running xp.

The issue is less your firewall and instead your whole network. If XP has internet access and is on your home network, it gives hackers and malware a route through to your other devices.

If you want to connect XP to the internet then there are two realistic options.

One is give the XP machine its own isolated network alongside your home network - a VLAN (virtual local area network) - i.e. a second physical network if your router supports it. One easy way of doing that is to see if your router has a Guest Wifi set up, and if so ensure that is configured to be entirely separate from your main network. But this is still risky because if you dont know what youre doing you could accidentally leave your network exposed. Also if you already use the guest network - for guests for example - then you'll put those devices at risk, and should make a whole dedocated vlan instead.

The other option is get a second router, create a wifi with that (or ethernet connection ideally) and connect that router to the internet via an always on VPN (virtual private network). The second router and network would completely physically isolates the XP machine from your home network, even though it needs to connect through your first router to reach fhe internet. The VPN is key there, but if you dont want to use a VPN you could also isolate the second in a VLAN on your main router. This is similar to option one but would allow a totally separate dedicated wifi connection without losing your guest wifi or compromising your home wifi.

The XP machine itself will always be vulnerable whatever you do. Obviously configure a firewall and antivirus on it, and be safe in how you use it, to minimize the risk.

Whatever you do, do not connect rhe XP machine directly to your home network if you're giving it access out onto the internet.

Edit: I may have misubderstood the question. If the device is not being allowed internet access at all, its safe to be on your network as long as you are careful what you load onto it. Malware on the XP device would still have access to your network. But yes if its contained behind your firewall and locked in, its not a problem in itself. I'd question why it needs to be on the network at all if you're not giving it internet access though.

[–] Rhaedas@fedia.io 6 points 1 day ago (1 children)

Haven't there been videos showing either XP or 98 or both connected as fresh installs and within minutes having all sorts of issues?

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com 2 points 1 day ago (1 children)

Nobody is targeting XP these days, and you have to be trying to get infected within minutes. Can it happen? Yes.

But behind your firewall with NAT it cannot magically get infected from the internet unless you do something.

[–] Zwuzelmaus@feddit.org 4 points 1 day ago

Nobody is targeting XP these days

The bots out there do.

it cannot magically get infected from the internet unless you do something.

That's too theoretical!

XP itself will "do something" and expose itself.

[–] Zwuzelmaus@feddit.org 3 points 1 day ago

Yes, bad idea.

[–] Berttheduck@lemmy.ml 1 points 1 day ago (1 children)

Could you just put Linux on the old machine instead? I suspect that would be safer.

[–] daggermoon@piefed.world 3 points 1 day ago* (last edited 1 day ago) (1 children)

I mean yeah, safer and better but I wouldn't be able to game on it though. It's not like the thing supports Vulkan.

[–] Berttheduck@lemmy.ml 1 points 14 hours ago (1 children)

Steam OS? Or emulators? It's not like an old laptop is going to be running modern games

[–] daggermoon@piefed.world 3 points 13 hours ago (1 children)

I doubt SteamOS will run on a laptop from 2003. Maybe Atari 2600 and NES emulation will work fine. I don't expect this shitbox to run Cyberpunk 2077. I was hoping more for Postal and Quake.

[–] Blemgo@lemmy.world 1 points 6 hours ago (1 children)

Maybe SteamOS wouldn't work, but maybe something like Debian or Linux Mint. Especially Debian is designed with a lot of backwards compatibility, even though it is very slow at adopting new updates for software (that are not security relevant).

[–] daggermoon@piefed.world 2 points 3 hours ago

Debian is dropping support for i386 sadly.

[–] JigglySackles@lemmy.world 1 points 1 day ago

Only if it's an air gapped network with no internet access.

[–] BoxOfFeet@lemmy.world 1 points 1 day ago

I'd say no. I have a separate router with no internet access for my XP LAN gaming.