Don't tell people to turn off Windows Update
troyhunt.com
troyhunt.com
Microsoft shares part of the blame here for pushing features that the user clearly doesn't want through updates (especially to the major OS version). Look at the recent ads in Windows file explorer for one example. A lot of the advice to turn Windows Update off is a misguided response to Microsoft's own bone-headed moves in recent years to install bullshit that the user doesn't want.
I still sort of regret installing Windows 10 to this day because of the obnoxious Cortana bar it foisted upon my start menu that I can't get rid of. And yet not installing Windows 10 would've left me less secure with an OS hitting EOL for security updates much sooner.
Microsoft definitely shares some of the blame for this precisely because they have automatically "opted in" their users to stuff they don't want during past updates. Stop the bullshit, Microsoft.
The attack could come from the internal network (it spreads first via email). Also, don't forget the upnp shenanigans
No, unfortunately not - it spread using SMB internally on LANs, but travelled internet-to-LAN by "regular" phishing. It downloads its payload off the internet, but most good firewall would allow that (was the WannaCry payload detectable by virus scanners at the time of the infection? A "good" firewall might be one expected to intercept and scan all downloads).
> A legitimate reason like "this Windows runs on a medical/factory/etc. device that CANNOT go offline to install updates willy-nilly".
"Cannot go offline" implies that it's operationally critical. If you operate such devices, it is an absolute imperative that you have a procedure for taking them offline regularly for updates (not "willy-nilly" and anyone using that word about running a two-year out of date OS on a critical device is objectively not qualified to run them - and anyone buying such a device that can't be upgraded isn't qualified to buy them (and anyone making such a device...)).
In some contexts that simply isn't a viable strategy. As an extreme example, consider something like an implanted medical device that needs to run 24/7 for the rest of a person's life, which can only be replaced via surgery under hospital conditions, and for which any failure is already a life-threatening event. Of course that kind of device probably isn't going to be running an OS like Windows, but it makes the point. In fact, the USSS has reportedly had the standard wireless update facility disabled in such devices for prominent public figures who might be at risk of being attacked that way.
Some equipment used in hospitals or to run other essential infrastructure might be within the realms of running a "normal" OS like Windows but still be in a position where any time out of service is extremely expensive in one way or another, so routinely disrupting operation to apply updates still isn't acceptable. There are also contexts where the device is regulated and making any change at all requires re-approval -- a legitimate and serious conflict when faced with this kind of security risk if the situation when a regulated device goes out of spec can also be serious.
You need different security strategies for this kind of environment, which rely more on external controls. You can't just say everything must be able to come out of service at frequent intervals for security updates, and you can't just handwash the problem away by calling people who understand the issues "unqualified". It's a far more complicated problem than that, and often there are no completely satisfactory arrangements.
Also, those $100m devices aren't in service 24/7/365. No-one takes an airplane out of service in mid-flight to apply a security update.
> No-one takes an airplane out of service in mid-flight to apply a security update.
No, not mid-air, but close to: https://en.wikipedia.org/wiki/Emergency_airworthiness_direct...
The folks at hospitals are not going to fight with such an expensive machine, not even for updates - if something goes wrong, they would be to blame, they can live without that.
Then spend an afternoon going through each option, setting enabled/disabled for everything you don't want or don't recognize.
You can easily disable entire subsystems like Cortana, tips, telemetry, camera, biometrics, error reporting, games, Homegroup, Defender, Windows Store, and a whole bunch of other garbage.
So, this should work - but only in the pro Version.
When 7 goes end-of-life, I'll be 100% Linux.
I've heard this setup be described as a Wintendo. Not sure why, but that cracks me up.
GPUs' memory management isn't exactly security friendly.
But then i get myself thinking of Gnome, and how i have seen similar tools sprout for tweaking it in recent years...
Ms is trying to turn Cortana into the Google play services of Windows So they can consensually(forcefully) collect data from every windows device.
Some years back Google went through a period of trying to hitch every new, and a bunch of existing, services to Google Plus.
It just so happens that the guy in charge of G+ was a former MS exec. And over at MS it was typical to attempt to hitch your project to any other project coming down the grapevine (the Google people actually called this "cookie licking" on stage after he had left the company).
And if you look back you could see this going on with .NET, you can see some semblance of this with Surface, and now with Cortana.
I guess it can be seen as some kind of in-office bandwagon politics.
I see apparently there are workarounds to get Cortana in all regions but most people aren't going to bother. If we're getting degraded local search because of where we live that seems pretty dumb.
I never use the "Windows Search" anymore, i hate it. It's slow and useless. I always disable the service. Then again, searching with standard windows search is probably my biggest annoyance on Windows
IIRC there were other tools: regain, lookeen, ...
[1]: https://www.mythicsoft.com/agentransack [2]: http://www.voidtools.com/
This is a good analogy, but does it work in different circumstances? (Apologies for the derail)
Over on Android, the apps have got so big (and the storage was until recently so small) that automatic updates _cannot_ be installed - the new apps are too big, the phone is full. What do we do then?
Moving all my photos and ebook .pdfs off did alleviate the burden somewhat, but hasn't completely solved it.
My current workaround for very large apps is to uninstall, redownload, install. Apparently, holding both the update and the installed app uses much more space than doing a fresh install.
Then apply that to a local copy of the previous APK.
If that goes well, it attempts to install the new APK alongside the old install.
And if that works out, the user data is switched over and the old install and APK removed.
So at certain points during the install you need to have enough space for two full installs of the app, and the APKs they came in.
Or just leave them all on the internal system, until a system utility wakes up to the fact that there is not enough space, and suggest moving apps to the sdcard. After few rounds of updates, rinse and repeat.
What to do? Upgrade the hardware. It's not supported anyway. Modern Android devices which have updates published do not have this problem anymore.
A Moto G 2015 has only 8GB storage.
Even mid-range devices sold today only come with 8GB storage, of which 6GB are used by the OS.
The Moto G 2013/2014/2015
https://www.amazon.com/Motorola-Moto-3rd-Generation-Unlocked...
> And what price range are you using to define mid-range?
$200-$250
> Is there even a low-range (lower than 8 GB) if 8 GB seems to be the absolute minimum, since the OS won't even fit on something smaller?
See above.
The only Moto G model that doesn’t offer 8GB anymore is the 2017 edition.
I suspect this is an artifact of using the Linux kernel. As said kernel puts a focus on IO ops, and the EXT file systems spend a whole lot of time looking for contiguous free space before committing a write.
Thus if your app do a bunch of writing (say syncing local data with the cloud) at start, it will start quite slowly on a near full Android device.
Apps take up 6.32 GB of storage on my phone. The remaining space is taken up by the app cache. This isn't useless information like you'd expect, but it turns out it is data that is vital to the operation of my apps. I clear it fairly often, but it fills right back up again within a day.
Luckily I have an SD card slot, so I have space on my phone, but Google does not like expandable storage. Probably because they are a cloud organization or something.
I personally like to stay on a fairly new phone, but I think it is stupid that your phone can become obsolete within a few years. If the radios are still compatible with the cell towers, manufacturers should be obligated to support them. If you can't support your phones, don't churn out so many crappy phones.
I know times are different, but I used a Motorola Razr V3 from 2004 to 2011. It worked just fine for the entire time. Obviously internet sucked, but I was going to school in a place where the internet barely worked anyways.
If you just want a phone for texting, calling, and maybe as a GPS here and there, there is no good reason to buy a new phone other than planned obsolescence.
Outside of the app binaries and such you have their core data, stuff that gets generated or downloaded on first run.
Besides that you have a cache directory pr app that is housed outside of the tree location of the binaries and main data.
More recent Android versions have introduced yet more complications on this via the storage access framework, by providing APIs that give apps limited RW access to "external" storage areas without having to request the related permission.
And that's without going into the whole history of just what "external" means when dealing with Android file storage.
Microsoft needs to deliver updates in tiers in order to regain trust. Simply dividing it up into mandatory security updates, optional bug fixes, and optional feature upgrades would go a long way to addressing that even if the default is for all three tiers.
And when you do get one, you don't lose sight.
(My favourite complaint is Windows replacing GPU drivers with MS approved broken ones on major updates.)
Except that there were demonstrated cases of MS inserting the "brainwashing drugs" on the updates. Many people had legitimate copies of Win XP bricked by XPA, MS alti-malware broke install a couple of times in Win7 (and off-line machines were bricked by DRM more than once), and, finally with Win10 we've officially got the spyware and adware coming through updates like people were long expecting.
And not restoring jack shit. I wouldn't mind Windows Update so much if it could competently restart my applications and restore my Explorer windows, but the only thing it does every fucking time is make the taskbar icons disappear until I force-restart the Explorer process.
Though I would still mind it a lot for the insanely slow and unhelpful update process at shutdown, every update requires half an hour of shutdown as the machine does who the fuck knows what with an unhelpful throbber telling you it's at 30% of some arbitrary process you've no idea about and which looks exactly as if the entire thing had crashed.
Nothing is better than running a simulation for twenty hours and waking up to a nice blank desktop. /s
In a similar vein, imagine that you're ill-advisedly using a Windows server to host your node for cryptocurrency mining, and then it restarts when you're not around. You could lose serious amounts of money from that.
Vaccinations are awesome, but Microsoft's heavy-handed bundling is similar to how the CIA was using vaccinations as cover to collect DNA[1] samples in Pakistan. This inadvertently led to a distrust of vaccinations[2] which harmed the efforts to eradicate Polio (or biological WCry, if you will).
Additionally, Microsoft abused the update system to download an entire, multi-GB OS (Windows 10) on systems running on Windows 8, "just in case they will want to upgrade". This was very expensive for people on metered bandwidth. Microsoft should separate critical updates from the less critical ones and give users the ability to opt-in for critical updates only.
1. https://www.theguardian.com/world/2011/jul/11/cia-fake-vacci...
2. http://www.nytimes.com/2012/07/10/health/cia-vaccine-ruse-in...
If we want people to regain trust in auto-update there need to be something that prevent abuse. If that is regulations, liability laws, or just industry practice will be up to the future to decide. Until then a person will have to rational decide on auto-update as past people did with the uncertainty of not know what is snake oil and what is real.
You are far too confident in current medical practice.
People avoid doing firmware updates on various devices for the same reason, as there is no indication what will change or go missing (never mind that it likely will reset the device, and thus require a full reconfigure before being useful again).
The basic problem of our world is that it is ruled by 20-sometings that loath working on "old" tech. The epitome of this is the FOSS world that goes through a wrenching rewrite churn every 5 years or so as new heads take over "old" projects.
For all their antics, one reason MS is still top dog is that they support APIs and ABIs first introduced with Windows 95 (or even older, if you manage to do a 32-bit install).
Never mind that MS did offer XP updates, for a price. One reason the NHS got hit hard was that some penny pinching bureaucrat decided they could not afford to pay said price.
Disagree thoroughly. The reason why people push shit through the security-updates channel is because of money and structural pressure from management to ensure adoption of the company's new $THING.
It's a big problem in tech, trying to get people to update. We might like to think of ourselves as progressive, but a lot of people in our world tend to be very conservative and resistant to change. Microsoft knows that as well as anyone else. The only way to ensure people are using the latest version is to stop giving them a choice. You can't always rely on people making the best choice for themselves.
That sounds super authoritarian, sure, but the nice thing about technology? Microsoft isn't the only game in town. They can do whatever they want with their platform and you're free to leave. You don't need a passport, or any more money, or really even any additional knowledge at this point. You're only locked in if you choose to be locked in.
*with "everyone" being the typical Internet strawman that only actually exists in a random selection of HN comments.
Agree with the first part, the second needs a very twisted definition of best or themselves.
Offer something people want and they will upgrade. This alone tells very much about the win10 situation. Microsoft game is lock-in, if the cost of leaving their garden is trivial they are doing something wrong!
