this post was submitted on 11 Aug 2026
12 points (92.9% liked)

No Stupid Questions

49342 readers
783 users here now

No such thing. Ask away!

!nostupidquestions is a community dedicated to being helpful and answering each others' questions on various topics.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules (interactive)


Rule 1- All posts must be legitimate questions. All post titles must include a question.

All posts must be legitimate questions, and all post titles must include a question. Questions that are joke or trolling questions, memes, song lyrics as title, etc. are not allowed here. See Rule 6 for all exceptions.



Rule 2- Your question subject cannot be illegal or NSFW material.

Your question subject cannot be illegal or NSFW material. You will be warned first, banned second.



Rule 3- Do not seek mental, medical and professional help here.

Do not seek mental, medical and professional help here. Breaking this rule will not get you or your post removed, but it will put you at risk, and possibly in danger.



Rule 4- No self promotion or upvote-farming of any kind.

That's it.



Rule 5- No baiting or sealioning or promoting an agenda.

Questions which, instead of being of an innocuous nature, are specifically intended (based on reports and in the opinion of our crack moderation team) to bait users into ideological wars on charged political topics will be removed and the authors warned - or banned - depending on severity.



Rule 6- Regarding META posts and joke questions.

Provided it is about the community itself, you may post non-question posts using the [META] tag on your post title.

On fridays, you are allowed to post meme and troll questions, on the condition that it's in text format only, and conforms with our other rules. These posts MUST include the [NSQ Friday] tag in their title.

If you post a serious question on friday and are looking only for legitimate answers, then please include the [Serious] tag on your post. Irrelevant replies will then be removed by moderators.



Rule 7- You can't intentionally annoy, mock, or harass other members.

If you intentionally annoy, mock, harass, or discriminate against any individual member, you will be removed.

Likewise, if you are a member, sympathiser or a resemblant of a movement that is known to largely hate, mock, discriminate against, and/or want to take lives of a group of people, and you were provably vocal about your hate, then you will be banned on sight.



Rule 8- All comments should try to stay relevant to their parent content.



Rule 9- Reposts from other platforms are not allowed.

Let everyone have their own content.



Rule 10- Majority of bots aren't allowed to participate here. This includes using AI responses and summaries.



Credits

Our breathtaking icon was bestowed upon us by @Cevilia!

The greatest banner of all time: by @TheOneWithTheHair!

founded 3 years ago
MODERATORS
 

My router has a pretty descent firewall so i feel like it should be safe? Maybe. Obviously I won't be signing into any online accounts or anything like that on the XP machine. Is this a bad ideas? Obviously using Windows in general is a bad idea but I'm sort of limited by the hardware here.

top 21 comments
sorted by: hot top controversial new old
[–] Zwuzelmaus@feddit.org 2 points 3 hours ago

Yes, bad idea.

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com 4 points 4 hours ago (1 children)

Are you starting fresh with XP or using an old crusty install. If you start fresh you should be fine. Just don’t browse the internet on it, or run sketchy ass software on it. And turn it off when you’re done. Behind NAT the only way for your device to get infected is for something else on the network infect it.

Also FYI it’s probably not going to work with your WiFi. You’re probably going to need to be hard wired. Most built in network cards from windows XP era machines don’t understand WPA2, and WPA3 is allegedly backwards compatible, but it REALLY hates older devices that barely speak WPA 2.

I have an old router that I installed DD-WRT on that I use for my old devices. I have the WiFi power dropped down to the bare minimum, and it barely leaves the room. Then I have an open WiFi network with MAC address filtering, that automatically turns off after a few hours of no devices. I can turn it on with the WPS button. That gets me a relatively not entirely insecure wireless network that I can use on devices all the way back on my iBook G3 or earlier.

Just remember, you are the biggest threat to your network.

[–] LedgeDrop@lemmy.zip 2 points 1 hour ago

If you start fresh you should be fine. Just don’t browse the internet on it, or run sketchy ass software on it. And turn it off when you’re done. Behind NAT the only way for your device to get infected is for something else on the network infect it.

