Don't tell people to turn off Windows Update
troyhunt.com
troyhunt.com
I don't see anything in the guidelines about duplicates here - https://news.ycombinator.com/newsguidelines.html
Are moderators responsible for pointing this out or just regular users? Who eventually marks something as a dupe? Is it in response to a comment like this?
Is this actually the most highly rated comment or did mods put it there?
(Again - just curious!)
https://news.ycombinator.com/newsfaq.html
If a story has had significant attention in the last year or so, we kill reposts as duplicates. If not, a small number of reposts is ok.
And you can see more commentary on it from dang via this search:
https://hn.algolia.com/?query=dang%20significant%20attention...
Any user can point out that a link is a dupe or has been posted before. It's helpful for others to be able to see earlier discussions (whether or not it was in the past 12 months and qualifies as a dupe), and evidently moderators don't always realise something is a repost until a user points it out.
There are no hard and fast rules about what user can or should comment about stuff like this, but the mods seem to appreciate it any time people are helpful.
And when a post is marked as dupe, the mods will push the explanatory comment (either from them or another user who already pointed it out) to the top of the thread.
Microsoft especially needs to do two things:
1) respect the DHCP settings that tethered devices provide (Android provides option 43/ANDROID_METERED) and NOT suck every data plan dry when on the road (maybe would be worth to expose an API to applications "the primary internet connection is metered, do not suck dry", given how huge any kind of update is these day)
2) give users the fucking option to only subscribe for security updates and not for the latest "feature" set. I know many people who disabled Windows 7 auto-updates after every other month MS would re-enable the W10 update nagware screen. This is way beyond hostile behavior, not even Apple goes this low. I went Apple once Win8 was coming out, definitely not going back until MS either gets a grip or makes W10 LTSB (the one on a "stable" track e.g. for embedded devices, without nagware, ads or other bullshit) available for general sale.
oh, and 3) provide a Windows 7 Service Pack 3 and installation media with all the updates preinstalled. Having to either upgrade by hand or mess around with ISOs is not exactly customer friendly.
That's an interesting new standard of bad behaviour :)
Scenario: hook up laptop to projector etc, make sure everything works. Step out for 30 minutes to chat with people coming to see your presentation. Come back, just to realize Windows did the good old "say Uncle in 5 minutes, or I'll start installing updates" thing.
The app just lies in the background, does nothing else than this. Suspend/hibernate works as it should, it just stops auto-reboots.
Apple goes just as low, OS X asks me every day to update to High Sierra and the option is only "Later" and it can't be swiped away quickly like a normal notification.
I ran an iPhone 4 for until the iPhone 7 launch, I used to keep it on iOS7 because after iOS4 rendered my 3G unusable I knew to no longer update. Every single morning it would ask me to update, which I had to carefully dismiss. It would always download the update filling up my phone to the brim which I would have to then manually delete. If my phone was full it would give me another option offering to temporarily delete apps (Which it claimed would have data restored from iCloud but I knew they would not).
My Mothers iPad auto-updated locking her out of her painting app (Brushes, as used by David Hockney), I had to use a dodgy 3rd party app to extract her documents or they'd be lost for good.
At least Microsoft gives you options to downgrade and supports old OSes, unlike Apple who stops handing out the encryption keys.
A customer that is satisfied with their current setup is a lost customer. So Apple's only hope is to make sure the battery is as difficult to replace as possible - because this component is sure to fail sooner or later.
Apple on the other hand still makes money off of customers -- app sells, services, music, media, etc.
A satisfied customer is a customer who will eventually come back (want something new, lost or damaged device, or just general wear and tear). A dissatisfied customer will look elsewhere.
I notice a lot of Apple users who update devices and OS religiously get defensive as if this stuff doesn't happen. I encourage them to try to live behind updates for once and see how bad the user experience can get.
I definitely do not tell people to turn Windows Update off but I also definitely do not try to convince to turn it on because I don't want them to hold me accountable if something weird happens. That's where MS messed up, turning updates on should be a no-brainer, not a compromise. It's easy to lose trust, it's hard to regain it.
Failures have generic error messages that don't point to any useful information from the (abysmally bad) MS forums.
So yes, it is disabled. Once every few months, I try again, and usually get the same result.
I have multiple backups of everything, so hopefully if WannaCry 2 hits, I'll survive. Or maybe not, but in the meantime, I'm sorry but I can't spend all my time watching my PC doing updates that don't update anything.
I followed all the instructions from Microsoft to reset Windows Update and ran their "Fix It" assistant multiple times. Guess I just won't be booting into Windows anymore, I only used it for a single game anyway.
And at this time I'm not concerned about patiently waiting for ~1 hour, I'm worried that someday that "update+fail" cycle will botch my system.