I have a friend who buys $500 laptops. They last him a year, and then he has to buy another laptop. He laughs when I buy $1000 laptops, but those $1000 laptops last me three years. Over that three year period, he's spent $1500 on laptops and I spent $1000.
I have a friend who uses Windows XP. Windows XP is better, it's faster, it's leaner, Aero is garbage, Metro is garbage. DirectX 12 is just a scam to get you to upgrade, there's no reason Windows XP isn't the best. But once a month he's calling me about some kind of virus he's gotten even though he runs Symantec every day.
Relying on an outdated piece of software is never the best decision. If Microsoft's updates bother you that much, stop using Microsoft software. Microsoft can't lock you in to anything, and there's very little that Windows offers that OSX, or to a lesser extent Linux, doesn't offer. The arguments against switching come down to "I hate Apple/Linux", in which case you've locked yourself into one vendor for irrational reasons, or "Apple is too expensive", in which case you have to wonder if that's actually true considering you're spending hours complaining about Microsoft updates, or the worst one, "I'm a Windows developer", which... why? If you hate Microsoft enough to want to switch but Visual Studio is the only thing holding you back, I don't feel bad for you. The only slightly legitimate complaint is the lack of games, but there are a ton of games for Mac these days and consoles do exist.
It's not really lock-in if you choose to be locked in.
The arguments against switching come down to "I hate Apple/Linux"
Not at all. Many people are forced to use MS software, they don't have a choice. Not just running Windows, but using various MS Office apps, formats, Skype etc.
Also, there are others (mainly elderly) who are only familiar with Windows, learning another platform is not a freebie for everyone.
Most apps people need have alternatives on other platforms, but there are many - besides games, that target Windows only. Well, VS being the bloatware it is, not one of them of course.
You've identified a source of inefficiency in his workflow. If he really hates everything after XP though, maybe it's better (more efficient) to handle a big problem once a month than a dozen little problems (disliking aspects of the tool he's using) every day.
> "I'm a Windows developer", which... why?
That seems like an easy answer, though. Because someone's paying me to work on the technology that they want to use, which may be very different from the technology that I decide to use on my own time. Things can be personally suboptimal, but professionally useful. You don't hate it, but you don't love it as much as the things you use on your home machines.
> Relying on an outdated piece of software is never the best decision. If Microsoft's updates bother you that much, stop using Microsoft software. Microsoft can't lock you in to anything, and there's very little that Windows offers that OSX, or to a lesser extent Linux, doesn't offer.
Using software that actively works against your best interests, even while acting in your best interests in other ways, without a way to separate the two...is never the best decision. Microsoft can't lock you in, but platform choices of other developers can.
On a separate point about OSX: One thing it won't ever offer is the ability to run it on my hardware of choice. I happily pay Apple-like prices for hardware configured in ways that Apple doesn't offer.
> The only slightly legitimate complaint is the lack of games, but there are a ton of games for Mac these days and consoles do exist.
Games aren't fungible. Mac and Linux support lots of games, including what I was playing last night. Sometimes, what I want to play is limited to a single platform, and that platform is one that I wouldn't choose for general-use. C'est la vie.
> It's not really lock-in if you choose to be locked in.
That sounds like one of the arguments I've heard to justify things like TSA searches, or the various statements from politicians saying that internet access isn't a necessity and shouldn't be considered a right. "You don't have to fly! You can drive! No driver's license? You can bike!" Well...right. You don't "have" to use Windows, because you don't "have" to make software that works with Windows. It's your own choice to target customers using the most-used PC OS in existence.
disagree completely, it's not the 20-somethings that come to you and say "the budget we have is limited, and we have to prioritize, feature X might get us more exposure, so work on that and it doesn't matter if it breaks backwards compatibility, users will adapt"
If upper mgmt goes after "oh shiny" there's not you can do at the individual contributor level, and if you know you are in a "oh shiny" management situation there is also no incentive whatsoever in spending time making sure you think about the future when developing, since you're going to have to throw everything away anyways in a few months or a year at the most.
It's all about "being nimble" and "velocity" and "being innovative", where all of them are more or less shorthands for "churn things quickly until something sticks". Stable, reliable, dependable software is unsexy, if the company you work for is large enough you might be able to find a team that works along those lines and be happy, otherwise it's fighting fires all the time.
But maintaining code (especially shitty code) gets you much fewer rewards and recognition than writing new code from scratch (including shitty code) -so that may be a better explanation of why most people don't like being "maintainers".
We run Windows 10 and the lastest Windows server on all our machines and don't have problems because we have good, in-house, local IT people and also good security on the edge routers.
In System Preferences -> App Store
I can uncheck the box that says "Automatically check for updates". It's trivial to override these perceived "flaws" in OS X.
Try doing that with Windows. The best you can do is peruse some lists that people maintain in places like Github. Maybe those work, maybe they don't. Consequently I've avoided Windows for well over 10 years now (except for XP in a VM, which I use for playing Freecell).
> Microsoft abused the update system to download an entire, multi-GB OS (Windows 10) on systems running on Windows 8, "just in case they will want to upgrade".
Just pointing out that Microsoft is not alone with the above practices? It's not a question of whether you can disable it or not, it's that ALL companies do this. I don't necessarily like this but I empathize, general consumers don't know what's good for them, and Microsoft's reputation for security is on the line here.
I also far too often see this logicaL fallacy being used. I was recently railing against MS and someone said, "well I'm more worried about facebook, what about them?" Your comments about OSX and Chrome have almost nothing to do with the the current discussion topic which is MS updates systems. I wish people would stop doing this equivicating, it's tiring and logically fallacious.
A person can call out any company they want for anything they want on the merits of their argument without it having to turn into a major company comparison.
All that said... gnu+linux actually allows the user control, and things like this can be stopped.
Bottom line is this, either the user controls the program, or the program controls the user. Google, Apple, and MS have all shown they are more concerned with controlling the user than giving them freedom. GNU+linux or really just GNU, is the future of freedom, and until people start understanding how inherently political software is, and stop basing their software choices purely on pragmatics (but mah lozedoze gaming!), these types of problems will continue to happen and have things written about them, but the solution is already here.
Stop using closed source proprietary systems.
Here's a better analogy: suppose you were pushed to get a vaccination, but the vaccine company secretly added a virus to the vaccine which alters your DNA so that your hands turn into claws and you grow antlers, because they thought this would be a great idea somehow. Then after word gets out about this, they say anyone who doesn't get this vaccine is an "anti-vaxxer" and "ignorant". That's basically what Microsoft did.
(reference for the body modifications: http://dilbert.com/strip/2004-04-18)
Why should they do this? And why should they care at all about people on metered bandwidth? What are Microsoft users going to do if they don't like getting a huge bill for downloading Win10 unexpectedly? Stop using MS? Not likely.
When are people going to wake up and realize that Microsoft has absolutely zero incentive to worry about keeping their customers happy?
Most people don't know/care about Windows Update pushing features.
However most people DO care when their computers spontaneously reboot themselves with no warning (sometimes even in the middle of "active hours"!) which is what msft has set by default (and indeed has/had no UI to modify in some versions of Win10)
But inversely, i'm annoyed that this "upgrade phenomena" seems squarely targeted at Microsoft when people who run Linux or OSX upgrade the second new shiny comes out. I'm not ranting here other than expressing a curiosity of culture that leads to cultural problems lingering much longer than they should.
Windows 10 is awesome.. the experiment with "ads" sucks but its all tweakable.. just jump to Rs2 and provide feedback if there is something you do/don't like. MS listens.
The problem are not (security) updates themselves. The problem is the intrusive update process and non-security updates bringing "features" nobody asked for.
I'm not sure where these absolutely incorrect assumptions are coming from but they're entirely false. Windows believe it or not is community driven these days. MS is delivering features for its "enterprise insides" and for its "xbox insiders" and for its "windows insiders" and this is a HUGE community.
Because all in all, Windows is getting less and less useful and more and more annoying. No, you don't need to stuff Cortana, Onedrive or whatever new initiative you have. If I wanted it, I would sign up by myself.
In my case, after I disabled the infamous KB 3035583 update for N-th time and it was back again, I lost my patience and switched the platform. I'm too old for such games. Some of my colleges still need win32 specific apps, but you can be sure, that as soon as they will be able to replace them, they will jump too.
I have no idea what the KB 3035583 problem is.. everyone makes mistakes. My mac had failed updates where I had to reset, my iPhone has had bad updates, my kindle fires have been borked, my android phones have been bricked, my wifi routers have been bricked.. I just take the time to learn and move on.
People are obsessively convinced Microsoft is bad, for no other reason that they're not giving them another chance yet the world turns a blind eye to very similar issues across the board.
Software isn't perfect. You don't fix software by never updating it. We're used to updates on Mobile/Tablets - many people are used to updates on PC/Tablet/Desktop but there are people who continually beat this non sequitur horse that PCS can't and shouldn't be updated.
Software is eating the world. If people want to compare MS to google - Google updates their shit all the time - does hundreds of releases a day. Now so does Microsoft. But hot damn, if MS does it they're "Evil" and "pushing crap or features no one wants" when we full know that is BS.
If Microsoft has feedback hub, throws parties, online meetings, etc., then they are very good at ignoring the feedback. Did they fix the privacy issues with Windows 10? Did they re-enable end-user control over updates? Did they stop resetting user preferences after updates? It's not that they are not aware of all of these.
The problem with KB3035583 (gwx - Get Windows X) was, that no matter how many times you have hidden it (to indicate do not install), Microsoft un-hided it, and several times it has flagged it as security update, which caused for many people to install it automatically. It definitely wasn't an mistake, it was clear intent, to make target figures with Windows 10 upgrades. It is one of the biggest reason why people were turning off windows update!
> People are obsessively convinced Microsoft is bad
You know, I'm some 25 years in this business and there are many reasons why they are right. Microsoft worked hard to earn this reputation. From "knifing the baby" to their today's attitude regarding privacy and pushing their services.
> Software isn't perfect. You don't fix software by never updating it. We're used to updates on Mobile/Tablets - many people are used to updates on PC/Tablet/Desktop but there are people who continually beat this non sequitur horse that PCS can't and shouldn't be updated.
As I've written elsewhere, existence of updates is not the problem. The update process (hogging up entire core with wsupdate service? No problem! Installing updates for 30 minutes? No problem either!) is one problem. The shoveling of unwanted stuff into updates is another. Compare that to apt/dnf on Linux side or App Store on Apple side - they are as unobtrusive as possible.
> Google updates their shit all the time - does hundreds of releases a day.
Google updates do not make your machine unavailable for 10-30 minutes at the most unfortunate times in the day. Ever been to ambulance, where the nurse has lined up patients, because her computer doesn't work right now? Guess which fault it was, Googles or Microsofts?
I'm pushing 41.. I've been into computers since i was 8. I've been through wishing OS/2 would win, Hating on Windows for years, begrudgedly using WIn95 OSR2.. I was the first BBS in Houston to offer Linux to download on 8 floppy disk images, i was the first to mirror a larger FTP site for Linux distros (ygdddrasil), I use Linux on THOUSANDS of computers - i work for a larger internet company running 10-s THOUSANDS of servers running Linux.. sometimes i wish they were all solaris since that was what really grabbed my hart but guess what - things change - systems change - people change - companies change.
Today i sport a Surface Pro 4, an iPhone 7, a MacBook pro and a Ryzen 1700 as my primary compute/phone devices.. I use them all. Windows 10 on my Surface Pro 4 is the best mobile experience I've ever had. i have Ubuntu/Suse/Redhat as bootable native shells, i have a web browser with extension support, gesture support and great experience, i have power shell, i have hyperv if i need it, i have docker - the experience in windows 10 lately far surpasses the experience of say - docker on OSX which has always been very goofy until recently and now with docker on windows i can run windows or Linux native containers.
