Slashdot Mirror


'Don't Tell People To Turn Off Windows Update, Just Don't' (troyhunt.com)

Security researchers Troy Hunt, writing on his blog: Often, the updates these products deliver patch some pretty nasty security flaws. If you had any version of Windows since Vista running the default Windows Update, you would have had the critical Microsoft Security Bulletin known as "MS17-010" pushed down to your PC and automatically installed. Without doing a thing, when WannaCry came along almost 2 months later, the machine was protected because the exploit it targeted had already been patched. It's because of this essential protection provided by automatic updates that those advocating for disabling the process are being labelled the IT equivalents of anti-vaxxers and whilst I don't fully agree with real world analogies like this, you can certainly see where they're coming from. As with vaccinations, patches protect the host from nasty things that the vast majority of people simply don't understand. This is how consumer software these days should be: self-updating with zero input required from the user. As soon as they're required to do something, it'll be neglected which is why Windows Update is so critical.

507 comments

  1. Excluding the unfortunate exceptions by JimToo · · Score: 5, Insightful

    Unless you have a production environment with a software product that breaks with Windows update turned on. In which case you have to take additional security and maintenance measures and have a team that is tasked with (and funded properly) to do testing and updates on a regular basis.

    1. Re:Excluding the unfortunate exceptions by xxxJonBoyxxx · · Score: 5, Insightful

      Or the Windows 10 update doesn't work and keeps downloading/restarting/bluescreening your computer. (Looking at you, "Anniversary" edition.)

    2. Re:Excluding the unfortunate exceptions by mikael · · Score: 4, Interesting

      For me, it takes around three manual restarts, because I have a dual-boot system and the default option is to boot into Linux. Even if Windows does download the update, it then sits around for so long with no indication of what it is doing that the screen blanks out. Then it just sits there pondering and reboots into Linux. Then I reboot back into Windows, which tells me that updates have to be installed. Then it sits around a bit more with a blank screen, then it reboots.

      So an automatic update isn't going to be automatic, and it comes as a rather unpleasant surpise to boot into Windows, only to find that the updates weren't installed or need to be downloaded and installed before I can get any work done. If this update system were designed correctly, it should simply clone the existing Windows config, apply the updates, and only say a new version is available when everything is working correctly.

      --
      Vintage computer adverts: http://www.vintageadbrowser.com/computers-and-software-ads
    3. Re:Excluding the unfortunate exceptions by mhollis · · Score: 5, Insightful

      Mod this up, folks!

      I know at least five different business environments which have been, essentially, shut down by a Windows update. One of them was signing a new service contract as I was talking to him—he had been down all day, unable to see his customer files, his books, the jobs his company was supposed to be doing, unable to route his employees to where they were supposed to go. They went back to a paper only system they have not used since 2002 and they were guessing at that. They were taking credit cards over their website, but could not record the result in their books and had to just save all of the emails and spend an additional day or so just doing data entry into their bookkeeping system.

      Of course, these are anecdotes (which is what the anti-vax community uses instead of Science). The problem is not the update, it is what Microsoft does to the computer upon emerging from the update. Elsewhere, people have written of resetting all of the browser preferences, BSODs and other issues. Microsoft needs to restore the previous state of the computer or server (as much as is practical) after the patch. They need to go in like a surgeon with the same motto: "First, do no harm." And if they figure out how to do that, their updates will be seen as innocuous as Apple's

      --
      Gods don't kill people, people with gods kill people.
    4. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      I have a Win7 machine that has an issue with updates. They fail, and it freezes. Luckily I can turn off automatic updates (and scan for malware a lot).

    5. Re:Excluding the unfortunate exceptions by mysidia · · Score: 2, Insightful

      Makes sense, but not an excuse for turning off Updates.

      How about your company's team (with the prod. servers) does their job, then? And tests and Rolls out the updates BEFORE Windows update automatically installs it.

      Leave Windows Update Enabled, schedule all new updates to install on X Day; However, If Windows updates rolls out the patch its own, then YOUR TEAM failed to conduct its job appropriately, which was to perform a controlled rollout in a timely manner (BEFORE The update is a week old, And the failsafe triggers to protect your organization's security).

    6. Re:Excluding the unfortunate exceptions by Austerity+Empowers · · Score: 1

      Unless you have a production environment with a software product that breaks with Windows update turned on

      And this is the scenario that happens more often than a patch was ahead of the exploit. It still makes the most sense to keep update OFF.

    7. Re:Excluding the unfortunate exceptions by peragrin · · Score: 2

      Yep. Whenever work preforms security updates we literally lose a days worth of business as everything has to get reset. Local printers vanish as thier connections are disabled, with office 365 and outlook down for so long those caches get flushed, etc.
          You wanna know fun? Get 30 people to download 3-5 gigs of emails in an hour on a 100 mbit connecting because that's the best the area has.. talk about a wasted day.

      All because vendors reset settings that had no requirement of beingâ reset for siad Patch.

      --
      i thought once I was found, but it was only a dream.
    8. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 1

      > And if they figure out how to do that, their updates will be seen as innocuous as Apple's

      "Innocuous", like downloading multiple GBs worth of update files over my slow DSL connection, only to tell me *after* the fact that my MacBook Pro is too old for Sierra. Gotcha.

    9. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      This happened to me on a laptop with an EoL vga card. Windows 10 kept updating the driver, crash during the install to bios, reset twice, then involve me to load a restore point. Once restored, it would attempt to reinstall the driver.

    10. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      It sounds like your security and compliance team doesnt know what they are doing. I patch windows and linux systems for a living. Been doing it for the last 8 years on numerous different environments. If you are having problems, then look at the team and fire them. They arent doing their job. Its a full 40 hour a week to keep things compliant (thanks linux, daily updates are the worst). You need dedicated people or else shit breaks.

    11. Re:Excluding the unfortunate exceptions by xxxJonBoyxxx · · Score: 5, Insightful

      >> How about your company's team (with the prod. servers) does their job, then? And tests and Rolls out the updates BEFORE Windows update automatically installs it.

      So...Windows shouldn't be used by small or medium-sized business without IT workstation teams then?

      Microsoft, can you confirm?

    12. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Unless you have a production environment with a software product that breaks with Windows update turned on.....

      #Facepalm

      Test updates and patches in your staging environment *THEN* push product to production.

    13. Re:Excluding the unfortunate exceptions by toonces33 · · Score: 1

      Or WU that literally runs for 24 hours with the CPU pegged at 100%. I haven't seen that in a while - maybe they finally have it fixed. Or if your C:\ drive is full - then you get all sorts of weird failures. You go and clean some space up, and within a day it has gone and downloaded more junk to fill it back up again. Or your WU databases have somehow gotten corrupted, and WU just runs and runs and never actually does anything. I have seen that one as well.

    14. Re: Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 1

      You need dedicated people or else shit breaks.

      That's strange. I'm sure I've worked in several different organisations with 25-50 people and no dedicated IT staff, yet they all managed to keep their systems working just fine.

      Oh, wait, that was before the modern updates-every-ten-minutes junk. Never mind.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    15. Re:Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 3, Informative

      You do understand that the majority of professional work is done by small businesses, and most of those don't have dedicated IT teams at all, right?

      Enterprise IT is actually the exception, not the norm.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    16. Re:Excluding the unfortunate exceptions by Wolfrider · · Score: 2

      --What I did for dual-boot is to set Grub to boot last selected entry, might work for you...

      --
      .
      == WolfriderV6 == I'm willing to admit that *I just might* be wrong... Are you??
    17. Re: Excluding the unfortunate exceptions by mhollis · · Score: 1

      Okay, you are an expert. And you patch systems and I want to thank you for the un-thanked-for work that you do all of the time. But we're talking about the Microsoft-pushed updates that destroy everything (you can see all the anecdotes, so I know you are aware.

      I will offer you this: I know a company with $3M in sales that signed a contract with a (hopefully) good IT firm right in front of me that I would have loved to refer to you. Send me a private message with your location and I will refer you if you are local.

      --
      Gods don't kill people, people with gods kill people.
    18. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Every clean install of Windows 7 SP1 I do does this. Getting a new install up and running with patches is very laborious.

    19. Re:Excluding the unfortunate exceptions by bongey · · Score: 2, Informative

      Windows update(10) all the way back to XP, is horribly slow is part of the problem and it has just gotten worse. Run into a problems with windows update and you can lose 1-3 days, just because it takes forever for it to eventually fail. I went to update the windows load on my dual boot machine and it took 3 freaking hours on 4.5Ghz machine, ssd and 32GB of RAM. Same machine with Ubuntu updates took all of 2-3 minutes even with multiple dkms modules being built. Microsoft there is no excuse for it being that slow, I can just have btrfs root, take a snapshot before updates and have the equivalent of your system restore and your horrible over engineered windows installer without the headaches.

    20. Re:Excluding the unfortunate exceptions by darkain · · Score: 3, Interesting

      1) There is one particular update that addressed and fixed the WU CPU issue (I don't remember the KB number right now, but it is easy to find)

      2) Just slipstream a Windows WIM file. Take the ISO, download the cumulative updates, inject them into the WIM, and then install Windows from there. It'll be a smaller install over all (less SxS crud), and current as of which ever updates you slipstream into it. Additionally, you can add drivers this way too such as NVMe, USB3, and 10gbe if you use stuff like that.

    21. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      That *is* innocuous. The MS way is to patch anyway and fail halfway through because it's unsupported.

    22. Re:Excluding the unfortunate exceptions by Drethon · · Score: 1

      >> How about your company's team (with the prod. servers) does their job, then? And tests and Rolls out the updates BEFORE Windows update automatically installs it.

      So...Windows shouldn't be used by small or medium-sized business without IT workstation teams then?

      Microsoft, can you confirm?

      Yep and they shouldn't use Apple or Linux because of the lack of document compatibility with customers and suppliers. So this leaves us with...

    23. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 2, Insightful

      It also doesn't help that when I try to find details about updates there's no information in the Windows Update panel. "Install this update to resolve issues with Windows." Thanks you fuckers... what issues? "Click here for more information." I click and get taken to a page that says "Install this update to resolve issues with Windows." Oh for fucks sake...

    24. Re:Excluding the unfortunate exceptions by networkBoy · · Score: 1

      no, they haven't. Just happened to me two days ago on my work lappy.

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    25. Re:Excluding the unfortunate exceptions by CFTM · · Score: 3, Insightful

      So, if you read the article, you'd know that he's actually talking about home users and states before hand that enterprise environments have their own processes and procedures for dealing with these things (and if they got hacked, they screwed up because it's been three months).

      The problem is that technical users, like those found on Slashdot, tell home users that they should turn this stuff off because it causes all these problems, when it really doesn't when you're running a system with known hardware and under typical operating conditions.

      By typical, I mean you use Chrome and maybe a few other applications. You're not a developer, you're not a big time game player.

      This is 95% of MS home users. These people should all have Windows Update on at all times and what's more, they could care less about the crap that Microsoft packages in along the way. We may consider it invasive but most people just shrug their shoulders and move on.

    26. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Exactly. So far, in my ~15 Years in the company we have had NO downtimes because of Virus and/or Malware (mostly because no Windows machines can talk to the internet directly, and we virus scan on the mail sever an on the two "USB copy machines"), but we have about 3-4 downtimes a year because of Windows Updates on various systems.

    27. Re:Excluding the unfortunate exceptions by networkBoy · · Score: 2

      as I *abruptly* learned a year ago when I left Intel and started at a relatively tiny 40 person shop.
      We have an IT guy (actually rather spectacular dude really) but there's no way he can get much past firefighter and core infrastructure maintenance mode... and there's no money for more people for something that simply doesn't make money.

      Yes we all know that IT doesn't make money, it prevents you from losing it all... but my intro to the "real world" after two decades in multinational corp. environment has been eye opening.
      I think of our 20 or so clients, only 2 have serious pro level IT, another 5 have functional IT. The rest? bwahahahahahaaaaaa

      --
      whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
    28. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Just means you had a lot of data to hash, index, and upload to the NSA. How do you know it wasn't?

    29. Re:Excluding the unfortunate exceptions by sbjornda · · Score: 1

      So...Windows shouldn't be used by small or medium-sized business without IT workstation teams then?

      You contract that stuff out to a local computer company. Doesn't have to be in-house.

      --
      .nosig

    30. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Easy fix, turn off Windows Update, just do it.

    31. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Or the Windows 10 update that: 1) breaks the mouspad driver on the laptop or 2) messes with all the settings, or 3) reboots even when the system is hibernating, drains the battery in the process, and fails miserably half way through after running out of power.

      If Microsoft wasn't so unreliable with their updates, to the point of making the system unbootable or breaking things in less severe ways, then people wouldn't be tempted to disable it. Same for updates that decide to occur in the middle of people trying to complete time-sensitive work. Why then? Why is that kind of default behaviour acceptable? Yes, updates are important, but in the middle of my presentation? Really?

      In my experience the chances of breaking things via Windows update are *greater* than getting sideswiped by the latest piece of malware. I know, it does sound like the equivalent of some crazy anti-vaxx claim, but it's seriously bad, especially for Windows 10. Thus I update on my schedule, not Microsoft's. Give me better control over the process and I'll consider turning it back on by default. Until then, no. This is one case where the cure really is worse than the disease.

      For large organizations with huge numbers of machines I understand why they turn it on as a matter of routine for simplicity sake, but poll the users and you'll discover they're profoundly annoyed by the way Windows does it. MS needs to do better.

    32. Re:Excluding the unfortunate exceptions by mysidia · · Score: 1

      So...Windows shouldn't be used by small or medium-sized business without IT workstation teams then?

      If you're a SMB, then it is vanishingly unlikely that an Update-induced outage will cause a critical interruption of business.
      If it would, then either change your design, Develop a plan to mitigate Update-induced outage, OR else, it really is worth paying
      for the team to do this right.

      ON THE OTHER HAND, a Security-breach-induced-outage could very well put you out of business;
      if Uptime of this application is as critical as you would like to suggest.

    33. Re:Excluding the unfortunate exceptions by StormReaver · · Score: 2

      I love Windows 10. Because of it, I have people asking me to install Linux over Windows 10 that would never before have considered such an option. Thank you, Microsoft!

    34. Re:Excluding the unfortunate exceptions by nine-times · · Score: 1

      Sure, but then... you really should have maintenance with the vendor, and the vendor should be keeping the software product up to date so that it works with the latest Windows patches.

      I'll admit it's not that easy. Sometimes you're stuck with some weird application that nobody supports anymore, but you need to keep it going. However, there's a part of me that wants to point out that, to some extent, it's the fault of whoever purchased that application. What I mean is, I've seen companies that are still running on some product that was purchased 20 years ago, and they just haven't updated. I've seen companies that rely completely on some application that a company built in-house before firing their development staff, leaving nobody who knows how the code works. To some extent, if you base your business around some random janky application that nobody is supporting, it's kind of your own fault. Businesses should anticipate that, for any business-critical application, they should have a support contract with developers capable of patching/fixing/updating that application. If you can't find someone to do that, then find a different application. If you can't do that (or can't afford it), then your business just isn't sustainable. Sorry.

    35. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 1

      Seriously? LbreOffice runs fine across Linux, Windows, Mac stuff AND it has 'document compatibility' with Office. I presume you tell people not to use Google Docs because of 'document compatibility'. Here's an idea, tell MS to make their shit 'compatible' with other products NOT the other way around.

    36. Re:Excluding the unfortunate exceptions by h4ck7h3p14n37 · · Score: 1

      You could also just not connect any Windows computers with Internet access (used for email or browsing) to your internal, secure network. Yeah, you'll probably need multiple devices at your desk, but you won't have to worry about email viruses getting to the secure network.

    37. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      This is the winner right here. It doesn't even require a guru to implement some complicated config. One simple option, and it's done.

      Microsoft is not responsible for every PEBKAC issue on the planet.

    38. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Why the hell isn't there any redundancy? What if the computer's drive fails, or the power supply dies, or if the computer just up and catches on fire?

      It's merely inconvenient, rather than catastrophic, when Windows Update takes down a computer where I work because there are multiple systems, with each replicating the correct working environment.

    39. Re:Excluding the unfortunate exceptions by EndlessNameless · · Score: 1

      It'll be a smaller install over all (less SxS crud)

      For the sake of completeness, it should be mentioned that the SxS crud will only be removed if DISM is run with the /cleanup-image option.

      On Windows 7, KB2852386 must be installed to run the cleanup from the GUI.

      Windows 8 and newer include a scheduled task which does this automatically every 30 days.

      --

      ---
      According to the latest ruleset, this post should be modded as Vorpal Flamebait +5.
    40. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Not everyone works for the government.

    41. Re:Excluding the unfortunate exceptions by scdeimos · · Score: 1

      Local printers vanish as thier connections are disabled, with office 365 and outlook down for so long those caches get flushed, etc.

      We had a large percentage of Win10 computers stop working with one or more network printers after the Anniversary update. They could access the affected printers' web management pages, could telnet to the affected printers' IPP ports, but the printer icons had disappeared from the Printers control panel applet and could not be re-added via the Add Printers wizard. We've never solved it, but my suspicion is that GUI settings got trashed in the upgrade and there's still some evidence of the prior printer registrations in the Registry preventing them from appearing again in the Add Printers wizard.

    42. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      What about when WindowsUpdate is broken and sits at "0% Downloading Updates" never finishes, and none of Microsoft's proposed (copy and paste) solutions can correct it?

    43. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 1

      All because you keep clinging to windows despite these troubles. There are alternatives. Linux if you want to save the most money, Mac if you enjoy paying for a polished product. Even the mac is cheaper than windows - because you don't get that sort of downtime & panic fixing.

    44. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Makes sense, but not an excuse for turning off Updates.

      How about your company's team (with the prod. servers) does their job, then? ... then YOUR TEAM failed to conduct its job appropriately, which was to perform a controlled rollout in a timely manner (BEFORE The update is a week old, And the failsafe triggers to protect your organization's security).

      so we have to double or triple number of servers to keep one PRODUCTION, one PATCH_TESTING and another as BACKUP?
      Good sales pitch.
      We prefer to do it unix way - we decide when it is downloaded, what is installed,
      and we do have backup ...

    45. Re: Excluding the unfortunate exceptions by dougdonovan · · Score: 1

      i just love the computer intelligence level of the global general public. i know they change oil every 3k in their vehicles but to maintain a computer. seriously. not gonna happen. computers are supposed to be self sufficient.

    46. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 1

      So you have never used Windows. Why didn't you mention that up front?

    47. Re:Excluding the unfortunate exceptions by mhkohne · · Score: 2

      Unless you have a production environment with a software product that breaks with Windows update turned on. In which case you have to take additional security and maintenance measures and have a team that is tasked with (and funded properly) to do testing and updates on a regular basis.

      That's a nice sentiment, but I for one have never been lucky enough to know beforehand that a Windows update was going to break shit. I just have to put them on and hope. So I can hardly blame any company that relies on software for taking a very critical approach to them.

      --
      A thousand pounds of wood moving at 300 feet per minute. Don't get in the way.
    48. Re:Excluding the unfortunate exceptions by Trogre · · Score: 2

      How about your company's team (with the prod. servers) does their job, then? And tests and Rolls out the updates BEFORE Windows update automatically installs it.

      And... then what?

      If the update causes unacceptable behaviour, which does in the GP's case, what exactly can you do about it?

      --
      "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
    49. Re:Excluding the unfortunate exceptions by mhkohne · · Score: 1

      Seriously? LbreOffice runs fine across Linux, Windows, Mac stuff AND it has 'document compatibility' with Office. I presume you tell people not to use Google Docs because of 'document compatibility'. Here's an idea, tell MS to make their shit 'compatible' with other products NOT the other way around.

      Ahh, you naive child. LibreOffice for all that it does try VERY hard to be compatible with the M$ products regularly fails on relatively simple documents created by people who have no idea they are doing anything strange. It's not really LO's fault, but you can't run a mixed LO & M$ shop if you care about your documents looking the same all over - the M$ formats are just too arcane and goofy for that to ever work 100%.

      If you can go all LO, you're set, but if you have to interact with other companies that want M$ documents, you're hosed.

      --
      A thousand pounds of wood moving at 300 feet per minute. Don't get in the way.
    50. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      I've got three employees. I can either pay $crazy for windows server, WSUS, Win10Pro and spend time I don't have doing this shit myself, or I can pay $crazy+$insane for someone else to remote in and manage it for me. Or I can just deal with shit randomly rebooting. So far win10 hasn't killed any of our computers.

    51. Re:Excluding the unfortunate exceptions by Gr8Apes · · Score: 1

      How about your company's team (with the prod. servers) does their job, then? And tests and Rolls out the updates BEFORE Windows update automatically installs it.

      How about MS actually doesn't screw its customers over and only sends security patches down the pike? New/changed features should be optional downloads selected by the users, never forced.

      --
      The cesspool just got a check and balance.
    52. Re:Excluding the unfortunate exceptions by tjanke · · Score: 1

      Not even a production environment.

      Awhile back, windows update nearly bricked my computer. The new driver for the Southbridge chip was corrupt, and suddenly the mouse stopped working. The keyboard and everything else still worked, so I was able to limp along. It took me nearly two weeks to diagnose the problem and then find and install the right driver. Two very long, very, very frustrating weeks.

      Since then I've never let windows automatically install anything. I always review the updates, and choose which ones to install and which not. As you can imagine, the recent move to monolithic updates is really pissing me off.

      --
      Cheers, Tim -- Tim Janke Part mad scientist, part lion tamer: sr. software engineer, global team leader, project mana
    53. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Same. My router has been blocking smb for like 10 years sooooo IDC. The worm aspect isn't the whole story. You can still deliver wannacry like regular malware and it will work on win10.

    54. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Why the heck would windows update touch my video drivers?!?

      No. Just no.

      I used to be a gamer. I control what video drivers I use.

      No, I don't use windows anymore.

    55. Re:Excluding the unfortunate exceptions by BarbaraHudson · · Score: 1

      The people who blindly accept all updates are also the people who blindly click on every link in an email or on a web page. So it doesn't matter if they have updates turned on - they're going to fsck up anything more complicated than an Etch-a-Sketch.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    56. Re:Excluding the unfortunate exceptions by JohnFen · · Score: 2

      If you can go all LO, you're set, but if you have to interact with other companies that want M$ documents, you're hosed.

      I hear this quite a lot, and I could see it being true for very complex documents. But I use LO exclusively, and have for a very long time. I exchange documents with Office users daily. I don't remember ever having a serious problem. I have, on occasion, experienced an easily-corrected glitch.

      My experience is hardly statistically sound, but it does not support the extreme incompatibility claims I see frequently.

    57. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      If computers are a business critical component - if you cannot run your business at all with them up and running - then you DAMN well better have IT. You can hire someone in-house to do it, or you can use a 3rd-party hosting service, but you need support and process.

    58. Re:Excluding the unfortunate exceptions by Excelcia · · Score: 2

      Really, are you forgetting the turmoil that people with pre-Windows 10 versions were put through when Windows updates first started inviting them to upgrade to Windows 10? First it was hey do you wanna? Then it was hey, we're just going to go ahead and "upgrade" you unless you say no. Then it was we're just going to upgrade you. That's what automatic windows update buys you.

      No one should give Microsoft unfettered access to their computer. With Windows update turned on, Microsoft deletes features, they take away options and control, they upgrade drivers you don't want to have upgraded, they break things. More problems have been caused by bad updates than by any malware I've ever had, which has been exactly none. A good firewall will protect you better than Windows update will.

      I vet each and every update that goes into my computer. I look every one up, which is increasingly hard because all they want to tell you is "this is an update that addresses an issue in your computer." I avoided all the Windows 10 upgrade nag nonsense pain. When I finally had to buy a computer with Windows 10 on it, I immediately disabled Microsoft's automatic update mechanism and installed Windows Update Mini Tool, which lets me choose which updates to install again. As such, I have drivers that work, a computer that is stable, and a platform I can trust to be there when I want it.

      Do you think the NSA needed that vulnerability to get into computers? They only needed that vulnerability to get into pre-Windows-10 computers, because after Windows 10's auto-update nonsense, any other computer they want to get into just gets pushed an auto-update the user can't stop.

      The very last thing anyone should have is a computer that just blindly installs whatever Microsoft decides.

    59. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 1

      So it's not just me that loses printer access after so many updates. Having to reinstall the driver package so often is getting annoying. Nothing else seems to work.

    60. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      So, it needs to be outsourced. Some large IT-support firm needs to provide a repackaged version of Windows, receiving updates from them, rather than directly from Microsoft. This intermediary firm does all the stuff usually done by the IT team at a large company, picking out which updates are necessary and which just break things.

      I bet this would hit some legal obstacles - probably something to do with reselling Windows against the strictures of the EULA - but it's the logical option, given that Microsoft apparently can't do this themselves.

    61. Re:Excluding the unfortunate exceptions by 0111+1110 · · Score: 1

      The problem is that technical users, like those found on Slashdot, tell home users that they should turn this stuff off because it causes all these problems, when it really doesn't when you're running a system with known hardware and under typical operating conditions.

      Probably they only get told to turn it off after it causes some kind of problem. If I get a call from a friend about a computer problem that was caused by a MS update what the fuck do you think I'm going to tell him to do after that.?

      I keep it turned off on my own computer because it caused me similar problems and is a total nightmare in almost every way. Microsoft thought that randomly taking over someone's computer for a few hours at a time without any warning was a good idea, but actually it's not. Even on Windows 7 I keep it off. Can't even imagine what it would be like to run Windows 10 with auto update on. Jesus. That must be a nightmare. I don't ever want to know what that is like. There is enough suffering in this world without that.

      --
      Quite an experience to live in fear, isn't it? That's what it is to be a slave.
    62. Re:Excluding the unfortunate exceptions by Tough+Love · · Score: 1

      they shouldn't use Apple or Linux because of the lack of document compatibility with customers and suppliers. So this leaves us with...

      This leaves us with Apple and Linux, which do not have document compatibility problems. Only Microsoft does. Honestly, just cut that turd loose and let it float away into oblivion.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    63. Re: Excluding the unfortunate exceptions by roc97007 · · Score: 1

      In fairness, the general public doesn't change the oil in their vehicles. If you're lucky they'll pull into a lube station and pay someone else to do it, if it's not too expensive. Mostly, I suspect, cars don't get serviced until something goes wrong. Kinda like computers.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    64. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Now imagine you have Linux, macOS, Windows 7 and Windows 10 installed on the same computer (1TB SSD). So Windows 10 update overwrites Clover, which is your default boot manager. Then you need to insert Linux live USB, fix Grub first. After you fix Grub, Clover is gone, so you need to restore Clover as well. Now as you have both Windows 7 and Windows 10 on the same drive, when you choose Windows in Clover, you still need to choose which Windows you would like to start, and if that is not the same as the Windows you booted last time, you need to reboot again...

    65. Re:Excluding the unfortunate exceptions by Tough+Love · · Score: 1

      LibreOffice for all that it does try VERY hard to be compatible with the M$ products regularly fails on relatively simple documents...

      That what you don't get, you aging Microsoft shill. Nobody needs Microsoft documents any more. Hey, hey, hey, goo-ood bye. There are better, cheap and faster ways of doing everything that the poor clueless Microsoft victims have been suffering with for so long.

      And if should they choose voluntarily to go on suffering, then fuck em. It's their choice, it's not on me.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    66. Re:Excluding the unfortunate exceptions by mea_culpa · · Score: 1

      No, but they can budget for and hire a reputable IT service provider that does, most of which can be done remotely. Problem is many of these small businesses don't see the need and pay as little as they can get away with or do it themselves.
      They have no problem paying for proper preventive maintenance on their fleet of vehicles but heaven forbid they give IT similar focus.

    67. Re:Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 1

      You "need" a lot of things even in a small business. Plenty of problems can kill a young business before it becomes established at all. The reality is that you almost certainly won't be able to deal with some of the issues for a while, and you have to prioritise and do the best job you can in the meantime.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    68. Re:Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 1

      There are plenty of IT consultancy businesses that will stand in for an in-house IT group.

      There are also plenty of small businesses who aren't tech experts and have no idea why they would need such a service or how to judge who can competently provide it. Most people have absolutely no idea how crazily bad most software is.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    69. Re:Excluding the unfortunate exceptions by LVSlushdat · · Score: 1

      Yup.... Came here to say the same thing... I've had friends who bought new systems at a big-box store come to me when their new i7 system that came with Windows NSA Edition (my name for it) shit the bed, and want me to fix it.. ummm... no? I spent 20 years cleaning up after MS, and when I retired, I left that ecosystem for my favorite OS.. That being Linux.. I show the Windows "victim" a LiveUSB of Linux and tell them this is what they need to avoid the abuse that MS heaps upon people who *still* use Windows. Assuming their machine use-case allows it, everyone I've shown Linux to has opted to have me upgrade their systems to it.. FUCK YOU MS!

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    70. Re:Excluding the unfortunate exceptions by arglebargle_xiv · · Score: 1

      Exactly. At the moment I have several machines on which Windows Update causes them to go into a bluescreen-reboot loop. If I turn off updates, the machines keep working. There's a chance they may get pwned at some point, but probably they won't. So turning off updates is vastly less damaging than what Microsoft will do to them if updates are enabled.

      Ergo, Updates are disabled, and will have to stay disabled in order for the machines to continue functioning. Thanks, Microsoft, you've created a "solution" that's a worse option than the malware.

    71. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Isn't it the job of Microsoft to make sure their own updates don't break their own other products? Where is the point of using MS Office and MS everything if it does not guarantee working updates?

    72. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      In my experience the chances of breaking things via Windows update are *greater* than getting sideswiped by the latest piece of malware.

      This is my philosophy with all software. The first thing I do when I install anything is to see if it's default configured to try and update automatically and stop it. Adblockers, firewalls, and basic common sense are 99.9% effective against infections in my personal experience, while updating something that already works is at best a waste of bandwidth and time.

