Windows only updates when you're doing something because you're putting everyone else at risk by not running the damn things in and you've had plenty of notice.
Windows only updates when you're doing something because you're putting everyone else at risk by not running the damn things in and you've had plenty of notice.
Or you wake up, get dressed for an important meeting, unlock your door, and suddenly realize you're going to be late because your car decided this was the best time to finish refueling in spite of your instructions to refuel at another time of day.
See update notifications? At the end of the day, restart and install the updates. It's not rocket science. It doesn't just hit patch Tuesday and then reboot immediately, shafting you. And it doesn't screw your workflow up.
Really this has to be done because even the best of us put it off eternally.
The whole point of active hours is that, when updates are pending, they install and the system reboots outside the hours in which I've expressed the desire to have my machine not reboot itself. Yet I've lost count of the number of times where this does not happen - I see an update notification, shrug and assume it'll be applied in the window I've set, and take no action - only to find the next day that the updates haven't been applied, the reboot hasn't been performed, and if I don't interrupt my work day by applying updates and rebooting immediately - which rarely takes less than 15 minutes, not counting getting all my tools up and going again - then I can rely on losing some work, and a lot of time, later on, when something important needs doing on a deadline. And that's insane! If for whatever reason the updates legitimately can't be applied in the window, the right action in response is to wait for the next window, and not to fuck-start my workday. That is always the wrong thing to do.
I mean, I get what you're saying, right? If active hours worked as claimed, you'd have a real point here. But they do not work reliably at all, and that's a whole 'nother issue.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings
Set DWORD IsActiveHoursEnabled to 0.
I'm nearly resigned to the fact that I may have to segregate engineering workstations to their own network and whitelist their traffic.
IsActiveHoursEnabled is ignored.
At that point you should probably be using windows server + wsus. Which give you a lot more control over updates.
However this IS definitely an edge case and it is possible to turn it off. I have run a physical host as a build agent that has uptime of months on Windows 10.
This is administrative competence, not a problem with the product or the use case.
WSUS + Windows server is definitely fine for most workloads though.
I have this dreadful feeling that Microsoft is A/B testing this stuff, making sure that there is just enough inconsistency between sites to sow doubt and confusion.
I wish we used wsus though. M
You should assume that windows users doing batch stuff over night are people who have better things to do with their computers during their day or want their computer to work for them while they're not sitting in front of it. Try considering the whole instead of splitting to only address the large majority.
Windows 10 is focused as a consumer os, designed for users to run their applications. Similar to iOS or android.
If you want to run batch operations, use the right product.
Sorry, but this does come across as a bit asinine.
What's the right product for running software written for Microsoft Windows, if not Microsoft Windows?
"Users running their applications" isn't just Grandma on Facebook, or your little sister playing Candy Crush Saga. Microsoft's unquestionable strength has been it's support for enterprise, small-business and professional desktop users. There is a lot of deserved anger thrown their way as a result of deliberate decisions to force flexibility and choice-limiting behavior down the throat of their core market.
My shop is small, but I can count COMSOL, SolidWorks, OrCAD, LabVIEW, various SPICE frontends, and a dozen other small odds and ends for instrument control and data capture without even leaving the engineering suite. All of which are going to be forever stuck on Win 7, at this rate.
You may get the need to have things to run overnight using engineering, simulation, rendering products with some sort of long running process. But these normally have server component that you install onto Windows Server, which the client offloads to.
I'll be sure to let them know that long-running computations deskside are now only an experimental feature /s
In all seriousness though, we've managed over a decade without the need for dedicated compute nodes along with the costs that would entail. The only case I can make for that right now is that current Windows now ships with unpredictable uptime.
And if you want your machine to DDoS Playstation Network that's your right too, right?
And if I want my kid to get measles and spread it around, that's my right?
As much as you may argue it's your machine, and your right, sooner or later your choices start to impact other people. What about their rights, then?
Still, I see the software you're using as much a part of the problem as Windows here. Needing weeks of solid up-time to complete something is a challenge and doesn't seem like a realistic assumption by a developer for software running on Windows.
Why can't it remember progress and resume after a restart? That would not only make the impact of Windows Updates much smaller, but also power outages and the like.
Definitely gunna use this as an opportunity to resume that conversation though
Man you're in for an amazing time when you will learn about that stupidity called the Internet of Things.
(and yes, I am well aware of, and utterly terrified/upset/bamboozled by, the Internet of Things)
A client had started a time consuming process before leaving the office, came back the following morning with the process having failed due to windows applying updates and rebooting killing the process and losing a day worth of work.
YMMV.
I don't know what you mean by "this has to be done", there is no obligation to apply updates. What if I want my computer to run a windows without updates ? Am I not entitled to use my own property as I so choose ?
> I don't know what you mean by "this has to be done", there is no obligation to apply updates. What if I want my computer to run a windows without updates ? Am I not entitled to use my own property as I so choose ?
If your machine becomes a botnet node and causes problems for other people, which is a big problem, then you forfeit the right. The same thing if your apartment leaks water into another one. Be a good citizen.