MS is not only providing lots of open source code but they're a HUGE sponsor of the Linux foundation - a SUPPORTING member - the biggest you can achieve.
As for update times, you can schedule your updates. If you need to upgrade your android phone, you're not going to be able to use it during the upgrade - same with your PC, if you have pending updates - just schedule them when you need them.
You're still defending everyone else for facing the same problems MS does and for some reason, still hating MS for solving problems that need to be solved.
I for one am SO FREAKING GLAD windows doesn't fester for years between "Service packs" that then took years to get released because people had it in their goofy heads that people actually tested them for them.. i'm so glad that windows finally releases iterative updates on TUESDAYS and everyone in the world knows when PATCH TUESDAY IS if they run windows.. if you KNOW patch Tuesday is coming up, reboot when you're done patching on TUESDAY.
It really isn't as hard as everyone is making it out to be.
Now that I've written all this, its laughable how hard people are making this appear to be.
I hope the responsible people at Microsoft are better at receiving and processing the information regarding their products and the problems with them.
Likewise. Stop spying on me, stop advertising to me, stop pushing products I don't want on me, stop treating my computer like your personal playground.
None of this is going to gain traction. All of those are the point. No amount of listening will fix this.
BTW, this isn't unique to MS.. phones update all the time and the concept of the phone is going to change.. soon you will have just one device that does everything. Are people going to complain that MS can't then do what Apple/Google do in regards to spying, updates & patches?
That's already true, for people who only have a phone. In the long term, it's completely wrong. Today's "super"-devices will explode into a constantly-changing constellation, as soon as personal networking is ironed out. Future generations will laugh at caricatures of people today, who constantly tend to and obsess on one hunk of plastic to the exclusion of the wider world.
Apple actually fights to protect your privacy, when you pay them money for hardware they just try to make it work well for you, not advertiser. And their updates/reboots are optional.
MSFT takes your money, then doesnt protect your privacy AND sells you out to advertisers.
Microsoft offers a very similar ecosystem.. You can use office online, One drive, bing.com, skype, Cortana, Outlook.com and many services free for use with advertising (or no advertising)
MS doesn't "take your money" either, you buy something with Windows 10 on it or you buy a mac with OSX..
iOS updates aren't usually optional, as they quickly spam the crap out of you to upgrade and stop allowing publishers to post apps for the old release ergo "forcing" upgrades.
Android has the inverse problem.. handsets never getting upgrade so people flock to versions that do and happily upgrade away..
which is why I don't understand anything you have said. :)
oh and MS doesn't sell your privacy data to advertisers..
Microsoft does take my money--just because the cost for the OS is hidden in the hardware doesn't mean some fraction of that money isn't going to Microsoft, i.e. in the end I have to pay to use Windows. Windows 10 was not free either as advertised, since it required an older version to upgrade from.
Compared to Google's and Apple's offerings, Microsoft's do kinda look shitty.
[1] https://products.office.com/en-us/compare-all-microsoft-offi...
As far as product comparison, I prefer Office over google docs (And the link you posted is about their commercial offering).
office.com offers the online versions of office (web like google docs) and its as feature rich.
Also, lets be real.. You can get office 365 for up to 5 pcs for 99 a year and each account you link to it gets the extra benefits such as terabyte of onedrive and such, its not a bad deal at all.
That was the only part that was correct. Apple reminds users of critical updates, doesn't force. Apple allows every publisher to upgrade their apps (I'm an IOS dev), just don't try to link with outdated APIs. I have iOS 6 apps that still run fine without changes.
And you don't know what MSFT sells to advertisers.
MSFT does spell out what they share with advertisers the very same way Apple and Google do.
https://www.google.com/policies/privacy/
This isn't true for many of us that build our own computers. I bought a boxed copy of Windows and installed it. It certainly didn't come with or on anything.
30 bucks in most stores..
or get licenses through visual studio benefits, schools or transfer from another PC you may be shutting down. It's not rocket science to save money if thats your biggest concern.
> This is now fixed..
Once bitten, twice shy.
Most if not all of the non-tech people I work with would respond to this with "yeah, well, I don't care, I don't want to take the chance it reboots during a presentation/webinar/demo/etc ever again".
I don't want to have to tweak my fucking operating system to remove ads!! Also, I think we're asking too much of the average user. It's not obvious how to do most of the tweaks, so your random older/casual user won't do them, or maybe even realize that such a thing might be possible and go off to look up how to do it. They're more likely to just turn off updates.
I am slightly bemused we're making excuses for people not trying anything.. especially when computers these days are all about "Expressing yourself" and "identity"..
Presumably some freak compatability issue (I've noticed ads always appear when I open files using a certain program).
if we're playing this game, we should play it fairly.
What i do see is that when i use outlook.com it doesn't pop down telling me to switch to Edge, but when i use Gmail its always telling me to switch to edge.
Have you actually used MS products in comparison to google? didn't think so..
Windows is the paid one here.
YouTube, Gmail, Google et all have a dropdown advertisement asking me to switch to chrome no matter which browser I user that isn't chrome..
Lets also not forget that MS apps show up on google store, apple store and are fully cross platform whereas google is selective in what it supports. We're at a day and age where Microsoft has Cortana, One Drive, Office, Bing, Skype, Photos and so much more on iOS, Windows, Android and people are telling me that MS is bad when google is good (and is far from as cross platform as ms is) I just say use whatever, but if people want to nit pick about "Ads" that everyone does without knowing how everyone does it, that's lame. MS has a TON of "Free stuff" that isn't always dropping toasts to switch browsers, switch to chrome so on and so forth..
If people have so much energy to hate on something, that should be directed at sloppy companies like Yahoo that actually are detrimental to security/safety..
With the Microsoft services, the crucial difference is, that "Cortana, One Drive, Bing, Skype, Photos" is stuff that Microsoft is pushing on people, not stuff that people asking for from Microsoft. It is me too solution, it is Microsoft's version of Google+, except that Microsoft didn't learn their lesson yet.
Out of this, Office is an exception. iOS and Android users would not give up their platform, but they were willing to use another lite office suite. On a platform, where there is not a such threat, such as desktop Linux, there is no Office port. Even the macOS port hasn't got feature parity with the Windows version. Google is treating Windows Phone exactly the same way Microsoft is treating other platforms with Office.
If you consider this hate, maybe you should also consider whether it is deserved. There's no reaction without action.
People are asking for these services.. just because you don't run them doesn't mean no one does. Skype is still the largest voip network, bing is slowly still growing against goole, onedrive is huge for private and corporations, Cortana ins on over 600 million devices..
As for office on OSX, it is updated all the time and feature comparable if you bother to run 2016 with updates enabled..
THe hate is far from deserved, its misguided.
Microsoft is so cross platform Visual studio for OSX is full RTM, Visual studio code runs great in Linux/windows/OSX, they're writing Linux drivers, they have the Linux subsystem for windows that runs native windows apps, they're a core supporter of the Linux foundation. .net is cross platform now too and they're starting to merge xamarin/XAML/xml forms so apps can be written once and run everywhere..
doing more for software and systems than google is but people will continue to have this misguided hate
If you claim people are asking for these services, then what about not showing them down the throats of those who didn't ask for them? Seem simple, right? If they are so popular, why piss off those who don't care about them? Why do I have look after every Cmd-O at Onedrive file chooser, when I'm never going to use it and there's no option "do not bother me with this again?". I'm sure that Cortana might be on 600M devices, but there are not 600M active users... more likely users what resigned on looking for a new ways to turn it off. See the difference?
Office for Mac 2016 is updated every month indeed, but it is still missing features. For example, everything that starts with Power (PowerQuery, PowerPivot, PowerMap), or Inquire. The Mac version of Office does work with exactly 3 ODBC drivers. It doesn't work with exactly the same ODBC drivers, that the Windows has no problem with (PostgreSQL, for example - it crashes).
There was a lot written about Visual Studio for Mac and it being a rebranded Xamarin. See past discussions here, at HN.
And let's go back to the Office for Linux, shall we? That's the Microsoft prime lock-in device for many. Drivers for Hyper-V or Linux subsystem for Windows help Microsoft, not Linux.
BTW, i never see any ads/popups other than after a fresh install when the guided tour is starting up so i have no clue what people are flipping out about.
VIsual studio for mac is a re-write of xamarin, that doesn't change anything - xamaerin/visual studio/c# are all converging to offer a unified platform.
And i'm so glad you seem to know everything about everyone. THe same "billion google now" users probably only 1% USE it day in/day out.. but we're just going to be blindly bashing windows..
please, do us a favor and get over yourself. We get it, you don't run/don't like windows... so just stop wasting energy hating something you really don't have any clue about or care about.
The "ads" are recommended software. It is annoying that you get a toast notification asking if you want to use office online just as its annoying every few weeks my iPhone asks if I want to buy more icloud.
But what is really happening is that anything with an app store is tracking you to build a marketing engine that recommends other apps to you. The fallacy is that Microsoft is the only one doing this, the truth is that everyone is doing this.
There are ways around this in OSX and Windows.. you don't have to use the store, you can still download stuff and install away and you can still enable developer mode and side-load anything you custom write if you want to use the new API features.
I don't like it when I choose to use edge and every time I go to gmail it asks me to swtich to chrome.
I don't like it on my iPhone that every time I use gmail it asks me to switch to chrome even though I selected the checkbox to use safari.
I'm tired of this conversation being so one sided and biased as it is doing the world a huge disservice.
Ads for apps are ads, no matter how you spin it. People don't pay for android, they pay for windows. A pay OS/platform shouldn't force you to disable ads. Gmsil/Chrome are free apps.
Apple doesn't track you. On installs it asks if it can collect usage info, but you have to agree, and it's one time. They don't show you ads in either OS. They don't track your personal info. They don't give government agencies backdoors like MSFT got caught doing. They go to court to fight illegal searches of your devices.
Its painfully apparent you really hate Microsoft for your own deply personal reasons. I'm not changing that. But I will stand up and say that what you have said is not true and not the case of Microsoft today.
I'm not saying you have to change but we must be clear that you are speaking from perceived history rather than current day times.
Google android is "Free" as Windows 10 is free.. you paid for it with hardware... now if you could build your own handset you could install android but it would NOT be the official "google" android because reality is - hardware companies still have to license it in such a way to get the official apps. But again, we're not going to talk about this in apples and apples, you're only framing it in your obsession of fear/doubt/hate against Microsoft. And again, that's ok, I really don't give a hoot.
Apple does track you. The Apple Privacy statement is almost exactly the same as GOogle and Microsofts. https://www.apple.com/privacy/manage-your-privacy/ - they all enable services and warn you about services that provide value add in some cases but can seem in violation in others.
Its up to YOU to understand what you want to share, enable/disable what you want to share and understand how changing that changes the system you're running in.
But its up to you to use what YOU want to use and respect others for what they want to use.
Spending so much energy spreading FUD does nothing.
Chromebooks aren't free, phones aren't free, tablets aren't free, Apple/Google/Microsoft all provide app metrics to all their respective app stores and all go above and beyond to try and make them secure (google actually having to struggle with this compared to the other giants)
This isn't true. I had to explicitly go out of my way to pay hundreds of dollars for a Windows license for my computer, which I assembled from components. It's not possible to pay money to anyone for Android; it's gratis. Google makes money on ads, not on selling Android.
unfortunately i can't find any cases that show how much of the estimated ~60 dollars per handset is licensing costs for the google apps (as some have been licensed to mfrs) or patent / indemnification agreements needed that google doesn't offer but still are a cost to selling android handsets.
I know google makes a LOT more money on ads.. but lets be real, while android was open source its current incarnation is nowhere to be found and his hidden behind represive agrements, advertising, and marketing and android phones in the end are no cheaper than any other phone price wise..
When i buy a surface/tablet/oem pc it just comes with windows.. When i build a PC i buy an OEM license for 30 bucks.. if you know the platform you're running you can know how to save cash and make the best of it.
