Microsoft Pulls Broken XP Update
Cally writes "Yahoo! reports that
Microsoft have pulled a Windows XP update from the Windows Update servers after it killed network access for some users of the claimed 600,000 who installed it. (Does this mean only 600,000 XP users trust Windows Update?) The story hints that the problem was something to do with VPN or IPSec drivers clashing with Symantec software - however I haven't found anything about this on the Microsoft KnowledgeBase (the link Yahoo provide goes to the generic support home page.) Anyone got more info?"
windows mustive been getting too stable. .
Do they have any sort of quality control?=)
How Now Brown Cow
I am currently porting apt-get to Windows. This will mean that these types of embarassing security breaches never happen again. apt-get is the answer to all of today's problems.
If XP is allowed to go find its master and patch itself, any problem with a patch will spread widely to the people least able to deal with it.
At least this patch made it perfectly obvious that it had a bug.
Maybe because they couldn't get online to report the problem???
Unfortunately, it's something we've all heard before. I'm a recent entrant to the world of tech support, and the company I work for (much like many other large companies) refuse to touch a new Microsoft OS until it's been through at *least* one, preferably two service packs. Likewise, updates that Microsoft class as "critical" are not to be installed for at least a fortnight, unless they are for serious security holes with known exploits. Whilst I think this is probably a rather conservative approach, it sure as hell is better than having the network crash down around you. I believe this company was bitten badly by such a problem with a patch a couple of years ago, hence their policy on updates.
Does this mean only 600,000 XP users trust Windows Update
What do you think is more likely: "only" 600,000 people trust Windows Update or everyone else just hasn't patched for checked for patches yet? I personally don't use the little auto-notification thingie, I just check every once in a while.
Also, how is this different from any automated Linux update method? Software has bugs. Patches may have bugs. Regardless of vendor, patches are not perfect and may induce problems.
Agree or disagree with me, when you think about it without bias it's true.
A new worm has begun infecting XP systems that didn't install the latest patch. "It's their own fault, they should have kept up to date" said BG.
One line blog. I hear that they're called Twitters now.
The article says that since this wasn't a critical patch, just an 'improvement', auto update doesn't install it.
All I know is that, having decided to pull down some of the critical updates (not on auto, you understand) I can no longer get the properties window to appear for a directory in Explorer, except in safe mode. Kind of makes it difficult to administer security that does; oh and the performance went down a heap too. Even tried backing them all out too, but the system restore was disabled - too little disk space apparently, nice of it to tell me in time(!).
Only four hours ago, I was on the phone to MS support. If the p.c. is started with only MS services enabled (there's only Norton or MS ones on this machine) via the msconfig utility, everything is fine. If I disable all the non-MS services in the services window though and do a normal restart, everything is broken again - duh!
I'm going to try unloading/reloading all the Norton stuff again but don't hold out much hope. Oh well, looks like I'm up for another rebuild, the sixth in five months... and no, I won't be using the updates in future
Go permanent? In your dreams and my worst nightmares.
>Does this mean only 600,000 XP users trust Windows Update?
Umm... NO. It doesn't.
And stop taking cheap shots at MS, it just make you look like a whiny school kid.
There is plenty of reasons to bash MS policies and software, but the signal-to-noise ratio is getting silly.
... allows an admin to release patches to users when they have tested them. SUS retrieves patches from Microsoft. An Admin approves them. Client PC's (with an appropriate Group Policy) retrieve and install approved updates from the SUS server. Easy.
If you're paranoid^H^H^H^H^H^H^H^Hsensible, wait a week or more to give the rest of the world time to find bugs, test the patch thoroughly in a test environment, and of course ask yourself if you actually need it.
ps. how many of todays slashdot readers know what ^H means?
Yet another example of MS trying toi pass the buck and dodge the bullet...
I had NO symantec s/ware on my system, (I use Mcafee) and I lost all networking / internet access.
Also, the Yahoo article says that the update had to be removed which is bull$hit, the update could NOT be removed, and the only way to fix my system was to re-install and re-update Windoze.
MS said only a small number complained, well, I did, and a couple of days later the update was pulled, no reply to my email though, not even a thank you or aknowlegment - typical MS =O(
fLaMePr0oF
This is not good for the average consumer.