There is a lot of wisdom here, but be cautious...

"Back in the day" (when xp was still relevant), I installed a VM with xp on the cooperate LAN. ...as it took eons to install all the patches and updates, this turned into a multi-day task. I didn't browse the internet or do anything (because the patches were still installing/rebooting/ect).

When I came back to the office, the next day, the networking on the VM was disabled and I got a message from the local IT guy saying that my VM was part of a botnet and was spreading worms, so they had to quarantine it (by disabling the networking).

I literally did nothing with it, other than install updates. I assume someone in the office had a worm and it infected my VM during the night.

...so if you're playing with xp (or any unsupported version of windows) - be careful.

[–] Janx@piefed.social 6 points 5 hours ago

Unless it's built into something and can't be changed, what possible benefit could there be to connecting an old, unsupported OS to the internet!?

[–] Toes@ani.social 8 points 6 hours ago (1 children)

Any particular reason it needs to be XP?

Last time I checked there was over 40 open exploits that are fairly easy to trigger. (Mostly related to web browsing or gpu acceleration)

I'd imagine something like Debian or Alpine would run on it?

[–] daggermoon@piefed.world 4 points 6 hours ago

I wanted XP to play old games but now i'm thinking that's a waste of time. I might try AntiX on it. This thing has 512MB or RAM and 32MB of VRAM I think. It can't even run Windows 7 lol. I gotta wait for the laptop charger to come though as I haven't even been able to verify the thing will power on. Let's hope for the best. Also, the CPU is 32 bit and Debian is dropping support for it. We'll see how that affects AntiX.

[–] PP_BOY_@lemmy.world 13 points 7 hours ago (1 children)
[–] daggermoon@piefed.world 4 points 7 hours ago (3 children)

Wouldn't any attackers need to penetrate the firewall first though?

[–] WolfLink@sh.itjust.works 2 points 55 minutes ago

The risk is your computer reaching out to something on the internet (either by you browsing, or some automatic background activity) and whatever it finds infects it.

This could be something like an ad on an otherwise trustworthy website.

[–] NutinButNet@hilariouschaos.com 5 points 7 hours ago* (last edited 7 hours ago) (1 children)

Yeah but why risk it?

This is like asking “Is it alright if I leave my garage door open while I’m at work today? It’s detached from the rest of the house and I just store junk in there I don’t care to lose.” Yeah, I mean it’s detached from the house and let’s even say for argument’s sake, you live in a gated community. The risk is very low of someone actually breaking in and getting your valuable stuff inside your home. But by doing this, you’ve kind of invited people to come take a closer look at your house too. Someone decided to see what’s in your garage and didn’t see anything, but hey, looks like a bathroom window on the side of the house is cracked a bit. Could easily slide into the main house and take a peak in there. I would’ve never seen this from the sidewalk/city street until I got into the open garage.

Best case of a bad situation is that something gets into your XP computer and infects it. You don’t do much with it, so trashing it isn’t the worst possible thing to fix this issue. Worst case of a bad situation is you’ve infected that computer and now an infection is checking out the rest of your network and other devices on it including stuff you didn’t think of or stuff you thought couldn’t reach the web. You blocked your smart TV from accessing the web but left it connected to the router so it is still discoverable on the private network. Or you have a cheap Temu camera you got a while back and forget is still active and it’s sitting on your network with really poor security, easily vulnerable to attack.

I guess if you have that much faith in your network and devices, go for it, but probably not a good idea if you want the best possible defense.

If you really need something off the web to that XP machine, better to find a way to get it there like on a separate VLAN.

[–] PP_BOY_@lemmy.world 3 points 6 hours ago

Thank you for saying much better what I couldn't figure out how to phrase

[–] CameronDev@programming.dev 4 points 7 hours ago (1 children)

Yeah, its pretty safe. XP on the open internet is bad, but behind a NAT is mostly fine. Just be very careful not to port forward or UPnP any ports to the XP box. The other concern would be ie6 reaching out to the internet, ideally you'd want to restrict that, as there are probably ie6 exploits around, but even this is fairly low risk.