So you're suggesting I avoid Microsoft then? Because that's the only way I can control it, otherwise I'm only an OS update away from MS re-enabling features I explicitly disable.
Microsoft is 100% responsible for this malware, they trained users to turn off updates by making them unbearable.
I have a MacBook pro, a surface pro (windows 10), a gaming pc (windows 10), a Plex HTPC (windows 10) and an iPhone.. I'm quite happy regardless and I find all ecosystems have their +/-
I clicked the option to disable this when prompted when I upgraded. It was easy and I've moved on. Life is great, i'm back to playing games, watching content and enjoying my device without it asking me if I want to upgrade office.
(but my damn iPhone keeps telling me to upgrade icloud)
Users have been very very vocal about dozens of things that Microsoft refuses to stop. What about all of the forced upgrades to Windows 10 without consent? For the longest time Microsoft just denied that they were even doing it. Then they just tried to justify it with marketing B.S. about how "Windows 10 is great, so no one should be complaining."
Then there's the embedded spyware in Windows 10 that's not able to be removed or disabled. Even just the adware, it should go without saying that no one wanted ads to show up in their OS. This shouldn't be something I should be forced to opt out of, it shouldn't exist in the first place. I shouldn't have to deal with Microsoft installing crap like candy crush on every windows PC on the planet.
Microsoft categorically doesn't listen to their users. Can you name a time when Apple or a prominent Linux distro has pulled any of this crap?
Yes, unfortunately. Ubuntu served Amazon ads in the dash search. No idea if they're still there (I use Fedora) but it's not like they had to ask anyone what they thought of it to be well aware that the majority of their users would think that sucks.
Apple? Well now- that's the company that continuously tries to force its users to run only the apps it choses, isn't it? Apple sucks as much as MS in the way it treats its users.
As for Apple though, I disagree with a lot of their design decisions but Apple hasn't introduced Spyware, Adware, and Malware into any of their products. Their walled garden philosophy is crappy but they aren't doing what Microsoft has been doing.
Even just the upgrade itself broke more than hundreds of thousands of computers. Sure, you can blame that on drivers or sketchy hardware but the bottom line is that Microsoft still upgraded those computers and caused them to become nonfunctional. Even after the upgrade, Microsoft allowed users to revert back to the previous version of Windows but I've personally seen that fail on three separate occasions.
I'm not just using hyperbole here, Microsoft really did do all of that and more with Windows 10.
And if you doubt the users who say that it upgraded when they weren't at the computer and that they never consented, there are plenty of cases of isolated machines like HVAC computers that didn't even have a display or input hooked up to them that broke because Windows 10 was installed. How exactly did Microsoft get consent for a computer that had literally zero input devices and no display?
Yes, Microsoft had some updates that updated some machines but they fixed that so it wouldn't. Yes, MS mad some silly assumptions to cache the update - that isn't what this is about.
THis is about the fact that the HVAC company SHOULD have upgraded. They should have known their outdated/unsupported OS constitutes a security risk and THEY should have corrected it and not assumed to leave it up to users who have/had no clue.
Windows 10 "Redstone 2" allows you to disable the supposed "spyware" that isn't really spyware when compared against any other OS out there. There are also easily abundant scripts to completely remove the concept of the store and anything attached to it from ever starting.. luckily you can do that on Windows 10 and pretend being isolated is what matters more than being current..
As for the ads, its supid easy to turn off the notifications. There is this "Notification center" where when you see the Office Notification - just click "don't show notifications for this app" and its gone. And if you see "Recommend apps" in start bar, click click and disable show recommended apps.
Both are dumb defaults, we can agree on that, but they're there and they can be removed/disabled. It's not that hard.
I've personally seen a computer that was upgraded to windows 10 after being left on over the weekend. The user claims that they never clicked on the upgrade and seeing as tons of other people reported the same thing I'm inclined to believe them. Fun fact, rolling back the Windows 10 update frequently doesn't work. The longer you wait after upgrading, the less chance you have of it working IMHO. After seeing this, I figured I'd test it myself and I booted up an old netbook that I had lying around and after running updates on it, it started installing windows 10.
>Yes, Microsoft had some updates that updated some machines but they fixed that so it wouldn't. Yes, MS mad some silly assumptions to cache the update
I've yet to see any reasonable explanation as to how that could possibly have been unintentional. MS just started trying to excuse their BS behavior by lying about what they did and trying to justify it with "but it's an upgrade".
>THis is about the fact that the HVAC company SHOULD have upgraded.
That HVAC company shouldn't have upgraded to Windows 10, they should have upgraded to a reasonable operating system fit for the purpose.
>Windows 10 "Redstone 2" allows you to disable the supposed "spyware"
>As for the ads, its supid easy to turn off the notifications.
Just because I can remove Microsoft's adware and spyware doesn't change the fact that it's spyware and adware. As for being easy to do either of those things, you might as well be speaking Greek to at least 95% of Microsoft's users. It's simple if you know a little bit about Windows, but most users out there don't know much of anything about Windows. Just look at all of the outrage over changing the start button in Windows 8. There was literally hoards of people who couldn't even figure that out. I guarantee you those same Einsteins aren't ever going to figure out how to disable telemetry with third party software or figure out that "Notifications" are all of the ads that they're getting spammed with.
Also, Redstone 2 isn't out yet, and to be honest, I don't have high hopes that Microsoft will allow Home users to completely disable telemetry when it does come out. They've lied about everything else involving Windows 10, why should this be any different?
In its infinite wisdom Windows won't let me set "7am-11pm" as active hours - it caps it at either 10 or 12 hours. So no matter what I set it to, Windows 10 updates will inconvenience me more than just about any other OS in the house.
I think the biggest thing is that people should care about being secure.. care enough to check for updates and be a part of the community they choose to be a part of - be it Linux/windows/osx/android/whateverthe* you want
In snapcraft, all updates are automatically installed: https://docs.ubuntu.com/core/en/reference/automatic-refreshe... https://www.youtube.com/watch?v=DLxqdf89hRo
There were some hilarious hacks to disable the Update Orchestrator and prevent the reboots. They work well, although allegedly you should not need them any more with the new Creators Update OS refresh.
By contrast, every single Windows Update that I deal with (a) requires a restart for seemingly no reason, (b) slows down the shutdown process immensely, and then (c) goes through sometimes multiple long installation processes, during which I cannot use my machine.
Of course, as a casual user, I would find Windows Update annoying enough to want to disable it. More so when my computer decides to restart of its own accord, sometimes right in the middle of me actively using it.
(Obviously, I am security conscious enough that I don't really disable Automatic Updates on my Windows boxes, and instead just remember to reboot my machine once in a while so it goes through them on my schedule.)
Could switching the Windows Update UI to a scheduled weekly reboot + updates (call it "Maintenance" or something) be useful? Would fewer people see the need to try to disable the updates if they could control exactly when they would happen, consistently?
Laptop decided it had to update while i was also updating security settings on my wifi.
both laptop and network were unable to reboot on their own.
luckily i also have wired network and other computers. so, i was able to recover; network didn't take too much to come bac k up. needed to create and use a recovery drive for the win10 laptop.
Basically, a computer running Windows is actually owned by the Microsoft overlord who can do whatever the hell it wants to do. Occasionally it allows you to use the computer at its mercy.
It seems the decision was forced down by management. I hope someone up the chain realizes how much its cost to the actual users.
There was a joke at MSFT "you don't become a VP without making the company lose a billion dollars"
I think it still applies today.
Personally, I don't understand computers well so thus might be misguided but what I want is something similar to se Linux or jails but every application stack lives on its own and does not share libraries with anyone else. The idea us upgrading one application should not break another.
But can any of it overcome worse-is-better? Are these things really that desirable for a personal computer or are they more suited to production servers? I've been using Gentoo as my main OS since 2007, on my current rig that I put together in 2009, and I wouldn't be that surprised if I'm still using it in 2027. Even knowing about other systems' advances I'm still using my own preferred set of compromises.
People really don't care about eventual (in)security. If given the opportunity, we pick convenience every time.
I set up a PC for him with a legal, licensed copy of Windows 10, and he promptly reset it using a pirate/cracked version of LTSB because he didn't want the "Windows 8 stuff" and he didn't want "Microsoft spying on him"
Within 2 days it was full of viruses and malware. I don't let him plug his computer in to our office network, and I don't let him near any of our office computers.
Of course, I've also had SMBv1 disabled for many years (there's no reason to retain support for it unless you need to support WinXP machines, in which case you have my condolences), the desktop sits on an isolated subnet with a very restrictive router and firewall in front of it and all telemetry, Cortana and other malware has been eviscerated via group policy and other settings, along with router-level blocking of telemetry and update servers.
I fully understand that my case is atypical and the average user isn't going to follow comparable precautions, so I don't actively recommend my approach to anyone else, but it works great for me. Apart from wasting about a day per year on maintenance, I'm as happy with the OS itself as I've ever been with any Windows version, and it fulfills my Windows development and occasional gaming needs just fine. Obviously, I'm much less happy with Microsoft as a company for forcing me to go through such lengths to make their OS into something I'm comfortable using.
You surely jest!
Individual users are not customers of Microsoft in any meaningful sense. Microsoft sells the OS mostly to companies who install it on machines so that the end user buys a computer with Windows already installed.
If MS wanted to keep me as a customer they would have provided a proper upgrade path for all the millions of lines of VB6 code that are out there and they would create an IDE that has a usable editor.
I seriously question that presumption. I think Microsoft is generally trying to satisfy enough of my needs to keep me in their ecosystem while extracting as much value as they possibly can (within legal, technical and business constraints) from collecting data on me, pushing ads, etc.
I'm certainly not saying Microsoft are "more malign" (by whatever moral standard) than hackers out to steal people's money, however, by virtue of using Windows, I automatically have a degree of exposure to Microsoft that can only be mitigated rather than eliminated altogether. My exposure to ransomware and other non-targeted attacks by non-state actors is vastly smaller, and much easier to mitigate.
I am under no illusions about my ability to withstand targeted attacks by more competent parties, but that isn't a particularly significant concern to me.
Yes. And there is no /s on this comment.
We don't use much recent Microsoft software because we no longer trust it. They are going down a path we don't want to follow.
With the older OSes that we do still use, principally Windows 7, we are similarly sceptical about updates, and typically we only apply necessary security patches now.
[Edit: For whoever is downvoting a lot of the comments with this sort of sentiment, you might consider that objectively we have had far more downtime as a result of bad updates from Microsoft than as a result of malicious actions by hackers over recent years, and I doubt we're alone in that.]
So in reality we do have more concern about Microsoft's update channel, which has a trusted, straight-shot channel directly into the core of our system than we do random Joe hacker who had to bypass our NAT, find a zero-day, etc.
From a secure point of view, Windows update operates within the secure zone with root privileges. Of course that's more concerning if you don't trust it that an external hacker.
I haven't seen it put that way before. You're not alone.
One of the recent update cycles had some kind of interaction the video drivers on several of my machines, resulting in monitors connected via DisplayPort intermittently failing to wake up following a screen blank. The current workaround is for users to reach around the back of their monitor, unplug and replug the power. I burned an entire day on that one, plus the continued frustration.
Knock on wood, but I can't remember the last time I had to scramble for a security incident or malware outbreak.
The anti-vaxxer movement makes no sense outside the backfire effect, in almost all cases it has little to no basis or justifications. On the other hand there is a long history of very valid reasons of distrusting windows update and disabling it.
Using windows update to force people into windows 10 is only one of the most recent examples that windows update is by Microsoft and for the interest of Microsoft not the user. This is totally different from the system update you have with apt and Debian.
Autism is the product of having a differently wired brain than a non-autist does. It's something you're born with, not something you can get later.
Certain medications used by pregnant women can result in children being autistic, but I seriously doubt that this extends to any vaccines as well. Perhaps some really exotic ones maybe, but common vaccination definitely not.