Failed updates, now that's the only valid part of your point. I've had a few and they weren't disruptive but this is just my case.
There was no event log or logs of any kind, her system got entirely replaced by win10. For this specific case I would tend to not trust the log anyways. What I do find strange is that the windows 10 installation process should have asked to accept the EULA before installing, it did not and went on as if it was an unattended installation.
Good luck trying to explain people that they have to forfeit their freedom because they have to behave like good citizen. Anyways windows update is barely relevant here as the common vector used for botnet infection is almost always the user, not windows vulnerability.
Mine is that this has never happened to me since I switched to different OSs than Microsoft's, circa windows XP.
However the former has a different security model and the latter is mainly run by experts. The point is moot.
Our software and engineering staff are no longer confidently able to perform long-running operations overnight or across weekends. Simulations, and data-capture runs in particular are now routinely being done during normal business hours since users cannot trust that their OS won't kill everything for an update midway.
Among my tasks for this coming week is working up plan to isolate key workstations, and estimating the required budget to provide the affected users with secondary PCs for routine tasks which require internet connectivity.
So, you're admitting in public that your organization is using the consumer editions of Windows for business use instead of the enterprise edition, which allows administrators to control updates and reboots? Sounds more like your IT department basically doesn't know what it's doing; the additional cost of the enterprise edition is negligible compared to the cost of your engineering software and other tools.
Using an appropriate analogy to make something clearer works better than shoehorning something to push your view.
I plug my laptop to charge the battery when convenient and operate in a geographical area where power shortages are still an exception so I have no fuel issue in my computer usage whether I use automatic system update or not.
Actually I do not use automatic system update, if there is such a thing for this OS, it is discouraged as updates can sometimes break the system if applied blindly.
How exactly can someone not applying updates when windows asks for it put everyone else at risk ? What risk do I face from this from behind my BSD firewall on an Arch linux powered computer ?
Then again my experience of windows computers since windows update was introduced is not in line with what you describe here, getting even worse in recent times with updates applying themselves with little to no warning, sometimes running several times in a row: logs you out of your computer, applies updates for 10-45 minutes, reboots, applies updates for 15-60 minutes, logs you in, crawls your computer down by downloading more updates, logs you out of your computer, applies update for 10-45 minutes, etc...
I've witnessed this happens 3 times in a single week, the owner of the computer was pissed, I'm paid by the hour and happily browsed the web on my linux laptop while the client pestered against his computer, microsoft, technology, corporations, politicians allowing this to happen and so on.
You are better than 99% of users which is what this issue is about. You are a power user capable of looking after a machine. The problem the people who aren't.
Assuming that things work the same elsewhere as they do around you is akin to self-deception.
I'm probably leaning towards the power user category of computer users nowadays, but I wasn't born that way I learned it the hard way by having to deal with Microsoft's crap for years. Now it has become a habit too.
In your case it should be possible to have a windows "branch" with just critical vulnerabilities patched with binary diffs or something rather than 680-odd Mb patch sets.
Download the updates manually and share them via USB storage with other peoples, assuming you have other people in similar situation around you and they are willing to do the same.
I like this analogy! A car that runs out of fuel when its manufacturer tells it to!
> Windows only updates when you're doing something because you're putting everyone else at risk
Are you sure it's me putting people at risk, and not Microsoft?
The global scale of it shows how the end user is less trustworthy than the vendor.
The default attitude of most people I've interacted with regarding technology is apathy. If it works, they're happy and they leave it alone.
Do you really think that a significant number of non-tech people would have gone to the trouble of looking up how to turn off updates to their facebook/email/google machine if Microsoft hadn't caused a massive shitstorm with their forced update BS?
The vendor is entirely at fault for making stupid short-sighted decisions that caused users to lose trust in the update process. No amount of handwaving can change that fact.
- If Microsoft had coded its software properly there would be no need to patch vulnerabilites,
- If the NSA had told Microsoft about the vulnerabilities when they were discovered instead of exploiting it (Assuming the NSA did not tell MS to not patch them on purpose),
- If Microsoft did not have decades of being untrustworthy gathering the logical response of disabling auto-updates,
- If Microsoft had not paid vendors to have windows pre-installed on new computers it would have the monopolistic position it has today,
- if the NSA exploit and tools had not been made public,
- and so on...
All these are also valid ways that would have prevented wannacry spreading.
> putting everyone else at risk
What hyperbole. And what a bizarre thing to socially shame people over. This is like using 9/11 to emotionally argue for behavior changes, a week after 9/11.
That's a terrible analogy. I have been shaming people for bad security practices and self-righteous ignorance for many years (even before 9/11 ironically!).
I've seen too many people have been wrong and had a bad outcome including complete data loss and in one case livelihood being shot entirely. This isn't a random assertion from thin air. You can't trust people to look after their computers.
The case you mention seems to be cases where having backups would have prevented the dramatic outcome.
Then again cars only warns when the fuel tank is getting empty, Microsoft updates may happens at times and is totally unrelated to the ability of your computer to continue working.