What do plan on doing with the box? That may increase your risk level.

[–] fyzzlefry@retrolemmy.com 1 points 4 hours ago (1 children)

Ehhhh, bots are constantly crawling for vulns these days. I wouldn't trust in security through obscurity anymore.

[–] CameronDev@programming.dev 3 points 3 hours ago (1 children)

A NAT/Firewall isn't obscurity, its actual protection. Any scanning bot would need to breach the firewall/NAT first before it could ever see the XP box. And if the bot can do that, it doesn't need the XP box.

Making sure the XP box doesn't poke holes in the NAT is important, so depends what OP is planning on doing.

[–] black0ut@pawb.social 1 points 23 minutes ago

XP has background services that automatically connect to the outside for stuff. Most of those remain inside your network, but not all. It only takes a hardcoded expired domain to get instant infection without any user action.

I would never consider connecting a winXP machine to the internet safe.

[–] BananaTrifleViolin@lemmy.world 4 points 7 hours ago* (last edited 6 hours ago) (1 children)

The XP device is a major security risk because its got known security vulnerabilities that are not patched and actively targetted. Its targetted because hackefs know there are bad businesses and users still running xp.

The issue is less your firewall and instead your whole network. If XP has internet access and is on your home network, it gives hackers and malware a route through to your other devices.

If you want to connect XP to the internet then there are two realistic options.

One is give the XP machine its own isolated network alongside your home network - a VLAN (virtual local area network) - i.e. a second physical network if your router supports it. One easy way of doing that is to see if your router has a Guest Wifi set up, and if so ensure that is configured to be entirely separate from your main network. But this is still risky because if you dont know what youre doing you could accidentally leave your network exposed. Also if you already use the guest network - for guests for example - then you'll put those devices at risk, and should make a whole dedocated vlan instead.

The other option is get a second router, create a wifi with that (or ethernet connection ideally) and connect that router to the internet via an always on VPN (virtual private network). The second router and network would completely physically isolates the XP machine from your home network, even though it needs to connect through your first router to reach fhe internet. The VPN is key there, but if you dont want to use a VPN you could also isolate the second in a VLAN on your main router. This is similar to option one but would allow a totally separate dedicated wifi connection without losing your guest wifi or compromising your home wifi.

The XP machine itself will always be vulnerable whatever you do. Obviously configure a firewall and antivirus on it, and be safe in how you use it, to minimize the risk.

Whatever you do, do not connect rhe XP machine directly to your home network if you're giving it access out onto the internet.

Edit: I may have misubderstood the question. If the device is not being allowed internet access at all, its safe to be on your network as long as you are careful what you load onto it. Malware on the XP device would still have access to your network. But yes if its contained behind your firewall and locked in, its not a problem in itself. I'd question why it needs to be on the network at all if you're not giving it internet access though.

[–] Rhaedas@fedia.io 5 points 6 hours ago (1 children)

Haven't there been videos showing either XP or 98 or both connected as fresh installs and within minutes having all sorts of issues?

[–] fuckwit_mcbumcrumble@lemmy.dbzer0.com 2 points 4 hours ago (1 children)

Nobody is targeting XP these days, and you have to be trying to get infected within minutes. Can it happen? Yes.

But behind your firewall with NAT it cannot magically get infected from the internet unless you do something.

[–] Zwuzelmaus@feddit.org 3 points 1 hour ago

Nobody is targeting XP these days

The bots out there do.

it cannot magically get infected from the internet unless you do something.

That's too theoretical!

XP itself will "do something" and expose itself.

[–] JigglySackles@lemmy.world 1 points 5 hours ago

Only if it's an air gapped network with no internet access.

[–] BoxOfFeet@lemmy.world 1 points 7 hours ago

I'd say no. I have a separate router with no internet access for my XP LAN gaming.