Source: I am autistic, read up on it to be able to better deal with it and am dealing with it on a daily basis.
And truth be told, I don't know if I'd be better or worse off without it. It doesn't make my life unlivable and I guess the understanding of autism of most people is too much based on rumor-mongering and hearsay, than any actual facts.
It's one of the downsides of autism that understanding the intent of other people can be hard or impossible, so I'm always grateful for hints like that.
No, it isn't. Anti-vaxxers think that vaccines are harmful (or useless). Most users think security updates are important, they just don't want to be interrupted.
Vaccines are harmful; it's just that the positive effects vastly shadow the negative effects in the general case.
This is why the anti-vaxxer analogy is foolish and frankly rather offensive. Managing updates is about risk, and the risk from Microsoft screwing up your entire system with updates was demonstrably very high before. For example, anyone who was using the default settings to trust Microsoft's suggested updates got changed automatically to an entirely new OS not so long ago -- a new OS, incidentally, which has also had compatibility problems with various hardware, which also has significant privacy concerns particularly in places like doctors' surgeries or other environments managing sensitive information, and which is also infamous for disrupting normal day-to-day work by changing things and/or rebooting at undesired times.
I know plenty of smart, well-informed people who work in IT and made an active decision to reduce or disable updates on some of their Windows systems for these kinds of reasons. Whether they would have advised home users with no technical knowledge to turn updates off completely is a different question, but it's not an entirely unreasonable policy given Microsoft's recent track record of abusing automatic update processes.
Microsoft lost every single ounce of credibility with the way they force-loaded Windows 10. Turning off Windows Update isn't enough anymore. The only solution is to dump Windows. Install Linux, or buy Apple hardware. It's unfortunate, but Microsoft will never recoup the trust it lost with the push of Windows 10. Microsoft cannot be trusted.
I disabled it a long time ago and haven't looked back. Get back to me when MS starts remembering their customers are human beings again.
> Get back to me when MS starts remembering their customers are human beings again.
Oh, they know. Their whole abusive process is build around milking that fact for all it is worth.
MS has MILLIONS of people yammering for features and they go to great lengths to shorten the release cycle for getting new features to developers and customers.
I find this as a positive thing and this concept of MS as "the enemy" is absurd..
You're essentially writing off 10s of millions of happy customers participating in a growing and flourishing community without any regard..
Empathy.. its a good thing.. even if your personal choice is that of something else.
But yeah I get a notif when the update is available and I install it whenever possible.
Regarding unwanted features, have you tried Classic Shell / Classic Start Menu? Literally first thing I install on a new Windows installation.
At that point, Windows 10 became a liability, and that laptop still doesn't have automatic updates turned on anymore. (It still gets routine manual updates, but it's definitely not ideal.)
Running an MS OS has been a one-way ticket to owned for roughly 18 years now.[1]
You are fragile to these things because you choose to be - not because this is a necessary condition of participating on computer networks.
This ransomware attack was based on an SMB vuln. One of the stuxnet vectors was an autorun vuln.[2] Would you wake the fuck up and see that it is 2017 and you're getting owned by SMB and autorun vulns ?
[1] Melissa virus was 1999, BO2k was 2000.
[2] Has any single file caused more mayhem in the world than autorun.inf ? The net negative effect of autorun.inf on the world must be in the tens of billions of dollars by now.
We avoid taking a big amount of medication that would fix some problem just because it's harmful (and even medication that is less worse than the disease).
"Do you want to upgrade to Windows 10? Press the hidden button to cancel, otherwise upgrade commences." This is how malware works.... But published and pushed by MS's own channels. And his jab at people who say that turning off WU is similar to anti-vaxxers is completely inane and false - we know the damage Microsoft has done to user's computers.
In reality, I'd rather they upgrade to Linux. Those machines wouldn't get bit by this, unless you run the executable with WINE. But I blame MS for being spammy and spyware-y and malware-y, which encouraged users to turn off harassing and onerous updates.
I also have more than a few stories of people hiring me precisely due to a hijacked OS install of Win10, accompanied by slower machine and worse usability. It only takes a few of those and a whole social circle will warn about it (because of the time and harassment).
In fact, I remember this getting so bad, that local news media was talking about how to stop having your machine hacked by MS with a forced Win10 install. In all honesty, if this were you or I, we'd be facing CFAA charges for this shit.
If I have a desktop pc and I shutdown, I don't mind an update. but if it's a stealth download of windows 10 pro when I have home, then NO.
if people never shutdown, then yes maybe force a reboot for critical updates. but windows needs to figure that out.
if I shutdown a laptop because i'm running out of battery, then updating windows for 30 minutes is not a good idea.
and sometimes you'll get 30 updates in one go when I've shutdown the PC every day and it should have installed a few in that timeframe.
But really, it's getting worse. I remember seeing a bunch of articles last month about how to preemptively defend against the "creator's update" because it came bundled with a bunch of software people didn't want. They use windows update as a trojan horse to install new applications, that sets a very bad precedent.
I've even stopped urging my friends and colleagues to enable auto-updates because I'm worried that they'll end up having windows auto-update to a new version and break something and then I'll have to help them through it. I just can't be bothered anymore.
The other day I helped a friend set up a new computer, we installed a brand new (paid for) Windows 10 on it, straight from the Microsoft-provided DVD.
It worked just fine for a few hours, then it would get stuck in a reboot loop continuously. You'd log in and 10 seconds later it'd hard reboots.
Given the brutality of the crash I assumed a driver issue or something like that. Turns out it's just Windows failing to install an update and crashing the OS for some reason. So I thought "well, let's just boot up and quickly disable auto-updates". You can't do that. "Well let's boot up in safe mode". Nothing works in safe mode, you can't access Windows update (the page remains blank). We ended up downloading an updated version of windows and reinstalling it.
I have a Windows 10 PC that I use for gaming, the creator's update installed itself the other day. Amongst other niceties it added a MS edge link in my taskbar and changed my desktop wallpaper. I also noticed that it tries to argue with you when you try to change the default browser from Edge to something else ("We're good now, we promise!!"). Minor details, nothing major but it adds up to a general distrust for the OS and the feeling that I'm not in charge of my own computer.
I just can't put up with that nonsense anymore. If my friends want support they'll run Linux, otherwise I'll let them deal with Microsoft's support or whatever.
You don't get free service from lawyers, accountants, doctors, or mechanics, I don't see why people expect free help from me. I used to help people, but I've realized how limited my free time is, and I prefer not to spend time doing work-like activities outside of work.
I will direct people to the appropriate resource if they ask for advice though.
Dealing with Microsoft's support is quite an experience, I think I would be better off talking to some indian "anti-malware" "security experts" that would install remote controlling software and would tell you some fancy tech words that you could listen to while they're at it.
I should be able to tell my friends "yes, you should turn on auto updates, there's absolutely no reason not to" without having to follow with any caveats like "oh well, it can upgrade your OS, reboot on you when you don't expect it and change the ergonomics of your desktop without asking you but in the end it's worth it for the security updates, and it's not like you have a choice anyway".
> I should be able to tell my friends "yes, you should turn on auto updates, there's absolutely no reason not to"
The anniversary update was mainly a shit show. It was a staggered update that cause issues for many folks. Some people kept getting fail update errors. Others got stuck in boot loops. Others lost certain device functionality. If you were able to get it to successfully install without hitch, it broke some things for a non-trivial amount of people.
Your comment is spot on, but it's not what I was talking about.
Bingo. For a while, Microsoft was really good about not requiring restarts to install updates. I haven't had a restart-free update since I installed Win10.
That should be unacceptable and I don't know why it's not.
I have updates set to download but not install automatically and I periodically manually install them. Microsoft's active-hours thing is BS too as it must be less than 12 hours. I honestly don't care as much if my machine reboots between 1:00am and 7:00am but apparently that's not enough time.
How long does it take to install updates anyway? Why can't I just set my inactive period to 4-6am?
When you have a small SSD it sucks.
I ended up having to delay my working day by about 45 minutes while Windows decided to do a mandatory update without any granularity of choice on when is convenient for me. That's what is frustrating. I ended up being unproductive for a whole hour because Windows forced an update on me.
Windows definitely have to make it better as Troy suggests. The frequency is also costly.
shutdown /r /t 0
AFAIK, this has always avoided updates.
^_^
This can be rather dangerous if your laptop is stuck in a backpack with no airflow on a hot day.
The laptop would be hot enough to toast bread when I pull it out.
If I'm out of town for 2 weeks, I cannot have my Windows 10 machine reboot, it runs the software for my security cameras and that can't start until I log back in. Thankfully, I set up Windows Update to not install updates automatically(Win10 Pro) way back when it came out and it has continued to stick. Major updates are a constant worry that they will finally break this forever when it shouldn't even be a concern in the first place.
ChromeOS updates the system once every 6 weeks and still has a far more secure system.
Is it not still like that? MacOS seems worse to me, since restarting when an update exists isn't sufficient: you have to remember to go back to the update and click 'update & restart'...
Linux handles this best though, by a long shot.
IME OSX is way better, the shutdown update process is much shorter than on Windows (where it is frustratingly long) and not all updates require rebooting.
There is.
In my configuration this is still working. I went to services.msc and searched for "Windows Update". I stopped the service, went to its preferences and selected "Disabled" as startup type.
It works fine.
One of the reasons I choose a PC over a Mac is because I want to decide things for myself. Microsoft's updates seem very Appleish to me.
All they need is large text that says something like, "You are more likely to get viruses, malware, randomware, etc if you uncheck this setting." Heck, make them confirm the choice two or three times. Some people want to risk it, some people need to risk it. Let them, it's their machine and their data.
Implementations actually matter. Hordes of us would jump ship if we could, but convincing vendors to port flagship software, or even do something as seemingly straightforward as a license migration is never easy.
Sorry, I have no sympathy. Look for alternatives, or roll your own. Or find a new line of business altogether. Whining about your OS vendor abusing you is getting really, really old now. Like an abusive boyfriend, they're not going to change, so it's up to you to make a change.
Then one day windows realizes, holy smokes, we have to install those updates now! And proceeds to restart your computer regardless of your update preferences, typically right in the middle of your business day.
Changing the updates to install on shutdown is slightly more challenging than disabling updates (it is hidden in an option about power settings on boot). So guess what people do?
Their current solution is scheduling updates to periods when the computer is not in use. I think recently they added an option for you to define a set of hours where updates take place.
But the problem with this is that people don't treat Windows PCs like always-on devices like they treat mobile phones and tablets. So in those night hours the computer is off forcing daytime updates.
Well, how do Linux and other unices do that?
services: they are specifically designed to be updated and restarted
I write plenty of daemons (you call them "services"). What exactly do I write specifically for them to be able to continue to run when a library is upgraded?
From what I know, Windows doesn't allow a library to be replaced until it's not used by anything, which is more intrusive and is IMO the root cause (though indirect) why people hate updating Windows.
I don't think systemd supports what you are asking but it shouldn't be too hard to write a service that restarts other services if their shared libraries change?
gcc --staticIf you never restart a Linux desktop (or at least log out), you will be running outdated libraries, even if you run updates in the background.
(The best solution would be what Android does, where every program is supposed to know how to checkpoint itself, and they are forcefully restarted on a upgrade, transparently to the user. But even there, updates to system libraries still require a full reboot.)
In fact, if you can't afford the restart even when you schedule it, there's ksplice and a variety of similar solutions that can switch to a new kernel without a restart.
I did have firefox behave weirdly once after an upgrade until I restarted it, around v15 or so -- but I believe even that is no longer an issue; at the very least, I haven't had any issue with upgrading firefox while using it, and restarting it a week later.
But whatever windows does is way worse, I dread seeing the "please wait while Windows is configuring your updates" screen. I have an SSD, rebooting Windows takes less than 30 seconds, it's a non issue. But those update installs can take a long time and your computer is completely unusable while that happens.