    73. Re:Excluding the unfortunate exceptions by Pentium100 · · Score: 1

      Also, why does almost every update require a reboot? I mean on Linux you need to reboot only when updating the kernel (though there are ways to avoid even that) or a reboot may be more convenient if the update affected a lib that pretty much everything uses (glibc).

      But with Windows, almost any update requires a reboot, sometimes more than once. Couldn't they just restart the affected services (in this case, the SMB service)? I remember somebody writing that Microsoft places special empty space in all its libs so that they can be patched while in memory. I guess this feature is not used...

    74. Re:Excluding the unfortunate exceptions by Pentium100 · · Score: 1

      Well, the different OSs serve a bit different purposes. Linux is great on a server and good on a desktop if it is managed by somebody competent. Linux on a desktop is kind of like an automatic system (say, a car with automatic transmission) - whne it works, it's great, but when there is a problem, there problem is usually difficult to solve.
      For example - video card drivers. Usually Linux detects the video card automatically and works OK (disregarding games for now), but if it does not have the proper driver for my video card, then installing it is much more difficult than doing that on Windows.

      Also, there are software that only works on Windows or even a specific version of Windows. I have a good navigation software (Garmin MobilePC), but it does not work on Windows 10 or Linux.

      In addition, Linux can run some games, but not all games that Windows can.

      So, In some cases, Linux is an incomplete solution (games for example), so I would need to dual boot (since VMs usually do not have good graphics performance), but since Windows can do pretty much everything that Linux can, I might as well run Windows and use a Linux VM or server (for things that Linux does better than Windwos).

    75. Re:Excluding the unfortunate exceptions by Slayer · · Score: 1

      You do realize, that it was huge enterprise scale deployments which were hit by this worm. Nobody bats an eye if small mom&pop shops get wormed and ransomwared.

    76. Re:Excluding the unfortunate exceptions by Drethon · · Score: 1

      they shouldn't use Apple or Linux because of the lack of document compatibility with customers and suppliers. So this leaves us with...

      This leaves us with Apple and Linux, which do not have document compatibility problems. Only Microsoft does. Honestly, just cut that turd loose and let it float away into oblivion.

      I tried open source office products (never tried Apple, I like the OS but not the price premium) when working on my Thesis in college. They mostly work but some weird format inconsistencies crept into word document and excel formulas kept getting mangled. I just couldn't use the open source programs if I wanted to send my paper to a professor.

    77. Re:Excluding the unfortunate exceptions by Drethon · · Score: 1

      I have a number of professors I would love you to convince that I don't need to give them Microsoft documents. Best of luck.

    78. Re: Excluding the unfortunate exceptions by Marxist+Hacker+42 · · Score: 1

      Yep. STILL dealing with this on my laptop. Of course, I do not have idiots opening spam links in emails either, and SMB is blocked even for LAN on my network

      --
      SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
    79. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Most of the default tooling will keep working after an update.

      The only things I have seen failing were custom software jobs where developers took shortcuts or were 'clever' by exploiting an 'undocumented feature' from Windows.
      And if you don't have a dedicated IT Team, don't have custom hackwork running on your machine.

      If these problems were caused by a bought software product, complain to the developers of said product.

    80. Re:Excluding the unfortunate exceptions by Ol+Olsoc · · Score: 1

      Ergo, Updates are disabled, and will have to stay disabled in order for the machines to continue functioning.

      Rinse and repeat, just like those eternal reboots or other update fun..

      mustn't..........rant.........arrrrrghhhhh!

      Jeebuz fucking kryste on a goddamned pigsticker, it's 2017 for fucking gawd's sake. And this piece of shit company and it's amalgamated pus from the unholy taint of Beelzabub operating systems are still wrecking updates, are still vulnerable to ridiculously simple malware attacks.

      And the Stockholm syndrome mental patient assholes that browbeat people who can't update because of Microsoft's criminal incompetence need to accept that slavish BOHICA on updates isn't a fucking fix when you have acomputer that was working one day, then the next day it was all fucked up.

      Security through malfunction.

      Okay, I feel better now, sorry for the rant.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    81. Re: Excluding the unfortunate exceptions by Ol+Olsoc · · Score: 1

      Yep. STILL dealing with this on my laptop. Of course, I do not have idiots opening spam links in emails either, and SMB is blocked even for LAN on my network

      I just had my ass handed to me by a PC expert who insisted that SMB was safe and I was full of shit for calling it an insecure security attack surface. Went absolutely nuts on me.

      While he was of course wrong, I think it illustrates why this sort of thing is continually happening to Windows. Deny, insult, and make certain to blame the victims. We've seen it over the years, and it shows no sign of abatement.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    82. Re:Excluding the unfortunate exceptions by Ol+Olsoc · · Score: 1

      > And if they figure out how to do that, their updates will be seen as innocuous as Apple's

      "Innocuous", like downloading multiple GBs worth of update files over my slow DSL connection, only to tell me *after* the fact that my MacBook Pro is too old for Sierra. Gotcha.

      So tell us why Apple doesn't detect which hardware you are using? Calling bullshit.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    83. Re: Excluding the unfortunate exceptions by Marxist+Hacker+42 · · Score: 1

      He wanted to leave the 4xx ports open to the internet? I block them at Windows Firewall, or in Linux and Android, I refuse to even install SMB derived protocols (SFTP is good enough)

      --
      SJW: a person who perceives an injustice, and while correcting it, commits a greater injustice.
    84. Re: Excluding the unfortunate exceptions by radiumsoup · · Score: 2

      One word: VirtualBox

    85. Re:Excluding the unfortunate exceptions by Tough+Love · · Score: 1

      I just couldn't use the open source programs if I wanted to send my paper to a professor.

      Sounds like 100% bullshit to me. Ever heard of TeX?

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    86. Re:Excluding the unfortunate exceptions by Tough+Love · · Score: 1

      I have a number of professors I would love you to convince that I don't need to give them Microsoft documents.

      If your professor forces you to use Microsoft products then you went to the wrong school.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    87. Re: Excluding the unfortunate exceptions by pfg23 · · Score: 1

      Unless you're producing a virus, your program shouldn't break with Update turned on.

    88. Re:Excluding the unfortunate exceptions by Agent0013 · · Score: 1

      I would change that to say Windows should only be used for playing games. It is too much of a pain to use for work related stuff. And if the games ran the same on another OS, I wouldn't be using Windows still.

      --

      -- ssoorrrryy,, dduupplleexx sswwiittcchh oonn.. -Quote found on actual fortune cookie.
    89. Re:Excluding the unfortunate exceptions by Agent0013 · · Score: 1

      Microsoft Office regularly fail to open its own documents. I have had to use Open Office to open a document and save it again just so Microsoft Office would be able to open it again. No version changes or anything either. Office saved the document but could not open it again.

      --

      -- ssoorrrryy,, dduupplleexx sswwiittcchh oonn.. -Quote found on actual fortune cookie.
    90. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      No you don't, but thanks for playing.

    91. Re:Excluding the unfortunate exceptions by unicornzvi · · Score: 1

      It's not really LO's fault, but you can't run a mixed LO & M$ shop if you care about your documents looking the same all over - the M$ formats are just too arcane and goofy for that to ever work 100%.

      If you can go all LO, you're set, but if you have to interact with other companies that want M$ documents, you're hosed.

      While this is true, you also can't run a pure M$ shop if you want your documents to look the same all over. Even if you have all your machines running the same version of office you're going to get occasional differences, if try running different versions - disappearing graphs, margins jumping around header and footer font change at random, etc, In other words libre office does at least as good a job as M$.

    92. Re:Excluding the unfortunate exceptions by Cederic · · Score: 1

      Yeah, my Windows 8.1 machine had Windows Update disabled in June 2015.

      Comically I can't re-enable it. Just hangs there now, waiting for updates, hammering a CPU core.

    93. Re:Excluding the unfortunate exceptions by tendrousbeastie · · Score: 1

      There's an outrageous amount of exaggeration going on in this thread. I have Windows 10 installed on a few machines at home, and the update process is almost invisible. There is no trouble or hassle involved in it at all.

      Basically, once a month the computer asks to restart. That's all there is. I can choose to do it manually, or it claims it will do it automatically at a quiet time. There is nothing else that I have ever noticed, no intrusion, no taking over the computer, nothing. Just a restart request once a month. I have one gaming desktop with some good specs, I have an old laptop with some fairly low specs, and a couple in between, and this holds true for all of them.

      I agree it would be nice, in an abstract sort of way, to have the option of whether to install non-security feature updates. But honestly, in a practical rather than abstract way, it has never bothered me in the slightest. The only time I have ever noticed any changes was the recent 'creators' update, when a few basic options and menus got a bit easier to use (e.g. connecting to a VPN now requires few clicks).

      All the hysteria going on here on this thread does not correspond in the slightest with my experiences - talking about it being a 'nightmare' and adding the 'suffering in the world' suggests either people haven't actual any experience of it, or they have a system so unusual that it can't possibly be used as being representative of anything.

    94. Re: Excluding the unfortunate exceptions by tendrousbeastie · · Score: 1

      If been thinking this while reading this whole page. What sort of software are people running or writing that is being broken so easily by a Windows Update process? And why are they purchasing or writing better software that isn't so fragile? Repeatedly it seems, since many people are claiming this is a constant problem for them.

    95. Re:Excluding the unfortunate exceptions by hierofalcon · · Score: 1

      TeX and pals. For when you really care about how your document looks - and you don't have too many embeded pictures - cause they are still a pain in TeX. I keep hoping, and have some basic ways to do particular things - I want a picture on the left, right, or full column - I do these things. But getting the text to actually freely flow around it without a lot of effort is still tough.

    96. Re: Excluding the unfortunate exceptions by Ol+Olsoc · · Score: 1

      He wanted to leave the 4xx ports open to the internet? I block them at Windows Firewall, or in Linux and Android, I refuse to even install SMB derived protocols (SFTP is good enough)

      He's an idiot. "SMB is a cornerstone of industry and is constantly updated, and is not a security risk".

      Except when it is, of course. Which is most of the time.

      He really hated my citations. Whatever, he's an example of why this stuff happens. A supposed expert who makes things worse.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    97. Re:Excluding the unfortunate exceptions by david_thornley · · Score: 1

      Sure I've heard of TeX. Everybody in the mathematics and computer science departments has. My default format for writing stuff was LaTeX. Get into the less technical departments, and people haven't heard about it, and don't know what to do with it. TeX is great if your professor wants a hard copy or a PDF. It isn't if your professor wants a Word file.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    98. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Unless you have a production environment with a software product that breaks with Windows update turned on.

      If this is the situation, you have a poorly designed piece of software, and should really invest in replacing it.

      Place the blame where it belongs.

    99. Re:Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 1

      It was huge organisations that are widely reported as being hit. It's more obvious when a big organisation takes a hit. But small organisations have been hit as well, and in any case the advice about whether or not to install updates is being repeated all over the place without reference to organisation size.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    100. Re:Excluding the unfortunate exceptions by Anonymous+Brave+Guy · · Score: 1

      The only things I have seen failing were custom software jobs

      Then you have been very lucky. Unfortunately, not everyone is. I've had to reinstall entire machines because of things as stupid as bad updates to malware signatures for the security software that wound up quarantining/removing critical files so the system would no longer boot, for example.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    101. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      The problem is that technical users, like those found on Slashdot, tell home users that they should turn this stuff off because it causes all these problems, when it really doesn't when you're running a system with known hardware and under typical operating conditions.

      What I tell home users if they ask me (or will call me for help later)
      is:
      - do not touch Outlook choose your own email client or use web email
      - do not use IE/Edge as default browser
          I am installing them Firefox with couple extensions. flash blocker is one of mandatory.
      - I make recovery cd and train them to keep copy of pictures and documents on external disk.
      In case of problem insert recovery cd and restart computer.

      my mother has laptop with Win8 home. she has updates blocked, couple programs blocking Win10 upgrade and disabled updates. no anti virus. firewall enabled.
      Works as charm.

    102. Re:Excluding the unfortunate exceptions by syntotic · · Score: 0

      No, no, the REAL problem is you are assuming complete INDIFFERENCE from the company for customers, that they are not personally biased in any way. Any update can aseptically change YOUR ways to do things, exactly THE way that gave you the advantage, and keep the fact hidden. This already happened several times with Windows, they ate companies and developers by including software or changing ways without acknowledging it was giving them an advantage over other users, or worse, a market. See how badly browsing ended up integrated in the OS? I was totally, completely, **ruined** by Outlook no longer being a standard include in OS distributions. Up to date I do not even consider it, now you have to RENT it not even just buy it! And funny enough making your own email client is real easy, just need the time. I suspect that decision has nothing to do with marketing but with keeping some people out of it. SImilarly with games, several games I cherished suddenly became unplayable. NOW I can think of a few things that if they change... and they can change and be deprecated at any moment in an update! I also stopped listening experimentally to music before amazon prime... trashed my own tree list control... 3D library control (border options)... see what I mean? I am even switching to android because of so many CHANGES that keep ruining my ways! Like laptop keyboards going open... laptops no longer having SD cards... SEE WHAT I MEAN? TO make matters worse, now you cannot even get a good technical explanation of what is the problem and how it is being handled so that you can decide to take it or get your own solution if possible... FOR INSTANCE. It is not that easy to just admit a new rug while you cannot leave the rOOm.

    103. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      What lack of document compatibility? This isn't 1997. I don't even have MS Office on my Mac, and I have zero problems reading Office docs or trading PDFs. VM windows for when you actually need it, and don't let it see a network connection at all. Problem solved with zero downtime.

    104. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      You can always just import the pdf output into word as full page pictures.

    105. Re:Excluding the unfortunate exceptions by Slayer · · Score: 1

      Small companies with few installations were only affected, if they opened and executed the malicious email (let's for a moment ignore imbeciles with XP servers and port 139/445 open to the internet, these are beyond redemption anyway). The exploit kit packaged with this piece of malware affected large companies mostly and most strongly, because one single mistake (opening email by any staff member) could corrupt so many computers at once.

      As far as small outfits are concerned, this attack was no different from previous malware laden email mass attacks and could have struck any OS or version thereof.

    106. Re:Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      What's the point of this comment?

    107. Re: Excluding the unfortunate exceptions by Anonymous Coward · · Score: 0

      Not every non-techie hates Linux. A year or so ago my mum was complaining about Linux which she had used for a few years. She's getting on in years and occasionally forgets how to do things. So my sister bought her a Windows laptop. A week later she called me and said "don't take away my Linux". Eventually Windows ground to a halt like it usually does and I offered to reimage it for her but she said "don't bother I hardly used it anyway".
      She now evangelizes Linux to her friends. She's 80 I think you can guess how tek savvy she is.

    108. Re: Excluding the unfortunate exceptions by Dudds · · Score: 1

      I worked as a desktop support consultant for several years supporting organizations like the ones you're describing: 20, 50, 100 staff and no dedicated IT. These places were a nightmare of "we had a problem and worked around it" solutions that took caused hours long appointments for just simple "the printer doesn't show up on one computer".

      A lot of these places I had remote contracts with that I would go in and do maintenance on their "servers" (somebody's machine under the desk, usually the office secretary or boss) that staved off a lot of problems, but the point still stands: these places were in no way stable on their own.

    109. Re:Excluding the unfortunate exceptions by LienRag · · Score: 1

      This is 95% of MS home users. These people should all have Windows Update on at all times and what's more, they could care less about the crap that Microsoft packages in along the way.

      Or they should not have Windows at all...

    110. Re:Excluding the unfortunate exceptions by Tough+Love · · Score: 1

      TeX is great if your professor wants a hard copy or a PDF. It isn't if your professor wants a Word file.

      If your professor wants a Word file then your professor is a drivelling idiot and/or you don't have much taste in institutions.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
  2. Generally Sound Advice by maz2331 · · Score: 2

    This is generally sound advice, although some IT shops prefer to manage the process to ensure that either (a) a particular update doesn't break some proprietary code, or (b) because of regulatory reasons particular machines may not be permitted to have the software changed without some sort of documentation being generated.

    1. Re:Generally Sound Advice by dc29A · · Score: 5, Insightful

      I would do that if (1) MS didn't cram W10 down my throat; (2) every major update doesn't reset browser preferences; (3) stop updating and breaking hardware drivers; and (4) I could disable telemetry. My Macbook and Ubuntu machines are auto-update enabled. Not my Windows gaming box. No thanks.

    2. Re:Generally Sound Advice by Kili · · Score: 1

      This!

    3. Re:Generally Sound Advice by TWX · · Score: 2

      I've worked in those kinds of environments, where we had propretary applications that were not compatible with the latest stuff. This is especially aggravating when you've got three web-delivered systems, all of which have mutually exclusive requirements. At one time users had to have Chrome, Firefox, and IE, and we had to block updates to IE so that the legacy system would work.

      It's extremely labor-intensive and requires excellent recordkeeping if one wants to do updates in this kind of environment, which means that it becomes expensive. It's usually cheaper in the short-term to just turn off updates, and it's often very difficult to convince a nontechnical upper-level director of the need to spend the money before the problem hits.

      --
      Do not look into laser with remaining eye.
    4. Re:Generally Sound Advice by Anonymous Coward · · Score: 5, Insightful

      The blame for people not updating/patching computers lies squarely on Microsoft.

      Automatic updates, with no user action required, is a really great thing, but ONLY when the updates are strictly for important security patches, and NOT all sorts of other crap that randomly changes or breaks things.

      And then there's the whole "we're going to shove Windows 10 up your ass whether you want it or not" fiasco.

      Microsoft has fucked so many people, so many times, that users have become averse to automatic updates.

    5. Re:Generally Sound Advice by Entropius · · Score: 5, Interesting

      Yep. I had a laptop that came with Windows 8 on it.

      I booted it once into Windows to change UEFI settings and then put Lubuntu on it.

      Well, a friend had a Windows question for me when I was away at a conference. No problem! I booted my laptop into Win8, looked up how to do the thing, and told her. I went to bed.

      I woke up to find that my system had:

      1) autoupdated to Windows 10
      2) fucked the bootloader so I couldn't boot into Linux any more.

      This is on top of the fact that Windows updates take about a year to complete and reenable a bunch of crap that I keep disabling ("Windows Media x").

    6. Re:Generally Sound Advice by Anonymous Coward · · Score: 3, Interesting

      The blame for people not updating/patching computers lies squarely on Microsoft.

      Automatic updates, with no user action required, is a really great thing, but ONLY when the updates are strictly for important security patches, and NOT all sorts of other crap that randomly changes or breaks things.

      And then there's the whole "we're going to shove Windows 10 up your ass whether you want it or not" fiasco.

      Microsoft has fucked so many people, so many times, that users have become averse to automatic updates.

      Exactly correct. MS lost many people's trust with updating around the Win10 forced-upgrade fiasco. I've deleted wusa.exe from my win7 box and I've done the same for any number of family and friends on various win7/8.1 boxes. I just make sure backups are in place and re-image if infected.

      If these devices get pwned and cause damage blame MS for destroying trust in their update platform.

    7. Re: Generally Sound Advice by Anonymous Coward · · Score: 0

      Lubuntu works under UEFI with secure boot. No changes needed

    8. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      LOL. "Yeah, that guy, he hasn't robbed anyone for 6 months straight, he's turned honest as a bell guv'".

      Look, Microsoft are known scumbags. They've been scammers, cheaters and bullies for over 30 years. They couldn't change even if they wanted to, and nothing indicates they are even willing to try. You don't get to whitewash them just like that.

      If they were an ordinary person, they'd be in prison for life at this point.

    9. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Or if MS would warn/label "important" updates that are W10, Telemetry BS in disguise.

    10. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      but it's been more than 6 months since they've stopped

      Burglars usually don't come by the next night either.

    11. Re:Generally Sound Advice by phayes · · Score: 5, Insightful

      So how often should people re-evaluate when a company like Microsoft breaks their trust by forcing upgrades and other such nonsense? 6 months are sufficient according to you apparently.

      News flash: When a company breaks it's users trust, the time it takes can be measured in years and is often never. Yeah it'd be great for security if people were applying upgrades ASAP but MS's new policy of only making rollup updates forcing the inclusion of all previous updates can only backfire making people even less apt to apply them. Hey, they've already broken our trust once, they're likely to do it again.

      The problem is in large part MS's own creation.

      --
      Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue
    12. Re: Generally Sound Advice by Entropius · · Score: 2

      I had to turn off "Fast Boot" anyway, and wanted to preserve the ability to boot off of other things as well. Boot-sector shenanigans are pretty uncommon these days, so on balance I wanted it off.

    13. Re:Generally Sound Advice by Anonymous Coward · · Score: 3, Insightful

      Exactly. If Microsoft behaved decently and simply provided security patches that fix vulnerabilities ONLY, there would be no issue. However Microsoft does shit like changing user settings (making IE/Edge your default browser), breaking hardware drivers, installing spyware etc.

      In my particular case I run a pirated Windows 7 gaming machine, with the "Genuine Microsoft" Windows activation disabled via a pirate-written patch. Both were downloaded via a Piratebay torrent. It turns out every time I update this machine, the Windows activation gets re-installed and I get this "Your computer is not running Genuine Microsoft, certain features have been disabled, you have 30 days to register Windows blah blah" message. And I have to dig out the pirate patch again and re-do the activation all over again.

      So I stopped updating, and changed the Windows Update setting to "Never". This was back in 2014. My Windows has not been updated since then.

      So did I get hit by shitload of viruses and malware and Wannacry? Nope. Not been infected with anything, not one single issue that I'm aware of. I'm typing this on the same pirated Win7 machine, connected to the internet full-time 24/7, and it's running like a champ.

      This is possible because 1) I don't click on email links or open attachments. In fact I don't even bother reading any emails unless I know exactly who is sending it. Rest get mass-moved into Junk folder. And 2) I run Ublock Origin adblocker, so I don't even get to see most of the malicious web adverts. And if I do see a web advert, I'm smart enough to not click on them. And yes, I never click on or buy any shit advertised on interwebs sites and I'm not missing anything as far as I know. Anything I need, I just go straight to Amazon or ebay and buy it that way, not through any ads. And 3) my firewall blocks random people trying to port scan or connect to my machine.

    14. Re:Generally Sound Advice by Anonymous Coward · · Score: 2, Insightful

      This. I was fine to leave auto-update on for security fixes but then microsoft started cramming their telemetry and other crap into them - making them bundled so you couldn't get your security fix without letting microsoft scoop up every piece of info on your computer that it wanted.

    15. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Windows 7 and 8 also include essentially the same telemetry now.

      You don't get to blame it all on Microsoft.

      Pick one.

    16. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      The blame for people not updating/patching computers lies squarely on Microsoft.

      Oh please. People turned off automatic updates way before Windows 10 was even a thing.

    17. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      So how often should people re-evaluate when a company ... breaks their trust

      There is a grocery store in my area that used to have a policy that if an item rang up different from the shelf price, it was free. I had a jar of mushrooms that rang up $1.50 instead of $1.40. I didn't notice until the transaction was done, so I had to go to the service desk. The service desk lady sees me coming with the mushrooms, and without a word rings it up and gives me a dime. On my way out, I realized what they had done, so I go back. The service desk lady sees me coming with the mushrooms and my dime, and without a word rings it up and gives me another $1.40.

      This was 20 years ago. I still don't shop there unless I have to.

    18. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      It's cute that you think only Microsoft has telemetry. Just because you never agreed to it in a big dialog box doesn't mean you're not being tracked.

      "No reasonable person would believe [us]" ;)

    19. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Trust, once lost, is almost impossible to regain.

      It's why you don't break it.

    20. Re:Generally Sound Advice by Tailhook · · Score: 4, Insightful

      This is hard to argue with. I personally prepared for this by preventing the Win 10 upgrade (even using third party software to stop the constant, malware like badgering complete with deliberately misleading prompts) until I was good and ready to deal with it, then I did a full clean install and manually migrated stuff over because I knew there was no way my complex, roughly used installation could possibly upgrade well automatically. One simply cannot, however, expect a planet full of Windows users to take this conservative approach; even if they were inclined to, which they aren't; most of them simply aren't competent to deal with this stuff and would do more damage than what the upgrade inflicted.

      So they all got put through the upgrade ringer creating bad outcomes for millions and leading to widespread "anti-vaxxer" behavior. Since then the "anti-vaxxers" have had their behavior affirmed by disruptive updates doing unwelcome stuff. The glacial slowness of the Windows 10 update process alone is a huge failure in my mind; this has badly regressed from earlier releases; I have a laptop I boot maybe once a month and I've come to expect the Windows 10 updates to take a hour or more. Ridiculous.

      After putting the whole world through all this shit one simply can't point a finger at millions of beleaguered users and blame them for their negligence. I'm sure they'd be happy to have they're system automatically updated, as long as it wasn't the computing equivalent of getting a SOA style beat down every few months.

      --
      Maw! Fire up the karma burner!
    21. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      How do you know you aren't part of a botnet?

      The fact you live behind a firewall and never actually expose your computer to the net, and presumably update your browser, makes you way safer than the average laptop (which connects on wifi to other random machines all the time).

      Next, what are the *odds* someone acting like you gets caught into a botnet or ransomware. 1% over 2 years? 0.1%? I mean, your router ends up with an exploit, they tunnel through it and take over your computer. Your ad blocker screws up and lets an evil ad through. You download some open-source tool that was hijacked by malware writer and your system is infected.

      0.1% is enough to be a massively horrible problem.

      The fact you haven't been infected? That is very weak evidence that you have a 99.9% chance of not being infected following your advice.

    22. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Yeah, it's more like here's your update... with a side of extra advertisement and other crap... euh, no thanks.

    23. Re:Generally Sound Advice by Anonymous+Brave+Guy · · Score: 1

      Windows 7 and 8 also include essentially the same telemetry now.

      None of my systems do. Oh, wait, that's because with previous Windows versions I could just choose not to install that crap in the first place.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    24. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      I would do that if (1) MS didn't cram W10 down my throat;

      (1) It was ultra-scammy when they were doing that, but it's been more than 6 months since they've stopped, so it's time to throw out this reason.

      No, 6 months isn't nearly long enough to gift Microsoft with restored trust. 6 years and I'll maybe think about it.

    25. Re:Generally Sound Advice by bongey · · Score: 3, Informative

      You can trick windows from messing with it and bios that only look for a windows efi boot file. This will boot to grub and allow you to select windows if you want, and windows update doesn't mess with it.
      open cmd.exe as Administrator and lunch the command vmount s: /s
      go to s: and navigate the directories until you find where the grubx64.efi is located. Mine was under s:\EFI\debian\.
      go to s:\EFI\Microsoft\boot and create a backup of the bootmgfw.efi file and then overwrite it with the grubx64.efi.
      reboot. Now you should be able to reach the grub menu and boot to Linux but you'll be unable to boot to Windows. Boot to Linux then.

      On linux you
      open a shell and go to /boot/efi/EFI/Microsoft/Boot and restore the previously backed up bootmgfw.efi.
      run grub-install (it may require root privilege - sudo)
      run update-grub2 (it may require root privilege - sudo)

    26. Re:Generally Sound Advice by BronsCon · · Score: 1

      Indeed they did. That, coupled with the fact that they would then never go manually apply updates, and the ensuing malware shitstorm, is why we have forced updates in Win 10.

      Thanks, assholes. And I don't mean Microsoft.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    27. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Yes, yes we can. MS Windows is THE most popular home & business OS and therefore MS's customers are a wide spectrum. TO threat them with aggressive contempt is to move people away from MS.

    28. Re:Generally Sound Advice by Darinbob · · Score: 3, Insightful

      The problem with the sound advice is that Microsoft is actively undermining the update process by treating customers so badly. They don't test their updates well, they make them forced in later versions, they tie the updates to earlier updates, and worst of all their malware inspired forcing of Windows 10 on people has justifiably trained customers to distrust Microsoft.

      It's time consuming to check out each and every update to make sure it's safe. But I have to do that because I cannot trust microsoft not to play games with my systems.

      Applications too, I don't update iTunes because every time I do it screws up, changing the UI in drastic ways, and takes me a very long time to get it working properly again. But that's ok, I do not use the store in iTunes, it does not execute any strange attachments, and as a malware vector it's pretty low compared to the OS itself. If it played nice then I'd update it more regularly.

    29. Re:Generally Sound Advice by Darinbob · · Score: 1

      I don't on macbook. Too many updates require reboots and that's very disruptive if it happens outside of my control.

    30. Re:Generally Sound Advice by Darinbob · · Score: 1

      You do hear people defend Microsoft that way. As in "but that was in the past!" They forget that trust has to be earned.

    31. Re:Generally Sound Advice by Darinbob · · Score: 2

      It's been 6 months but have they done even one thing to earn back trust? They have not even apologized! This reason is still valid.

    32. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      I woke up to find that my system had[...] fucked the bootloader so I couldn't boot into Linux any more.

      It's easy enough to fix the bootloader with a live session. Here's how to do it if you're running Ubuntu..

    33. Re: Generally Sound Advice by Anonymous Coward · · Score: 0

      Oh, eat all the dicks. You know damn well people don't go out of their way to change OS settings. This is your fault. You did this. You. You need to turn off Windows Update. Just do it. Do it now.

    34. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Weird. I've had Ubuntu installed along with Windows, and it has survived three major upgrades (7, 8, 10) and several minor ones (like 8 til 8.1, insider builds on 10, etc).

    35. Re:Generally Sound Advice by h4ck7h3p14n37 · · Score: 1

      Why not just run Windows 8 inside a VM, or fire up an EC2 instance?

    36. Re:Generally Sound Advice by HiThere · · Score: 2

      Even then... the thing that drove me from Apple to Linux was a security update. It worked without problem...but they used it to smuggle a license change in that I found unacceptable. So that machine was immediately disconnected from the internet, and everything that could touch the internet was migrated to Linux.