Bugs like this keep the common microsoft user from installing the latest and greatest updates. They might not understand that their security is troubled until they recent damage; however, they understand this:
"I finally ran windows update... and now I can no longer get on the internet. Crap, I'm never doing that again."
Methinks it's a Microsoft-is-too-huge-syndrome. Microsoft can't test its fixes on every possible configuration; therefore, problems like this will occur. Episodes like this have previously occurred and will occur again.
It's the nature of the beast.
btw, thanks Slashdot. I could have installed that this morning!
Davak
True enough, but then again, I heard this story on NPR on my way to work today, so it's only natural that /. would carry something about it.
:)
But you're right, this does remind me of the kernel-that-never-should-have-been. I don't remember the version number (it was in the 2.4 series), but it was the one that corrupted your drives when you unmounted them. Of course, IIRC, that kernel wasn't pulled, the next version was just released very quickly. You can still get that kernel version if you really want to corrupt your data
"Save the whales, feed the hungry, free the mallocs" -- author unknown
Every software update is a risk. Especially OS updates. With software, I always fear that beside enhancements, also restrictions will be built in (happend with quicktime once years ago). Therefore, I usually
keep a copy of the old software or to make full backups before upgrading the OS. Updating software is not trivial because it X + A + B is not equal X + B + A : the update A can and will in general change something of the modification B. After a few such operations it becomes very difficult to keep track about all possible
states the users can have on their machine.
My experiences from updates:
- even for modern Linux distributions, it is a good idea
to make full new installs rather then upgrading. I personally
always had problems with upgrades and almost never had problems
with full reinstalls.
- the OS X updates went all smooth so far. Still, I always upgrade
first one machine, wait to see if everything works fine before
updating the others.
- XP updates. No problem with vmware. Just keep an copy of the
old virtual machine around. If something screws up or one of
the software has decided to "upgrade" itself:
rm -rf winXPHome
mv old.winXPHome winXPHome
Virtual machines can also easily be copied from one machine to
an other.
It's not a bug, it's digital rights management preventing illegal file sharing!
For most people, it is the only way they're ever going to install updates on their computer. However, I've found production Windows 2000 servers with this feature enabled! This is at least the 2nd or 3rd time that I've read a story on /. about a Windows XP/2000 patch that was no good.
If you want to disable automatic updates on your computer, go to Control Panel->System->Automatic Updates tab and click the buttons to turn it off. You'll be better off picking what you want to update manually.
Never hit your grandmother with a shovel, for it leaves a bad impression on her mind...
If you're running XP SP1, you definitely do not want this fix. It will bring your system to a crawl. See this for more info.
>Also, how is this different from any automated Linux update method?
/. has an anti-MS bias. So do a lot of people, but losing network connectivity is pretty serious, especially on the world's monopoly OS.
/. crowd complains about ignorant users who don't patch. Now the patchers are the problem?
Its not. Well, this wasn't automated, it had to be downloaded from the windowsupdate.com site, but I think we're just seeing something of a double standard here.
Okay
What really gets me is that whenever there's an MS problem the
MS's automated patching system isn't bad, it keeps Joe User updated and there simply will be x amount of problems over y amount of time, as you said just like with any other vendor.
Enjoy the schadenfreude guys, it'll just make real MS complaints sound all the less convincing. Optional supplemental reading: the boy who cried wolf.
Crying wolf is a big problem when criticizing MS to the uninitiated. I have the displeasure of taking a 3 hour class with a rabid anti-MS type and at this point no one takes him seriously because of his zeal, even though 2/3 of the stuff he says are actually excellent points.
Engaging in simple-minded schadenfreude simply makes people look less credible. Seems like a tough lesson to learn for the loud-mouth anti-MS types.
I guess I was not the only one who got hosed downloading this update recommended to me by MS thru the update site. It ruined my DSL connection and could not be uninstalled. I wound up fdisking and formatting, which of course required the nice little phone call to Microsoft to get this number and that number. When they asked me why I was calling, I told them I downloaded an update from the update site that killed my internet connection - they were very polite after that.....wonder why? :)
When Apple comes out with their new PPC 970 systems I will be first in line to buy one. I dont like what I see coming down the Microsoft trail re DRM and all the spying going on. I liked my G4 when I had it but it was so slow compared to my windows box I sold it. Seems like Mac maight make a comeback, I'm sure I'm not the only one thinking this way. But there's no way I'm buying a G4 unit.