Stealthy Windows Update Raises Serious Concerns
UniversalVM writes "What is the single biggest issue that bothers open source advocates about proprietary software? It is probably the ability of the vendor to pull stunts like Microsoft's recent stealth software update and subsequent downplaying of any concerns. Their weak explanation seems to be a great exercise in circular logic: 'Had we failed to update the service automatically, users would not have been able to successfully check for updates and, in turn, users would not have had updates installed automatically or received expected notifications.' News.com is reporting that all of the updated files on both XP and Vista appears to be in windows update itself. This is information that was independently uncovered by users and still not released by Microsoft."
Here's the complete list to prove it (sorry for the lame formatting, it's Slashdot's lameness filter):
The last update they did was stealthy enough that I didn't realize it was happening, and my XP system lost power during the middle. End result, XP is now acting erratically, proclaiming update is invalid at bootup, sometimes not booting at all. Forced me to re-evaluate Linux for my 1 game machine, and trying out Cedega to get my last real Windows game (City of Heroes) to run.
Karma Whoring for Fun and Profit.
Just a bunch of people bitching for no reason, trying to generate traffic to their blogs. Let's see...
The update only updated the Windows Update software itself, nothing in Windows.
It did not update if you have automatic updates turned off.
It did update if you had "Notify me" turned on. This is a point of contention, but MS says they needed to do the update to continue to notify users of actual updates.
Finally, this doesn't apply to any networks running a WSUS (or whatever it's called now) server.
Give in to the Dark Lord and life will be predictable and simple. Freedom is for babies.
Table-ized A.I.
We already did this one just two days ago.
The anti-Microsoft FUD was thoroughly debunked by numerous Slashdot posters. It was also thoroughly debunked by numerous comments in reply to the various external sources cited in the older Slashdot article.
They updated Windows Update, when people explicitly visited the Windows Update site. That is all. They are not pushing out updates to critical system files without any user intervention.
Last time, several posters asked whether Slashdot would at least have the decency to correct the blatantly Microsoft-bashing headline/article. They didn't, they posted it again. <sigh> Go Zonk!
If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
My understanding is that this update arived even if automatic update was turned off.
In this case Microsoft was illegaly entering the custumer owned computer, using the customer paid connection, hardware, in order to achive something that is beneficial for Microsoft.
Just try to do the same for a Microsoft owned computer: the full power of legal prosecusion will fall on your neck for countless charges, with likely jail term panishment if convicted.
Who is going to press charges for the same act against Microsoft? And if Microsoft is found guilty, who is going to jail from Microsoft?
Some systems and applications are so mission-critical sensitive that the systems have to be certified in their configurations -- medical systems, traffic control, pharmaceutical manufacturing, banking and financial systems -- too many to be subject to this outrageous behavior.
The most secure setting provided (that I am aware of) is "do not install updates". If a system's certification can be sabotaged by Microsoft covert behavior, who's going to pay when a system fails and the system is demonstrated to have been subverted with tripwire-like checksum failures? Microsoft? The applications vendor?
-- Gary Goldberg KA3ZYW 301/249-6501 AIM:OgGreeb Digital Marketing Inc., Bowie, MD
I have disabled, then removed completely the windows update service from all my computers. I will manually install updates from now on, when and if I want them.
I hadn't known there were so many idiots in the world until I started using the Internet -Stanislaw Lem
So now that hackers know there exists a backdoor to the windows update which will let them update a stealth patch to anything they want in the system because it runs with admin rights, this isn't a big deal to you?
We were all warned a long time ago that MS products sucked, remember the Magic 8 Ball said, "Outlook not so good"
I noticed that with Firefox. I rarely use it. At least there IS an off switch.
"I have never heard of anything this evil before. An OS that updates it Update Notification system if it is turned on."
Read it again (the first time?), it wasn't on.
That's the problem, it updated even when disabled.
If tyranny and oppression come to this land, it will be in the guise of fighting a foreign enemy. - James Madison
So now that hackers know there exists a backdoor to the windows update which will let them update a stealth patch to anything they want in the system because it runs with admin rights, this isn't a big deal to you?
Sure, all they need to do is forge all of Microsoft's digital certificates first. Patches are signed or else they don't install without warnings.