      I'll grant that what Microsoft is doing is arguably worse. I don't know, I left MS for Apple when THEY forced a license change on me that I found unacceptable. I think these companies rely on people either not reading or not believing the EULAs.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    37. Re:Generally Sound Advice by HiThere · · Score: 1

      It's not really impossible to regain, but it takes a lot more effort the second time, and MS hasn't yet started. PR doesn't count in my book.

      OTOH, that's actually about trust that is lost due to inattentiveness. When trust is lost because of what appears to be malice, it actually *may* be impossible to regain...but if it is then it's a lot harder than it would be from mere inattentiveness.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    38. Re:Generally Sound Advice by DRJlaw · · Score: 1

      None of my systems do. Oh, wait, that's because with previous Windows versions I could just choose not to install that crap in the first place.

      So you haven't installed any security updates since they switched to monthly rollups where you cannot pick-and-choose?

      Shame on you...

    39. Re:Generally Sound Advice by Gr8Apes · · Score: 1

      Thanks, assholes. And I don't mean Microsoft.

      You can still "thank" MS. They are the reason people turned off auto-update, all the way back when XP SP2 or whatever it was first came out. The standard practice for a MS OS install: Create install image, disable and remove wusa, install selected updates, use that image to install systems and manage "updates" as necessary for fixes. MS has this nasty habit of including all sorts of crap in their updates which coupled with their terrible non-modular architecture regularly resulted in overwriting non-MS drivers and support files and generally shitting on systems that might dare to run something non-MS. Managing that kind of infrastructure for more than 2 or 3 machine configurations requires a decent team, and most that have teams are not up to the job.

      --
      The cesspool just got a check and balance.
    40. Re:Generally Sound Advice by Gr8Apes · · Score: 2

      I'm curious as to the license change.

      --
      The cesspool just got a check and balance.
    41. Re:Generally Sound Advice by Anonymous+Brave+Guy · · Score: 1

      On unmanaged systems, we install the security-only rollups, not the all-in ones that you get through Windows Update. As far as we're aware, the security-only bundles don't include the telemetry malware. If you know better, please cite, because finding detailed information about exactly what each of the new monthlies includes is often a pain.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    42. Re: Generally Sound Advice by BronsCon · · Score: 1

      Businesses with have IT staff who manage updates and ensure that security updates are installed regularly are not the problem. Though, with more than say 5 (the minimum enterprise license) workstations should have had their own WSUS servers in the first place.

      Home user's were not doing all of that. They would just (stupidly) turn off WU and never install a single update. Those idiots are why we now cannot turn off automatic updates in Win 10.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    43. Re:Generally Sound Advice by Darinbob · · Score: 1

      Ha I'm on Windows 8.1 so it doesn't do the forced updates. But does require the reboot for even the most innocuous changes. So I delay the reboot because I know it may take half an hour. Then when I'm done I shut down. However this doesn't count as a reboot! Because Windows essentially hibernates, those updates don't end up getting applied and I am not warned later on that I hadn't actually rebooted. So three or four weeks later if I reboot for some other update, then the Windows update finally takes effect and the quick reboot is suddenly a major effort.

    44. Re:Generally Sound Advice by LVSlushdat · · Score: 1

      I'm betting I'm like most, such that once a company has lost my trust, it has lost it for good... I used/supported Windows for 20 years as a sysadmin. I retired in 2010, and decided I was tired of MS's insane licensing schemes, and since I'd been using and supporting Linux for about 1/2 of that 20 years, I made the decision to "yank the bandage off" and move 100% to Linux. Been MS-free now for nearly 7 years and couldn't be happier.. As for trust in MS.... hehe I trust them as far as I can throw them, and thats not ever gonna change...

      --
      THANK YOU, Edward Snowden!! Americans owe you a debt of gratitude (whether they know it or not..)
    45. Re:Generally Sound Advice by Anonymous Coward · · Score: 0

      Man, do I feel your pain. I once loved the idea of web interfaces but now I'd prefer dedicated installed applications once again. I wish applications (not 'apps') installed and maintained their own dependencies and even better than that be portable. Why does everything need to touch the registry, C:\Program Files, C:\Program Files (x86) and even worse, C:\Windows? Doing so in most cases is a design choice not requirement.

      In a way, I don't completely blame the browser makers. They do have to make decisions based on security. However, they KNOW websites are slow to 'conform' and they just throw out the baby with the bath water. At least IE has 'compatibility mode' which does help... sometimes. Chrome on the other hand, man, I hate that browser. Users love it though and will want us to make Chrome work because they prefer it. Well, does it work in IE? Does it work in FireFox? Then use that instead. Response: Don't wanna. More interest is had in using a specific piece of software vs what will get the job done.

      Don't even get me started about people that use Excel as a production database or worse a graphic design layout program. Look, I get that you don't know anything beyond Excel. I can't change Excel such that it becomes the best tool for the job at hand. I can teach you other programs that are the best tools for the job. You refused the offer. Stop bitching.

      As far as non technical decision making, it is just about impossible to convince someone of something they have a vested interest in not understanding. If they 'got it', they can't blame it on you anymore. They get to avoid responsibilities and work because being computer illiterate is still acceptable - it's a badge to be worn proudly. When I meet new staff and the first thing they boldly and unabashedly say is that they 'don't get this computer crap', I know right away to open a brand new CYA file for interactions with this person.

    46. Re: Generally Sound Advice by Anonymous Coward · · Score: 0

      No shit. They stopped forcing it when they got called out for making the X close window button count as clicking Yes. Also, it's not free for everyone anymore.

    47. Re: Generally Sound Advice by Anonymous Coward · · Score: 0

      You could have stumbled on to an inside scam. The employees were ringing up a 10 cent difference for everything and pocketing the dough. Their leader was the lizard brain in CustSrv. That's why she had the dime. How many r00bs did they sucker and get away with it, though?

    48. Re:Generally Sound Advice by cm5oom · · Score: 1

      So you're bitching about windows update not working with your pirated copy of windows? Holy fuck are you retarded.

    49. Re: Generally Sound Advice by Gr8Apes · · Score: 1

      WSUS servers weren't even available at one time. :) As for 5 licenses, no, most won't have a running WSUS. Maybe at 50 or 100, when they decide they actually need an IT service or person and that person goes "Hey, for a mere 5K (license and hardware) you can manage all this with minimal fuss" and then still have issues as stuff gets pushed. But, as for Win10, that doesn't make any difference either because everything will get pushed within 9 or 12 months, whatever the latest arbitrary deadline is.

      Home user's were not doing all of that. They would just (stupidly) turn off WU and never install a single update. Those idiots are why we now cannot turn off automatic updates in Win 10.

      Home users had just as many reasons to turn off WU as businesses did. In fact, they more likely would be affected by an update screwing up their system and would be less likely to be able to fix it. That they did not know enough to intelligently apply security fixes over time isn't really their fault. The fault still lies with MS for not breaking up "updates" into mandatory "security patches" and optional everything else and then not abusing that system with crap like the "Upgrade to Windows 10" program. MS is still the root of the problem, and always will be. Facts are facts.

      For comparison, look at Apple's update program which also has a mandatory update process. It's only been used once or twice AFAIK to push actual fixes down. For the most part, their updates don't screw up their systems, although there's been upgrades that have caused some issues. Then again, they upgrade once a year, sometimes more, across multiple devices and OSes. And yet they have yet to have a single screw up as big as any of the reported ones by MS just in the last year. Linux I've always carefully managed, mainly because I like to know what my server configurations are.

      --
      The cesspool just got a check and balance.
    50. Re:Generally Sound Advice by HiThere · · Score: 1

      I don't remember the exact language, but it essentially said "We have the right to add, modify, copy, or delete any file on your computer". MS used that first, and Apple followed a few years later.

      P.S.: When I showed the license to the company lawyer his reaction was "I'd like to see them try to enforce that.". He didn't seem to realize that this was merely to cover them for actions that they took technically, and which required no legal enforcement.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    51. Re:Generally Sound Advice by Agent0013 · · Score: 1

      Most of the computers that were infected with the WannaCry crap were in China and Russia. Where most of the Windows installs are pirated. Pretending otherwise isn't going to solve anything. Who is the retarded one again?

      --

      -- ssoorrrryy,, dduupplleexx sswwiittcchh oonn.. -Quote found on actual fortune cookie.
    52. Re: Generally Sound Advice by BronsCon · · Score: 1

      WSUS servers weren't even available at one time. :)

      When were WSUS servers not available for Windows 10? It's been a standard offering wince Win2k3.

      As for 5 licenses, no, most won't have a running WSUS.

      Won't and can't are two different things. I was stating the 5 license minimum for Enterprise versions of Windows.

      Maybe at 50 or 100, when they decide they actually need an IT service or person and that person goes "Hey, for a mere 5K (license and hardware) you can manage all this with minimal fuss" and then still have issues as stuff gets pushed.

      No competent IT person would quote $5k, as you only the Windows Server 2012 or newer system that is already running your domain controller and AD; tick the box to enable WSUS and add it to your policies; done. As an added bonus, a competent IT person would thoroughly test each update before adding it to WSUS and avoid the "issues" you allude to. It shouldn't take more than a day for a mid-level ($75-100/hr) tech to get working; in fact, it should only take an hour or two. That's $75-200 for a competent tech, up to $800 if he's really really slow.

      As for the ongoing cost of having someone review updates, if your team is big enough that bad or poorly-timed updates are actually incurring a measurable cost in lost productivity, paying someone to properly test updates and only apply those which don't break anything will surely be cheaper than the lost productivity. The peace of mind that comes with knowing what's running on your systems, on the other hand, is priceless.

      This isn't even what I do for a living, but I could set it up with one hand tied behind my back.

      But, as for Win10, that doesn't make any difference either because everything will get pushed within 9 or 12 months, whatever the latest arbitrary deadline is.

      Not so with WSUS. No version of Windows that is configured to use a WSUS server looks anywhere other than the configured WSUS server for updates.

      Home users had just as many reasons to turn off WU as businesses did.

      And anyone who turns it off also has a responsibility to periodically install that shit themselves. Guess who didn't live up to that responsibility and lost the ability to decide for themselves!

      In fact, they more likely would be affected by an update screwing up their system and would be less likely to be able to fix it.

      Then they should have learned what they were doing before they did it.

      That they did not know enough to intelligently apply security fixes over time isn't really their fault.

      Will you say the same of Mac users who disable automatic updates because Apple has released a few bad video drivers (more than just that, but it's what I recall off the top of my head) for older Macs? What of Linux and BSD users?

      The fault still lies with MS for not breaking up "updates" into mandatory "security patches" and optional everything else and then not abusing that system with crap like the "Upgrade to Windows 10" program.

      So it's Microsoft's fault people disabled Windows Update during the time before Windows 10, back when Microsoft did allow you to install updates by category? Going back at least as far as XP SP2, I know you could opt to have just "Critical Updates" installed, and those were just security patches.

      It wasn't until Windows 10 that they began abusing that, so you can't really cite that abuse as the reason Windows XP users disabled Windows Update on day one and never installed a single update.

      MS is still the root of the problem, and always will be.

      Interesting opinion; I prefer to believe that ignorant users are the problem, as they are on any system.

      Facts are fac

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    53. Re:Generally Sound Advice by Cederic · · Score: 1

      Sorry but I fear you're missing his point: When did leaving a system running overnight justifiably ever need you to fix the bootloader the next morning?

    54. Re:Generally Sound Advice by Gr8Apes · · Score: 1

      I fully expect that. It's why we keep offline backups. So far, no problem, even on a hack.

      --
      The cesspool just got a check and balance.
    55. Re: Generally Sound Advice by Gr8Apes · · Score: 1

      WSUS servers weren't even available at one time. :)

      When were WSUS servers not available for Windows 10? It's been a standard offering wince Win2k3.

      I wasn't aware we were only discussing Win10, or even just post 2k3. Since most people in business are running flavors of XP through W7 that I've been aware of (yes, at least 3 Fortune 100 companies I personally know of were running XP as recently as 2 years ago) and only recently moved to W7. At least 2 have had issues with upgrades, in one case taking down 30% of the company's computers for about 2 days. This is with dedicated IT support teams in place, and they still can't get it right. At least they only rolled it out to portions of the company at a time.

      As for 5 licenses, no, most won't have a running WSUS.

      No competent IT person would quote $5k, as you only the Windows Server 2012 or newer system that is already running your domain controller and AD; tick the box to enable WSUS and add it to your policies; done. As an added bonus, a competent IT person would thoroughly test each update before adding it to WSUS and avoid the "issues" you allude to. It shouldn't take more than a day for a mid-level ($75-100/hr) tech to get working; in fact, it should only take an hour or two. That's $75-200 for a competent tech, up to $800 if he's really really slow.

      You're living in MS fairytale land. I can assure you that small businesses don't as a rule run WSUS, nor have IT folks that deal with it. They generally contract with a low-bid support firm that sends some random clown over when called to "support" them. The going rate is under $60/hr for what the SMB considers no more than helpdesk support. And they complain about it. These are under 100 people shops. They they don't run their own internal mail, they don't even have servers actually, and they're running off the shelf systems they buy from Dell. So the $5K quote is actually realistic for them to upgrade to Windows Enterprise and get a domain server.

      This isn't even what I do for a living, but I could set it up with one hand tied behind my back.

      As could I, but I won't do it for $20 or $30 / hr.

      But, as for Win10, that doesn't make any difference either because everything will get pushed within 9 or 12 months, whatever the latest arbitrary deadline is.

      Not so with WSUS. No version of Windows that is configured to use a WSUS server looks anywhere other than the configured WSUS server for updates.

      Right, and that WSUS server will push those updates after 'x' time, as determined by MS, unless you take steps to isolate your WSUS server and do some other non-standard things to it. There's a reason W10 uptake by business has been, well, let's say it's been "slow". There's also a reason IBM chose to go with Apple instead and invest the resources to generate a new business service model for Apple.

      Will you say the same of Mac users who disable automatic updates because Apple has released a few bad video drivers (more than just that, but it's what I recall off the top of my head) for older Macs? What of Linux and BSD users?

      You're shifting the blame conversation. :) As for bad video drivers, I don't recall those and was never subject to them. I was subject to the upgrade issues with 10.11 and 10.12, but that's a different issue and can be fixed. However, Apple doesn't automatically update (or doesn't on my systems, but will nag. I do apply updates on my schedule.

      So it's Microsoft's fault people disabled Windows Update during the time before Windows 10, back when Microsoft did allow you to install updates by category? Going back at least as far as XP SP2, I know you could opt to have just "Critical Updates" installed, and those were just security patches.

      "Critical

      --
      The cesspool just got a check and balance.
    56. Re: Generally Sound Advice by BronsCon · · Score: 1

      I wasn't aware we were only discussing Win10, or even just post 2k3.

      Prior to Windows 10 you could disable automatic updates entirely and manually select which updates to install. Absent WSUS, which we were only without for a year and a half, the procedure followed by competent IT staff was to disable automatic updates in the standard images applied to end user workstations and manually apply those updates (to the images, not to the workstations individually) after testing. Roll out the new images over the weekend and, since user profiles and documents are stored on the network (remember, competent IT staff), everyone comes in Monday to find working and updates computers.

      Since most people in business are running flavors of XP through W7 that I've been aware of (yes, at least 3 Fortune 100 companies I personally know of were running XP as recently as 2 years ago) and only recently moved to W7.

      So you're saying most companies don't upgrade to the newest OS right away? They typically wait two years or longer (that's been my experience, at least; and you're demonstrating that they often wait much longer) as the software they run on a daily basis doesn't support the new OS right away? So, you mean, by the time most businesses would have upgraded to XP, WSUS was out and this whole back-and-forth is largely pointless?

      Got it.

      At least 2 have had issues with upgrades, in one case taking down 30% of the company's computers for about 2 days. This is with dedicated IT support teams in place, and they still can't get it right. At least they only rolled it out to portions of the company at a time.

      I stipulated competent IT teams, not just dedicated.

      You're living in MS fairytale land. I can assure you that small businesses don't as a rule run WSUS, nor have IT folks that deal with it.

      Does that mean they can't? I mean, if all of this is really a concern and there is a solution available, why can't they utilize that solution?

      They generally contract with a low-bid support firm that sends some random clown over when called to "support" them. The going rate is under $60/hr for what the SMB considers no more than helpdesk support. And they complain about it.

      Sounds like they need more than they're paying for. Poor management exhibiting incompetent decision making that ends up costing the company more than it saves in terms of downtime incurred by not having someone on staff. That's not Microsoft's fault; I've seen it happen in all Mac offices as well.

      These are under 100 people shops.

      Then they should have an AD to manage logins, at the very least. It costs less to pay someone to click a few buttons to add and remove accounts on a central server than it costs to have them walk across the building to do the same thing. Bonus if they install even a low-end SAN solution and store user profiles and documents on it; then they don't even have to reimage machines when someone leaves the company. These are things that should be considered once a company reaches about 20-25 workstation users and should certainly be in place by 50.

      If they had that (and you can pay the $60/hr places to install and maintain it, by the way), they'd be set. Again, outsourcing IT doesn't eliminate the incompetence, it simply shifts it from the IT department to the manager or exec who decided to outsource to the low bidder and ignore IT infrastructure as a whole. An, again, this happens in all Mac shops as well, so no, it's not Microsoft's fault.

      If anything, Microsoft makes it easier to get it right by offering the tools to do so as part of their server OS and actively trying to educate IT workers about those tools. Apple, on the other hand, killed off the server version of OS X and never bothered migrating the management tools; those are just gone

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    57. Re: Generally Sound Advice by Gr8Apes · · Score: 1

      Prior to Windows 10 you could disable automatic updates entirely

      That's kind of the point regarding the Win10 you must update statement that started these discussions.

      Absent WSUS, which we were only without for a year and a half,

      Really? (W)SUS didn't come out until 2005. Last I recall, XP was released in 2001.

      So, you mean, by the time most businesses would have upgraded to XP, WSUS was out and this whole back-and-forth is largely pointless?

      Nice rewording there. I said companies remained on XP. Nothing about XP's own take up could be inferred from that statement.

      I stipulated competent IT teams, not just dedicated.

      So MS Services isn't competent? I'll be sure to note that next time.

      You're living in MS fairytale land. I can assure you that small businesses don't as a rule run WSUS, nor have IT folks that deal with it.

      Does that mean they can't? I mean, if all of this is really a concern and there is a solution available, why can't they utilize that solution?

      Sure, they can, if they'd prefer to run in the red.

      Then they should have an AD to manage logins, at the very least. It costs less to pay someone to click a few buttons to add and remove accounts on a central server than it costs to have them walk across the building to do the same thing. Bonus if they install even a low-end SAN solution and store user profiles and documents on it; then they don't even have to reimage machines when someone leaves the company. These are things that should be considered once a company reaches about 20-25 workstation users and should certainly be in place by 50.

      It's a solid argument. Many won't pay for it. I've seen 5 year old Dell laptops with busted keys and cracked screens in daily use. If they won't spend $300 for a new base laptop, you really think you're going to get them to pay $50+/hr for IT support?

      Apple, on the other hand, killed off the server version of OS X and never bothered migrating the management tools; those are just gone now. If I recall correctly, Microsoft has actually stepped up to fill that gap on the Mac platform.

      It's IBM.

      Most companies don't run local mail anymore; it's too much of a hassle to deal with RBL bullshit and spam. What's mail got to do with this, anyway?

      Essentially, pointing out that while they use computers, they aren't IT shops in any sense of the word.

      You can't, on one hand, say downtime costs tens of thousands of dollars (30% of a Fortune 100's workstation users being unable to work for 2 days), then turn around and say $5000 is too much to pay to fix it. If something is going to cost me $10k to ignore or $5k to fix, the reality is that it's actually going to save me $5k to fix it.

      Who said anything like that? Honestly, those kind of remarks are bordering on Trumpian claims. A small shop that uses computers won't be idle for days if their systems are down. It'll be inconvenient, maybe, but not serious. A Fortune 100 has a dedicated IT staff. This portion of the discussion doesn't apply to them.

      --
      The cesspool just got a check and balance.
    58. Re: Generally Sound Advice by BronsCon · · Score: 1

      Really? (W)SUS didn't come out until 2005. Last I recall, XP was released in 2001.

      My mistake, I did misread. It came out in March 2005, which I read as March 2003. Either way, the same system of test, add-to-image, deploy-image that was used prior to XP should have been maintained until WSUS, and should have been kept in instances where WSUS wasn't used. As far as I know, it was kept anywhere that had competent IT.

      I said companies remained on XP. Nothing about XP's own take up could be inferred from that statement.

      You are not the only source for that information; I was in the industry back then and I remember how slow the move from NT4 and 2K was. It was a hair faster than the move from 98, which companies which didn't need a true multi-user environment were just getting around to installing over 95 around the time XP came out.

      At any rate, good to see you finally cite a source.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    59. Re: Generally Sound Advice by Gr8Apes · · Score: 1

      You are not the only source for that information; I was in the industry back then and I remember how slow the move from NT4 and 2K was. It was a hair faster than the move from 98, which companies which didn't need a true multi-user environment were just getting around to installing over 95 around the time XP came out.

      At any rate, good to see you finally cite a source.

      Honestly, if sources you want, I could have provided more, including for the (W)SUS stuff. I just figured that was so minor I didn't provide them. They're 1 google away, after all. :)

      As for the image/deploy process you're talking about, that's great, if you run a 1 or 2 machine type shop. Try running with 100s of different sets of hardware and about half as many configurations as you have people. I wasn't in a regular shop with clone copies for everyone. Each one of our special snowflakes had their own needs, and were spending upwards of 20K per machine to get those needs fulfilled. IT's support requirements where more like "here's our configuration, you support it". Were I in a standard shop, sure, that would be awesome.

      Finally, for XP uptake, it was far far faster than NT4 or 2K where I was. In fact, 2K wasn't even a blip on our radar when XP came out, which was a rather big blob. TBH, XP was just 2K with the fisher-price GUI. I was never really a fan of anything related to it other than the default background, which was nice green rolling hills. Win95 had tons of issues in our environment, so many never ran it, staying on WFW 3.11 instead. And post 95 it was pretty much a straight migration to NT as new machines came in for those on windows, 98/ME never had a chance.

      --
      The cesspool just got a check and balance.
    60. Re: Generally Sound Advice by BronsCon · · Score: 1

      First they won't even replace a broken $300 laptop, so spending $5k to set up WSUS is a no-go... now they're using $20k workstations and $5k wouldn't even be a drop in the bucket...

      Can you pick one side of your mouth to talk out of, please?

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    61. Re: Generally Sound Advice by Gr8Apes · · Score: 1

      Different shops, different needs. Shop A has special snowflakes with disparate machines. This was far prior to the age of WSUS. Was talking specifically about the pre WSUS statement regarding images and best practices. Doesn't always work.

      The small money bound shops, call them B, most wouldn't spend a dime on IT unless they absolutely had to.

      I have dealt with both extremes, and the "happy" middle.

      --
      The cesspool just got a check and balance.
  3. Maybe by SurenEnfiajyan · · Score: 0

    Maybe. Except when it causes BSOD (google for Amazon Kindle).

  4. Microsoft's fault by sconeu · · Score: 5, Insightful

    If they hadn't done shit such as the forced Win10 update, or forced GWA, or done a lot of other crap that broke peoples systems (in the name of marketing), then maybe people wouldn't have said, "Turn it off".

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    1. Re:Microsoft's fault by TWX · · Score: 5, Informative

      Pretty much. I had to take some fairly convoluted measures to keep my wife's laptop on 8.1 or some of my various other systems on 7 without entirely disabling updates. It's not that I liked 8.1, but I did not like what I read about 10.

      The easiest way to avoid having 10 forced on me would have been to just disable updates. Instead I had to read up on every individual update that would push 10, and ultimately resorted to third-party software to block or remove those specific nuggets from Microsoft so that my platforms would be left in the state I wanted them in.

      --
      Do not look into laser with remaining eye.
    2. Re: Microsoft's fault by macsforme · · Score: 5, Insightful

      Agreed. A level of trust is required when you allow vendors to push automated updates to your system, and unfortunately there have been breaches of this trust when vendors saw this as an opportunity for more than enhancing user security.

    3. Re:Microsoft's fault by Anonymous Coward · · Score: 1

      Anniversary Update that broke a lot of people's computers.
      Rebooting my computer when I don't want it rebooted.

    4. Re:Microsoft's fault by Anonymous Coward · · Score: 1

      Exactly. As I was reading the top post, I was thinking, I don't want Win10. I turn on automatic updates and one morning I wake up and there it is on my machine. Basically if I want to change the computer (OS version in this case) I change the computer.

    5. Re:Microsoft's fault by Anonymous Coward · · Score: 5, Insightful

      Plus, if Anti-Vaxxers could actually point to widespread deaths, they might have a point.

      People who advocate turning off Windows Update Can point to widespread windows deaths due to errant updates.

    6. Re:Microsoft's fault by war4peace · · Score: 2, Interesting

      It's a very complex ecosystem. Generally, the benefits of the many outweigh the "sacrifice" of the few.
      For every machine negatively affected by a forced update, there's a million which benefited from it. Unfortunately, that million machines don't yell "fault!" like that one which messed up does.

      Yes, Microsoft were too aggressive with pushing people towards updating to Windows 10, and they should have toned it down. But ultimately, it was not the "upgrade push" which pissed people off, but the whole telemetry debacle. People were turning updates off and messing with hidden Windows setting because of telemetry, not security updates. Problem is, Microsoft pushed back and started mixing security updates with telemetry, then people pushed back and turned updates off altogether, etc. It was, and still is, a general cat fight.

      I was never worried about a few machines coughing up during an automating update. Serious businesses should have internal update QA and separate WSUS servers. genpop users usually don't have really expensive stuff on their machines, and if they do, they should at least afford paying someone knowledgeable to help them with their setup in such a way they won't lose but a couple hours if an update fails. What I (and pretty much everyone with a bit of IT knowledge) was worried about was the telemetry additions, which really should have been opt-in since day 1.

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    7. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      That's just not true. There have been tons of people turning off Windows Update long before things like that.

    8. Re:Microsoft's fault by G00F · · Score: 2, Informative

      Because of other faults of Microsoft pushing updates that don't benefit the end user. Like void your installed windows, change your settings, or even broke your system.

      MS can't be trusted. They use security updates to force what ever they want on end users.

      --
      The spirit of resistance to government is so valuable on certain occasions that I wish it to be always kept alive
    9. Re:Microsoft's fault by phayes · · Score: 2

      but it does break some software and installs unwanted telemetry.

      --
      Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue
    10. Re: Microsoft's fault by Anonymous Coward · · Score: 0

      maybe it doesn't bite, but it sure talks a lot.

    11. Re:Microsoft's fault by war4peace · · Score: 1

      /. is not representative for genpop.
      My take is that if there were no telemetry components, the whole thing would have been a lot smoother than it was.

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    12. Re:Microsoft's fault by Tailhook · · Score: 1, Informative

      unwanted telemetry

      Most of that telemetry has been backported; you're not protecting yourself by avoiding Windows 10. All of Microsoft's supported operating systems are spyware and what distinctions exist between versions are trivial; if you care about keeping clear of Microsoft's collection system you're not running any contemporary Microsoft operating system. If you're clinging to Win7/Vista/whatever because you think you're saving your privacy then you're an idiot.

      --
      Maw! Fire up the karma burner!
    13. Re:Microsoft's fault by evolutionary · · Score: 1

      Uh, typo: you mean WGA, right? :D

      --
      "Imagination is more important than knowledge" - Einstein
    14. Re:Microsoft's fault by doom · · Score: 1

      Yeah, that's it: don't abuse the automatic update channel, and people maybe people won't shut them off. And abuse means pushing your fabulous new design changes because you're too lazy to figure out how to support multiple versions of the UI.

      (I'm not a Windows user, but I've been tortured enough by Firefox UI changes to understand the dynamic.)

    15. Re:Microsoft's fault by sgage · · Score: 1

      Does anyone know about the efficacy of Spybot Anti-Beacon? It purports to block all the telemetry, or whatever bits you specify.

    16. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      For a while, I tried to start updates manually, watch for the W10-up-the-ass patches, and set them to "do not download". Then they started to "update" those patches, which meant that the "do not download" got reset and it would happily go ahead and install them. I only use two W7 systems anyhow, one a laptop that I rarely use, and another a desktop with a real video card that I sometimes use for games. I'm just going to disable sharing and install the one-off kb4012212 patch. (I normally use ssh via cygwin when I need to copy files to them anyhow.)

    17. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Rebooting my computer when I don't want it rebooted.

      ...and often at the worst possible time. Not to mention the system performance goes to shit while the updater is doing its thing, hogging whatever disk bandwidth you have.

    18. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      It would be rather like if vaccines used radium instead of mercury.

    19. Re: Microsoft's fault by Anonymous Coward · · Score: 0

      Hang on, you want me to reinstall the Windows 95 that I replaces with SuSE Linux in 1997 and do what next? Update it? Pass...

    20. Re:Microsoft's fault by HiThere · · Score: 1

      You think MSWind10 is the first time this happened? Read the older news. MS was just more aggressive this time, and made it more difficult to avoid without jumping ship. (I jumped ship around 1998.)

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    21. Re:Microsoft's fault by sconeu · · Score: 1

      Yes, I meant WGA. Thanks.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    22. Re:Microsoft's fault by phayes · · Score: 1

      That would depend on which patchs you have applied to your pre win10 installation. If you haven't installed the patches that apply the back ported snooping...
      It's a major reason why they removed individual patches in my opinion

      --
      Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue
    23. Re:Microsoft's fault by citylivin · · Score: 3, Interesting

      "Yes, Microsoft were too aggressive with pushing people towards updating to Windows 10, and they should have toned it down. But ultimately, it was not the "upgrade push" which pissed people off, but the whole telemetry debacle."