>Lost productivity to malware = 0hrs. Lost productivity to windows auto updates = 28 hrs. Sitting here right now losing time and money to an unauthorized update. I know how to avoid malware on my work laptop.
That's a bit like how some people (who weren't THERE) think the Y2K-thing was a non-event: they didn't see all the work that got done fixing things before the big day.
Security without usability is worthless.
Windows always sucked at this, it just took a turn for worse in Windows 7 and 10. If I tried to come up with a more annoying updates system I really couldn't. It's incredible how difficult it is for them to pull their act together on this one.
I am not sure about windows 7 and 10. We are arguably better off today than in the ActiveX days. It made no sense to require using windows internet exploder to download windows update.
That's what happens when you 1) don't understand the problem you're solving, and push things that aren't appropriate updates through an update mechanism, and 2) lose user trust.
Compare the number of patches vs windows 7 or the number of cases that require a reboot since XP...they are working towards a better system. That being said, I really, I'm not trolling here, think that you can't make users happy in this age. People have been trained by interactions with crap companies, Microsoft included, to go from 0 to apoplectic immediately just to get a resolution. There's no benefit to being a happy user, you won't get your issues looked at...and there are always issues!
Yes. Every single person who turns Windows Update off should be considered a critical bug, and their use case should be understood and fixed. The fact that they instead still use it to push anti-features means they still don't understand why people still turn it off.
If they started, today, focusing heavily on getting people to trust Windows Update again and leave it turned on, they'd have a massive uphill battle. But I've seen no signs that that's a focus at all.
Something that is an "anti-feature" to you is someone else's (in the case of windows, several million someone else's) every day must have.
It has to be unobtrusive to achieve acceptance.
I have a Windows machine I use for gaming. Its started about once a month and whenever I turn it on it is almost unusable for the first 30 minutes because its checking for updates and installing them. This is totally on Microsoft and their bloated update mechanism.
For example, my Chrome ("stable") right now just renders most new windows as completely white -- no address bar or anything else. Because Google decided to force-feed me a buggy version I never wanted or asked for. So I have to open 2-3 new windows before I get a working one. It's painful but I can still do that, or use Firefox/IE if all else fails. If this kind of crap happened with the OS I would not be able to use my laptop at all.
Now, they have completely broken my work flow for staying up to date. There are no "active hours", if my computer is on, I am using it. No, I don't want you downloading updates without my permission, I am actually trying to use my internet without latency and bandwidth issues.
I understand I am not the majority of users, but it is very clearly the power users that understand windows update that are creating blog posts on how to disable windows update, so maybe to avoid the cobra effect Microsoft should cater to such power users even if the majority of people aren't going to use those features.
As it is, for me, a more effective work flow would be to disable automatic updates and just check every Tuesday when I don't actively need my internet or mind my computer rebooting. The problem is, I am fallible. If only there was some way to remind me.
That's a failing of your software, not the customer.
OSX and Chrome gets it right. It's possible.
Good that it turned out I really didn't have to copy that CD then.
Firstly, it'll keep prompting even if you choose "restart later".
Secondly, unlike most linux environments, it doesn't perform the updates which take effect next restart, it actually performs the update next restart.
That means if you find yourself needing to restart forgetting you've updated, you can find yourself suddenly having to wait a very long time before your computer is usable again.
They often take multiple 'restarts' to apply, typically you might have to wait the first shutdown, then when it boots back up it'll be "applying updates", then it'll restart again having done those updates. Occasionally you'll even get a third restart.
That's compared to 'nix applying the updates but them not having taken effect until a restart which isn't normally noticeably slower than any other restart.
In Windows 10 it's even worse, you have to define off-hours when you're not using the PC, and in those hours the device will reboot itself if it feels like it. Don't worry, the applications you had open will be restarted, surely no data can be lost.
Edit: Windows 10 even has the configuration panel "Restart Options," which tells you "We'll show a reminder when we're going to restart. If you want to see more notifications about restarting, turn this on".
I've also had lots of trouble with failing updates.
Hey at least Windows 10 learned to reopen Explorer windows.
Nothing else though, but Explorer windows it sometimes manages to remember.
Not every time.
But sometimes.
* Windows's reboot nag screen is way more insistent and naggy, OSX just has a notification in a corner going "there are updates available", Windows has a big dialog front and center, which comes back frequently
* Windows updates requiring reboots are significantly more frequent than OSX's
* Windows will eventually refuse to put things off and reboot on its own, IME OSX won't
* The Windows update process takes ages, and there's literally nothing you can do with the machine during it
Having both Windows ans OSX personal machines, updates to the Windows one annoy me much more than OSX's. Though to be fair the W10 experience is still a significant improvement over the XP and W7 days (I haven't had an update repeatedly fail yet).