It's also frustrating when that happens while shutting down because I normally turn off my computer's power outlet when I'm done (it switches off the rest of my equipment) so I have to wait patiently for Windows to allow my computer to shutdown before I can do that.
Oftentimes it looks suspiciously as if the (rightful) need for security and quick responses is used as an excuse for "OS-as-a-service" shift that mostly benefits the vendors.
What happened to the old practice of clearly distinguishing between "security" and "feature" updates? What happened to actually educating the users?
"Fuck you, I want some sweet data and money" is what happened.
I take that as a proof that the whole discussion is more about pushing Windows-as-a-service than about actually caring for security.
[1] https://news.ycombinator.com/item?id=14340449
[2] https://docs.microsoft.com/en-us/windows/deployment/update/w... "Long Term Servicing Branch"
* Don't reboot it without my consent
* Don't install/run advertising without my consent
* Don't install/run spyware without my consent
* Don't keep interrupting my work to nag me for my consent
The tasks I want to accomplish using my PC are more important to me than the tasks you want to accomplish using my PC. If the latter get in the way of the former, I will take whatever steps are necessary to prevent this from happening.
One might reasonably claim that allowing Windows Update free reign prevents malicious software installing itself on my PC and introducing undesirable behaviour.
However, if the introduction of undesirable behaviour by malicious software is a risk, but the introduction of undesirable behaviour by Microsoft a certainty, the incentives do not favour enabling automatic updates.
The best solution, of course, is to switch to a stable Linux distro.
Wrong: you are implicitly agreeing to the above 4 behaviors if you willingly use a Microsoft OS. Any time you select a vendor, you implicitly agree to their business practices and the way their product/service works. For MS, that means you consent to it rebooting whenever it wants, advertising to you, spying on you, and interrupting your work to nag you for consent. If you don't agree with these things, then you need to find another vendor.
>The best solution, of course, is to switch to a stable Linux distro.
Exactly!
Without those, you aren't much of an owner of anything.
Of course it is not as bad as on OSX, where if you install any Google product, like Drive or Chrome, it will nag you to authenticate it, by misleading you with messages like "We need you to authenticate so that our software can run properly" (It will run fine without you authorizing it). Google will then install the deceptively named "Keystone Agent", which runs as root, and monitors your filesystem for Google software, and will silently delete and replace it with the latest versions. Often, these newer versions remove existing functionality, such as the ability to disable DRM in Chrome [1].
The reason for this pattern for updates, is because users might not agree to this if they were given a choice.
Author here blames people that took prudent actions to preserve their autonomy, while MS was holding them hostage by bundling security updates with unwanted monitoring. Many of them switched to Linux/BSD and are using Windows minimally as a consequence.
Win10 is a shame.
They could have at least separated security updates from random crap updates. A button would be nice as well.
If anyone knows how to disable updates on non-professional win10, please let me know.
edit: I do know about security and the importance of updates. You few downvoting me can go shove it up your arse. It's crap behavior from win10, period.
Start --> 'services.msc' --> find "Windows Updates" service --> right-click --> properties --> switch it to Disabled and reboot.
Turn it on once a month or whenever YOU want to update. Done.
Thx.
Time to msconfig this laptop to "usable" state.
edit:
Parent comment flagged ? Are we on "Anti-hacker Non-news" ?
Anyway; Start-> type "services" (or "msiconfig" for more options, basically the same as winXP) and you can turn off "windows Update" there. Don't forget to turn it on every once in a while, especially if you use public networks.
update: There's also a thing called "Background Intelligent Something", that is the thing doing the actual downloads. Seems it continued downloading even without the update service running. Said service looks mildly important, but still it had to die.
I once had to turn off updates on all laptops in my workplace so we could use the internet. (They thought the network was under a virus attack)
In such a situation you can dramatically reduce the bandwidth required by setting up an update server. There's no need for every laptop to download the same patch from the internet, download the patch once and everyone gets it.
(I appreciate that doesn't help the situation where you don't have enough data for one machine)
Yeah yeah you can turn of Windows updates or whatever, but you shouldn't have to do that just to force Microsoft to respect your wishes to update when you want to. And no, I'm not talking about some stupid restricted 8-hour window with no other option outside completely shutting down the service. TBH I'm still surprised they haven't tried to block users from doing that too at this point.
In the atmospheric/climatology lab there are a number of computers running very specific versions of Windows (down to specific patches) tailored to really obscure science research software packages, some industry standard, most custom-rolled and tailored to that project. Which means they're very fragile and need to be left alone.
Of course Microsoft blasts Win10 installer files down our very expensive, very slow satellite link, and proceeds to force Win7/8 systems to Win10 which broke a few multi-million dollar experiments in a place that takes MONTHS to get to in the winter. So effectively killed the research.
And yeah, you can argue "well you should've disabled Windows updates etc etc" but in REALITY, not perfect-theory world, you should be able to trust your OS manufacturer not to force-install a major OS revision without your consent. And in the old days of Microsoft, you could. Now they just say "f--- you, we're installing it regardless what you want."
That company can die in a fire for all I care.
Imagine this: you're a broke grad student and you're given $xx grant money to conduct a certain experiment in N months. What are you going to spend your VERY limited time+money on? Finding a good Linux hardware developer to roll some custom solution that no one can understand or support? Or just throw together some hacky Python or .net MVP that will run on Windows which practically anyone in the world can troubleshoot with basic knowledge?
Linux is great and all (runs on all my systems except one), but it is NOT the best option when there are heavy time constraints and the system is going somewhere very remote where there will be one, MAYBE two people with basic IT knowledge to troubleshoot.
Just install some distro and "just throw together some hacky Python". If you had some hardware and measurement instruments that require Windows for drivers then I could understand it, otherwise it's just negligence.
> or .net MVP that will run on Windows which practically anyone in the world can troubleshoot with basic knowledge?
In my experience people who claim that they could troubleshoot Windows is usually just that - they claim it but rarely can they actually fix anything.
I don't know, maybe Windows is that much better and easier to use for everyone and I just can see it - who knows...
It likely is. I have read similar stores about having to refurb an aging 386 or 486 running DOS. This because it is being used to operate a very expensive particle sensor, and the company that made it is long gone.
And if you want to replace said sensor you first have to get the funding to do so, and then you have to shut down the lab for a year to run calibrations so that the results from the new sensors can be compared to those of the old one.
I have some doubts about this story... The forced Windows 10 update was only sent to non-enterprise versions of Windows. I highly doubt any of these experiments were running the home editions of Windows due to the lack of control. Also, I am pretty sure that running home versions of Windows in contexts like this is against the Windows TOS.
If you had a mixed OS environment with a Samba-based domain (or no domain at all, because these machines just take data from lab equipment and shovel it onto network shares), there was a good chance of the update firing off anyway.
FWIW there was a handful of reports of exactly that happening on /r/sysadmin. There was also a ton of domain joined machines that were spammed with the Windows 10 nagware but didn't actually upgrade on their own.
I guess you've never worked with budget-constrained grant projects before.
> I do remember you talking about going to Antarctica in the Tron subreddit
7 months on ice.
> I hope that there isn't some undocumented part of the script that is disabling automatic updates.
Tron doesn't perform ANY undocumented actions. Unlike most the people defending Microsoft's actions in this thread, I am pro-user and seek to minimize negative impact to users in any project I'm involved in.
> Also, I am pretty sure that running home versions of Windows in contexts like this is against the Windows TOS.
If you're telling me there are people in the world using Windows in violation of its TOS I'm shocked, SHOCKED to say the least.
And you're pissed at MS because of this?
And yet he wants to completely blame them.
They are useless for a small team doing a research project.
These project machines are shipped (or physically hand-carried) by grad students from random universities all over the world. They come from who-knows-what IT department running who-knows-what software packages, often cobbled together JUST enough to get it working because they're so budget and time constrained that's all the resources they had to throw at it. So the lab is full of bespoke machines running a variety of very obscure software, much of it on tailored Windows boxes.
So no, "me and my colleagues" didn't "destroy a multi-million dollar project by trying to save a few dollars."
Unfortunately that also comes with completely incompetent IT staff.
For Windows, Microsoft restricts features but not what purpose you can use it for if you're talking about Home versions. For Office however, the home version actually has restrictions in the TOS that limit use to only noncommercial purposes. For a standalone Windows box that is only used for some lab equipment and will never be domain joined there's a good chance that there's no technical reason to go with Windows Pro over Home.
The lesson there is that you should always quarantine computers that need to be pinned on very specific versions of an OS, especially in such a precarious setting! Those computers should not have been able to communicate over the internet at all, except for those cases where communication is part of their purpose (e.g., monitoring the experiments), and that should happen via a dedicated VPN allowing only the traffic necessary.
I'm surprised this isn't the standard operating procedure for this kind of case.
Best i recall, MS was very very insistent with their Win10 "upgrade". To the point that they relabeled the installer patch as critical (aka, reserved for pushing 0-day patches or similar) after people found they could change certain settings to make it go away.
Well, sure, and if they ran a critical machine with no backups whatsoever it might have also been fine for years, but that hardly makes it reasonable practice.
Totally overlooked the suspicious timeline of Microsoft releasing patched for vulnerabilities that were exploited for a long time by the NSA right after it was made apparent those had been stolen and were about to be released in the wild. No question asked about NSA having known and exploited those vulnerabilities for a while, no question about Microsoft possibly willingly playing along or being legally forced to do so.
No mention that disabling Microsoft update trend is a logical answer to Microsoft using the system to silently installing spying software, breaking the system altogether, disabling pirated versions among others.
No mention that the solution to things like the wannycry outbreak is not turning on windows update but less windows and more other OS and backups. With a sane backup policy ransomware is merely a joke.
No, it isn't. Disabling update isn't a logical answer to _anything_ except "what's the best way to get malware". If you don't want Microsoft's "spyware" don't install their OS. There is no coherent logic to simultaneously not trusting Microsoft, and running their code - any version of it.
I disabled Win10 updates over 1.5 years ago with zero issue. Security people love to claim the sky is falling, but it's all about risk/reward. Risk of issue due to actual exploit is pretty low for most people, so even though the potential IMPACT is very high, because the probability is so low compared to the constant irritation of Microsoft arbitrarily forcing whatever they want down your throat once a month, they just deal with it and shut off updates.
edit: downvote if you want, I'm not wrong.
Try doing the Windows 10 anniversary upgrade if you run bitlocker and have customized your UEFI.
Windows will screw up, bluescreen, and destroy the bitlocker keys.
I’ve fought with that before.
Windows’ Anniversary Update works by adding an additional, hidden EFI bootloader, and loading that for the upgrade.
If you instead load the normal Windows EFI bootloader while the upgrade has half-way finished, then it fucks stuff up.
I’ve been through it multiple times, last time, Windows even destroyed all its own EFI entries.
Of course there is. Many of us found Windows 7 to be a useful OS and trusted Microsoft of that era to produce it. That doesn't necessarily mean we trust Microsoft of this era or more recent Microsoft products to be something we want to use. There is no logical incompatibility here. They've simply changed their strategy to one some of us don't like, after we bought some of their earlier products and before the support lifetime of those products ran out.
So it's a trade-off: Security threats or antifeatures.
Get some error code, search for it, find 1001 sites that offer you to tell exactly what is wrong, for a price.
1) Windows update installed just security updates instead of potentially disruptive crap "features". The epitome of that, is of course forced update to Windows 10. Ads in Explorer is a close second. This would reduce the frequency of updates significantly as well, which would also help.
2) Windows update would use a sane default of not rebooting you while you are in the middle of something.
There's a setting that you can do where windows installs update in the background, with no user intervention, but IFF it doesn't require a reboot, and asks otherwise. But this setting requires Group Policy (or being part of a domain), so it's not available to non-Pro Windows customers (and it's a very esoteric option users won't know about anyway).