      Revisionist history. Before we even knew the extent of windows spying we had the windows update advisor (GWX) show up in the system tray on everyones windows 7 machine in it seems june 2015 ( https://tech.slashdot.org/stor... ) and a year later, forced it on everyone ( https://tech.slashdot.org/stor... ). That is the day that microsoft lost my confidence that they had worked since windows 95 to build.

      You can go read that slashdot article to see the day when everyone lost trust in microsoft, and people started recommending that people deactivate windows updates Very few people mention telemetry. What they do mention is that MS pushed a "security update" that was anything but.

      I turned windows updates off that day, but being an industry person, i found a work around that allowed me to keep them on. There was a program quickly developed called GWX blocker or something like that which allowed the gwx framework to be stopped.

      So yes, its bad to not run windows updates, but its also 100% microsofts own god damn fault.

      --
      As a potential lottery winner, I totally support tax cuts for the wealthy
    24. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Yeah, the earlier telemetry patches were malicious "security" updates, but people figured out which ones they were and started blocking them. Don't worry about that though, Microsoft rolled them up into "cumulative" patches so that if you want any of the security patches you have to install all of them, including the malicious ones.

    25. Re:Microsoft's fault by Darinbob · · Score: 1

      Windows 10 does bite, and on Windows 8.1 I do remove the telemetry updates (because it's allowed to do so on 8.1). There's a distinct difference between basic opt-in telemetry and what Windows 10 does. Note especially that the enterprise edition allows disabling telemetry because they have more clout than home users. If it's a big enough issue for corporations to turn off then it should be a big enough issues to allow home users to disable. Microsoft didn't even disclose the types of data it is collecting until this year, they message was "trust us" which is a ridiculous rationale from one of the least trusted corporations out there. Most other applications or operating systems make the telemetry opt-in, and that's the way it should be because they're not so utterly arrogant as to demand it from everyone.

    26. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Yes, the telemetry has been backported to windows 7, but it doesn't magically appear on your system. You too could have had a telemetry-free Windows 7 install if you left automatic updates disabled. See how that works?

      And no, the argument put forth in this article isn't convincing. It's not like having automatic updates turned off means you are forced to miss security updates. Wait for independent verification of what's in the patch before downloading it from the Update Catalogue and installing it manually. I already had MS17-010 without needing to cede privacy or control of my machine.

    27. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Lemme think about that.

      No.

    28. Re:Microsoft's fault by Sir+Holo · · Score: 1

      I'm about to install Windows 8.1 on a Boot Camp partition of my laptop's HD.

      Please share any tips or web-links that you found most helpful. Or to the 3rd-party software.

    29. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Most of that telemetry has been backported; you're not protecting yourself by avoiding Windows 10.

      Why do you assume I let my Windows 7 install the backported telemetry?

    30. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      I bet a benjamin that you don't understand what the word consent means. I win.
      Loser

    31. Re:Microsoft's fault by F.Ultra · · Score: 1

      And the complex ecosystem is mostly Microsoft's fault as well so this is their old behaviour biting them in the ass finally. I.e look at how completely insane some of the ACPI tables are on many systems that break the specs but they still "work" in Windows due to Microsoft implementing workarounds instead of enforcing vendors to adhere to a defined standard.

    32. Re:Microsoft's fault by Anonymous Coward · · Score: 0

      Windows 8.1, when used with one of the classic Start Menu shells (I like Start8 - $5, but there are other free ones), which basically hide the tiled "Metro" side and give you the regular Windows desktop by default, is MUCH better that Win 10. It has the fast booting and other internal performance upgrades w/o any of Win10's annoyances.

    33. Re:Microsoft's fault by david_thornley · · Score: 1

      Most people don't care about telemetry. It's widely publicized here because we're largely geeks, many of whom are interested in computer security and privacy. Any large-scale disabling of Windows Update was caused by other things.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  5. But... but... by Anonymous Coward · · Score: 2, Insightful

    The telemetry spying though,,,

    1. Re:But... but... by Anonymous Coward · · Score: 0

      Don't forget the Geforce Experience - that sends more telemetry than Microsoft and to Microsoft servers in Ireland.

    2. Re:But... but... by Anonymous Coward · · Score: 0

      I use an AMD video card, you insensitive clod!

    3. Re:But... but... by Anonymous Coward · · Score: 0

      Well, at least you can install nVidia drivers without that. MS does not give you that option, there it's either all or nothing.

  6. Poor advice. by Anonymous Coward · · Score: 0

    What's worse, having guaranteed malicious software (windows telemetry), or possible malicious software?

    I'll take my chances with other security measures until MS stops intentionally breaking security.

    1. Re:Poor advice. by Anonymous Coward · · Score: 5, Insightful

      nobody cares what you do on your PC

      Then why did they implement telemetry in Windows?

    2. Re:Poor advice. by Anonymous Coward · · Score: 0

      Yea, who want privacy now a days anyway.

    3. Re:Poor advice. by Anonymous Coward · · Score: 1

      Guess what, nobody cares what you do on your PC or what porn sites you visit.

      There are MANY companies that want EXACTLY this data. The marketing/analytics business is pretty huge.

      Only an idiot would worry about telemetry.

      So have you stopped beating your wife yet?

    4. Re:Poor advice. by BronsCon · · Score: 2, Insightful

      Because they do care about what crashes on your computer and why, so they can fix those issues. That's more to do with what other people (software developers) do on your computer than what you do on it.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    5. Re:Poor advice. by Anonymous Coward · · Score: 0

      There is a difference between caring what YOU do and what PEOPLE IN GENERAL do.

    6. Re:Poor advice. by JohnFen · · Score: 1

      I don't think that's the complete explanation. If that's all it was, then we'd have the ability to turn the telemetry off.

      That telemetry is mandatory tells me that Microsoft has much more nefarious reasons afoot. Probably centered around monetization.

    7. Re:Poor advice. by Anonymous Coward · · Score: 0

      Perhaps they should rehire all the OS testers that they laid off, rather than forcing a large percentage of the world's population to become unwilling testers for their shitty operating systems.

    8. Re: Poor advice. by BronsCon · · Score: 1

      Crash reporting is literally the only telemetry you can't turn off...

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    9. Re:Poor advice. by Anonymous Coward · · Score: 0

      ok answer me this, if my computer IS NOT CRASHING then why diagtrack was reading and writing from my hard drive the first 5 minutes uninterrupted making my computer unusable? what data, of a NON CRASHING computer is sending exactly?

      disabled the service completely and now it boots ultra fast and is usable from second one

    10. Re:Poor advice. by Voyager529 · · Score: 1

      Because they do care about what crashes on your computer and why, so they can fix those issues.

      If Microsoft wants telemetry data to resolve issues with system crashes, they can earn it. Start by actually reading through the forum posts with thousands of people reporting the same issue, and work to address that issue, rather than having an offshored 'support rep' copy/paste a 'solution', mark the issue as solved, never following up on the thread, and then waiting until page 807 for some enterprising individual to figure out the registry hack + permissions change + third party utility that *actually* solves the problem. This is the norm in the Microsoft support forums. Microsoft cannot simultaneously argue that they need telemetry in order to address crashes, performance issues, and system instabilities, while also ignoring the green pastures of such information volunteered to them that goes unaddressed and unresolved unless another end user provides a workaround.

      That's more to do with what other people (software developers) do on your computer than what you do on it.

      So then why don't they provide an opt-out if I would prefer to deal with the crashes personally and not get their help? Why don't they provide the raw data that gets sent back? You are defending Microsoft taking data that my computer has generated and not showing it to me while appearing to be perplexed as to why "*.microsoft.com DENY ANY ANY" is becoming a progressively more common firewall rule. They want information about how well my computer runs, they can ask for it, and I will be more than happy to give it to them (fairly commonly in the forums, see point #1). MS wants to take it, not show it to me, write a EULA indicating that they can do whatever they want with that data, and expect me to trust them to do the right thing on my behalf? Sorry, no.

    11. Re:Poor advice. by BronsCon · · Score: 1

      If Microsoft wants telemetry data to resolve issues with system crashes, they can earn it. Start by actually reading through the forum posts with thousands of people reporting the same issue, and work to address that issue

      How many of those thousands of people do you think can actually accurately describe the actual problem they're facing, let along provide the technical details that come from crash telemetry? It's honestly like Ford asking someone who was involved in a car accident due to a bug in their car's anti-lock braking system to help them fix it, rather than asking the car itself what went wrong; cars store post-crash and post-fault telemetry for a reason, and Windows does for the very same reason. Only the system knows why the system failed.

      This is the norm in the Microsoft support forums. Microsoft cannot simultaneously argue that they need telemetry in order to address crashes, performance issues, and system instabilities, while also ignoring the green pastures of such information volunteered to them that goes unaddressed and unresolved unless another end user provides a workaround.

      A feature or function not behaving as expected and a program crash are two different things. One (the program crash) will provide telemetry and the other will not. Microsoft does not need telemetry to learn that sometimes the Start menu does not open when you click it; and telemetry will not tell them that, either. Those types of issues do belong in forums, as they're not crashes but, rather, UI and UX bugs that telemetry can't possibly nail down; they're not failures of the system, they're failures of the design of the system.

      A program crash, on the other hand, is much easier to track down and fix when you have the actual system that experienced it provide details about it that the end user who was sitting at that system can't possibly even be aware of. Sure, you can have a thousand people report the crash, each giving a slightly different account of the issue, and you can assume that all of those similar-sounding crashes follow the same root cause, spend countless hours attempting to reproduce an intermittent problem, finally get it to happen once so you can now confirm that a problem does exist, then spend countless more hours trying to reproduce it again and again with every proposed fix because, well, it's an intermittent problem, it doesn't happen every time you do the thing that triggers it...

      Or, you can have the failing system tell you how and why it failed, immediately know what needs to be fixed and how to verify that it ha been fixed, and possibly learn that there are a handful of "whys" for a given "how". That's something a thousand forum posts can't give you.

      Imagine a thousand people posting about Word crashing when they open files saved by a certain older version of Word. You read all thousand reports, they all say Word 2016 sometimes crashes when opening files saved by Word 2003. Do you know, from a thousand descriptions of the crash scenario, what caused those crashes? Do you know that there was just one cause? Might there be multiple causes? I mean, come on, we're talking about Microsoft, right? Even you should agree that a single issue in their software is likely to have multiple causes.

      So, what, they see the forum posts, reproduce the issue on their end--they found a working test case, they're not gonna keep looking for more of them--and fix the issue they reproduced. Well... They fix one cause of that issue. Then they report back that it has been fixed.

      And it has, for about 10% of the people who reported it.

      Telemetry lets them see the actual problem, and not just the result of the problem, so they can fix it right the first time.

      You can't honestly be sitting there with a straight face, comparing pre-XP Windows to post-XP Windows, and telling me it doesn't work. Every version of Windows released since XP has been more stab

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    12. Re: Poor advice. by JohnFen · · Score: 1

      This is almost, but not quite, true.

      If we accept that Microsoft is being forthright and truthful about this, then the telemetry you can't turn off includes "basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information."

      This is quite a bit more than only crash reports. Also, crash reports are not exactly innocuous. They can contain very sensitive information themselves.

    13. Re:Poor advice. by JohnFen · · Score: 1

      It's honestly like Ford asking someone who was involved in a car accident due to a bug in their car's anti-lock braking system to help them fix it, rather than asking the car itself what went wrong; cars store post-crash and post-fault telemetry for a reason, and Windows does for the very same reason.

      Except that, with the exception of more modern cars (which are just as unacceptable as Microsoft's mandatory telemetry), your car is not constantly phoning home with that telemetry. Someone has to physically retrieve it, which involves your active consent.

      If, in the event of a crash, Windows asked if it could send the crash report to Microsoft (like it used to!), there'd be no issue.

      Telemetry lets them see the actual problem, and not just the result of the problem, so they can fix it right the first time.

      You're arguing in favor of telemetry, but I don't see anyone arguing against it. What people are arguing against is that it is mandatory.

    14. Re: Poor advice. by BronsCon · · Score: 1

      If we accept that Microsoft is being forthright and truthful about this, then the telemetry you can't turn off includes "basic device information, quality-related information, app compatibility, and Microsoft Store. When the level is set to Basic, it also includes the Security level information."

      Basic device information (such as CPU type, RAM and storage sizes and utilization, and what hardware and drivers are installed) would seem to be somewhat required as part of a crash report. In fact, quality-related information would seem to be more user-friendly name for "why did it crash", coupled with "app compatibility" as a way of saying "what crashed". It really seems as though they've broken "crash report" into its component elements; likely in an attempt to be somewhat more transparent about what's in them. Looks like that backfired.

      Also, I would certainly hope Microsoft, and not some other party, is getting information about how I use the Microsoft Store. How do you suspect the Windows Store works? Do you think every Windows install comes with a full copy of everything that has ever resided in, or will ever reside in, the Windows store (including the app I am currently writing), and just calculates the current state of the store based on the current date and time? Or do you think, more reasonably, that the current state of the store resides on Microsoft's servers and you have to send data back to those servers so they know what to serve you?

      I don't think Microsoft has devised a way to see into the future and determine every single piece of software that will even be submitted to the Microsoft Store, nor have they invented a compression algorithm efficient enough to fit all of that onto a single DVD, so I'm leaning toward the server solution.

      This is quite a bit more than only crash reports. Also, crash reports are not exactly innocuous. They can contain very sensitive information themselves.

      There is actually a setting (set to disallow by default) to allow or disallow automatic sending of potentially sensitive contents (e.g. contents of RAM or files) along with crash reports. I don't recall where I saw it, but I do know it's there and defaults to asking the user prior to sending such data.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    15. Re:Poor advice. by BronsCon · · Score: 1

      Someone has to physically retrieve it, which involves your active consent.

      You gave that consent to Microsoft by installing a non-Enterprise version of Windows 10 and accepting the license agreement, or by installing an Enterprise version of Windows 10 and not disabling automatic error reporting.

      If, in the event of a crash, Windows asked if it could send the crash report to Microsoft (like it used to!), there'd be no issue.

      If Microsoft wasn't, then, forced to deal with idiots who insist they fix their crashing programs, yet refuse to provide crash reports when asked, there'd be no issue.

      You're arguing in favor of telemetry, but I don't see anyone arguing against it. What people are arguing against is that it is mandatory.

      Except that it's not. Either you work in an industry where Windows is mandatory, in which case you can afford the 5-license minimum for Enterprise and disable the telemetry, or you don't and you can use something else.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    16. Re:Poor advice. by BronsCon · · Score: 1

      Perhaps they should... What they're doing now seems to be working just as well, if not better, given that Win 10 is more stable than previous versions; but I imagine it would be even more so if they still had a QA team.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    17. Re:Poor advice. by BronsCon · · Score: 1

      You say it was reading and writing your hard drive, but you don't at any point mention network activity. Considering that the only way, out of the box, to monitor disk access is Task Manager and you specifically mention that this was the first 5 minutes, that's what you must have been using. Did you see network activity in that time? And which process are you referring to as "diagtrack"? If you have a process that's actually called "diagtrack", that's not Windows and you should contact your OEM about it.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    18. Re:Poor advice. by JohnFen · · Score: 1

      You gave that consent to Microsoft by installing a non-Enterprise version of Windows 10 and accepting the license agreement, or by installing an Enterprise version of Windows 10 and not disabling automatic error reporting.

      Legally, yes. In the real world, though, no. Consent through EULAs cannot be considered "active consent" by any reasonable definition.

      If Microsoft wasn't, then, forced to deal with idiots who insist they fix their crashing programs, yet refuse to provide crash reports when asked, there'd be no issue.

      Fine. If Microsoft doesn't want to deal with people who think that clicking the "send crash report" button means that Microsoft will fix the crash, then do it in the background -- but let people disable the automatic reporting if they wish.

      Except that it's not. Either you work in an industry where Windows is mandatory, in which case you can afford the 5-license minimum for Enterprise and disable the telemetry, or you don't and you can use something else.

      Well, yes, in the big picture, nothing about Windows is mandatory. Even using a computer at all is optional. But that argument is a bit disingenuous. I was talking about telemetry being mandatory if you're using consumer level Windows.

    19. Re:Poor advice. by BronsCon · · Score: 1

      Legally, yes. In the real world, though, no. Consent through EULAs cannot be considered "active consent" by any reasonable definition.

      You actively clicked the "Agree" button. If you didn't actively read what you were agreeing to, that's your own fault. Perhaps, if people actively refused to agree to shit that was onerously long and difficult to read, that shit would be made a lot shorter and in plain English. Companies care about market share and they won't change as long as we keep giving it to them. Take responsibility, say "NO!" to things you don't agree to, rather than lying and saying "I AGREE!", then trying to make it someone else's fault when the thing you claimed to agree to happens to you and you don't like it.

      Fine. If Microsoft doesn't want to deal with people who think that clicking the "send crash report" button means that Microsoft will fix the crash, then do it in the background -- but let people disable the automatic reporting if they wish.

      You misunderstand. These aren't people who think clicking the button means MS will fix the crashes, these are people who REFUSE TO CLICK THE BUTTON and bitch that MS never fixes the crashes. Go back and read what I wrote again, because you clearly missed something.

      Well, yes, in the big picture, nothing about Windows is mandatory. Even using a computer at all is optional. But that argument is a bit disingenuous. I was talking about telemetry being mandatory if you're using consumer level Windows.

      And what we have here is an informed market. We all know telemetry is there. Don't like it? Don't use it. You really do have a choice.

      Just don't believe that Apple collects any less telemetry, or that you can disable all of it. They don't and you can't. You might know this if you ever read that EULA we were just talking about.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  7. Telemetry and Windows 10 by Anonymous Coward · · Score: 5, Insightful

    Windows Update also wanted to install telemetry on my Windows 7 system until I removed the patch. Then for 12 months Windows Update wanted to 'upgrade' me to Windows 10, the software employed all sorts of tricks to make me say yes and in the end I just disabled updates as it was less hassle.

    My Windows 7 system was not affected by the events over the weekend as all it does is run some test equipment. It still has Windows Update disabled and it's going to stay that way.

    1. Re:Telemetry and Windows 10 by Anonymous Coward · · Score: 0

      And worse, even if you have an edition Microsoft doesn't allow to upgrade to 10, they still push the Windows 10 update app than then when it runs it tells you that you're not allowed to upgrade. Why shove it down our throats only to then tell us we can't have it?

  8. Windows Users... by hackel · · Score: 0, Insightful

    Why would anyone *disable* automatic updates on Windows? With it being widely known as such an insecure OS, that just seems insane. I've never heard anyone give such advice, but if they did, they surely deserve a smack on the head.

    1. Re:Windows Users... by Gilgaron · · Score: 1

      It is pretty common to see people recommend setting it to only do the critical updates, so with somebody that doesn't understand what they're doing, playing a little telephone and purple monkey dishwasher disable all security features in Windows.

    2. Re:Windows Users... by DontBeAMoran · · Score: 2

      Enjoy the Windows 10 telemetry yet?

      I mean, I use Windows 10 too but only as the OS required to run games. As far as Microsoft knows, all I use is Battle.net, Steam and GoG.

      --
      #DeleteFacebook
    3. Re:Windows Users... by Anonymous Coward · · Score: 0

      Because Microsoft's ridiculous overreach with Windows 10 forced my hand.

      I decide when my computer restarts, not Redmond. If I have documents and browser windows open that I want to keep open for a week, that's my prerogative. I will never consent to an update scheme that comes with the disclaimer: "Oh, by the way, we might just randomly restart your computer whenever we feel like it and your unsaved work will just go straight into the garbage."

      If that means I have to disable their Windows Update Gestapo Service and run updates manually, so be it.

    4. Re:Windows Users... by Khashishi · · Score: 1

      Because of getwin10

    5. Re:Windows Users... by Anonymous Coward · · Score: 0

      'cause they have been burned again and again by undertested, overmarketed "security updates" like WGA and Diagnostig Tracking...?

    6. Re:Windows Users... by squiggleslash · · Score: 3, Interesting

      Because Windows Update reboots your computer without your permission or control over the process. We're essentially back to Windows 95 in terms of operating system stability because Microsoft cannot figure out how to update an operating system without resetting the computer in the process.

      If Windows 10 (1) avoided reboots unless absolutely 100% necessary, and (2) prompted you to reboot (perhaps nagging you until you do) rather than running a timer you often don't even see before it expires do it, then, well, people would be a little happier about the tool.

      Updating is good. Microsoft's implementation is shit. If you want people to install security updates, don't do implement it in a way that's indistinguishable from a kernel level bug that crashes your computer every few days.

      --
      You are not alone. This is not normal. None of this is normal.
    7. Re:Windows Users... by Hognoxious · · Score: 1

      It goes further than that. Plenty of times my XP laptop would hang after an update, or the networking was disabled. The latter was great since it stopped you downloading the update that fixed the other update unless you had another machine.

      Still, it made me learn about restore points.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    8. Re:Windows Users... by Anonymous Coward · · Score: 0

      You should complain to the authors of your software that it's not saving it's state for an Update reboot.

      https://msdn.microsoft.com/en-us/library/windows/desktop/aa373347%28v=vs.85%29.aspx

    9. Re:Windows Users... by prunus.avium · · Score: 1

      ... rather than running a timer you often don't even see before it expires do it...

      HAH! That's exactly how I wound up running Windows 10. Left my Windows 7 machine running over the weekend and came back to Windows 10. Fuck!

    10. Re:Windows Users... by EnsilZah · · Score: 1

      Because getting some kind of virus is a hypothetical, while seeing several people's presentations ruined, my own work stopped for half an hour on three occasions, bad drivers installed multiple times, all those are tangible experiences.

    11. Re:Windows Users... by Anonymous Coward · · Score: 0

      All the other OSes that "update" without rebooting the computer means that the OS is *STILL* running old unpatched updates until the process is restarted.

      This means that lazy people who don't shut down or restart their apps are *STILL* running vulnerable code. If you, for example, forget to restart Apache / IIS, you're still running vulnerable programs.

      If it's a popular system service that many apps depend on and use? Good luck.

    12. Re:Windows Users... by fazig · · Score: 1

      I disabled automatic updates on my Windows 7 machines when MS started to offer only cumulative updates for Windows 7 through the updater that combine security updates with non security updates. Before that I installed security updates automatically. But with rollup updates, this is something of the past. I don't want them to install whatever crapware they want on my machine. For that reason I already avoid Windows 10 whenever I can.
      So I prefer to download security updates manually from http://www.catalog.update.micr... (yes, you can do it without using IE) and pay something like ~$30 a year for a proper proprietary anti-virus than putting up with Microsoft's shit. Hey, I'd even be willing to pay that money to MS every year if they offered a better service and didn't try to screw me over every chance they get.

    13. Re:Windows Users... by Anonymous Coward · · Score: 0

      That's a very nice feature especially if you're downloading a podcast, a binary program, or your system doing an auto-backup every night. Windows update will appear from no-where then restart your system. Then when you awoke you shout at the top of your lungs because of your frustration and your wife gets up crying and wanted a divorce because you're too abusive.

       

    14. Re:Windows Users... by JohnFen · · Score: 2

      Why would anyone *disable* automatic updates on Windows?

      To avoid all the nastiness that comes with Windows updates, perhaps?

    15. Re:Windows Users... by JohnFen · · Score: 1

      And how would that stop the rebooting?

    16. Re:Windows Users... by BronsCon · · Score: 1

      Because getting some kind of virus is a hypothetical

      Until it happens to you or you see it happen to someone else. According to you, seeing it happen is enough; after all, you did say

      seeing several people's presentations ruined [...] are tangible experiences.

      All of the "ruined presentations" I've seen have been reported in the news media. The very same news media who reports on these viruses people are getting, mind you.

      And yes, I've had updates interrupt my work before. Twice, on two different systems. I treat those incidents as bluescreens and, well, even with those, Windows 10 is still more stable and reliable than any previous version.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    17. Re:Windows Users... by Anonymous Coward · · Score: 0

      I've seen it explained as basically related to DLL Hell. Other parts of the system may be using the older versions of DLLs, and there may be linkage problems between versions if a patched DLL refers to another patched DLL, or something like that.

      The other side of the problem is the file semantics in Windows. In Unix, each individual file gets an inode, and the file goes away when the sum of directory links and open file descriptors to the inode goes to zero. If you delete, say, a log file that is opened for writing, it continues to exist and be appended to until the logging process closes it. It still exists with allocated space, but you can't access its data from another program because there is no longer any directory linkage to it.

      Windows, on the other hand, refuses to even let you rename a file if a process has an open file descriptor to it, and it certainly won't let you delete it.

    18. Re:Windows Users... by EnsilZah · · Score: 2

      The ruined presentations are ones that I've actually attended and had to sit through Windows suddenly deciding to reboot and the presenter not knowing what to do, and the attendees having to sit through the installation process.
      Or ones that I watched live streamed.

      I do digital painting from live model, after a few times of having Windows install an update for 40 minutes or botching a driver update that took me a similar amount of time to figure out how to fix, that's the limited time I have with the model, and the money paid wasted, I'm not enabling updates on this device again.

      Now on my main desktop I still have Windows 7 so I'm less apprehensive and do update manually every couple of months.

    19. Re:Windows Users... by Darinbob · · Score: 1

      "Automatic" updates are routinely disabled. Most updates from Microsoft are crap. The updates take lots of wasted time (seriously, I've applied a service pack in the past that installed faster than some of these new Windows updates). Not every update is for security, even Microsoft still manages to make a distinction So you can be routinely applying security updates (manually or automatically) while still disabling other updates and remain secure.

      And precisely because Windows is known for being insecure means you should never trust it for security. Many of it's holes came about from updates either to it or to its applications. The fact that Microsoft shoved out a marketing feature as a security update should say very clearly to never trust them. ALWAYS review each and every update manually to see if it's safe. Pro users are allowed to delay updates for some months, even security updates can be delayed, and Enterprise users can put off updates indefinitely. Only the Home users (known internally in Microsoft as "suckers) are forced to take updates immediately.

    20. Re:Windows Users... by Darinbob · · Score: 1

      Most malware doesn't cause the kinds of damage that Windows does.

  9. Telemetry by Anonymous Coward · · Score: 0

    I'll turn it on when they stop sending telemetry in the updates. Until then, no dice.

  10. Maybe if Windows Update behaved decently... by ToTheStars · · Score: 5, Insightful

    The reason folks turn off Windows Update is that it behaves kind of like malware itself! I'm technologically savvy enough to set my registry and so on to disable the awful "Get Windows Ten" updates, but when so many users got shafted by Windows "self-updating with zero input required from the user" to a completely new operating system (a new operating system that actively thwarts end-user control over updates!), is it any wonder that so many of them switched it off?

    The comparison to anti-vaxxers is interesting, and apt in more ways than Troy may have known. Much like Microsoft hijacked their Windows Update program to push Windows 10, the CIA used a Pakistani polio vaccination campaign to gather intelligence about Osama bin Laden (see here: https://en.wikipedia.org/wiki/...). This has resulted in the killing of other relief workers and general suspicion of medical aid programs in that region, and so polio persists.

    1. Re:Maybe if Windows Update behaved decently... by Gilgaron · · Score: 2

      That is a shame about the polio.... so very close to being eradicated, too

    2. Re:Maybe if Windows Update behaved decently... by Anonymous Coward · · Score: 3, Insightful

      Thank you. The polio vaccination ruse by the CIA and the telemetry comparison is exactly what I thought of as well.

      On a separate note, WU used to specifically tell you what the update fixed, right in WU. Then they started making you click a link to go to the MS web site. After a while the web page stopped saying anything useful. Now you have to research each one manually, which is unacceptable. There is no reason MS would go to those lengths to obfuscate what a patch does, unless it's so they can foist more crapware on you. I can't think of a good vaccination analogy for that, but it pisses me off.

    3. Re:Maybe if Windows Update behaved decently... by Anonymous Coward · · Score: 0

      Yes, yes it is a shame.

    4. Re:Maybe if Windows Update behaved decently... by Anonymous Coward · · Score: 0

      I can't think of a good vaccination analogy for that, but it pisses me off.

      That's easy, a Microsoft update vaccinates you against polio (actual malware), while at the same time infecting you with syphilis (telemetry spyware).

    5. Re:Maybe if Windows Update behaved decently... by Anonymous Coward · · Score: 0

      I agree in general with what you're saying, but the attacking and/or killing of polio workers long predated the CIA phony vaccination/Osama bin Laden thing, and not only in Pakistan
      BTW, the fake CIA vaccination wasn't for polio, it was for hepatitis. They needed a needle-based vaccine to get some blood for DNA testing.

    6. Re:Maybe if Windows Update behaved decently... by Anonymous Coward · · Score: 0

      Much like Microsoft hijacked their Windows Update program to push Windows 10, the CIA used a Pakistani polio vaccination campaign to gather intelligence about Osama bin Laden (see here: https://en.wikipedia.org/wiki/... [wikipedia.org]). This has resulted in the killing of other relief workers and general suspicion of medical aid programs in that region, and so polio persists.

      Ha ha, yes! In my experience Pakistani Muslims absolutely require foreign intervention in order to behave irrationally and against their own interests! Left to their own devices they just quietly meditate!

  11. anti-vax by Anonymous Coward · · Score: 0

    it's also why I run Linux.

  12. What about the updates that hurt users? by evolutionary · · Score: 4, Insightful

    The problem is that around 30% of MS Updates actually hurt the user, either by introducing "features" that (like Apple) inadvertently or deliberately adding things that are of no benefit to anyone but MS and in many case hurt he users. Windows 10 Basically is capable of hijiacking itself (as per it's design) so it's hard to know what is good and what is not especially MS gives VERY vague descriptions of it's updates as per the new windows 10+ policy to tell users, it's our update, just take it (up the rear end). The sooner we start admiting that we don't in fact NEED MS Windows at this point, the better. Linux anyone?