I am on the other side of that fence, managing about 100 machines across all versions W7-W10 and Server 2008-2016.
Win7 boxes are by far the most stable desktops, in the past year I have had at least ten win10 systems blow up due to updates, stuck in and endless loop of installing at shutdown and reverting at startup. A few weeks ago two stock server 2016's with nothing but SQL Server installed outright died to a windows update (unbootable).
I am never upgrading my personal windows machines past windows 7.
- The update popup often tabs you out from full screen applications. For exclusive full screen games, it often takes a couple seconds to tab back in, so in any kind of skill intensive game you're now way behind.
- The download/p2p upload mechanism does not respect 'active hours'; updates will happily hog your entire bandwidth and destroy your latency.
You’re at the doctor’s office waiting for an appointment. You open your laptop for a minute to check your mail. Surprise! Windows is booting up with an update. The nurse then calls your name and you have to carry your laptop around with the lid open like a jackass or risk bricking it.
Chrome is a piece of software that is much less complex and has a much shorter cycle time than a PC.
So you are pretty much comparing apples to oranges.
An OS connected to the Internet is secure given a good firewall that blocks all incoming traffic. Firewalls are a solved problem and ship with every mainstream desktop OS.
Browsers on the other hand are directly exposing the user to the web, being the primary attack vector for mallware and viruses. This issue is made much worse given that browsers download and execute JavaScript code locally, the potential for remote exploits being enormous. And historically speaking their attack surface has been much greater due to the proliferation of plugins, like Flash, Java or Adobe Acrobat, which have been exploited again and again — thankfully we've gotten rid of them.
The OS can help somewhat in securing the browser or any process of course, but it's never foolproof on mobile devices, as can be seen by the dozens of iOS exploits used to jailbreak it and it's a pretty weak protection for the desktop — a compromised browser on the desktop means you're pretty much screwed.
This is why the browser has to be the ultimate sandbox. Because it's directly exposed, because it executes code loaded from random locations on the web and because it's been abused by plugin makers, as everybody wants a piece of it.
Unfortunately, that is an understatement. If you are using a Windows computer at home, it's one thing. If you are responsible for a company network of 80+ clients, Windows updates (pre Windows-10, at least, I have no experience with Windows 10, yet) are a little bit like Russian roulette.
It's one thing if an update breaks third-party software; I suspect this usually means the third-party software did some questionable things begin with or is just crawling with bugs (I am looking at you, Siemens!).
But if Windows updates break functionality like, say, communication with a WSUS, or booting properly (I could go on and on and on...), it is my responsibility to at least do some research how this month's update may affect my users, instead of blindly installing anything Microsoft throws my way.
I wholeheartedly agree that keeping systems up to date is very important. But unless Microsoft gets its act together and makes updating as painless as on, say, Debian or CentOS, I am going to have mixed feelings on the subject.
But for the last two days Windows Update has gone rogue and started gobbling up CPU. GOG Galaxy has gone nuts as well, I uninstalled it but I can't uninstall Windows Update. I can't even stop Windows Update, it'll go into the "Stopping" state but ... no dice.
It's like literally everything is coming for my CPU [1] for updates updates updates. It's a 6700K so there's 8 threads at 4GHz being used 60%...
I'll probably re-install Windows 10 over the Christmas break and cross my fingers.
[1] https://imgur.com/a/8hZXE (Windows Update is Service Host: Local System (3) along with Update Orchestrator Service and Remote Access Connection Manager.
If Windows Update provided only essential updates for security and stability by default, and if it did so transparently so everyone could see exactly what was being done and why, and if it did so with minimal interruption to the user's real work, he would have a decent argument. But none of those things is the case.
Look at the comments on the article, or here, or on countless other forums since the Windows 10 fiasco started. Heck, look at Troy's own acknowledgement:
I've had Windows Update make me lose unsaved work. I've had it sitting there pending while waiting to rush out the door. I've had it install drivers that caused all manner of problems. I've had it change features so that they work differently and left me confused. I've had it consume bandwidth, eat up storage capacity and do any number of unexplainable things to my machines.
I've seen those things too, and more. I've seen unfortunately timed updates cripple a sales team right before a crucial demo, months in the making, that was supposed to close a £1M deal... in a small business that closes perhaps 2-3 such deals a year and relies on them to pay everyone's salary. Not much point worrying about encrypted filesystems if your business went bust already.
The fundamental problem here is that Microsoft is no longer trustworthy. They have demonstrated, repeatedly, that through both negligence and malice they will break systems that install their updates. The Microsoft that some of us trusted back when we bought our Windows 7 machines is not the Microsoft of the past few years, but we're stuck with those machines now, so we have to find the least risky path forwards taking into account as many potential problems as we can. It is far from clear to me, on the evidence to date, that accepting all of Microsoft's updates by default is safer than rejecting all of them by default.