You can also reduce the frequency of updates with "install updates for windows only", but you can't really restrict yourself to only security updates (unless you run Windows 10 Enterprise LTSB edition, which you don't).
Actually the best thing for Windows, both usability and security wise would be to make Windows 10 Enterprise LTSB edition the version of Windows people use.
As I said, it is totally feasible because Microsoft is already doing it with LTSB.
But in reality they are spreading dangerous misinformed information.
Windows's auto updates though can be annoying, ensures that the average computer is up to date. Like in the example of this article:
"If you had any version of Windows since Vista running the default Windows Update, you would have had the critical Microsoft Security Bulletin known as "MS17-010" pushed down to your PC and automatically installed. Without doing a thing, when WannaCry came along almost 2 months later"
The average user cares that their holiday photos, documents or credentials don't get stolen or ransomed.
On the other hand, this is how I started programming when I was 15 :D
But well, I didn't write it in my resume till I finished my CS degree.
> The average user cares that their holiday photos, documents or credentials don't get stolen or ransomed.
Are both true. However, windows updates also occasionally cause restarts in the least opportune moments (e.g. when you have unsaved work and left for the day), or make a restart take 40 minutes when you need your computer right now (in the middle of an important phone call). Both of these have happened to virtually every Windows user I know, prompting some of them to disable Windows Updates.
Other issues with windows updates are bandwidth abuse (getting Win10 downloaded automatically on metered mobile connection), breaking some software/drivers/configuration, or installing unwelcome telemetry spyware. Each of these only happened to one or two persons I know.
The average user now keeps all their holiday photos on their mobile phone / cloud, but they do care about documents and credentials.
You are not wrong, but the way Microsoft Update behaves, you have to choose the lesser of evils (potentially get ransomwared, vs potentially avoid things listed above). It is not patently clear that Windows Update is universally the better option.
And it wouldn't be a choice between evils in the first place, if microsoft didn't try to advance their agenda by stopping the practice of "security updates" vs "other updates". Microsoft deserves all of the blame for the disdain to Windows Update, and therefore a big chunk of the sorry state of its users.
I've never had such intrusive updates on Mac or Android.
Perhaps Microsoft needs to figure out how to make updates much more seamless. You shouldn't need a 2-hour reboot in the middle of editing a word file just to protect against malware.
Oh, and if Microsoft actually had a QA department to make sure they don't brick machines.
https://www.sysnative.com/forums/windows-update/22645-win10v...
Tracking it down required using sysutils' procmon.exe to log about 4GB of event data and correlating it with the CBS.log. It was a broken embedded unicode string registry value with a byte swap from x36 to xFE.
My point -- there are a LOT of posts out there with people with broken windows 10 updates, and I think Microsoft could better address this.
Windows only updates when you're doing something because you're putting everyone else at risk by not running the damn things in and you've had plenty of notice.
Then again cars only warns when the fuel tank is getting empty, Microsoft updates may happens at times and is totally unrelated to the ability of your computer to continue working.
Or you wake up, get dressed for an important meeting, unlock your door, and suddenly realize you're going to be late because your car decided this was the best time to finish refueling in spite of your instructions to refuel at another time of day.
See update notifications? At the end of the day, restart and install the updates. It's not rocket science. It doesn't just hit patch Tuesday and then reboot immediately, shafting you. And it doesn't screw your workflow up.
Really this has to be done because even the best of us put it off eternally.
The whole point of active hours is that, when updates are pending, they install and the system reboots outside the hours in which I've expressed the desire to have my machine not reboot itself. Yet I've lost count of the number of times where this does not happen - I see an update notification, shrug and assume it'll be applied in the window I've set, and take no action - only to find the next day that the updates haven't been applied, the reboot hasn't been performed, and if I don't interrupt my work day by applying updates and rebooting immediately - which rarely takes less than 15 minutes, not counting getting all my tools up and going again - then I can rely on losing some work, and a lot of time, later on, when something important needs doing on a deadline. And that's insane! If for whatever reason the updates legitimately can't be applied in the window, the right action in response is to wait for the next window, and not to fuck-start my workday. That is always the wrong thing to do.
I mean, I get what you're saying, right? If active hours worked as claimed, you'd have a real point here. But they do not work reliably at all, and that's a whole 'nother issue.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings
Set DWORD IsActiveHoursEnabled to 0.
I'm nearly resigned to the fact that I may have to segregate engineering workstations to their own network and whitelist their traffic.
IsActiveHoursEnabled is ignored.
At that point you should probably be using windows server + wsus. Which give you a lot more control over updates.
However this IS definitely an edge case and it is possible to turn it off. I have run a physical host as a build agent that has uptime of months on Windows 10.
This is administrative competence, not a problem with the product or the use case.
WSUS + Windows server is definitely fine for most workloads though.
I have this dreadful feeling that Microsoft is A/B testing this stuff, making sure that there is just enough inconsistency between sites to sow doubt and confusion.
I wish we used wsus though. M
You should assume that windows users doing batch stuff over night are people who have better things to do with their computers during their day or want their computer to work for them while they're not sitting in front of it. Try considering the whole instead of splitting to only address the large majority.
Windows 10 is focused as a consumer os, designed for users to run their applications. Similar to iOS or android.
If you want to run batch operations, use the right product.
Sorry, but this does come across as a bit asinine.
What's the right product for running software written for Microsoft Windows, if not Microsoft Windows?
"Users running their applications" isn't just Grandma on Facebook, or your little sister playing Candy Crush Saga. Microsoft's unquestionable strength has been it's support for enterprise, small-business and professional desktop users. There is a lot of deserved anger thrown their way as a result of deliberate decisions to force flexibility and choice-limiting behavior down the throat of their core market.
My shop is small, but I can count COMSOL, SolidWorks, OrCAD, LabVIEW, various SPICE frontends, and a dozen other small odds and ends for instrument control and data capture without even leaving the engineering suite. All of which are going to be forever stuck on Win 7, at this rate.
You may get the need to have things to run overnight using engineering, simulation, rendering products with some sort of long running process. But these normally have server component that you install onto Windows Server, which the client offloads to.
I'll be sure to let them know that long-running computations deskside are now only an experimental feature /s
In all seriousness though, we've managed over a decade without the need for dedicated compute nodes along with the costs that would entail. The only case I can make for that right now is that current Windows now ships with unpredictable uptime.
And if you want your machine to DDoS Playstation Network that's your right too, right?
And if I want my kid to get measles and spread it around, that's my right?
As much as you may argue it's your machine, and your right, sooner or later your choices start to impact other people. What about their rights, then?
Still, I see the software you're using as much a part of the problem as Windows here. Needing weeks of solid up-time to complete something is a challenge and doesn't seem like a realistic assumption by a developer for software running on Windows.
Why can't it remember progress and resume after a restart? That would not only make the impact of Windows Updates much smaller, but also power outages and the like.
Definitely gunna use this as an opportunity to resume that conversation though
Man you're in for an amazing time when you will learn about that stupidity called the Internet of Things.
(and yes, I am well aware of, and utterly terrified/upset/bamboozled by, the Internet of Things)
A client had started a time consuming process before leaving the office, came back the following morning with the process having failed due to windows applying updates and rebooting killing the process and losing a day worth of work.
YMMV.
I don't know what you mean by "this has to be done", there is no obligation to apply updates. What if I want my computer to run a windows without updates ? Am I not entitled to use my own property as I so choose ?
> I don't know what you mean by "this has to be done", there is no obligation to apply updates. What if I want my computer to run a windows without updates ? Am I not entitled to use my own property as I so choose ?
If your machine becomes a botnet node and causes problems for other people, which is a big problem, then you forfeit the right. The same thing if your apartment leaks water into another one. Be a good citizen.
Failed updates, now that's the only valid part of your point. I've had a few and they weren't disruptive but this is just my case.
There was no event log or logs of any kind, her system got entirely replaced by win10. For this specific case I would tend to not trust the log anyways. What I do find strange is that the windows 10 installation process should have asked to accept the EULA before installing, it did not and went on as if it was an unattended installation.
Good luck trying to explain people that they have to forfeit their freedom because they have to behave like good citizen. Anyways windows update is barely relevant here as the common vector used for botnet infection is almost always the user, not windows vulnerability.
Mine is that this has never happened to me since I switched to different OSs than Microsoft's, circa windows XP.
However the former has a different security model and the latter is mainly run by experts. The point is moot.
I like this analogy! A car that runs out of fuel when its manufacturer tells it to!
> Windows only updates when you're doing something because you're putting everyone else at risk
Are you sure it's me putting people at risk, and not Microsoft?
The global scale of it shows how the end user is less trustworthy than the vendor.
The default attitude of most people I've interacted with regarding technology is apathy. If it works, they're happy and they leave it alone.
Do you really think that a significant number of non-tech people would have gone to the trouble of looking up how to turn off updates to their facebook/email/google machine if Microsoft hadn't caused a massive shitstorm with their forced update BS?
The vendor is entirely at fault for making stupid short-sighted decisions that caused users to lose trust in the update process. No amount of handwaving can change that fact.
- If Microsoft had coded its software properly there would be no need to patch vulnerabilites,
- If the NSA had told Microsoft about the vulnerabilities when they were discovered instead of exploiting it (Assuming the NSA did not tell MS to not patch them on purpose),
- If Microsoft did not have decades of being untrustworthy gathering the logical response of disabling auto-updates,
- If Microsoft had not paid vendors to have windows pre-installed on new computers it would have the monopolistic position it has today,
- if the NSA exploit and tools had not been made public,
- and so on...
All these are also valid ways that would have prevented wannacry spreading.
In your case it should be possible to have a windows "branch" with just critical vulnerabilities patched with binary diffs or something rather than 680-odd Mb patch sets.
Download the updates manually and share them via USB storage with other peoples, assuming you have other people in similar situation around you and they are willing to do the same.
Our software and engineering staff are no longer confidently able to perform long-running operations overnight or across weekends. Simulations, and data-capture runs in particular are now routinely being done during normal business hours since users cannot trust that their OS won't kill everything for an update midway.
Among my tasks for this coming week is working up plan to isolate key workstations, and estimating the required budget to provide the affected users with secondary PCs for routine tasks which require internet connectivity.
So, you're admitting in public that your organization is using the consumer editions of Windows for business use instead of the enterprise edition, which allows administrators to control updates and reboots? Sounds more like your IT department basically doesn't know what it's doing; the additional cost of the enterprise edition is negligible compared to the cost of your engineering software and other tools.
> putting everyone else at risk
What hyperbole. And what a bizarre thing to socially shame people over. This is like using 9/11 to emotionally argue for behavior changes, a week after 9/11.
That's a terrible analogy. I have been shaming people for bad security practices and self-righteous ignorance for many years (even before 9/11 ironically!).
I've seen too many people have been wrong and had a bad outcome including complete data loss and in one case livelihood being shot entirely. This isn't a random assertion from thin air. You can't trust people to look after their computers.
The case you mention seems to be cases where having backups would have prevented the dramatic outcome.
Using an appropriate analogy to make something clearer works better than shoehorning something to push your view.
I plug my laptop to charge the battery when convenient and operate in a geographical area where power shortages are still an exception so I have no fuel issue in my computer usage whether I use automatic system update or not.
Actually I do not use automatic system update, if there is such a thing for this OS, it is discouraged as updates can sometimes break the system if applied blindly.
How exactly can someone not applying updates when windows asks for it put everyone else at risk ? What risk do I face from this from behind my BSD firewall on an Arch linux powered computer ?
Then again my experience of windows computers since windows update was introduced is not in line with what you describe here, getting even worse in recent times with updates applying themselves with little to no warning, sometimes running several times in a row: logs you out of your computer, applies updates for 10-45 minutes, reboots, applies updates for 15-60 minutes, logs you in, crawls your computer down by downloading more updates, logs you out of your computer, applies update for 10-45 minutes, etc...