    --
    "Imagination is more important than knowledge" - Einstein
    1. Re:What about the updates that hurt users? by Anonymous Coward · · Score: 0

      >The sooner we start admiting that we don't in fact NEED MS Windows at this point, the better. Linux anyone?

      Who's this "we"? There are literally millions of people that play Windows only computer games, that do so out of choice ("need").

      You don't speak for me. Hell, you don't speak well for yourself.

    2. Re:What about the updates that hurt users? by Anonymous Coward · · Score: 0

      The sooner we start admiting that we don't in fact NEED MS Windows at this point, the better. Linux anyone?

      Basically you kiss all mechanical engineering and PCB/schematic capture goodbye. Pretty much all parametric 3D CAD and EDA software runs on Windows exclusively. So I guess we can kiss Windows goodbye - and also completely halt all future laptop/computer development at the same time?

    3. Re:What about the updates that hurt users? by JohnFen · · Score: 1

      Basically you kiss all mechanical engineering and PCB/schematic capture goodbye.

      That's a BS argument. There is Linux software that is reasonable to use for such activities. It's not as good as the Windows stuff, true, but it is fully functional and usable.

      And if Windows went away completely, all of the really great tools would be implemented on Linux very, very quickly.

    4. Re:What about the updates that hurt users? by Anonymous Coward · · Score: 0

      I have to use Photoshop, which runs like hell in a virtual machine.

      Windows dependency persists.

    5. Re:What about the updates that hurt users? by HiThere · · Score: 1

      And even if they remained MSWindows only, you could run it virtualized. Others have said that's the only way to run MSWindows. I would only disagree because I wouldn't agree to the EULA needed to do that.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    6. Re:What about the updates that hurt users? by Darinbob · · Score: 1

      Most still run on XP as well, no need to upgrade :-)

  13. Same problem with vaccines: trust by Anonymous Coward · · Score: 1

    Vaccines worked in a society that had trust and a belief in a brighter future. Our society is no longer trustworthy. The wolves are running the hen house. Anti-vaxxers are a natural consequence of the loss of societal trust. I am not an anti-vaxxer, but, as a conspiracy theorist, I understand how anti-vaxxers came to be. We, as a people, no longer trust our government, pretty much at all. Any trust is blind trust placed at our political parties and idols. We are blind fools to give that trust at all, but it is just about the only thing left keeping this obviously corrupt system running.

    And, guess what. We're seeing the same fucking thing from Microsoft. We can't trust them. The problem with the author (and as a security engineer by trade, everyone makes this mistake all the time) is that he does not understand the threat he's protecting against. People who advocate for disabling automatic updates have assessed the software vendor to be the bigger threat than hackers. They're not wrong, and the author has completely misunderstood the owner's threat model.

    1. Re:Same problem with vaccines: trust by Anonymous Coward · · Score: 0

      Nobody should be getting vaccines.

  14. There should be a separate "Security Updates Only" by Anonymous Coward · · Score: 0

    ...checkbox. I don't need the marketing fluff or whatever other crap Microsoft wants to shove down my throat. Give me the option to only install security updates automatically, and leave the rest manual.

  15. Pirated software. by Anonymous Coward · · Score: 0

    On the BBC news earlier, it was said that most of the Chinese machines that were infected had pirated Windows on them and because they were pirated, we not eligible for the upgrades. Those people got hit.

    1. Re:Pirated software. by __aaclcg7560 · · Score: 1

      If you use pirated software, you get what you paid for.

    2. Re:Pirated software. by __aaclcg7560 · · Score: 2

      If you buy Microsoft software, you get what you paid for.

      I haven't that problem since Windows XP. Then again, I'm not running on minimum spec hardware.

    3. Re:Pirated software. by Anonymous Coward · · Score: 0

      Way to spread that little tidbit without verifying.

    4. Re:Pirated software. by Anonymous Coward · · Score: 0

      On the BBC news earlier, it was said that most of the Chinese machines that were infected had pirated Windows on them and because they were pirated, we not eligible for the upgrades.

      Microsoft marketing propaganda.

      I've used every version of Windows since Windows 3.0 (circa 1990). The last time I owned a "legitimate" copy of Windows was Windows 98, and yet, I've never had a problem with updating my "pirated" copies of Windows. I guess there are just a lot of stupid people in China.

    5. Re:Pirated software. by djinn6 · · Score: 1

      I don't think having tons of vulnerable machines out there is good, even from a justice or karma perspective.

      Unlike IoT gadgets, which are exclusively bought by people with far too much money in their pockets, a regular computer is a necessity in the modern world, and not having one closes the door on many good careers.

      Now consider that some people are very poor and uneducated. The machine might have already cost them a year's salary, and a license would've been another year's. They probably don't have know anyone who knows Linux. They might not know what an OS is, or even what pirating is. And many of the cheaper computers are simply sold with a pirated version.

      Besides, the attacker could've just as easily made them a part of a botnet rather than asking for ransom.

  16. Don't Tell People To Use Windows, Just Don't by Tough+Love · · Score: 2

    Problem solved, permanently.

    --
    When all you have is a hammer, every problem starts to look like a thumb.
    1. Re:Don't Tell People To Use Windows, Just Don't by Anonymous Coward · · Score: 0

      Indeed, because then your machine becomes worthless, since Linux as a desktop continues to be a joke.

      And for added excitement, you get to be the guinea pigs of open source developers who will keep you running on the daily update treadmill.

    2. Re:Don't Tell People To Use Windows, Just Don't by Tough+Love · · Score: 1

      Linux as a desktop continues to be a joke.>

      Indeed. I get that joke. The joke is a great one, the joke is on assholes like you. HA ha. (suffer, you idiot)

      --
      When all you have is a hammer, every problem starts to look like a thumb.
  17. It is easy to say 'don't turn off updates' unless. by Anonymous Coward · · Score: 0

    If you find yourself, like many in the NHS or other regulated spaces, with no easy upgrade path. I understand the naive impression that 'the vendor is just trying to help, so let them'. I assure you that those of us in the regulated space where patches can cause life-threatening, and business altering affects on critical systems are always titrating risk on both sides. It has never been easy to run a network and mitigate change. It is true that there were a few months to patch for this issue. But the onslaught of all critical patches are beyond the resources of most IT departments that would make a best effort at patching their infrastructure every few weeks under a watchful eye of the FDA or the SEC.

  18. Turn off Windows Update by Dunbal · · Score: 1, Insightful

    But don't be a retard. Keep reading this site and others. I manually installed MS17-010 a month ago even though Windows Update has been off for years. People get what they deserve. You need to actively pursue your own security, not ignore it or worse, pretend that Microsoft is going to do it for you. Windows Update is more trouble than it's worth. Especially since Windows 10.

    --
    Seven puppies were harmed during the making of this post.
  19. I used to be one of those annoying people who said by Presto+Vivace · · Score: 1

    get a Mac. Now I am one of those annoying people who say switch to Linux.

  20. It needs to be less intrusive by Anonymous Coward · · Score: 0

    Windows Update needs a few changes to be trusted:

    1) An option that only installs critical security updates and not features
    2) Needs to stop rebooting your machine when it is busy doing something. This includes intrusive nags that interrupt what you're doing
    3) They need to stop breaking things like they did with third party boot loaders a year or so ago

    1. Re:It needs to be less intrusive by rudy_wayne · · Score: 1

      Windows Update needs a few changes to be trusted:

      1) An option that only installs critical security updates and not features
      2) Needs to stop rebooting your machine when it is busy doing something. This includes intrusive nags that interrupt what you're doing
      3) They need to stop breaking things like they did with third party boot loaders a year or so ago

      You are right, of course, but you fail to understand the mentality that exists within Microsoft.

      Windows 7 is by far still the most popular version. Microsoft could have left it alone and just made security and performance improvements "under the hood". But Microsoft suffers from "New Coke Syndrome", i.e., making pointless, needless changes that are driven by marketing, not by technical necessity.

  21. Auto Update Virus by Oswald+McWeany · · Score: 1

    I am in favour of auto-updating Windows, don't get me wrong; however, it could be catastrophic if anyone ever manages to figure out a way to spread a virus via the auto update.

    I'm not sure the technical route someone would have to take to do this; If, perhaps someone could somehow infect a DNS server to treat an infected server as a Microsoft update server.

    --
    "That's the way to do it" - Punch
    1. Re:Auto Update Virus by Anonymous Coward · · Score: 0

      I'm not sure the technical route someone would have to take to do this

      Updates are crypto signed. Bypassing or subverting the signing process or the key store is left as an exercise for the agencies.

  22. Those fuckers at MSFT ruined security updates by Anonymous Coward · · Score: 5, Interesting

    Those fuckers at MSFT ruined security updates by force-feeding the user spyware, or even forcing an "upgrade" to Windows 10.

    Now nobody trusts Microsoft, and would rather take their chances without the "essential updates".

  23. The problem is spyware and telemetry by WillAffleckUW · · Score: 4, Informative

    the continual additions of resource-heavy snooping spyware and telemetry services for in-app advertising delivery hammer many institutions that would otherwise happily install security patches, if they were JUST security patches.

    But many of the Important patches we have recieved from MSFT are just that. Ads, telemetry to try to sell us stuff that blows out the bandwidth in mission critical software and pops up things that get in the way of doing actual work.

    There's your problem. That and the "patching" of things in a way that breaks apps that believe the public documentation instead of the actual way MSFT codes and tests its apps.

    --
    -- Tigger warning: This post may contain tiggers! --
    1. Re:The problem is spyware and telemetry by WillAffleckUW · · Score: 1

      In a corporate build network. Not when you don't use MSFT network servers.

      Unlike you, I was/am paying attention. Not everyone works in your exact network space.

      --
      -- Tigger warning: This post may contain tiggers! --
    2. Re:The problem is spyware and telemetry by Anonymous Coward · · Score: 0

      No, I don't give a shit about telemetry and spyware. Or rather I do, but I care way, way more about not having the operating system DELIBERATELY DESTROY MY WORK.

      Pretty much the OS's one job is to ensure user data safety - so the moment it included an unstoppable automatic reboot is the moment the OS itself became malware - that's what makes it not fit for any purpose other than browsing the web and playing a game or two.

  24. Blame microsoft... by Anonymous Coward · · Score: 0

    I've started to "screen" updates after they again and again pulled crap like WGA, Trying to smuggle in DiagTrack with every monthly update, or simply rolling out updates that blew up 90% of all PC, 'cause they didnt think to test is properly. And their response was basically, "fuck you, now you're not turning off ANY updates, happy now??!"

  25. PDB symbols by yuhong · · Score: 1

    As a side note, the delay to release PDB symbols on MS's symbol server after a Patch Tuesday has been at least days and sometimes more than a week for the last two months (at least for the Win10 symbols I tried). I use them a lot with WinDbg.

  26. Re:There should be a separate "Security Updates On by green1 · · Score: 5, Insightful

    There is, it's the "critical updates only" checkbox.
    The problem isn't the lack of said checkbox, it's the fact that Microsoft doesn't respect that checkbox and considers all sorts of marketing fluff and malware to be "critical"

  27. Microsoft could be a big help here by JohnFen · · Score: 5, Insightful

    If Microsoft would just go back to the days when security patches were done separately from other sorts of updates, that would be a huge help. I know a lot of people who disable updates to avoid feature changes, but would accept automatic security updates.

    Microsoft's position of not making a distinction between the two is a large disincentive to allowing automatic updates for a lot of people.

    1. Re:Microsoft could be a big help here by evolutionary · · Score: 2

      That would be great, is MS didn't outright LIE about some of their updates. One of the "critical "updates turned out to be an ad server. That was a riot. Problem is, once the source proves untrustworthy, you can't rely on what they say. Question is, can you still rely on their OS? It think we all know the answer to that one.

      --
      "Imagination is more important than knowledge" - Einstein
    2. Re:Microsoft could be a big help here by JohnFen · · Score: 2

      Microsoft is an extremely weaselly company. The instant they stopped using the descriptor "security" and replaced it with "critical" was the moment it became clear that the update mechanism was going to be used for deceptive purposes.

  28. No, you tailor your message to the audience by satsuke · · Score: 1

    It's more accurate to tailor the message about automatic updates to the audience.

    For computer savvy people that are likely to read the message about available updates and install them, than turning off automatic installation is appropriate, because many of us can't afford to have long running processes or tasks dumped from memory with a reboot.

    For your average user or nontechnical person, absolutely, advise them to leave it at defaults (and to save often).

  29. Consider the source. by Gravis+Zero · · Score: 5, Interesting

    at troyhunt.com

    Hi, I'm Troy Hunt, I write this blog, create courses for Pluralsight and am a Microsoft Regional Director and MVP who travels the world speaking at events and training technology professionals

    It's obviously in his interest to make everyone Microsoft's puppets.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re: Consider the source. by Anonymous Coward · · Score: 0

      I heard his brother Mike Hunt is a strong supporter of the Windows As a Service model.

    2. Re:Consider the source. by mugnyte · · Score: 5, Informative
      This isn't necessarily a problem. The problem arises from a cult-of-brand and groupthink that MS cannot do wrong. If Troy Hunt wrote honestly, he'd explore the customers that had turned off MS Update with some interviewing and surveys, then report the results, give a nod to their core cause, report MS's renewed efforts to address these *core* causes and then talk about why Updates should be left on. Instead he delivers these sugar-free platitudes:

      It's not fun, it costs money and it can still break other dependencies, but the alternative is quite possibly ending up like the NHS or even worse. Bottom line is that it's an essential part of running a desktop environment in a modern business.

      He's a fly-around shill just trying to look good in the eyes of Sales. His "workshops" are an insanely expensive way of selling low-calorie information that's already discussed online in much finer detail. His Ghost-powered blog site doesn't offer a search feature, but I'd bet it wouldn't return any meaningful results for two-factor authentication, separation-of-concerns, what certifications exist for software security, or the track record of non-MS products. Quick example: There's no mention of Google's recent publishing of security flaws in open-source projects. Instead we get a pass-the-buck, blame-the-victim blog post that ignores the annoyances of MS Update and tells everyone to "just deal with it".

    3. Re:Consider the source. by Anonymous Coward · · Score: 0

      Microsoft is really pushing out the "it's not our fault our security is garbage" blogs the last couple days in light of their recent World Wide Debacle!

    4. Re:Consider the source. by Anonymous Coward · · Score: 0

      I've followed him for a while. His bread and butter is .Net and Azure and I don't agree with him on everything, but he's usually pretty sensible and willing to explore options. Case in point: I never once saw him recommend windows mobile.

      The post in question isn't about getting people to use Windows, or advertise Microsoft products. It provides cases edge cases (enterprise IT) where his advice doesn't apply. He specifically mentions that the update experience can be improved, pushes unwanted updates and can hose a system every now and then.

      His only point is this: If you know somebody who runs windows, recommending they disable automatic updates is probably bad advice because of future consequences. I find that pretty hard to argue against.

    5. Re:Consider the source. by RespekMyAthorati · · Score: 1

      Did anybody else read that in Troy McClure's voice?
      "Hi, I'm Troy Hunt. You may remember me from such hits as "MicroSoft: You Must Obey" and "How the Grinch Stole Updates".

  30. "Due Diligence?" by Anonymous Coward · · Score: 0

    What would happen if there were stockholder lawsuit charging Corp. X was not exercising corporate "due diligence" to protect stockholder interests by failing to apply vendor-recommended security patches?

  31. Microsoft only have themselves to blame by Gadget_Guy · · Score: 5, Informative

    Microsoft only have themselves to blame for people disabling Windows Updates because they made it untrustworthy:

    • The Windows 10 upgrade fiasco
    • The backporting of the telemetry to previous versions of Windows
    • The updates that crash or cause problems
    • The update mechanism that in older Windows peg the CPU usage at 99%
    • The forced reboots at highly inconvenient times
    • The massive Windows 10 updates that mean that I have to reinstall some of our legacy software because Windows keeps resetting some crucial registry entries
    • The bundling of updates into a single entity so that we don't have control over what gets installed on our systems
    • And the hiding of what is in those updates so that we don't ask questions.
    1. Re:Microsoft only have themselves to blame by Anonymous Coward · · Score: 0

      Exactly.
      The reason I turn it off is mostly for one reason: I want to control the update installs itself.
      I want updates to install after I decide it's time to power down - no nag screen or anything. Microsoft doesn't offer that option.

      On automatic updates, not only is my bandwidth/CPU taken when I least expect it, it actually forces a reboot on me immediately afterwards. Fuck that. There's probably a reason my computer is on, and microsoft has no business deciding to reboot it.
      On automatic downloads, after a download, I get a nag screen ever few hours bugging me to install it. Worse still, this nag screen steals focus and minimizes full screen apps. Nothing better than watching a movie and have it disappear because a "critical update" wants me to "upgrade" to Windows 10.

      If Microsoft starts using windows update to push critical bug fixes, and modifies it to silently "just work" whenever I decide to turn off my computer, it's being turned back on immediately. Right now though, the only way to protect myself against Microsoft is to expose myself to greater risk externally.

    2. Re:Microsoft only have themselves to blame by Hartree · · Score: 3, Insightful

      "The bundling of updates into a single entity so that we don't have control over what gets installed on our systems"

      This! Abso-fracking-lutely this!

      Give me the info on what the update is, and I can decide whether it's worth the risk to install immediately or if I need to run it on a non-important machine first to vet it. Yes, theoretically I can drill down on MSDN and the knowledge base but with some much redirection and info hiding in the documentation, in truth it takes too much time. Exactly as Microsoft intended it.

    3. Re:Microsoft only have themselves to blame by Anonymous Coward · · Score: 0

      Mod this up. Some combination of these reasons is exactly why I've turned windows update off on half my machines. I would literally rather lose everything on those machines (which is literally nothing since they're media pc's) and reinstall those machines from scratch rather than deal with repeated hassles from windows update. And quite honestly, once I find a media system that I like as much as Windows Media Center on Win7, I'm going to jump to Linux. All the ones I've seen so far are kludgy and don't have nearly as good a user experience.

    4. Re:Microsoft only have themselves to blame by Anonymous Coward · · Score: 0

      The updates that crash or cause problems

      This is somewhat related, but Microsoft, by their own ego, has disabled MS updates for everyone who is running advanced processors on non-win10 systems. https://tech.slashdot.org/story/17/03/16/2047215/microsoft-locks-ryzen-kaby-lake-users-out-of-updates-on-windows-7-81

    5. Re:Microsoft only have themselves to blame by Anonymous Coward · · Score: 0

      The problem with picking-and-choosing patches is this. There are literally hundreds of Windows 7 patches, and hundreds more hotfixes. That's billions of possible combinations of pick-and-choose updates. How do you propose that Microsoft test these possible combinations? They don't. They test with all patches installed, and put a huge amount of effort in to making sure that "all patches installed" scenarios work right. I have no desire at all to see MS revert back to non-cumulative updates.

      ... and how does Microsoft find out about patches, apps, or drivers that are breaking in the wild? Telemetry.. the feature you are yelling to turn off. :/

    6. Re:Microsoft only have themselves to blame by Hartree · · Score: 1

      " Telemetry.. the feature you are yelling to turn off. :/"

      Odd. I don't think I mentioned that in my comment.

      But what the hey, obviously in your view it would be impossible for them to issue unbundled patches the way they did for a couple of decades before this change.

      It's sad that MS has fallen so far that they no longer have the ability to do that. I guess Nadella et al just aren't up to the standard of the Gates/Balmer years.

    7. Re:Microsoft only have themselves to blame by toddestan · · Score: 1

      There are literally hundreds of Windows 7 patches, and hundreds more hotfixes. That's billions of possible combinations of pick-and-choose updates. How do you propose that Microsoft test these possible combinations?

      I would propose that once they've got a large enough number of patches, they could roll them all into one large patch which could be used to both apply all those patches at once, and to "reset" the state of the OS so that everyone is once again running the same base version. They could call these large patches something like a "Service Pack".

  32. Fuck you. by Anonymous Coward · · Score: 0

    "self-updating with zero input required from the user"

    If that's the default, great. If it's the ONLY way, like Windows10, Google Chrome, and yes, Mozilla (try to permanently disable Auto-Update and keep the mostly just broken Mozilla-update-service away from windows, i dare you), just go fuck yourself. It's one thing trying to patch as much of the dumb-users as possible, it's another thing to *force* it upon users...

  33. Patches are just like vaccines... by Noishkel · · Score: 4, Insightful

    Except if vaccines failed as much as a Microsoft patch did there would be no doctors... because people would be shooting them in the street.

    Yeah, yeah... I can already hear the autistic fast typing from some keyboard warrior looking to 'correct' me on this one. But sorry... Microsoft no longer has any credibility to tell people what to do with their machines. The entire roll out of Windows 10 has been nothing but train wreck after train wreck. And you know what? Even if we get the occasional virus it's still better than having to deal with the rest of the continuing train wreck that is Microsoft. People are just going to have go back to the old day when people had to actually learn how to protect themselves. Instead of waiting on the industry to sell you a next generation of device that 'might' be eventually patched.

    1. Re:Patches are just like vaccines... by Anonymous Coward · · Score: 0

      Your attitude is fine and supportable for knowledgeable and proactive computer users. It is not fine for Grandma, the hyperactive Twitter generation, and endless people who merely want e-mail, Facebook and the internets.

      The OP is correct but could maybe have explicitly shaded his meaning a bit. If you want/need to turn off active patching, you already know who you are. Don't turn off WUS on Grandma's computer though.

    2. Re:Patches are just like vaccines... by Anonymous Coward · · Score: 0

      > How could losing all your data to ransomware be better than letting Windows patch itself?

      Because the ransomware can be prevented if you disable services you don't use (in this case, and many others), and generally relies on some other mistake. Meanwhile, if you let Windows patch itself, it will eventually transform itself into a massive ball of waving tentacles and hazards.

      Even if you take no particular precautions beyond the most basic (connecting through a router instead of direct internet connection), you, personally, will be immune to the vast majority of wormable exploits.

      Meanwhile, turning on windows updates forces reboots while you are doing something, often something that can't be save-stated (render, video game), and definitely compromises your privacy, if that is a thing you care about.

    3. Re:Patches are just like vaccines... by mattventura · · Score: 1

      Easy: if MS takes private information, I can't put that cat back in the bag. If ransomware effectively deletes all my files, worst case I can treat it like a failed drive and restore from a backup.

  34. why do you use windows? by Anonymous Coward · · Score: 0

    I am in favour of auto-updating Windows, don't get me wrong; however, it could be catastrophic if anyone ever manages to figure out a way to spread a virus via the auto update.

    I'm not sure the technical route someone would have to take to do this; If, perhaps someone could somehow infect a DNS server to treat an infected server as a Microsoft update server.

    You walk around with a loaded gun pointed at your head and you hope that nobody pulls the trigger

    The brainwashing has mellowed your perspective to the point where you barely even care

  35. That assumes Windows update works at all by Anonymous Coward · · Score: 0

    On none of our Vista systems, which we still have to run because Microsoft is just so horrific and backwards compatibility plus it's what our customers run that create the most support tickets, we are forced by Microsoft to use Vista. Updates hang at 0%. We've wasted hundreds of hours trying to get updates to run. I think they last time they worked as April 11, 2017. After the last Microsoft-created problem, we've had half a dozen people hammering on Vista machines trying to figure-out a work-around for Microsoft decision to break updates to their OS. It's great to say you shouldn't disable updates, but it is Microsoft that is disabling them.

    1. Re:That assumes Windows update works at all by Anonymous Coward · · Score: 0

      Sucks that they can't get their act together well enough to make updates work.

      Keep mucking with Vista. I wasted about nine hours on the weekend trying to get Vista updated on my computer. I finally got it to work. I have no idea what actually fixed the problem since I tried so many things.

    2. Re:That assumes Windows update works at all by Z00L00K · · Score: 1

      One of the more common things that causes problems with the updates is if the clock on your computer isn't correctly set, and that includes timezone and daylight saving.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    3. Re:That assumes Windows update works at all by Anonymous Coward · · Score: 0

      That is good advice especially with Microsoft's constant NTP server problems this year, but that isn't the problem this time. I have to manually set my time every time I wake from sleep since Microsoft doesn't update the clock. If I put it to sleep at, for example, 9am on a Saturday then wake it on 11am Monday, then Microsoft will leave the time set to 9am Saturday even though it's Monday. I've gotten good at always remembering to set the time by hand since Microsoft can't even get damn NTP right.

    4. Re:That assumes Windows update works at all by Anonymous Coward · · Score: 0

      Ever wonder why that is? I've read that having accurate local time helps with the NSA snooping.

  36. Problems Caused by Updates vs Caused by Attacks by Anonymous Coward · · Score: 5, Interesting

    The number of problems caused by installing Windows updates for our IT department: THOUSANDS
    The number of problems caused by holes left in the Windows OS that an update or patch supposedly has fixed: 20

    Easy decision.

  37. A bit conflicted by roc97007 · · Score: 3, Interesting

    I don't think I've ever worked at a company that had "automatic updates" turned on. The reason being, company ecosystems tend to be predominantly all the same hardware, same Windows version and same patch level, and a bug in an update that affects that particular collection of hardware and software can take an astounding number of seats offline. (In much the same way a biological virus can take out an entire species if they're not sufficiently genetically diverse.) So yeah, no. Companies that want to stay in business don't do that. Of course, they *do* have a team that tests updates in a lab and sends out validated updates to the rest of the company, often a subset of what Microsoft spews out.

    I do something similar at home. We have three Winders boxes, and none of them have auto update turned on. Every week or so, I look at what updates are available, and apply at minimum the security updates to the least used of those three boxes. If it survives a reboot and some reasonable amount of smoke testing, I install on the game machine, and if that works out ok, after a day or two I'll install it on my own workstation. I have to take care because my machine is (a) my only conduit to my "day job", and (b) my main workstation for my side-business. I can't afford to be down because Microsoft botched a patch any more than any large company can.

    So yeah, security updates are important. Vital, even. But that doesn't mean you just install every update the moment it becomes available. An important part of "security" is "availability". And that's just as important as "confidentiality" and "integrity".

    Another contributor had it right -- there should be a way to auto install security updates only. So if Microsoft botched a driver update and it renders unbootable a certain brand of PC running a certain brand of video card, it's less likely to take large numbers of users offline.

    I know there are essential and optional updates (or whatever words they use) but most updates are considered by Microsoft to be essential.

    And this doesn't even address compatibility of updates with installed applications. You know, the software you use to actually do work.

    All that said, it does seem like Microsoft is doing a better job vetting their patches before release than they did the earlier part of this century. But being burned a few times breeds caution.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    1. Re:A bit conflicted by Anonymous Coward · · Score: 0

      "there should be a way to auto install security updates only" - there is. It's a group policy setting.

  38. Consumers Yes, Business No by sqorbit · · Score: 1

    Making a blanket statement like this is not really valid. I think for the average consumer desktop that searches the web, maybe plays some games and does some basic office stuff it is probably a good idea not to turn off updates. Telling a corporation that they absolutely need to update every time Microsoft releases something is probably a bad idea. The better advice would be for companies would be to educate themselves, hire people that know what they are doing, or hire outside contractors that are reputable and educated to handle their security. Simply saying "Update Windows" does not define a good security policy.

    --
    Sent from my TARDIS
  39. Patch failure rate... by oic0 · · Score: 1

    If you're managing hundreds or thousands of systems, you've always got a few with failed Windows updates. It's a never ending battle. It's nigh impossible to stay 100% up to date. THAT is Microsofts fault.

  40. No way do I have updates on in production... by bobbied · · Score: 1

    No way! I will NOT allow windows to just install updates into my production environment... Yes, I know it is a risk to leave systems unpatched, but given the frequency of Microsoft breaking my systems with their patches, the risk of downtime from a security flaw is usually LESS than the risk of having some exploit that causes down time.

    However.... This doesn't mean I don't pay attention to the released updates. Oh no, we have a test system where we DO let them load as soon as they are released and a functionality and performance test that we run as soon as we can. We update only after successfully passing the test suit (and fixing any issues we found), which sometimes can take more than a week. I choose when the updates go out, not Microsoft.

    So, for mission critical applications and systems, I recommend you NOT enable updates.... But I also recommend that you have resources available to test the updates and try to stay reasonably current with Microsoft's patches....

    But, that's business.... At home? I generally don't turn on updates either... But I'm aware of what's coming out, so I generally know when the really important stuff gets released so I will update accordingly... Of course, I'm in charge of the In-Laws computer maintenance needs and they live in another state. For them, I have automatic updates turned on, at least until things get hosed and I have to make a multi-state trip to get them going again.

    --
    "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
  41. Zero input from the user by Anonymous Coward · · Score: 0

    > This is how consumer software these days should be: self-updating with zero input required from the user

    I have no problem with making it "zero input from the user", *IF* it was also zero impact on the user. Meaning, no inconvenient reboots that'll shut down 50 opened windows that won't come back.

  42. Mr Hunt should talk to Microsoft... by QuietLagoon · · Score: 1

    ... and tell them to stop using the security update distribution channel to trick me into doing an unwanted operating system update. Recently, Windows Update has looked a lot like malware in the way it operated to trick customers into upgrading to Windows 10.

  43. 100% Microsoft's fault for forcing Windows 10 by Thud457 · · Score: 5, Insightful

    Don't use the channel for security updates to force advertising on your customers, just don't.

    --

    the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

    1. Re:100% Microsoft's fault for forcing Windows 10 by ITRambo · · Score: 1

      I pictured managers at MS seeing the comment and laughing their asses off. They just don't care what anyone, other than their largest Enterprise customers, wants anymore.