...with every stupid update, and after every boot up Windows insists on settings, programs and games it wants you to have. Should i have to curate my own powershell script to disable and remove some of the shit that gets forced on me. I paid for my OS, why do i get to suffer like this. Microsoft please sort this out, you're pushing me away. You know, looking at the Steam for Linux game list now, we're getting close to a point where the Gamer in me might see an opportunity to leave.
There are many improvements since Windows 7 that I can appreciate, but those practices—together with the increasing privacy violations—are a complete shame.
The article's point here is that no matter how much windows update might suck, you still need to use it. And that's the problem with security people in general. It's not like they "think their shit doesn't stink" it's that they everyone must put up with whatever level of stench because security is just that important. Which gives them zero incentive to reduce the smell. They'll probably just blame the developers for fucking up the distribution mechanism the same way they blame developers for having the temerity to write bugs.
Unfortunately, the impression I get is that "the security community's" answer is that users do things like disabling windows update because security hasn't been sanctimonious enough towards the unwashed masses, and we should just get on with taking away all of end users' control over their systems for their own good.
If Microsoft knew how to do system updates in a way that wasn't an absolute fucking pain, then I'd be a lot less tempted to just turn off automatic updates on Windows.
[0] Fairly ridiculous x265 settings on a laptop CPU, as I'm not keeping the source files so want to ensure optimal quality.
Keep your machines and software updated with the latest patches people. Keep your parents and non technical friends machines updated with the latest security updates. Don't ever tell them to disable it because your heavily customized windows 7 setup broke a little bit one time after a huge windows update.
There are so much abuse people can take before they start considering the actual malware a lesser evil than Microsoft's malware-like OS.
My Windows box is running 10 LTSB with wuauserv disabled. I keep zero important stuff there, most of my gamesaves are synced with cloud servers from the game's developers (Overwatch and Elite: Dangerous) or from the store (Steam and GoG), so I can wipe it out any time with no real losses.
The important stuff (taxes, documents, pictures, etc.) are all on a notebook running Debian that is mostly kept cold.
Speaking on Debian, Microsoft could learn a LOT from them. Specially with regards to the strict policy of not adding new features to a stable version.
Honestly regular Windows is a fucking joke.
That's a joke all by itself. Not even a rolling release distro like Debian Unstable or Arch produce that volume of patches in a whole year...
Windows has two major problems in regards to updates:
1. It's utter inability to update files that are currently open by programs. All Unix and Unix-likes can handle deleting/moving/replacing open files gracefully by keeping a reference to the old file in memory. Windows can't, so the only way to update the most used DLLs is by rebooting.
2. It's a monolithic system, with so many cross dependencies, it's almost impossible to make small, punctual updates of independent packages. Hell, Unix was 23 years already when Windows NT 3.1 was finally released, MS used to develop and sell Xenix, yet they learned nothing from those.
It ridiculous how inept they are handling updates. If they ever ask me how to do it properly, I'd advise them to throw the whole idea of Windows in the trash and start again from a BSD (or maybe buy Solaris from Oracle). Slap an improved WINE for partial, best performance compatibility and a full VM for lower performance, full compatibility. It worked well for Apple while transitioning from "classic" MacOS to MacOS X, it could work for MS, as long as they don't screw it up completely.
FYI, Windows is anything but a monolith - especially the kernel. It's heavily built around services and message passing.
Whereas actually Linux is a monolithic kernel (granted, the ecosystem on top is not so much).
> The "security updates" situation reminds me of organized crime's protection racket: Either pay us to "protect" you or bad things will happen. In the case of automatic "security" updates -- and not just Microsoft's -- we're compelled to pay in computers and programs that are corrupted with unwanted new behaviors. If you don't accept those, well then your computer will be insecure. So "pay up" or else.
This all worked perfectly on windows 7. It downloaded in the background and would install whenever I restarted the system myself. No nagging, ever. Of course, I get why some people might have problems with automatic downloads or automatic installation on restarts, but I feel it was still worlds apart from the current windows 10 behavior and a good compromise between staying up to date and getting annoyed. So why has this actually changed? Why does it need to nag all the time now and force-restart in the middle of the workday? Who gains form this?
The same goes for "feature" updates that break the existing workflow.
Of course, inconvenient or not, it's pretty hard to deny that disabling updates is a stupid proposition.
I'm starting to think published tech advice should be treated like legal or financial advice. If you give out stinkers like this and they turn out to be violently harmful to its readers, you are liable for it.
Microsoft doesn't get off free —they've been cocking this up consistently— but turning off WU is antivax level stupidity.
I'm using Enterprise LTSB. Solid as a rock. Windows as a service: they haven't done anything since 1607 that I want.