The biggest problem I have with this update, is that it proves beyond any doubt that Microsoft deliberately placed a "hole" in the security of their OS for their own purposes. It is nothing less than something on the internet contacting the OS, opening a hole, then running software with root/admin permissions to change something in the OS itself. Something many people have suspected because of the so-called security patches that move holes around instead of actually closing them, has now been proven to be true.
This must be a holy grail for a Windows hacker. This hole was put in the OS specifically to take over a computer, and Microsoft's reaction to its discovery shows they obviously have no intention of closing it - just continuing to use it when desired. You can bet that finding this hole and ways to exploit it are now the top priority of hackers around the world.
If I suppose this sentence true :
Had we failed to update the service automatically, users would not have been able to successfully check for updates and, in turn, users would not have had updates installed automatically or received expected notifications.
What append when someone install XP (OR Vista) from zero and get the OldAndBad Windows Update ? He will never be able to get update ?
Someone have feet in his mouth.
Ceci n'est pas une Signature !
Some drink at the fountain of knowledge. Others just gargle.
Here's a big difference... in Firefox, the "OFF" switch works. The "ASK ME FIRST" switch works. The "ON" switch works.
And the thing you missed, the installer asks you to choose how you want it handled during the install. If you installed this under Linux or some other OS that may not have an installer (or downloaded an archive instead of an installer), then you should have read the accompanying readme and manually set the option after "install" as instructed.
World of difference from MS
StarTrekPhase2 - The Five Year Mission Continues!
You re-install the operating system from the original media, configure your network connection, run Windows Update, and let MS do the work for you.
I'm a Programmer. That's one level above Software Engineer and one level below Engineer.
"Who will update the updaters?"
http://www.informationweek.com/830/hacker.htm
"City hall" in German is "Rathaus" Kinda explains a few things......
So now that hackers know there exists a backdoor to the windows update which will let them update a stealth patch to anything they want in the system because it runs with admin rights, this isn't a big deal to you?
So explain to everyone how a hacker without prior access will get the machine to go to their server instead of the MS server, present the correct authenication, which still has not been broken, and then forge security certificates for every file they want to download?
A system would already have to be compromised to even attempt to use or subvert this system and would be a lot harder than just taking control of other areas of the OS...
Are people really this stupid?
I have, multiple times. When you install and old version of OSX (and you can consider OS 10.1 old nowadays) it takes a while to upgrade.
/. is infested with clueless Apple fanboys these days. I lost a lot of karma just for pointing out flaws in Apple's hard- and software.
The following doesn't apply to you clang_jangle but I have to get it off my chest:
It's a pity that
-- Cheers!
a hacker without prior access will get the machine to go to their server instead of the MS server,
DNS poisoning
present the correct authenication,
Using "genuine" certificates from Verisign will get you much of the way to where you want to be, I suppose.
If you're a zombie and you know it, bite your friend!
nLite will solve your problem. With it you can slipstream a full Windows installation disk, plus patches, plus any drivers that you would otherwise need to install. You can even remove chunks that you don't need.
I do take issue with some of your points though. Your knowledge of the DOS/Win32 operating environment is no doubt something that you have accumulated slowly over a number of years. I too found the unix command line unfamiliar and painful when I first used it. I'm still a novice, but I now find it more productive than cmd.exe by an order of magnitude.
I found installing and using Gentoo to be a great learning experience. The lack of a graphical installer (at the time) forces you to use the command line for everything. If you follow the install manual "blind" you pick up a few things. If you go through it reading the manuals for every command you use, you pick up a lot of things. I didn't get along with the graphical distributions at the time, I couldn't find any of the options I wanted. They have improved, but my TV server still runs Gentoo since it was the only distribution that supported my hardware at the time.
Your old hardware is much more likely to be supported than newer hardware.
As for games? I'm not going to chime in with the rest of the people in this thread and claim you can use Linux to run them all. I like to play games. I intend to keep running Windows until I give them up (which may well happen, they innovate less every year), or until Linux versions are commonplace.
As a software developer, I also can't do without Windows. I depend on Windows, because it's where most of my code lives. But I love open-source. I'm lucky enough to be doing a job where I don't have to avoid it - I can use what I like. And if I have to pick and choose, using OSS tools are just overall much less hassle. I don't have to requisition them, justify purchase costs, fill in forms, wait thirteen weeks for approval. If they have bugs, I don't have to contact the supplier and engage in complex political games about who's fault it is, I just fix them. OSS for me is just far more agile and productive.