    2. Re:100% Microsoft's fault for forcing Windows 10 by NormalVisual · · Score: 1

      They don't even care about the enterprise customers. My employer does about $8 billion in business every year, and we're still on Win7 because of all of the MS shenanigans.

      --
      Please stand clear of the doors, por favor mantenganse alejado de las puertas
  44. Re:There should be a separate "Security Updates On by Anonymous Coward · · Score: 1

    There is, it's the "critical updates only" checkbox.
    The problem isn't the lack of said checkbox, it's the fact that Microsoft doesn't respect that checkbox and considers all sorts of marketing fluff and malware to be "critical"

    But they are critical updates from Microsoft's point of view: critical to marketing.

  45. Windows update took 100% CPU usage. by Anonymous Coward · · Score: 0

    (Or rather 25% since this system could use four threads.)

    I had to shut it down for while until I got around to figuring out what the heck was wrong with it.

    It turns out I had to clear the files out from C:\Windows\SoftwareDistribution.

    It took a while to find this out, since it isn't the first piece of advice I came across. Microsoft's own Windows Update diagnostic tool doesn't clear out these files and other solutions involved messing with tons of services via the command prompt.

  46. also... by Comboman · · Score: 5, Insightful

    also, doctors don't break into your house in the middle of the night to give you a vaccine (and snoop around your house while they're there).

    --
    Support Right To Repair Legislation.
    1. Re:also... by RespekMyAthorati · · Score: 1

      (and snoop around your house while they're there).

      And ever after.

  47. I've been 11++ yrs. "patched"/proof vs. wana by Anonymous Coward · · Score: 0

    See subject: Wana can't get to a setup w/ no SMB/port 445 access secured via CIS Tool (highly esteemed & took fixes from "yours truly" too) & does only SMB2 or better + I don't run Server or Workstation services, Client for Microsoft Networks (any AD stuff too), File or Printer Sharing OR NetBIOS over TCP/IP soliciting connections (wastes for me - no home LAN/network) saving CPU/RAM (& other I/O wasted along w/ longer networking packet train data) which automatically protects me right there 2 ways:

    1.) Nothing to get a 'handle' on to connect to via a port 445 listener in the 1st place & EVEN IF it did?

    2.) I am SMB2++ secured.

    * FOR SINGLE SYSTEMS NOT ON A NETWORK @ HOME (no LAN)? It works.

    It's ALL here how to do it FROM 11++ yrs. ago too no less "A look @ the future - & the FUTURE was THEN" + got me paid too, will wonders NEVER cease https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&btnG=Google+Search&gbv=1/

    APK

    P.S.=> Yes - "I AM LEGEND" immune here - didn't need Windows Update to do so (not knocking update though) ... apk

  48. Microsoft/NSA, trust either of them? by Anonymous Coward · · Score: 0

    Microsoft has no basis for bitching about people turning off Windows Updates when they were the reason it was turned off. Ever changing privacy settings, re-enabling adware/nagware/malware/updates after the user had disabled them? Everything or nothing updates where we can't see what you're doing?

    NSA hiding exploits that got leaked. You want to ban encryption for consumer products because we're supposed to trust you're the good guys and will never leak the backdoor you want created to the bad guys?

    No, both parties made this mess, each is hoping to blame the other.

    I'm not buying what either of them is trying to sell.

    1. Re:Microsoft/NSA, trust either of them? by JohnFen · · Score: 2

      No, end users made this mess and are hoping to blame Microsoft.

      No, Microsoft made this mess and you are blaming end users. If security updates were implemented and deployed with care, and if Microsoft behaved in a trustworthy way, then very few people would object to their being automatically installed.

    2. Re:Microsoft/NSA, trust either of them? by Pentium100 · · Score: 1

      Microsoft is the cause why a lot of end users disable updates. There is/was a setting to only install security patches and not install the rest. Microsoft then made telemetry and Windows10 appear as security patches so they would get installed. The users disabled automatic updates and started installing security patches manually (those users who bothered to do it, anyway). After that, Microsoft stopped providing patches individually, so that if you wanted to install a security patch, you had to install telemetry and GWX as well. So the users stopped installing updates completely.

      If Microsoft made it possible to only install security patches (and chose which ones, I may not need a patch that protects my computer from a local user) and preferable made it so that not every patch required a reboot, I think more people would update their OS. Of course, now that Microsoft has lost the trust of its users, it may be extremely difficult to earn in back.

      I chose to uninstall the protocol from my Windows 10 computer (Microsoft published workaround) instead of installing the patch because I do not trust the patch to not re-enable telemetry on my PC.

    3. Re:Microsoft/NSA, trust either of them? by BronsCon · · Score: 1

      Microsoft is the cause why a lot of end users disable updates. There is/was a setting to only install security patches and not install the rest. Microsoft then made telemetry and Windows10 appear as security patches so they would get installed.

      So you're saying that end users began disabling updates on Windows XP in 2001 because of something Microsoft did with Windows 10 in 2015?

      Nah. Don't think so.

      Before Windows 10 was released, end users spent 14 years making it clear they can not be trusted to keep their systems up to date with patches for critical vulnerabilities, so we've now all lost the ability to decide for ourselves. Even in the face of the option to only install critical (security) updates, people entirely disabled them, then never went back and manually applied patches which truly were critical, consistently enough over the course of a decade and a half that the end result was a mass of shit-spewing bot nests (which then formed shit-spewing botnets) and the general idea that Windows was inherently insecure, when the reality is that a patched Windows system is no more or less secure than any other fully patched system and, with those security patches regularly installed, the shit-spewing botnet problem would largely not exist.

      We've been dealing with that particular problem for as long as we have precisely because users chose not to install updates, and have made that choice for far longer than Windows 10 had been out.

      If Microsoft made it possible to only install security patches

      I like where this is going; we might see eye-to-eye on this after all...

      (and chose which ones,

      Oh, so close. The problem, here, is that when you can choose which updates to install, you can choose to install no updates, which is what people have been doing since 2001 when they were first given the option, which is why we can no longer make that choice.

      I may not need a patch that protects my computer from a local user)

      Right, because nobody every breaks into buildings and messes with (or steals) computers. You may be the only intended user of a system, but that doesn't stop someone else from gaining access. There is also the possibility of a trusted software vendor getting hacked and their application ending up with some code that exploits that "local user" vulnerability you didn't patch. You use that software regularly, you install the bad update, you run the application... you are the local user and now you've been exploited. Guess you needed that patch, after all.

      and preferable made it so that not every patch required a reboot,

      So many patches don't, actually. It just seems like they all do because there's usually (but not always) one that does in every update set.

      I think more people would update their OS.

      History has shown us otherwise.

      I chose to uninstall the protocol from my Windows 10 computer (Microsoft published workaround) instead of installing the patch because I do not trust the patch to not re-enable telemetry on my PC.

      Link, please? Actually, nevermind, I'm calling bullshit either way. You don't trust Microsoft's patch to do the job, but you trust their manual procedures? And you trust that no part of the system will act to protect the services you've removed? You do realize that Windows has had system file protection (and automatic repair and restoration of said files) since Windows 7, right?

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    4. Re:Microsoft/NSA, trust either of them? by Pentium100 · · Score: 1

      Right, because nobody every breaks into buildings and messes with (or steals) computers.

      If somebody broke into my home and stole my computer, I would be more unhappy because they stole my computer and not because now they can hack it (they can just pull the HDD out and connect it to another PC or boot my PC from a live CD if they want to access the data).

      There is also the possibility of a trusted software vendor getting hacked and their application ending up with some code that exploits that "local user" vulnerability you didn't patch. You use that software regularly, you install the bad update, you run the application... you are the local user and now you've been exploited. Guess you needed that patch, after all.

      And in Windows XP days my user was the admin - there was no need to exploit privilege escalation bug if the program was bad. Now my user is still the admin, but UAC sometimes pops up asking for my approval.

      OTOH, if I opened a wrong email attachment, it could encrypt my data even if running as limited user (me) on a fully patched system (or Linux). So, on a single user computer it is kinda pointless ("The malware encrypted all my data, but at least the system files are unaffected, yay!").

      History has shown us otherwise.

      So, with today's forced updates, everybody updates more often? Even Windows 7 or 8? I used to update my Windows 7 PCs (not very often, but I did), until GWX and telemetry showed up. And now I cannot even pick and choose to not install telemetry, so Windows Update got disabled. Though I will install the specific patch on my Windows 7 and Windows XP laptops as those may be exposed to the internet without a router.

      I would say that when telemetry and GWX came out, more people disabled updates if they wanted to avoid installing Windows 10.

      Link, please?

      https://technet.microsoft.com/...

      You don't trust Microsoft's patch to do the job, but you trust their manual procedures? And you trust that no part of the system will act to protect the services you've removed? You do realize that Windows has had system file protection (and automatic repair and restoration of said files) since Windows 7, right?

      Microsoft's patch means running their (new) code on my computer. It may just do what is promised, but it may also flip some registry or group policy setting that disables telemetry (enterprise edition). I do not know either way, so I would be back to sniffing packets on my router looking for any communication between that PC and Microsoft.
      On the other hand, I expect the manual workaround to work as promised, because I really doubt that Microsoft had the foresight to make uninstalling SMBv1 support also mess up the other settings.

    5. Re:Microsoft/NSA, trust either of them? by BronsCon · · Score: 1

      If somebody broke into my home and stole my computer, I would be more unhappy because they stole my computer and not because now they can hack it (they can just pull the HDD out and connect it to another PC or boot my PC from a live CD if they want to access the data).

      Why, when full disk encryption is so easy?

      And in Windows XP days my user was the admin - there was no need to exploit privilege escalation bug if the program was bad. Now my user is still the admin, but UAC sometimes pops up asking for my approval.

      Ok, so you don't care about security.

      OTOH, if I opened a wrong email attachment, it could encrypt my data even if running as limited user (me) on a fully patched system (or Linux). So, on a single user computer it is kinda pointless ("The malware encrypted all my data, but at least the system files are unaffected, yay!").

      Unless you run backups as an admin user; then, at least, it couldn't encrypt your backups without privilege escalation.

      I would say that when telemetry and GWX came out, more people disabled updates if they wanted to avoid installing Windows 10.

      Why do all of you idiots act like telemetry is something that's brand new? Not being able to turn it off is brand new, but it's nothing new at all and most of you have probably had it enabled this whole damn time. The best part? Many of you probably still have it enabled! Hell, most of you probably wanted it enabled and are just now starting to even care because you're losing the ability to turn it off any everyone is talking about it.

      Microsoft's patch means running their (new) code on my computer. It may just do what is promised, but it may also flip some registry or group policy setting that disables telemetry (enterprise edition). I do not know either way, so I would be back to sniffing packets on my router looking for any communication between that PC and Microsoft. On the other hand, I expect the manual workaround to work as promised, because I really doubt that Microsoft had the foresight to make uninstalling SMBv1 support also mess up the other settings.

      Oh, you were talking about disabling SMB; you mentioned telemetry, so that's what I thought you were talking about. I was confused, as I was not aware that Microsoft ever released an official method (manual or via patch) to remove telemetry from Windows 10. Hell, it's still not clear until you read the last sentence of that paragraph, as you still talk about disabling telemetry.

      You may be all over the place but, well hey, you're keeping the price of my Reynolds stock high. That is, unless you buy generic tinfoil.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  49. I can't take cumulative updates. by Anonymous Coward · · Score: 0

    I built a Windows 8.1 gaming desktop in Oct 2014. In Dec 2014, the keyboard and mouse would randomly stop working for about 10 seconds. This would happen a few times an hour. When you're online gaming, that generally means you die.

    After three months of troubleshooting and frustration, the root cause was the Windows Nov 2014 cumulative patch. After rolling back that update and disabling automatic updates, I've had no issues. Every few months, I'd only take critical security patches.

    Unfortunately, starting last year, Microsoft doesn't release security patches by themselves. You have to take the cumulative patches. 2.5 years have gone by, so I'd hope they fixed whatever bug I was experiencing, but I just can't risk taking the new cumulative patches! So my computer goes unpatched.

  50. Windows users have two options by JoeyRox · · Score: 4, Insightful

    Option A) Turn automatic updates ON and risk Microsoft making your machine unusable due to a faulty update
    Option B) Turn automatic updates OFF and risk Microsoft making your machine unusable due to the absence of a security update

  51. Except by ArhcAngel · · Score: 1

    When I go to update it just spins for hours and when it finally does update my tablets keyboard no longer works.

    --
    "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
  52. MS thinks "update" means "upgrade" by mugnyte · · Score: 1

    If an MS Update actually updated just the software you have (taking into account anything you've disabled or removed) - then this feature would be useful. As-is, it seems to Upgrade, Re-enable, Reset the OS to a state that is disruptive. This is not what such a feature should be doing. We've seen this before when updates required clicking (no scripting mode) and when updates required accepting EULA's that didn't allow a "No" - you were left with the half-way install. Each time, MS had to learn that their platform would be far more secure if they kept it simple. When they fail doing this well, the feature is disabled. The platform silently becomes a haven for compromised equipment - and a continued poor reputation for service. Has nobody written down the requirements for this type of tool over there? Or more clearly: The requirements should include what NOT to do as well as what is required. I'm very surprised, given that MS wants to be the go-to OS for corporate use. Every OS has flaws and attacks, but making patches into sales gimmicks is what pushes people away.

  53. Generally NOT Sound Advice (FTFY) by Anonymous Coward · · Score: 0

    Having been a victim of M$ updates over the years, I can understand why users want to be in complete control of the update process! every update seems to break something, and requires multiple reboots. I have heard that with the Win10 Spy-Virus, updates can occur at any time, most often in the middle of the user doing something important. I have also heard that some updates change user's settings, and interrupted work is not saved when the update starts.

    So now users have a choice of taking the chance of getting hit with ransomware, or taking the chance having M$ interrupt important work, change user settings, or make the users computer unusable (broken/wrong drivers). Some choice!

  54. like just a little bit pregnant by Anonymous Coward · · Score: 0

    "disable as much of this as trivially possible" is another way to say "not disabled". And your comment that enabling auto updates in Win 7&8 will also infect you with MS spyware that cannot be disabled is precisely why this person said they have disable auto update on even their older Windows installations.

    MS *is* largely to blame for the severity of this because they were put in a position of trust and then abused the shit out of it.

    1. Re:like just a little bit pregnant by BronsCon · · Score: 1

      Playing devil's advocate, here...

      By disabling automatic updates in earlier versions, before Microsoft played these games, the end users put themselves in a position of trust, in control of the security, stability, and performance of not only their own computers, but every computer connected to the internet, regardless of OS or version. Those same users also put themselves in a position of trust regarding the perception of the security of Microsoft's OS.

      Those users failed miserably to live up to the position they chose for themselves.

      As a result, Microsoft have, and perhaps rightly so, removed the option that previously allowed those users to put themselves in that position.

      It does have the side effect of screwing those of us who both disabled automatic updates and manually installed updates within a reasonable timeframe (or took sufficient security measures to mitigate the risk of not having installed updates). Now, we no longer have that choice and yes, that does suck.

      It sucks a bit less, though, when you take a moment to realize that, over time, the mess that is older versions of Windows with Windows Update disabled and manual updates literally never applied will clean itself up as those systems naturally remove themselves from the environment, either through obsolescence or hardware failure. They'll be replaced with new systems on which the user can't disable updates irresponsibly (that is, turn it off and "forget" to ever manually install updates that are actually important) and we'll all be better off for it.

      Yes, even those of us who are suffering with forced updates now.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    2. Re:like just a little bit pregnant by Gr8Apes · · Score: 1

      Playing devil's advocate, here... By disabling automatic updates in earlier versions, before Microsoft played these games,

      I believe they started playing those games with the second or third update. I can't tell you exactly which update it was, but it was way way early in the game and they fubarred lots of systems. Something about an internal MS driver updating and overriding third party drivers IIRC. They also have always pushed new features in "updates".

      --
      The cesspool just got a check and balance.
    3. Re: like just a little bit pregnant by BronsCon · · Score: 1

      Second or third update to...???

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    4. Re: like just a little bit pregnant by Gr8Apes · · Score: 1

      Second or third update served through WU. That was a long time ago, so I could be off by a couple of updates as I don't keep records of the number of times MS screwed me anymore.

      --
      The cesspool just got a check and balance.
    5. Re: like just a little bit pregnant by BronsCon · · Score: 1

      Update to what? Not from where. Windows XP? Because that's what I was talking about... you know, when I said "disabling automatic updates in earlier versions" and "before Microsoft played these games".

      If people hadn't done that, then not held up their responsibility (to the rest of the users, not to themselves or Microsoft) to install security patches to ensure their machines didn't become shit-spewing bot nests, perhaps Microsoft wouldn't have taken away the ability.

      You seem to only be able to mentally go as far back as the release of Windows 10, but we're discussing things that happened long, long before then, which lead to many of Microsoft's (admittedly ill-thought) decisions regarding Windows 10. Logical fallacy: attributing decisions made prior to an event to occurrences which followed. Correct that, then we'll talk.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    6. Re: like just a little bit pregnant by Gr8Apes · · Score: 1

      I'm talking XP for this one. I thought that was obvious, as that's where WU on the client started? WU always had the ability to do exactly what MS has completed with Win10, so disabling it way back then was the intelligent move for systems admins that needed to keep things running and avoid fire drills. Had MS followed a sensible update process with mandatory critical patches that only fixed holes and with proper warning if it would fubar an API which, admittedly, can happen, then people would have trusted them. As it was, MS acted like they knew better what should run on your computer and treated the updates as en blanc permission to reconfigure whatever they deemed appropriate. So admins started disabling this WU process, word got out, and many others saw their problems go away when they disabled it, so it spread. If disabling WU hadn't fixed something, then people would have stopped disabling WU.... So who do you blame?

      In truth, MS systems can be semi-secure at least from the bot-net spewing bits if MS had a sensible configuration and firewall in place on their OS. Ideally you'd have a separate firewall between you and the internet, but not having one on system caused massive issues. (I'm sure you recall the study that dropping a new XP system without an external firewall on the internet to update it via WU would infect it before it could even start downloading?) Also running all processes at System was another problem, directly with XP and still an issue with W10, although it's a touch more difficult to execute an overflow as System. (This is the root of most if not all of MS's exploit issues with their apps)

      --
      The cesspool just got a check and balance.
    7. Re: like just a little bit pregnant by BronsCon · · Score: 1

      I'm talking XP for this one.

      I don't recall early issues with WU, actually. I do recall being surprised that such a new system seemed to work quite well out of the box.

      I thought that was obvious, as that's where WU on the client started?

      One would think, but you seemed to be fixed on more recent events so I wanted to be sure.

      WU always had the ability to do exactly what MS has completed with Win10, so disabling it way back then was the intelligent move for systems admins that needed to keep things running and avoid fire drills.

      We actually agree on this point. Where it falls apart is that, while sysadmins would go back and eventually install updates after testing them, end users were disabling the updates, then not installing them later.

      WSUS or no WSUS, sysadmins can still disable automatic updates on Win 10 Enterprise, so nothing changes for a company that has at least 5 computers and buys the right version of Windows (which is no more expensive, mind you; it gets cheaper in a volume license). The same actually applies to someone with a single computer, if they're willing to pay the 5 license minimum.

      I've always been one to disable updates, myself. I've also always been one to manually install them. That is not the problem! The problem is when people do the first step, but not the second!

      Again, we're not talking about sysadmins, here. We're talking about end users who really have no business managing their own updates.

      In truth, MS systems can be semi-secure at least from the bot-net spewing bits if MS had a sensible configuration and firewall in place on their OS. Ideally you'd have a separate firewall between you and the internet, but not having one on system caused massive issues.

      Well, then, I guess it's a good thing one has been included since XP SP2. Mind you, it didn't really get good until Vista, but it was there. It's really a non-issue wince Vista, though, as one has been included, with a "deny by default" configuration, since Vista.

      Ideally you'd have a separate firewall between you and the internet, but not having one on system caused massive issues.

      Well, yeah, the same can be said of any OS, though, if no firewall is enabled. In fact, hardware firewalls should really be the norm (even cheap routers include basic firewall functions now), especially in the face of Intel's AMT exploits, which are OS-agnostic; even the best software firewall won't stop that from being exploited as the ME grabs the packets and the OS never even sees them.

      I'm sure you recall the study that dropping a new XP system without an external firewall on the internet to update it via WU would infect it before it could even start downloading?

      Actually, no, I didn't know any study was necessary. Blaster was so bad a friend of mine ended up having to reinstall 4 times to get the patch before infection occurred. I was there, watching and laughing the whole time.

      Also running all processes at System was another problem, directly with XP and still an issue with W10, although it's a touch more difficult to execute an overflow as System.

      Was, was, was, was, was. All I hear from you is a stream of "was". Really, only system services run as System anymore; it's something they started fixing with Vista and it's taken some time to get all the software vendors on board with running their applications as the user, but we're finally there. If it's still an issue on your Win 10 system, talk to the app vendor who hasn't been keeping up; Microsoft made it a pain in the ass to keep following the old and insecure model and that's really all they can do without everyone bitching about how they broke that one mission critical application.

      Yes, the problem dates

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    8. Re: like just a little bit pregnant by Gr8Apes · · Score: 1

      We actually agree on this point. Where it falls apart is that, while sysadmins would go back and eventually install updates after testing them, end users were disabling the updates, then not installing them later.

      And my point is that the same forces driving sys admins to disable it drove regular users to disable it. I do agree with your conclusion about them not following through afterwards, however the fault remains with MS in the first place, for forcing more than necessary down users throats. By way of comparison, Apple AFAIK has only used the mandatory push once. In over 5 years.

      WSUS or no WSUS, sysadmins can still disable automatic updates on Win 10 Enterprise, so nothing changes for a company that has at least 5 computers and buys the right version of Windows

      And with Win10, Enterprise or not, you will be forced to accept all updates within a 9-12 month window. I'm too lazy to look it up again for precision. It is no longer your choice. You will upgrade, soon or sooner.

      Well, then, I guess it's a good thing one has been included since XP SP2. Mind you, it didn't really get good until Vista, but it was there. It's really a non-issue wince Vista, though, as one has been included, with a "deny by default" configuration, since Vista.

      I recall some vague thing around SP2+ that while things were better, it was still best to not connect directly without a router + firewall in place. You are correct that once Vista came out, that concern seemed to diminish significantly.

      especially in the face of Intel's AMT exploits, which are OS-agnostic; even the best software firewall won't stop that from being exploited as the ME grabs the packets and the OS never even sees them.

      Well, if you have hardware with AMT in it. :)

      Also running all processes at System was another problem, directly with XP and still an issue with W10, although it's a touch more difficult to execute an overflow as System.

      Was, was, was, was, was. All I hear from you is a stream of "was". Really, only system services run as System anymore; it's something they started fixing with Vista and it's taken some time to get all the software vendors on board with running their applications as the user, but we're finally there. If it's still an issue on your Win 10 system, talk to the app vendor who hasn't been keeping up; Microsoft made it a pain in the ass to keep following the old and insecure model and that's really all they can do without everyone bitching about how they broke that one mission critical application.

      I can honestly tell you it's still a problem with Server 2012. It has little to do with the fact that the app process has a lower than system token. If any DLL used by the app, or, honestly, if the app can load a DLL, you can execute any arbitrary code with System privs. Like I mentioned, it used to be simple, it's harder now, but by no means impossible. The problem I'm highlighting is the core issue with Windows itself - it's insecure by design. That design has not changed since 2012 or, in fact, since NT4, in any meaningful way. Bandaids are starting to lean.

      Yes, the problem dates back to early versions of Windows, but the problem persists due to recent versions of applications.

      As mentioned above - it has little to do with the apps. It's actually an inherent "feature" if you will of the OS.

      Microsoft could fix it in the next release, but all of those applications that rely on it (still, even though they should not) would break and users would blame Microsoft, rather than the application vendors. Like you're doing right now.

      Hopefully I've laid clear why the blame is appropriately laid at MS's feet.

      --
      The cesspool just got a check and balance.
    9. Re: like just a little bit pregnant by BronsCon · · Score: 1

      And with Win10, Enterprise or not, you will be forced to accept all updates within a 9-12 month window. I'm too lazy to look it up again for precision. It is no longer your choice. You will upgrade, soon or sooner.

      I can't find anything pointing to that so, really, if you could be so kind as to look it up and provide a link, that'd be great. Otherwise, well, I'm having a really hard time trusting your "facts" when I can't verify them; I have sources for what I say, and I provide them when I make my more unbelievable claims, but I see none from you. Without some indication that your "facts" are anything more than conjecture, there's not a whole lot of point continuing this conversation.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    10. Re: like just a little bit pregnant by Gr8Apes · · Score: 1

      Sure, this has some discussion of when Business/Enterprise customers can expect to see updates, but doesn't relate the "forced" aspect. Note that there is no statement that they can be avoided. There's wishy-washy wording in there. This, while older, has the verbiage I remember being finalized last year. Another story implying there's no stopping the upgrades, but, like you, I cannot find the original smoking gun that made me walk away from Win10 as a viable OS. That was over 2 years ago, and digging through thousands of google stories on "forced enterprise windows 10 upgrades" isn't what I am doing today.

      --
      The cesspool just got a check and balance.
  55. downside by Anonymous Coward · · Score: 0

    The very last Windows 10 update bricked my work laptop. It took most of a day to recover. At least it only cost me time. Backup, backup backup!

    1. Re:downside by Anonymous Coward · · Score: 0

      At least it only cost me time.

      Your employer only pays you for your time too.

  56. Didn't MS just block updates on Win7/8 for Ryzen? by future+assassin · · Score: 3, Informative

    Yah blame the user for the virus exploits and not the vendor that created the software with huge holes and the vendor who is blocking updates when running new gen CPU's on older OS versions just to try and push people to W10.

    --
    by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
  57. Windows Updates by StonyCreekBare · · Score: 2

    The last time I left updates enabled, update started updating my machine and demanded a reboot in the middle of a major corporate presentation in front of a large audience. This is UNACCEPTABLE behavior!

    Windows Updates (1) Constantly reset browser preferences, (2) Frequently break hardware drivers, and (3) Often interfere with critical, urgent work tasks. Don't tell me not to turn them off! Don't tell me not to tell others to turn them off! NOT GONNA HAPPEN!!!

    Windows Updates should be TURNED OFF, during all business / production usage. Then updates should be enabled/installed manually during weekends, vacations or other non-critical times. I DECIDE when my machine can be down for maintenance. Not Microsoft. The Updates STAY OFF, until I purposely enable them when I am willing to allow time for reboots, and have the time to restore my machine to proper configuration and operation afterward.

  58. umm NO! by Anonymous Coward · · Score: 1

    I tell people to turn off the automatic downloading and installing of updates all the time. Instead of having updates shoved down their throats i TEACH people how to look up the updates that microsoft is putting out and how to decide whether or not those are updates that they need. I also teach people how to conduct regular backups in case they do miss something.

    Because blindly accepting anything from anyone is a bad idea. period. full stop! It encourages ignorance and helplessness, teaching people how to use these tools we call computers is the only way to stop shit like this and in the cast that something does happen a full and proper backup is only a wipe and reinstall away.

    also how are the words of a microsoft employee "news for nerds" we already have enough shills that post int he comments.

  59. then stop pushing useless updates that break stuff by Anonymous Coward · · Score: 0

    Just don't.

  60. do you even lift? by Anonymous Coward · · Score: 0

    I have a windows 10 laptop. It's great, but I primarily use Linux on the desktop. So I turn it on once or twice a week. This usually involves an update of some sort, deferred until the battery drains and I have to plug it in. Every updates seems to involve exercising the fan for two hours doing god knows what because process monitor is too vague and there's no notification of what's going on.

  61. Windows 10 automatic install by mgandalf · · Score: 2

    Tell Microsoft to stop pushing patches which install Windows 10 without my agreeing upon it, and I'll let Windows update run. No, I suppose Microsoft stopped with the whole Windows 10 thing a few months back, but there's now a trust issue I personally have to get past. The fact of the matter is, I don't trust Microsoft anymore.

    - Mark.

    1. Re:Windows 10 automatic install by cfalcon · · Score: 1

      It is only Microsoft's fault that Windows Update is not trusted. It is a usability issue and a privacy nightmare. It is Microsoft's fault that there is no setting to get security fixes without also by default slurping down megabytes of spyware and telemetry downdates.

      Microsoft is fully to blame. Disable Windows Update. Manually apply security patches. This is necessary because Microsoft is not willing to provide such a list universally to allow this correct and common use case. This omission is absolutely deliberate, as is their newly obfuscated KB notes.

  62. Take the ransomware out of WU by istartedi · · Score: 1

    WU is ransomware. It's just a different kind of ransom.

    WannaCry: "send us $300 in BTC or we'll kill your data if you don't have backups".

    WU: "Send us personal data via telemetry, take un upgrade you don't want, let us chew your CPU and interfere with your games. If you don't, we'll force you to do a lot of busy work to separate the security wheat from the marketing chaff, and if you don't do it right you'll be vulnerable to things like WannaCry".

    MS bears a lot of blame until they stop holding the familiar Windows experience hostage, and return it to us without forcing us to pay a ransom.

    --
    For all intensive purposes, "whom" is no longer a word. That begs the question, "who cares"?
  63. Broken drivers, AND broken updates break stuff by Anonymous Coward · · Score: 3, Interesting

    We personally have TWO laptops that got repeatedly broken by non-disableable driver updates (already told Windows to never update drivers, hid the offending update, etc) and it still managed to get through, multiple times, and do the blue-screen tango repeatedly until I gave up trying to fix, it went into safe mode and disabled the Windows Update service. I had to keep it that way for a couple months until I was able to load a "newer" driver from the video chip manufacturer that fixed it and/or MS stopped pushing the broken one. Then I was able to turn updates back on again.