I've witnessed this happens 3 times in a single week, the owner of the computer was pissed, I'm paid by the hour and happily browsed the web on my linux laptop while the client pestered against his computer, microsoft, technology, corporations, politicians allowing this to happen and so on.
You are better than 99% of users which is what this issue is about. You are a power user capable of looking after a machine. The problem the people who aren't.
Assuming that things work the same elsewhere as they do around you is akin to self-deception.
I'm probably leaning towards the power user category of computer users nowadays, but I wasn't born that way I learned it the hard way by having to deal with Microsoft's crap for years. Now it has become a habit too.
As implemented, Windows 10 feels like a system to deploy code and update computers that happens to run user software.
It's obnoxious. Many people I know have solved the problem by moving to Apple.
My Linux install never urges me to update. Updates come out many times a day, and I can ignore them entirely for as long as I want. My Windows install continually urges me to update. It makes them increasingly hard to ignore, to make sure I install them. The idea behind this is not bad: many people would postpone updates indefinitely without understanding the consequences. Browsers these days install updates without even asking the user, and complaints about that are rare.
The problem is that updating Windows is a terrible experience. It wants to install updates when I shut down, which on a laptop is often the moment I'm leaving, when I'm ready to put it into my bag and go home. This is a terrible time to install updates. It's even worse because the time the updates take is incredibly unpredictable. Sometimes they're done in a minute, but I've also had a single small update take 45 minutes. I ended up putting the laptop into the bag while it was running the update. When I arrived home it was very close to overheating, had burnt through much of the battery capacity (the battery in that thing isn't very good), and it wasn't done yet.
Then I figured the solution would be to avoid updates at shutdown, always executing them manually when I was going to keep using it for a while. This is how I handle updates on Linux, and it works perfectly. So I tried that a few times, and the experience was terrible. It would always require a reboot immediately after, while I was working. This is a terrible time to reboot.
Meanwhile, every time I update my Linux installations, it's painless. I just run the update command, it tells me exactly what it's going to update, I accept, and I can leave it running in the background. The longest one of those updates ever took was 10-15 minutes, on a machine that hadn't been on for 6 months. Hundreds of packages updated in minutes, without disrupting the work I was doing. An hour or so later I shut it down and from the next boot on I was running the newest kernel.
What Microsoft needs to do is to make updates painless. It needs to be clear what is being updated and how long it is going to take. It needs to stop requiring reboots all the time, and when that is achieved it needs to stop updating on shutdown.
Also important: It needs to stop requring multiple reboots for one update round. Windows, for me, is not the OS that boots by default. Every time it restarts I need to explicitly tell my computer that "yes, unfortunately there are still reasons to keep using this."
Until the browser decide to break something you used (see firefox and alsa support on linux, or firefox and australis, or firefox the upcoming drop of non web extension extensions, ...). Automatic update should be limited to critical security and not significantly alter or break user experience.
> Meanwhile, every time I update my Linux installations, it's painless.
You're lucky you did not have to deal with upgrading ubuntu, or linux mint update packs, or used a distro like sidux, or have been hit by a systemd bug preventing the system from booting making evident that systemd also broke the emergency shell used to fix things. Updating a linux system is usually less painful than a windows one, but it is not as flawless as your experience paints it. With the advent of systemd it is now more windows like requiring reboot and tightly coupled versions.
I jumped on that train when they moved to GTK3, but said train seems to be running out of track.
As of late, Mozilla have done a whole lot to alienate long time _nix users in their attempt at catching Chrome's tail.
And you bring up a good point about tightly coupled versions.
_nix was in part adopted because things were loosely coupled. But in the pursuit of attention the DEs and various other big projects have steadily pushed for more tight coupling so that they can deliver a certain "commercial" UX.
1. For home users, turn on auto updates. Yes, MS's policies for updates suck, but the alternative is probably getting infected by something worse. For professional use, IT is probably going to turn it off, but then it is their responsibility to make sure critical updates get installed.
2. MS's policies suck, so everyone should disable auto updates. Then, make sure the machines have critical updates installed manually.
Unfortunately, history has clearly demonstrated that the second step of #2 doesn't happen. Heck, the NHS probably has a dedicated IT staff and that particular update hadn't bubbled to the top yet. That produces option 3:
3. Turn off updates to be moar bettar, then be surprised when the machine starts acting funny.
Once you update, Windows 10 is gonna reboot sooner or later. You can schedule it, but there's nothing you can do to stop it. It's unavoidable. It doesn't care if you're running a long compile, or uploading a large file. If you aren't sitting in front of the computer, it's gonna reboot, period.
I find this to be unacceptable.
The previous behavior, where it essentially nagged you mercilessly until you acquiesced, was far superior. I didn't go out of my way to find a 3rd party program to disable that nag-- I found it useful, to remind me I had to reboot at some point, when I found it convenient to do so.
The NSA should be focused on protecting US interests by helping these things get patched ASAP, not sitting on a treasure trove of 0-days and then they get leaked and everyone has them whilst chaos ensues.
Microsoft should be focusing on providing less controversial updates, clearly categorizing essential security updates apart from new, often controversial features. What a mess Windows 10 roll out was.
They have billions of dollars and can throw legions of software engineers at this problem fairly easily with their resources, this isn't some minor company that can't handle this issue.
But it does not work that way and wishful thinking and shoulds have no impact.
Telling people they're powerless and that they shouldn't bother is a great way of making them powerless.
Blaming the users is nice and easy, but Microsoft definitely deserves half of the blame (if not more).
Snaps were designed from the beginning to push automatic updates, even of non-security updates: https://www.youtube.com/watch?v=DLxqdf89hRo
Few people really mind updates. What Microsoft really needs to do is minimize the number of forced restarts required, like Linux which only really needs a reboot if you update the kernel itself (and even then, there are ways around that).
So was pushing the original Windows 10 update from Windows 7. That didn't stop them.
Once bitten, twice shy.
It's mind boggling how much bad software is available for Windows. Microsoft is doing a rather impressive job maintaining backward compatibility and yet some vendors manage to lock their software to specific version or even "patch-level". How do that even happen? Actually I know how that happens, developers that don't give a shit about the platform they're developing for.
https://www.reddit.com/r/technology/comments/4mcdon/i_live_i...
I'm going all the way back to Windows 7 here.
The only machines that are terrible to use are those I use at work because they are laden with all sorts of corporate security crap that you can't escape and bring otherwise decent hardware to it's knees.
Of course, the evidence that Windows Updates are problematic seems overwhelming but I do wonder if this is a case where the complainant numbers seem large simply because the install base is so massive.
This article isn't advocating for Microsoft, it's advocating AGAINST turning off automatic updates whether that is from a Linux distro, Apple, Microsoft, Google, etc.
Just update your device/computer, if you don't like the OS switch, if you want a specific patch etc, maybe that should be run in a VM which is gated. But for 99% of users, do not recommend they turn off auto updates.
Also, remember that if you are reading this you are probably a power user. You are not my grandmother reading an article by a power user with simple enough to follow instructions to f- her computer up. There are multiple user bases, and your advice to non-tech people can be disastrous for them.
In fact, there's a "run security updates only" option, which Microsoft provides, but which they deliberately and blatantly violated, by pushing their non-security updates through.
If Microsoft wants to stop this happening, then they need to provide a "security updates only" option, THAT ACTUALLY ONLY PROVIDES SECURITY UPDATES. This is not a hard concept.
"Turn off Windows Update" is indeed a suboptimal choice, like you say - what you should ACTUALLY be recommending to users, is to ditch Windows entirely if at all possible, and switch to an OS that is both secure and doesn't ship antifeatures.
He hates Windows 10.
I rate Microsoft a strong sell.
It should be "tell people to use a non-windows OS" instead.
[Ex daily Windows user for 10 years+ now]
Ye gods, people, if MS updates or win 10 defaults offend you so much, switch OS.
If you consider it a crime that the most widely used consumer desktop operating system in the world's latest iteration dares to not be tailored on install to your specific philosophy or preferences, switch! The alternative is free!
Win10 takes it to the other extreme, where it is impossible to disable it. You can only disable it for Wi-Fi and for each network separately. It is insane really and creates all sorts of problems in some use cases.
PS: another problem - some of the Win10 updates caused dozens of incomprehensible errors in Event Viewer on my PC, now I turned on "defer updates" and hope that delay will help MS figure out problematic patches before they will arrive.
Usually I'd say it's their own fault but fuck it, it's Microsoft's fault. Everyone knows Windows licenses are overpriced and that if Microsoft actually cared about collective security they'd bring the price down. Stop pretending you're not a part of infrastructure.
Interruptive updates are _the_ reason many people choose Mac OS X over Windows. Updates are, obviously, important. Restarts (and notifications) are bad and will be postponed and ignored, no matter how hard we try to educated users. Solution: throw all resources to minimize restarts during updates, make everything as automated as possible. I realize that it is harder to do for Windows, due to their idea of putting everything to the kernel, but this only exaggerates the urgent need for something like ksplice to be integrated.
Best i could tell was that MS was trying to update some drivers, this failed badly, had to be reverted, but that still left the relevant patch in the queue, and so Windows would try again on next reboot.
Finally had to resort to some kind of downloaded wizard from Microsoft to blacklist the patch. Not sure if that will be possible on the education version (or am i confusing it with the more recent S edition?).
You can really avoid like 90% of the shit by...
* Not going on shady sites
* Not getting scammed via Phishing
* Not pirating (you know, its really funny how most illegal 'patches' say, oh yeah patch is detected as trojan and its a false positive)
Sadly i have seen various legit tools trigger the same warnings, because the developer used similar low level techniques that malware use to hide their true nature.
Basic thing is that at the CPU level all instructions are legit. And then we pile code upon code on top to try to extract the context and intent of the programmer from the behavior of the code.
In a sense that can quickly devolve into computer "racism".
I disabled windows updates and haven't had a problem since.
Being someone that regularly uses all three major platforms, Windows 10 has definitely been the worst experience.
This is yet another episode in "hey, software isn't just to make you rich". It turns out it runs shit like hospitals. Maybe don't pervert the security tool for marketing purposes.
- it would not potentially brick their computer
- it would not install all kinds of spyware
- it would be a net benefit to the user
- it would not be used to further MS's business goals at the expense of the users
Telling people not to turn of Windows Update is putting the horse behind the cart: Tell Microsoft to start respecting their users, then tell people to turn on Windows update.
Fat chance of that happening though.
KSplice shows that you can update a running system without restart.
Real shame that MS, Chrome etc don't all manage this.
1. Don't use a public IP on your laptop on the internet.
2. Don't run shit or use IE.
Bypass 2 if you're a developer and you are experienced in this stuff.
Seriously, I genuinely want to know, because the people that just got this, are going to continue to get shit in the future.
MacOS has been doing this for some time and while it's not perfect, it's definitely led me to be less concerned about rebooting my Macs.
Any idea if this also prevents security updates?
But hey, I can ask Cortana for some random stuff and have it fail 95 per cent of the time; nice priorities, Nadella!
In that case could not the president issue an executive order asking NSA to use the hack to protect everyone?
Our German chancellor, Angela Merkel, went from "this is unacceptable and can't happen under any circumstances and there will be repercussions" to "please don't do it" after the Snowden leaks went public.
There is little political backslash and no legal one. The spy agencies (NSA, CIA, GSHQ, BND, #insertanotherhere) do whatever they want with little to no oversight. And if the public finds out about it, the first move is to legalize it by law and continue as before.
NSA probably did some forced update of their own.
I would be surprised if there wasn't at least a couple of paragraphs in the eula where people give much more control over to Microsoft.
For apps that don't run on Linux for now, like Adobe, I'd rather move to OSX. Only reason for me to install Windows would be some obscure game that only runs on that platform. I honestly cannot think of any other reason to install Windows.