    All was fine, I THOUGHT, until several months later when the Anniversary updated got pushed to these systems. I bugged both my laptop manufacturer and Microsoft, repeatedly. Microsoft swore up and down that it would "only try to load the update once" and then stop trying if it failed. They also said the Anniversry update wasn't "certified" for this laptop model so I should just not install it, which would be fine except that _they forecully push it out, including to this laptop mode_! When I told them it had already attempted to update, failed and hung, at least twice they said it tries twice and then won't try again. Still incorrect. I tried basically everything including downloading the update to a USB and installing it manually, updating the drivers, downgrading the drivers, removing what I think was the suspect driver causing the hang during the update install, hiding the update with show/hide update tool, etc. Hiding disabled it for a while, but the dang thing is relentless, after a while it still comes back. The only 100% reliable way to make sure it will never try again, and hang the system (usually leaving it in a hung state with the fan blaring and screen showing 32% or something, all night long) is to completely disable the Windows Update service, or buy a new computer, or downgrade to an earlier version of Windows, or say to hell with and load Linux. The latter isn't an option because the laptops are used by family members who require Windows for specific applications.

    1. Re:Broken drivers, AND broken updates break stuff by hierofalcon · · Score: 4, Interesting

      Load Linux. Run the Windows in a virtual environment.

    2. Re: Broken drivers, AND broken updates break stuff by Anonymous Coward · · Score: 0

      Did you try just turning off Windows update? Just do it.

    3. Re:Broken drivers, AND broken updates break stuff by Anonymous Coward · · Score: 0

      Or better, use linux, ditch windows. No need for windows, and many reasons to stay off it. Why pay to be vulnerable for viruses? Why pay to be affected by ransomware - and then pay ransoms?

    4. Re:Broken drivers, AND broken updates break stuff by Anonymous Coward · · Score: 0

      Yep, had this on my HTPC till I nuked the update service and firewalled the box at the router just to be sure. Otherwise it kept installing bad DVBT2 drivers, on a lucky day it just failed silently to record anything instead of boot looping. It's still sitting on an ancient Win10 version because I can't trust it to come back after an update and recent versions can't be trusted to honor my attempts to stop it updating.

      My work PC is a never ending saga of failed updates. But more annoying is the way updates force reboot the PC so often. Can't leave VS and servers running for the next day because they won't survive the reboot. Can't run overnight project builds with any guarantee they'll complete. Hibernation doesn't work and if it did I have too much RAM to want to use it. Sleep hasn't worked for months now and I've given up trying to find drivers it will work with.

      Win10 is a clusterfuck of epic proportions.

    5. Re:Broken drivers, AND broken updates break stuff by Shirley+Marquez · · Score: 1

      One deterrent to doing that is that it will cost you extra. The Windows license that comes with your computer licenses one copy on that computer. A virtual Windows machine ON THE SAME COMPUTER does not qualify, so you would have to buy another license for that.

    6. Re:Broken drivers, AND broken updates break stuff by hierofalcon · · Score: 1

      When you kill the installed on iron copy, you just have one copy. I haven't messed with Microsoft at home for a long time. I generally shrink or move the MS partition out of the way or nuke it completely and install Linux. But if you're having problems with device drivers and updates, running virtual with a simplified and generally older chipset emulated means fewer driver problems.

      Are there issues? Of course. Getting sound to work may be problematic. You won't be able to game at the highest resolution or speed as on iron - just buy a console. But for most general work, running the few remaining "must have" applications that haven't gone over to Google or some other cloud provider or which have a Linux equivalent is generally good enough and not a performance hit that you notice.

      If Microsoft can try to co-opt Linux into running on it, they really shouldn't bitch about people running their stuff virtualized on Linux especially when it is to try to prevent downtime and problems that they are causing themselves. It's really convenient to be able to just copy back a known working image of your system onto a broken image when some update breaks things. That is true whether the system is Linux or Microsoft.

    7. Re:Broken drivers, AND broken updates break stuff by Shirley+Marquez · · Score: 1

      It's not the number of copies. It's that the OEM license only authorizes a bare iron install. The only Microsoft licenses that authorize virtual machine installations are full retail copies and certain forms of enterprise licensing, plus the exception of XP Mode in Windows 7 Professional which gave you a license for one copy of XP in a virtual machine on the system that was running W7. Upgrade licenses can be used for a virtual machine install IF they are used as an upgrade of a full retail license; they retain the same rights that the upgraded copy had.

      Even then, the licensing terms are unreasonably restrictive in that they only authorize ONE virtual machine. Not one running at a time, one period. (The licensing terms for virtual machines under enterprise licensing are more reasonable and do allow multiple VMs.) The net effect is to eliminate nearly all reasonable uses of virtual machines for home and small office users. And if you want both Windows and Linux on your system simultaneously you're forced to run a Windows host and a Linux VM, because doing it the other way around will cost you a bunch of additional money.

      I will grant that Microsoft has legitimate business reasons for some of the restrictions. A case they're trying to prevent is somebody running a hosting company or a remote terminal server on the cheap. If they allowed you to run unlimited VMs, somebody could buy a big honking piece of server-grade hardware with hundreds of gigabytes of RAM and run dozens of clients in virtual machines while only using one Windows license. I think a more reasonable restriction would be to stipulate that you can run as many VMs as you like with one license, so long as they are all used by the same human being at any given time. They could not be used to provide a UI to somebody else, nor to offer services to other people or computers.

  64. TCO by Anonymous Coward · · Score: 0

    But hey, I heard the total cost of ownership is much less than the alternatives! I'll even be able to buy a bridge with what I saved!

  65. Anti-Vaxxers by StormReaver · · Score: 1

    ...are being labelled the IT equivalents of anti-vaxxers...

    So, people who have done their research, and have decided that the cost/benefit ratio is too low. Sounds about right.

    1. Re:Anti-Vaxxers by StormReaver · · Score: 1

      I meant that the cost/benefit ratio is too high, not low.

    2. Re:Anti-Vaxxers by RespekMyAthorati · · Score: 1

      I don't think you know what the fuck you mean.

  66. i dont, by Anonymous Coward · · Score: 0

    I tell them to install Linux.

    Capcha: warfare

  67. Repeat After Me by John+Allsup · · Score: 4, Insightful

    If you value security, don't run the mission-critical parts of your infrastructure on a general purpose operating system like Windows, but rather run it on a minimalist, locked-down OS that has _only_ the facilities needed to do its job. The update carousel is a nightmare. If you want to ensure your Windows box doesn't sporadically reboot during a long unattended operation in order to update, what do you do? If you want to lock Windows down so it can only do the job to hand, and nothing else, you're screwed. If you run mission-critical stuff on a full-featured general purpose OS (and the same can be said for off-the-shelf Linux distros like Ubuntu and Fedora), you are kinda asking for it.

    That this idea is older than me, but is ignored, is laughable.

    --
    John_Chalisque
    1. Re:Repeat After Me by Bearhouse · · Score: 2

      Indeed - but who has the competence, and the budget, to do that these days?
      Of course you will (correctly) reply that budget should not be an issue, since the investment should recoup itself in opportunity cost of not having to spend a fortune in ongoing security efforts, and or recovery.
      But try explaining that to your average suit...

  68. Simple solution to that by Anonymous Coward · · Score: 0

    Or stop using Windows entirely, that will save time, money and Windows updates.

  69. Damned if you do, damned if you don't. by Opportunist · · Score: 1

    Basically, you have the choice between being taken down by one of their fucked up updates or by the malware.

    Pick your poison. No, survival is not a choice. Unless you dump that shit.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  70. No, fuck Windows update. by cfalcon · · Score: 4, Informative

    I turn off Windows update on the boxes that I still have. I recommend everyone I know disable Windows update on all boxes that they have.

    If you leave Windows update on, and just take the security updates by default, you will get owned by Microsoft. Constant telemetry will stream from your box.

    I also recommend people look up how to stop this on Windows 7 and 8, where it is possible to stop it. It is not possible in 10, though some people have had some success at limiting it.

    The article's advice is horseshit. WU should be disabled for personal computers if privacy is any manner of concern. Microsoft has revectored their security update mechanism to: try to upgrade you to Windows 10. Install sleeper services that only months after installation began transmitting telemetry. Remove useful names from KBs to prevent successful system administration. Transmit information about what programs you use, when you use them, how often you use them. Transmit information regarding crashes. Broadly expose envelope information about your non-Microsoft related activities to Microsoft and anyone they choose to share that information with.

    Disable WU on 7 and 8. Tear out the bad patches. Only EVER manually apply patches that you actually require for security and functioinality.

    Comparing being a sensible system administrator who doesn't want to transfer control over their personal activities to Microsoft to antivaxxers is disgusting. Anyone making this comparison is irresponsible.

    https://superuser.com/question...

    The list of KBs that you must manually remove (and prevent reinstallation of) to keep Windows without telemetry is provided on that su post. The list is:

    KB3065988 Windows Update Client for Windows 8.1 and Windows Server 2012 R2: July 2015 more info
    KB3083325 Windows Update Client for Windows 8.1 and Windows Server 2012 R2: September 2015 more info
    KB3083324 Windows Update Client for Windows 7 and Windows Server 2008 R2: September 2015 more info
    KB2976978 Compatibility update for Windows 8.1 and Windows 8 more info
    KB3075853 Windows Update Client for Windows 8.1 and Windows Server 2012 R2: August 2015 more info
    KB3065987 Windows Update Client for Windows 7 and Windows Server 2008 R2: July 2015 more info
    KB3050265 Windows Update Client for Windows 7: June 2015 more info
    KB3050267 Windows Update Client for Windows 8.1: June 2015 more info
    KB3075851 Windows Update Client for Windows 7 and Windows Server 2008 R2: August 2015 more info
    KB2902907 MS Security Essentials/Windows Defender related update [no description/information available]
    KB3068708 Update for customer experience and diagnostic telemetry more info
    KB3022345 Update for customer experience and diagnostic telemetry more info
    KB2952664 Compatibility update for upgrading Windows 7 more info
    KB2990214 Update that enables you to upgrade from Windows 7 to a later version of Windows more info
    KB3035583 Update installs Get Windows 10 app in Windows 8.1 and Windows 7 SP1 more info
    KB971033 Description of the update for Windows Activation Technologies more info
    KB3021917 Update to Windows 7 SP1 for performance improvements more info
    KB3044374 Update that enables you to upgrade from Windows 8.1 to a later version of Windows more info
    KB3046480 Update helps to determine whether to migrate the .NET Framework 1.1 when you upgrade Windows 8.1 or Windows 7 more info
    KB3075249 Update that adds telemetry points to consent.exe in Windows 8.1 and Windows 7 more info
    KB3080149 Update for customer experience and diagnostic telemetry more info
    KB3083324 Windows Update Client for Windows 7 and Windows Server 2008 R2: September 2015 more info
    KB3083325 Windows Update Client for Windows 8.1 and Windows Server 2012 R2: September 2015 more info
    KB3083710 Windows Update Client for Windows 7 and Windows Server 2008 R2: Octobe

    1. Re:No, fuck Windows update. by Anonymous Coward · · Score: 0

      Let's also not forget about this marketing-driven manoeuvre to try and get everyone onto Windows 10, which affects anyone running recent Intel or AMD hardware across several versions of Windows (W7, W8/8.1, Server 2008/2012 (w/ and w/out R2)). It also has erroneously affected some older CPU models. There is a third-party patch to work around this nonsense (which includes the disassembled and analysed code) -- https://github.com/zeffy/kb4012218-19. The downside is that it's likely to break every month and also will be flagged during an SFC scan, but it's all we've got right now.

      This is exactly a reason *not* to enable automatic Windows Updates. Instead, to tech-savvy folks I recommend disabling automatic updates and do the process manually every few weeks, reviewing every single KB -- and waiting 2 weeks before installing them, as Microsoft in recent days has botched and re-issued them more times than I can count.

      Relevant hack that works around this nonsense is here -- https://github.com/zeffy/kb4012218-19 -- but be sure to note that it's likely to break every single month and will be flagged during an SFC scan.

      We no longer can rely on Microsoft to provide even a basic semblance of trust. What Linux/BSD users (of which I am one, as a systems administrator!) used to harp on about, re: Micro$oft and MS taking over people's PCs, has now become an actual reality. The Nadella era of Microsoft seems to be more about "renting" copies of Windows to users, rather than the age-old classic of buying the OS and using it as you see fit, with the software company providing updates that do solely what they're supposed to and nothing else. I can't believe I'm saying this, but I actually miss the days Ballmer was running the show.

    2. Re:No, fuck Windows update. by Anonymous Coward · · Score: 0

      Comparing being a sensible system administrator who doesn't want to transfer control over their personal activities to Microsoft to antivaxxers is disgusting. Anyone making this comparison is irresponsible.

      Unless you study, inspect (open lab?) and control the vaccines as well as you can study, inspect (open source) and control software, then the comparison is apt. Simply substitute one so-called expert without your interests in mind (Microsoft) with another (big pharma).

  71. Trust Microsoft not to break mission critical by Anonymous Coward · · Score: 0

    software. Now who's the fool for running mission critical software on Windows!?

  72. Microsoft Knows Malware by Anonymous Coward · · Score: 0

    Microsoft installed their own malware on my old Windows 7 computer to hold it ransom. The malware was called Windows 10.

    1. Re:Microsoft Knows Malware by Anonymous Coward · · Score: 0

      That's funny because the recent ransomware breakout was just around 4 MB in size. The malware you mentioned is more than 15 GB in size.

  73. I have always run auto update by Anonymous Coward · · Score: 0

    I can only remember one time when I decided to delay updates and turned off the auto updates for Windows. Otherwise I let em roll and have not have any issues I can say really significantly affected any of my PC's. I think things are over hyped and exaggerated to a point where some are just control freaks and don't want anything done without their say. I can see some critical PC's not wanting to risk a bad update, but these days the risks of not updating are also pretty risky. It would be easier to work through a bad update then a infectious attack.

    1. Re:I have always run auto update by JohnFen · · Score: 1

      Translation: "I've never had a problem myself, so other people claiming to have problems are clearly either being hyperbolic or lying."

      some are just control freaks and don't want anything done without their say

      Your use of the disparaging term "control freaks" betrays your disdain for people who actually dare to think that their computer belongs to them and want to treat it as if it were.

      My computer should never do anything that I didn't approve of or ask it to do. If it does, then I call that "malfunctioning".

  74. I never understood by Anonymous Coward · · Score: 0

    why this update forces all applications to close without saving the documents. Holy FUCK what a *STUPID* default behavior. Terbaytes of cheap hard disk storage and you can't force a CTRL-S to every open application before closing??

  75. BIAS by Anonymous Coward · · Score: 0

    Troy Hunt is a paid by Microsoft fanboy.

    Move along.

  76. Tell Microsoft to fix it without funny business! by Chas · · Score: 1

    The problems here with people turning off Windows Updates can be laid right at the feet of Microsoft.

    Sneaking in "Urgent" patchs that introduce unwanted functionality, start spying on the end user, etc?
    Not to mention the older issues with newer patches breaking production software.
    And the oldest issue of all, Windows updates breaking (and bricking) systems to the point of needing a complete reload.

    If those jackasses up in Redmond would pay attention, and hire people to ride herd on all the Indian and Chinese programmers they're paying pennies a day for, they'd know this by now.

    But nope! Gotta shovel this shit out as fast as humanly possible. QA is for pussies! Isn't that what our paying user base is paying for?

    This situation has been going on for decades now. And it's only getting worse...

    --


    Chas - The one, the only.
    THANK GOD!!!
  77. As with vaccines - there can be side effects... by Anonymous Coward · · Score: 0

    I've had countless systems borked by bad patches from microsoft, or applications behaving badly after a patch has been released. For a lot of business it's a balance of risks.

    But then.........

    When some clowns have the hubris to think they are the only ones to find an exploit, and that they can keep such exploits secret, no amount of patching will keep you safe if a vendor isn't advised of it or heaven forbid they are 'Witting Industry Partners' of the C.I.A. and N.S.A. creating backdoors (Heartbleed anyone?) you're screwed until it's too late.

    We need a POLICY change to stop governments from behaving like this. Secure our computing for all, not weaken security for surveillance.

  78. A Profound, Reliable Solution... by CAOgdin · · Score: 0

    ...I was being plagued by the utter unreliability of Windows Update in Windows 7 SP1...with my own LAN, and with all clients' systems. It's been a nightmare over the past three years, with so many different variations of Windows Update components and configurations showing up and breaking perfectly running systems.

    But, I have FINALLY found a solution: It's Tweaking.com's "Windows Repair." (http://www.tweaking.com/content/page/windows_repair_all_in_one.html). For a mere $20 bucks, it's a clean, robust "reinstaller" that has cleaned up and improved performance of every system I've run it on (your single copy for $20 can be used on an unlimited number of computers, innumerable times). It's regularly updated, and it has never failed me, ever!

    The process is simple: Do some one-time steps to clear common problems (it guides you), then run the "Repair" tool: It changes all the files, registry entries and permissions to what they're SUPPOSED to be...and, that includes Windows Update!. You run the program in "Safe Mode with Networking," and you run it twice!. Most computers take about 30-40 minutes to run the program once; the second run is the same duration, but takes care of "early-stage"changes that might of been incorrect due to "later-stage" fixes. Worst-case, I have one Windows 7 SP1 system that takes 1.5 hours/cycle...and, after two cycles, it spends about another hour doing "post-repair" updates and consistency checks. It does not affect ANY applications programs. And, it all happens without requiring your constant attention while it does it!

    At the first sign of a problem (e.g., system gets sluggish, or updates don't get installed, etc.), I make a backup (usually overnight), then update and run Windows Repair...TWICE...and it's ready to use. It'll be a bit sluggish for the first hour or so, as the final stage of lots of reconciliation of different components get resolved.

    I emerge with another, repaired, Windows 7 SP1 system, up-to-date and reliable. It can be another three-to-six months before I find it necessary to do again. I keep a record of when each computer has been "Repaired," so I can confirm that Microsoft's lousy quality control has finally corrupted something again...and I find time to restore the system to "fresh-as-new" state.

    If you don't have this tool in your arsenal, you're wasting needless time trying to sort out a reliable source of information on how to fix some "0x85078630" error. If it's broken...again...just fix it, and go on with your life. I usually run my after business hours, while I'm enjoying time with my family. It runs for a long while...then you restart it, and it runs for another long while, but it only requires about 10 minutes to update the executable, and another 10 minutes to run it again. Then, leave it on overnight. You'll be a lot happy if you do!

    NOW, I can safely let my "Windows Update" enabled (although I always use "Download, but let me decide what to install"), because...after Windows Repair...I can trust my Windows system. Gone are the days of running "Windows Update" all night long just to discover that nothing got fixed the next morning!

    1. Re:A Profound, Reliable Solution... by CAOgdin · · Score: 1

      P.S.: I agree on the Windows Updates that delivery telemetry (above). I've removed all that junk, and my systems run smoother...and faster...without clogging up my system with "data for M$" and without using my Internet connection for something that appears to offer me absolute NO perceived benefit.

      If M$ has competent quality control practices, this "telemetry" would have no value. I suspect much of it is used to justify their own internal practices ("See how many people never use XYZ feature? Let's not waste time patching that PoS.")

  79. TELEMETRY OF WINDOWS by Anonymous Coward · · Score: 0

    Unitil Microsoft stops ading in telemtry and forced updates and forced migration to a

    PHONE OPERATING SYSTEM
    like fuck you and hte story your trying to cry on.

    I HAVE A FUCKING DESKTOP NOT A FUCKING PHONE
    fuck microsoft and the nsa two in one butyfuck
    what a bunch a losers at the nsa and microsoft
    LOSERS
    you cant get people to buy something so you trick and force them , then wonder why a explooit goes nuts on everyone.

    ITS YOUR FAULT MICROSOFT FOR THIS 100%
    xp would still be a great os had you kept developing that..heck even 7 is very very worthy

    8 onwards is garbage looks like shit it has to be shit

    1. Re: TELEMETRY OF WINDOWS by Anonymous Coward · · Score: 0

      Fully fucking agree with ya.

  80. Fuck off by Anonymous Coward · · Score: 0

    I won't only tell them to stop updating,
    i will tell them to switch to MacOS, Linux, BSD, anything other than Windows.

  81. bad example by Anonymous Coward · · Score: 0

    Vaccines doesn't change my hair color, my underwear pattern choice, or wich hand I use to scratch my arse

  82. dhcp update please by Anonymous Coward · · Score: 0

    Strange when every fuct up patch was almost mentioned except the dhcp patch which had disconnected everyone who have enabled their Auto-update in Windows.

  83. Nobody Draws That Comparison by NicknameUnavailable · · Score: 0

    Except maybe Microsoft's PR people.

  84. Reading the Article Helps by Anonymous Coward · · Score: 0

    So clearly, most readers of our beloved Slashdot chose not to read the article. I'm shocked, shocked, I tell you!

    The author isn't talking about enterprise environments. He's talking about home users, who listen to technical experts like those found on Slashdot, and proceed to turn off Windows Automatic Updates. For 99% of home users, they should just set it and forget it.

    We are the ones who care about this other nonsense - most folks just want things to work and do not care about marketing fluff.

  85. If only by Anonymous Coward · · Score: 0

    Maybe if Microsoft only used Windows update, or at least provided an option, for only installing critical upgrades more people would be likely to keep it running. How many stories have their been about the "Malicious Software Removal Tool" ripping out desired applications? Do I even have to mention the whole Windows 10 debacle?

  86. The problem isn't the update by JoePete · · Score: 1

    The controversy over whether to run Windows update or not misses the larger point. If you choose to buy a car with a deplorable safety record, despite its expense, then sure, by all means follow the recall notices and bring the car to the dealer every week to get the latest problem fixed. But suggesting Windows update is the "smart" move is like suggesting the same car owners are brilliant for wearing their seatbelt while driving their risk laden vehicles. The smart thing is just don't use a product with an horrendous security record.

  87. But...Update is broken by Anonymous Coward · · Score: 0

    The problem I've been having is every time Windows updates starts...even on a fresh install; svchost begins a memory hole and is soon eating all the memory it can. No one has a solution; Microsoft blames everyone else, everyone else says they can't be a problem; Microsoft then said the only solution was Windows 10.

    So I didn't disable update...it's so horribly broken I have to not run it or my computer will just...stall.

  88. Don't push features with bug features, just don't by Anonymous Coward · · Score: 0

    If MS just pushed bug fixes without cramming new features and worse, then perhaps folks would not feel the need to turn off updates.

    Just say no is a great plan, but it need to start at MS.

  89. MS Office runs fine on Apple (nt) by Brannon · · Score: 1

    nt

    1. Re:MS Office runs fine on Apple (nt) by Chris+Mattern · · Score: 2

      But how do you get NT to run on an Apple?

    2. Re:MS Office runs fine on Apple (nt) by Gr8Apes · · Score: 1

      Parallels.

      --
      The cesspool just got a check and balance.
    3. Re:MS Office runs fine on Apple (nt) by Drethon · · Score: 1

      Nice to know, I will definitely switch to an apple computer as soon as their price is the same as an ASUS or Lenovo laptop and I can change the hard drive or memory. (tangent rant I know, but these are the reasons I haven't switched to an Apple or upgraded from my galaxy s5 to a newer galaxy yet).

    4. Re:MS Office runs fine on Apple (nt) by Ol+Olsoc · · Score: 1

      Nice to know, I will definitely switch to an apple computer as soon as their price is the same as an ASUS or Lenovo laptop and I can change the hard drive or memory. (tangent rant I know, but these are the reasons I haven't switched to an Apple or upgraded from my galaxy s5 to a newer galaxy yet).

      If you have to have the cheapest shit, that's what you get.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    5. Re:MS Office runs fine on Apple (nt) by Drethon · · Score: 1

      Nice to know, I will definitely switch to an apple computer as soon as their price is the same as an ASUS or Lenovo laptop and I can change the hard drive or memory. (tangent rant I know, but these are the reasons I haven't switched to an Apple or upgraded from my galaxy s5 to a newer galaxy yet).

      If you have to have the cheapest shit, that's what you get.

      Well when I have so much money I can blow it on paying more for a product that gets the job done as well as a cheaper product, I'll consider it. M$ is annoying but rarely impacts productivity, worked at a place with Linux and the bugs are much more frequent.

    6. Re:MS Office runs fine on Apple (nt) by Ol+Olsoc · · Score: 1

      Nice to know, I will definitely switch to an apple computer as soon as their price is the same as an ASUS or Lenovo laptop and I can change the hard drive or memory. (tangent rant I know, but these are the reasons I haven't switched to an Apple or upgraded from my galaxy s5 to a newer galaxy yet).

      If you have to have the cheapest shit, that's what you get.

      Well when I have so much money I can blow it on paying more for a product that gets the job done as well as a cheaper product, I'll consider it. M$ is annoying but rarely impacts productivity, worked at a place with Linux and the bugs are much more frequent.

      Great if yout time is worth nothing. Annoying You are willing to put up with an insecure product that gets disabled with many updates. Penny wise, dollar foolish. Enjoy that.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  90. Microsoft made that pretty hard by gweihir · · Score: 1

    It used to be that you had the option to only install security patches, but with Win10, not anymore. MS routinely breaks things by adding functionality now. The push UI changes some people do not want and that can also break things.

    If anybody needs to change something here, it is Microsoft. First, they should stop writing really bad software. And second, they should stop forcing people to accept functionality-changes bundled with security patches.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  91. Or, don't use Windows? by Brannon · · Score: 1

    There are 7 billion people in the world, do you really think the right answer is for all of them to read /. and "hacker news" every day?

    Do you think bridge designers sit around saying "you shouldn't be allowed to drive across my bridge unless you understand how retention walls work"?

    Use an OS from a company that doesn't hate you and you won't have to disable auto-update.

    1. Re:Or, don't use Windows? by Dunbal · · Score: 1

      This is not rocket science. It's like wearing a condom before having sex with a stranger.

      --
      Seven puppies were harmed during the making of this post.
  92. windows nt 5 beta 1 by Anonymous Coward · · Score: 0

    lets jsut say in 1999 i got warning ahead of the beta 2 ( xp ) and it had enabled all the telemtry and more that windows 10 has back then that they could do.
    THEY KNEW what they wanted and that was it....THEY also knew no way anyone would go for it all at once so little by little each new version got to have a bit more....

    there are still back doors in xp up to windows 8.1 that none of you know of.
    no worries trust in microsoft and the nsa right....lol
    and how do i know

    1. Re:windows nt 5 beta 1 by Anonymous Coward · · Score: 0

      Stop smoking meth.

  93. General Security by Anonymous Coward · · Score: 0

    This and not turning of the UAC, no matter how annoying it is

  94. More hype than substance by WaffleMonster · · Score: 5, Interesting

    People get WannaCry by clicking on the wrong email not by SMB exploits. I get that repurposed NSA exploit angle makes for interesting and irresistible news stories but substantively it's way overhyped and using it to support blanket assertions is a nonstarter in my view.

    There is compelling quantifiable evidence to support the position vaccines help more than they hurt. The case for updates is closer to the question of whether throwing billions into the intelligence industrial complex makes real people quantifiably safer from being terrorized given opportunity cost of not investing these funds to address significantly more statistically substantial problems such as pulling down US murder rate.

    What we know for sure is social engineering accounts for 90% of general p0wnage worldwide. Even if all unintentional software bugs were patched with 100% coverage overnight absolutely nothing would change.

    In 2017 given Microsoft's proven track record of both incompetence and sleaze when it comes to updates it's an open question as far as I'm concerned whether updates are still worth applying at all. Majority of end users are behind stealth mode firewalls and the only whackable thing they have sticking out is a web browser. If you keep firefox or chromium or whatever up to date and lock down some associated configuration are you really appreciably safer vs probability of computer failing to boot or introduction of some new Microsoft "telemetry" malware or Microsoft false choice prompt dismissal scam? I honestly don't know the answer. I do know it very much depends on context not only in terms of the users needs and environment but the value judgments of the end user.

    If Microsoft would stop constantly peddling malware, firing QA staff, fix updates to not use insane amounts of resources while taking forever and requiring a reboot to sneeze... If only updates were properly labeled and people trusted Microsoft not to screw with them... my guess less will find value in disabling updates.

    I personally believe coordinated automated updates of billions of systems globally in a matter of days is an extraordinarily perilous activity in and of itself no matter how careful you are. Sooner or later this is bound to end in a major disaster. While updates do fix problems quicker they also significantly lower the cost and tolerance for releasing defective software. It sends a signal to the market releasing defective software is a cost free activity.

    1. Re:More hype than substance by Anonymous Coward · · Score: 0

      >People get WannaCry by clicking on the wrong email not by SMB exploits.

      That isn't exactly true, it does spread via SMB exploits as well as phishing. The phishing message helps it get past the border firewall, but once it is in it can spread on the internal network on its own.

  95. Forced telemetry made us turn updates off. by Anonymous Coward · · Score: 0

    Forced telemetry made us turn updates off.
    We considered the issues carefully.

    Based on our use of Windows, NOT agreeing to MSFT spying on our systems was more important than their updates. We use Windows only for very specific reasons, less than 1 hr a week. We never use email or surf the internet with it.

    So, for the last 14+ months, we haven't patched our Win7 systems.
    We've locked access for all Windows systems down at the network layer. No Win8, Win8.1 or Win10 here. If I wanted a touch-game system, I'd buy one.

    We need business operating systems.

    And we are religious about daily, versioned, backups.

  96. MS fix ReFS CoW filesystem, kill windows installer by bongey · · Score: 1

    Windows system restore and windows installer basically implement a horrible copy on write file system on top of ntfs. Windows installer does enormous amount of time upfront calculating how to rollback back the install if it is fails. Run into problems and windows update gets in endless loops , spending most of the time re-calculating how to do a failed install again. Microsoft bite the bullet and fix ReFS to have proper CoW filesystem with snapshots and shocker the ability to boot from a ReFS volume.

  97. Well. My Un-Patched windows XP machine ... by Anonymous Coward · · Score: 0

    .... wasn't harmed by this whole thing because it is behind a Linux firewall and virus scanner. Which gets security updates without breaking functionality all the time, the way Windows update does.

    Everyone who is running Windows in production for something other than Sandboxes legacy desktop applications and/or games (where you can backup an image, and just restore when something happens) is lost anyway.

  98. Tell Microsoft to give me back some control then by Solandri · · Score: 3, Informative

    I *have* to disable the update service on my laptop. Win 10 insists on installing newer Intel graphics drivers, except they don't work with the Optimus setup on my laptop. With the newer Intel drivers, any 3D game I start crashes when it tries to use the Nvidia card. So I have to let Windows 10 update my laptop, disable the update service, then reinstall the Intel GPU drivers provided by my laptop vendor (and also the Nvidia drivers if Windows 10 has auto-updated those).

    When Win 10 first came out, it gave you the option to disable updates to a specific device driver. But for some inexplicable reason, Microsoft removed this option in the Oct 2016 update. Because of Microsoft's brain-dead update policies, I literally cannot use my gaming laptop to play games if I have Windows Update enabled.

  99. Microsoft nanny state by MattiasAndersson · · Score: 1

    The so called "security experts" are preaching about the immense dangers of disabling automatic updates. Never mind the time consumed involuntarily by consumers having to patch their systems every second week. Never mind the unsaved files, permanently lost, due to automatic reboots in the middle of the night. Never mind the havoc wrecked on production and development environments running multiple virtual machines. It's time the security people stepped down from their high horses and realized that automatic updates should never be enforced -- only strongly recommended. Developers and power users don't want to live in the Microsoft nanny state of supervised reboots -- not even if you're able to schedule them.

  100. It's more understandable than you might think by Anonymous Coward · · Score: 0

    If you have been using a modern OS, this is fairly common sense. Only experts should be delaying updates, right? (Because, for example, they know their machine can't get to the internet.)

    Alas, my wife has to use Microsoft Windows at work, and lately she's been bringing home a laptop that runs Windows. It has been an eye-opening experience in misery. I suspect that most pro-update people haven't seen MS Windows in a decade or so. If you've lived a 21st century existence lately, then you have no idea how unutterably horrible Windows is. If you think it's just another OS, you are out-of-touch with how the industry punishes people in the modern day.

    Basically, imagine if updates were as painful and annoying and disruptive as possible. Then pause and ask yourself: How could I make it worse? Think of a way to make it even more inconvenient. Ok, got your idea? Now..

    ..lay down on your belly in a supine plaintive gesture of inadequacy and submission, and crawl with humility, because your imagination is so pathetic and limited. Windows updates are far worse than the worse thing a Linux user can imagine. They interrupt people, and they even happen at shutdown, where you're literally not allowed to turn the computer off. Microsoft takes your computer away from you.

    To get some idea of what Windows updates are like, just imagine if a flu vaccine caused 12 months of explosive unpredictable diarreah. Get this shot, and you're immune from the flu, but for the next year, at least once per day at any time and any place, a liter of liquidishit is suddenly going to explode out your ass. Maybe you're driving, maybe you're sleeping, maybe you're in a meeting at work, maybe you're eating at a fine restaurant, or maybe you're at a bar chatting up a member of the opposite sex. And with 0 seconds notice, whatever you're doing is suddenly interrupted by a stinky, messy, embarrassing experience. Every day, for a year. Good thing you didn't catch the flu, huh?

    Might you become an anti-vaxxer, if flu vaccines were like that? And so, you might avoid Windows Update, because it's hard to say whether malware can really be worse than Windows Update. What expertise in causing user misery do malware authors have, compared to the professionals in Redmond?

    You are getting DOSed one way or another. You get to choose how it happens, but not if. That's what it's like for people who still have to run Windows.

    And if you haven't seen Windows lately (e.g. since XP) I am dead serious: you don't know what it's like. You think you remember it as "bad." No. What you remember from before, is nothing like what it's like now.

  101. It's all give and take and they just TAKE by Rick+Schumann · · Score: 1

    Companies like Microsoft have to be responsible to their customers and not push updates that violate their sovereign right to control their own bought-and-paid-for hardware, not install unwanted 'features' like things that shove ads in your face, not brick people's computers, and otherwise not subvert and annex peoples' bought-and-paid-for hardware into their surveillance network. Companies like Microsoft seem to think that THEY own people's computers, not the PEOPLE WHO PAID FOR THEM, and that is FLAT OUT WRONG, AND FURTHERMORE POSITIVELY OFFENSIVE. If companies like Microsoft had a respectful attitude and respectful business practices THEN PEOPLE WOULDN'T BE TURNING OFF AUTOMATIC UPDATES IN THE FIRST PLACE!

  102. WRONG... by Anonymous Coward · · Score: 0

    It all starts with the shitty NSA infested OS called Microsoft Windows. Install Linux and forget about anti-virus protection and spying.

  103. ..except if you're in retail break/fix. by Anonymous Coward · · Score: 0

    Windows updates can break a just repaired install. No one wants a non-billable re-service because someone went home and M$ flubbed a patch.

    Just don't enable Windows Update - if you're in break/fix.

  104. Well by Anonymous Coward · · Score: 0

    " As soon as they're required to do something, it'll be neglected which is why Windows Update is so critical.".

    If' it's so important hn MS should not abuse thate criticality to push spying and adverts via that channel then.

  105. Don't make your software update so painful by rahenri · · Score: 1

    Don't push unwanted updates down people's throat. Don't make updates so annoying that you have to reboot your computer so often. People shouldn't be forced to stop everything they are doing to reboot their computer so often. If you want everyone to do them, these updates should be seamless.

  106. I disable Windows Updates until ready to install by Anonymous Coward · · Score: 0

    But I know what I'm doing. I haven't patched anything in almost two months. Haven't gotten WannaCry nor am I likely to. Even if malware/ransomware gets on my system, I have a simple solution: Scrub and reinstall everything. All of my data and apps are backed up to remote cloud hosts (and all of my backups are verified regularly) just in case the worst case scenario happens.

    For the general user and IT department which manages multiple users, I agree that disabling Windows Update is a bad idea. But some users need total control over when they install updates.

  107. Microsoft made same mistake the CIA did w/vaccines by Anonymous Coward · · Score: 0

    I'm too lazy to google it right now but wasn't it the CIA who actually did mis-use vaccination NGO programs to steal DNA samples in order to find out where Osama Bin Laden was hiding (by detecting relatives' DNA)? That particular boneheaded move actually discredited real, life-saving vaccination programs in the developing world.

    Microsoft's penchant for appropriating a *security update* mechanism for market-driven upgrades and advertising/telemetry feature installation has done the exact same thing: while there may be real security updates in their channel, nowadays we know it's proven there is actually harmful stuff being shoved through there as well. They've poisoned the well.

  108. MS, we're looking at you by Altrag · · Score: 2

    If MS really wants to make people do updates promptly, they need to get their heads back out of their asses. In the late WinXP and into the early Win7 era, there was a strong push for security and the updates were usually both relevant and easy to install.

    Fast forward to now, and half the updates you get are MS pushing their latest piece of crapware (*coughskypecough*) that you don't want, and like 90% of them require a full computer reboot -- which they'll happily do with our without your input and hope to hell you saved your work that day.

    If MS wants people to install critical updates then:
    a) Stop calling every fucking sales pitch "critical," and
    b) Go back to putting in the effort to avoid reboots. I know its easier to just reset and not worry about internal version conflicts and whatnot, but its a serious detriment to anyone who doesn't normally shut off their computer in the first place (and those people are the ones who least need to be force into an unwanted reboot!)

    Unfortunately MS has decided to do the exact opposite of that and compensate by giving you no choice -- enjoy losing your work.. what're you gonna do about it? Switch to Mac? Oh you are? Well fuck.

  109. Tell Microsoft to stop breaking stuff! by duke_cheetah2003 · · Score: 1

    Automatic updates are great and all, until the update becomes a problem in itself, breaking something.

    Microsoft really should have two update paths: CRITICAL (and take it seriously, no more stupid updates labeled as CRITICAL)
    And: Non-CRITICAL (everything else goes here, especially driver updates!!!!)

    Make one optional, make one mandatory. Problem solved, assuming M$ can adhere to a fairly strict no-nonsense policy to what gets flagged critical.

  110. Yes, don't do it. by eriks · · Score: 1

    How about: Whether or not you have automatic updates enabled, don't ever put a windows box on a public-facing IP, unless it's super-dooper-hardened/firewalled and has a 24/7 NOC staff to monitor it.

  111. No, this is not like vaccinations by Anonymous Coward · · Score: 0

    unless your idea of vaccinations is a permanently installed vein tap that is always connected to a drip line coming out of the wall. But they will only ever push good stuff through it, so don't worry.

  112. Microsoft is part of the problem by iCEBaLM · · Score: 1

    In Server 2016 you have two options: allow the server a full 8 hour window to reboot itself when updates need to be applied, or disable the whole thing via group policy. Nothing in between.

    I've been hit by this numerous times. HyperV server running a bunch of VDIs? FUCK IT, I'm Windows Update, I get to take the whole fucking thing down! Exchange for an international corporation that relies on 24/7 email? SCREW YOU, I'm Windows Update, reboot that bitch!

    Guess how many people have no choice but to disable them because they don't want their servers randomly rebooting?

  113. Re:Excluding the unfortunate exceptions - Ya! by Anonymous Coward · · Score: 1

    We had THREE Production servers that got Windows updates (Windows 2012 R2) and suddenly wouldn't boot! Our Windows admin spent the whole day on the phone with Microsoft and we had to rebuild ALL THREE servers!. Backups you say - yeah they wouldn't boot either. You see the servers didn't get rebooted until 5 days AFTER the updates got applied. So the backups were no good either. This latest Ransomware is just another death kneel for Windows now our IT executive management are looking at how soon we can start migrating anything we can to Linux servers even out Enterprise Architect is highly recommending it.

  114. As an alternative suggestion... by sigmabody · · Score: 1

    ... one could implore the software vendors to make the update process less arduous, cumbersome, error prone, and OBNOXIOUS AS ALL HOLY HELL.

    As someone who has, on multiple occasions/systems, got frustrated enough with Windows Update to disable the service (hint: that's the ONLY way to prevent it from randomly rebooting your system when you are trying to use it, whether you like it or not), I can say with some certainty that I would have no issue with leaving updates enabled, if the process wasn't so GODDAMN TERRIBLE. Suggestion to vendors and prognosticators: the vendors are as much, if not more, to blame as the users who respond to the INFURIATING behavior of their devices. Instead of blaming the users, I'd suggest perhaps it might be more productive to blame the vendors for the poor quality software which drives the users to disable it.

  115. Where is the answer then? by ShamblerBishop · · Score: 1

    How in fuck do I safely update a Windows install, without risking telemetry and all of the shove-Win10-down-my-throat bullshit? Nobody has a fucking answer to this. I need to update my installs, ASAP - but I'm holding off because I don't know how to avoid all of the fucking MS-produced malware... Someone give me a fucking answer...don't link me to offline installers, that just install all of the problematic updates as well...

  116. Don;t make Windows Update worse than a virus then. by Anonymous Coward · · Score: 0

    It's worse than a virus because you can at least theoretically get redress to a virus writer you track down.

    And I recall saying this in slashdot before, so this has got to be a dupe, or the submitted quote is from another MS wally writing to slashdot before.

  117. false dichotomy as business model by epine · · Score: 1

    Few sane individuals would turn off security updates at the critical security level concerning defects offering networked remote execution with escalation.

    These little reason for this relatively small group of patches to disrupt normal operations, if Microsoft were to take a conservative stance.

    But somehow Microsoft manages to bundle in weird instability bycatch, and you're either left with your pants down, or your pants on fire. For which the only viable solution is an OS-upgrade cycle with a new-and-improved EULA, which somehow never fails to be ever more Orwellian.

    Pants or privacy. Choose one.

    Nice business model, should your customers willingly board the train.

  118. hey troy by Anonymous Coward · · Score: 0

    have you consider that if many millions of people are turning down windows update maybe theres a reason for it?

    i mean, to turn it off completely you actually have to google how to do it to do it fully, its not like people load up google and search random stuff

    things ive avoided with windows update completely off:

    windows 10 ninja install
    diagtrack service making my computer hard drive unusable for the first 5 entire minutes after booting up
    windows update corrupted sitting iddle wasting 25 per cent of all my cores on a 8 year old computer (imagine how that felt, if my computer had balls it probably felt like it was being kicked in its balls)

    also, you can put the service up, download a patch from the microsoft update catalog, and put the service down again, in 2 months from a critical bug theres plenty of time

    windows update was FINE before the arrival of windows 10, then it wasnt

    theres no running, you shills CANNOT HIDE, microsoft did this indirectly because of windows 10, yet another reason windows 10 sucks, it manages to not only sucks itself, but make other versions of windows that were working perfectly fine for YEARS suddenly suck

    so to be perfectly clear, you can keep your "advice"

  119. Windows update IS the nasty exploit by Tyr07 · · Score: 1

    There are a lot of ways to protect your hardware, yes a bare system on the internet directly is vulnerable to a lot of exploits but IT professionals have been protecting these systems for decades from things before microsoft releases a patch and protects them.

    Windows 10 single handedly caused far more problems and cost for users of production software that any viruses for one company I worked for.
    We were flooded with calls from users who were FORCED into windows 10 and now ALL THEIR SHIT DON'T WORK.

    Trusting microsoft completely is bullshit, review the updates, decide if they're relevant. We can't trust these companies to blindly accept all their software "updates", a lot of them these days aren't even things that affect you, but they want their software to gather more data or other garbage.

  120. Re: Excluding the unfortunate exceptions - Ya! by Anonymous Coward · · Score: 0

    Why are you applying untested updates to all production machines at the same time? I do it for a small shop with six year old hardware (cheapskates) and I stage test everything in a vm before rolling it out sequentially to other servers.

    Sounds like you have a shitty IT guy. Maybe you should pay more for him, like you should do for a GOOD secretary.

  121. I don't think so by sentiblue · · Score: 1

    What you have is the opinion of a person having limited knowledged ... You only looked at one single threat and decided what you asked is good for everyone. Obviously you haven't done any risk assessment.

    In environments where hundreds/thousands of comptuers run to put together a massive operation, we don't do "automatic" updates... which gives MS the decision of when and what. Instead we evaluate the credibility of the patches even if it comes from its authentic provide MS. Why? Because unlike the patch that you mentioned, there were other patches that crashed thousands of servers worldwide... or upgraded the OS from Windows server 2003/2008 to Windows10 and render all of its applications useless because those apps are not compatible with Windows 10.

    Even if a patch is credible and verified... we run it through test, then QA, then Staging, then Production in that order. So you see... just because MS provides a patch, doesn't mean you have to install it. MS is not the only provider here. There are other providers that issued patches which consequentially created disasters and we were left with fixing their problems.

    For personal use computers, yeah sure it would be OK to have an abrupt patch that causes problems or do an upgrade without consent. For some that's still unacceptable since they rely on their machines to make a living.

    'nough said... what you said is wrong. Let the experienced speak and you'll learn from them.

  122. lie much? by Anonymous Coward · · Score: 0

    "As soon as they're required to do something, it'll be neglected"

    If it fits your agenda, then it must be true.

  123. Real world experience? by kugeln · · Score: 1

    I'm guessing as a security researcher, he's never had any real world experience.

    Allowing a software vendor to automatically apply updates and patches might sound like a good idea "in theory" but it requires a level of trust--something which Microsoft has never achieved in my organization over the past 17 years.

    As others stated, the *only* way for a business to manage updates properly requires building a test environment and funding knowledgeable staff to test updates against their system and software configurations. Turning on Windows Update without any oversight almost guarantees you eventually having a Really Bad Day at the office when you come in and MS has decided to update something having to do with the login authentication and none of your users can log in.

    Fast forward to Windows 10 and you have the "installing, failing, rolling back, rebooting" cycle and if you think calling Microsoft is going to get you a 5-minute fix, you're probably going to find yourself needing a new job.

  124. No thanks! by sinij · · Score: 1

    I would rather restore my mother PC from a backup than have to deal with Win10 on her machine. They turned it off for now, but it takes one under-perform quarter for them to get back at it.

  125. Re:There should be a separate "Security Updates On by Darinbob · · Score: 1

    "Security update KB12345: This update changes the color of the mouse cursor. Be aware that this update is required for all future updates to Windows 7 and 8.1. For a list of incognito non-security changes, please visit ."

  126. I promise to not say that by rewardian · · Score: 1

    But I'm not enabling automatic updates in any environment I manage.

    Too many times have I been alerted of a new security issue by a client, though I was already aware, and was asked to install the patches that correct the issue. The environment's already designed to prevent many of these issues (ACLs, competent firewall rules) and I'm not worried, but want to qualm their fears with something real, like Microsoft patches. ...

    So it's 3AM and I'm rebooting and I receive a real blue screen of death (i.e. 'we can't boot to shit, you want to recover?'), I scramble around and restore the last backup. The client isn't pleased, neither am I, and we forget about the ordeal because it's already solved.

    What I'm saying is just like many others. I don't need your patches, they usually fuck things up, but some people do. So, it's a deal. Microsoft can deal with a swathe of angry customers who fail to boot or reboot loop to oblivion and I'll keep my mouth shut (other than blaming Troy Hunt, maybe).

  127. They'll never be trustworthy by Anonymous Coward · · Score: 0

    Microsoft has criminally defiantly abused update to push technologies and other junk, and to force upgrades, etc. etc. with impunity. They can not be trusted.

    Updates tend to mess things up, including non-windows updates.

  128. Bad patches plus forced reboots by dbIII · · Score: 1

    Due to bad patches and forced reboots on some machines where losing time in working hours was a serious problem you just had to turn off updates. The sensible thing after that is disk imaging then manually applying the updates (and waiting through whatever patch rollbacks are needed) every few weeks.
    The extent of the current problem is partly due to windows updates being very poorly managed and used as a vector for a new product that is in some ways inferior to the one it replaces. Some people did the necessary for them step of stopping automatic updates and then never took the time consuming steps of doing the manual updates.
    Microsoft behaved badly and lost trust, leaving malware to exploit other areas where MS has behaved badly with bandaid fixes later.
    Blaming the users doesn't get anyone anywhere. They had their reasons. They may not be entirely good reasons but MS should be working on regaining their trust instead of blaming them.

  129. Well tell the carriers to stop metoring by DarkOx · · Score: 1

    For people on low capped 30 - 60gig cellular and satellite connection, Windows updates are often simply unworkable.

    You can't demand I use a day's worth of internet activity to install a updates. Sorry does not work that way. If M$ won't make individual updates available so people on the meter can pick just the critical, that affect them, people will continue to disable updates.

     

    --
    Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
  130. This is a joke. Right? by Anonymous Coward · · Score: 0

    The only thing worse than MS's OS is their Update scam.

  131. Re:Tell Microsoft to give me back some control the by Anonymous Coward · · Score: 0

    1) Enable test-signing.
    2) Generate your own key
    3) Change driver version to maximum 32767.?.?.?
    4) Install it

    Problem gone.

    Not for the faint of heart.

  132. Lost by Anonymous Coward · · Score: 0

    I just don't know what to do anymore. All I want is to play games on my custom built 4k gaming rig with the latest titles. I DO NOT WANT TO BE SPIED UPON by a machine I built. I would switch to linux in a snap if I knew the gaming houses would make a concerted effort to assist in the transition.
    I am so lost.

  133. Re: Excluding the unfortunate exceptions - Ya! by Anonymous Coward · · Score: 0

    Most of the ones complaining about Windows Update belong in the "shitty IT" category and should be required to surrender their Nerd Card. If all else fails MS does provide the utility necessary to uninstall any botched update and reset your system state. In a business environment you can turn off the automatic update and run the update any time you feel like. In the user space the overwhelming majority do want the automatic updates. If you can't take the time to review the update release notes BEFORE you allow the Windows Updater to install the update. And if you are going to complain about Windows Update you would be better off complaining to vendors providing their drivers to MS. A blue screen condition is almost always the result of a broken driver that was not developed by MS.

  134. windows update shouldn't make an asshat of itself by Anonymous Coward · · Score: 0

    just don't.

  135. Re: Excluding the unfortunate exceptions - Ya! by Anonymous Coward · · Score: 0

    Yes. Surrender your nerd card. You. And you. And you. You too. Surrender. Surrender.

    (Why am I all alone?)

  136. Linux by Anonymous Coward · · Score: 0

    >>'Don't Tell People To Turn Off Windows Update, Just Don't'

    Yep. Better tell people to use Linux.

  137. -Linux by stooo · · Score: 1

    >>'Don't Tell People To Turn Off Windows Update, Just Don't'

    Yep. Better tell people to use Linux.

    --
    aaaaaaa
  138. Re:Excluding the unfortunate exceptions - Ya! by stooo · · Score: 1

    >> Our Windows admin spent the whole day on the phone with Microsoft and we had to rebuild ALL THREE server
    That'S normal when administrating MS machines

    --
    aaaaaaa
  139. Damned if you do, damned if you don't. by Anonymous Coward · · Score: 0

    Seconding (Sextillioning?) the counter-argument.

    Microsoft has been increasingly abusing their Auto Update system with things they shouldn't be putting in there, lack of sufficient testing and general dickery.

    Things like the telemetry are an abuse of the system, and windows 10 should *never* have been pushed as an update. That and the raft of faulty updates that actually broke computers causing them to enter reboot loops or pieces of hardware to stop working mean the 'cure' is almost as bad as the disease!

    This inability to trust Microsoft is exactly why larger companies do their own regression testing before unleashing the updates on their users, and that takes a lot of time, leaving a window between patches that can be exploited. But frankly, this exploit apparently goes back to Windows 2000 and they only patched it in this March so who knows how many others there are.

    This is the price of a monoculture.

    If you want a secure system, you probably shouldn't be using an operating system designed for consumer users.

  140. If Microsoft would quit force-feeding us crap... by Anonymous Coward · · Score: 0

    Like Windows 10. Or even if you go to the trouble of fetching and installing the "security-only" updates, the April 2017 one disables updates on Win8 for new processors.

    The result is that I can't trust Microsoft. I don't want to choose between a remotely exploitable zero-day and being fucked by Microsoft, but the former happens less often than the latter.

  141. Yeah... by Anonymous Coward · · Score: 0

    Microsoft's invasion of my privacy, yeah.

    BTW, like me on Facebook. /s

  142. Information Theft & Unsupported H/W by Anonymous Coward · · Score: 0

    Latest update now forces a dirtbag popup every 3-5 min that I have "Unsupported Hardware" just because I want to continue running Win 7 on a newer processor which WORKS FINE. Have to disable the forced Information Theft in Win 7.

    Can't go to Win 10 due to excessive forced Information Theft (Why is there not a lawsuit?). Was also going to by a Roomba, but no longer for the same reason.

    Seems you can't use any technology enjoyably with out letting the companies steal your info.

  143. OK I won't by Anonymous Coward · · Score: 0

    However, I don't have automatic update enabled on my machines. First, one security patch was buggy and to this day if I enable automatic updates on one of my machines it will attempt to install it, fail, than rollback the changes. Once finished it will restart again trying to update this patch and fail. Instead I check monthly for updates and install the updates that are available. Another reason I don't automatically update is because one morning my laptop had a screen welcoming me to Windows 10 and that it is encountering problems with the update and is trying to fix it. I waited for it to finish but decided that my machine hung after 12 hours and tried to reboot. Sure enough, not only did I get upgraded to Windows 10 without my consent, I got the opportunity to re install my old windows from scratch. I'm not willing to take the gamble of waking up to a inoperable machine due to a botched Microsoft patch installation.

  144. Don't Care by Anonymous Coward · · Score: 0

    Since Windows 10 spam/Malware campaign I have had Windows updates disabled on my PC. I have not had any issues with this or any other exploit. Even if I get hit I don't care because I have backups. I have had issues with Windows update on multiple occasions. So what do you think I will be more likely to defend myself against hmmm?

  145. Re: Excluding the unfortunate exceptions - Ya! by hierofalcon · · Score: 1

    Well, one good reason is that most IT departments in the world can't afford to have exactly the same hardware on every production platform. It would be nice, and we'd like to have an exact duplicate of every hardware configuration / software configuration, but we just don't have unlimited cash to do that. So no matter how we test on the most prevalent hardware configuration, you can still get bitten by a particular hardware anomaly on a particular box. It's easy to blame the IT guys, but everybody has a budget they have to deal with and arguing for hardware to just test on is rarely going to be on higher management radar until there is a huge downtime that is public facing.

    That's another reason that running Microsoft Windows only virtually on Linux is nice. You can have better control of the hardware it sees. But there are some PHBs out there that want it running on the bare metal for whatever good reasons, so you can never be completely free of the similar hardware issues.

    Also, it is very rare for IT to use software in all the same ways that the actual end users do. It can appear to work fine, but fail when some engineer does "their" thing with the software that perhaps no other engineer does. Again, it's easy to blame the IT guys.

  146. Just Don't Tell People To Switch To Linux by Anonymous Coward · · Score: 0

    I work in IT and like job security and an OS that always breaks.

  147. Sorry Troy Hunt... by agrisea · · Score: 1

    Sorry Troy Hunt... Out here in the real world, Windows Update bricks PCs without notice. Most of my clients are in business and rely on their PCs & Servers to work day in and out reliably, yet when Windows Update pushes something out that brings that client to the paper & pencil age, that is not exactly a way to inspire confidence. And removing descriptions of just what a patch does, we should not have to play Russian Roulette.

    The Windows 10 upgrade was yet another example of a company not knowing when "No means No" and deserved to be blocked.

    So instead of blaming organizations for not patching, why isn't anyone telling Microsoft that we have had enough of their hole-filled software and to fix it or get your wallet out.

    --
    Agrisea Tsunami - Epyc Servers... https://agrisea.net/products
  148. If Windows hadn't tried to force 10 by Anonymous Coward · · Score: 0

    I turned off the auto update because almost every day Windows tried to take and overwrite the version I liked and needed, using their intrusive demand windows that were harder and harder to shut off or deflect. My wife accepted Windows 10 and hates it, and spends more time, some days, avoiding the ads than getting work done.

  149. Re:Tell Microsoft to give me back some control the by Anonymous Coward · · Score: 0

    Here's how you fix that for your Intel Driver.

    -Let Windows Update install the version of the driver it wants to, and do not uninstall it

    -Go to device manager (devmgmt.msc) and find your device

    -Right-click on it, and hit "Update driver software"

    -Click "Browse my computer for driver software"

    -Click "Let me pick from a list of device drivers on my computer"

    -Select the version of the driver you want

    Graphics drivers are responsible for a double-digit percentage of all BSODs. That's why MS is pusging these. Rolling back drivers is a huge irritant, but hopefully it will help a little to understand _why_.

  150. I'm telling you to turn Windows Update off. by Anonymous Coward · · Score: 0

    Fuck you, I say turn it off. Then, immediately thereafter, install a REAL goddamned operating system, not a pile of dog shit, pathetic excuse for an operating system with a swiss-cheese-like security model, like for example just about ANY BSD variant, or GNU/Linux.

    Even with Windows Update turned on, your computer can still easily be part of a bot-net, spam server, kiddie-porn server, ransom or other malware server, etc., or spreader of worms, trojans, viruses, root-kits, etc., etc., etc., and the VAST majority of this vulnerability is courtesy Microsoft DELIBERATELY and INTENTIONALLY shipping software that has deliberately added security flaws that COMPEL you, as a user, to USE Windows Update, which in turn requires you to REGISTER your copy of Windows, which in turn requires you to have a LEGITIMATE, recently purchased copy of Windows which you have NOT installed on TOO many machines, nor on the same one too many times, making it unable to be registered again. Making these be requirements means that you HAVE TO PAY for your copy, OR your data is subject to hacking, your computer subject to compromise, etc., and at the same time even if you do everything right, by the book, and legally, the holes could STILL risk your safety, all in an effort to prop-up Microsoft's failing, bullshit business model.

    You read that right. Microsoft sacrifices the safety and security of your data and ignores your rights as a property owner, etc., jeopardizes your very life, potentially, for the sake of making the rich bastards who own their company even more obscenely wealthy at YOUR expense.

    So yeah, I say FUCK Microsoft, and all who aid and abet their shenanigans, and if you're still one of those poor, unfortunate souls who has to use any kind of crippled crapware from Craposoft, PLEASE, for your own sake, upgrade to a REAL Operating System, and tell Microsoft that they can eat shit, die, and go straight to fucking hell where they belong to suffer for all eternity.

    If you need help or advice to do this, I'm sure /. .org has about 1000 people reading it at any time who can help you learn.

    Just... whatever you do, if someone tells you to open a terminal and change directories to root, and give it the command, "rm -rf *" or something like that... little bit of advice from me to you. DON'T.

    Take care, good luck, and fuck Microsoft and all the evil those piles of horse shit puree they represent.

  151. Re:Tell Microsoft to give me back some control the by Anonymous Coward · · Score: 0

    1) it's not a gaming laptop if you're using Intel graphics
    2) where's the hate for Intel for supplying a broken driver update to Microsoft for publishing?

    Removing a config option is MS fault, but they bulk of the blame for your specific issue lies with Intel.

  152. Sounds reasonable... by Anonymous Coward · · Score: 0

    ...until the latest MS patch takes down all of your accounting department and part of production. Cleaning up that mess this morning. Sigh.