Microsoft hints at new modern Windows OS with ‘invisible’ background updates
theverge.com
theverge.com
I don't know how they'll get magic transparent updates when their model is to always require restarts.
When the only thing stored locally is $HOME and everything runs on clusters on MS servers you will never know when the 'back end' reboots. The 'Future' is the same as the past but with updates.
You are (your smartphone) and will be running a dumb-terminal. Instead of one computer you are now using a very-large-cluster of servers. Each time you boot-up 'Your instance' may be a unique VM that gets spun-up in micro-seconds. When it's time for an update the patches can get all pushed out to the VM's and when you reconnect (i.e. wake from sleep-mode) you are now connected to an 'updated' VM with all the hard work happening on the backend.
This very of the future is really fucking COOL, and terrifying. It also pretty damn doable.
There’s no appetite for selling consumers ECC memory either.
If uptime and availability become a serious concern, then a partitioned system in which kernel data is in ECC memory while the remainder runs on cheaper non-ECC memory is possible as well.
A single 32GB SODIMM (as I have in my laptop, because it's a workstation laptop) see's roughly 12 bit-flips a month, these are correctable. This is pretty much in line with the 6-or-so bit flips I see on ECC memory inside servers (of which I have a few thousand, each having 32G modules spread over more area and enclosed in a heavy chassis, thus, less flips).
Bit flips are so common that it's even possible to have "double bit flips" in the same page, which is uncorrectable even with ECC.
So I think you grossly underestimate the percentage of bit flips, most are silent though (or attributed to bugs in software) so I understand you don't see it. If you had ECC memory you would.
My other point about Windows kernel being fairly large in terms of surface area is relatively self-evident, but I'll come back with some solid numbers, because those thousands of servers I was mentioning are all Windows.
EDIT:
As promised I checked the non-application memory usage of my fleet and the rounded value of Windows memory footprint by itself is 1.89GiB. FS Cache is also excluded.
That number is frankly absurd. No doubt it includes all sorts of things that shouldn't be included in a proper microkernel, which just goes to show to all those people that call the NT kernel a microkernel (or close to it), are full of it.
In principle, some book keeping memory for processes and the page tables are roughly all you need to live in kernel space.
http://www.admin-magazine.com/Articles/Monitoring-Memory-Err...
In addition they have things like the “security reference monitor” which resides entirely in the kernel.
It’s really apples to oranges, NT is truly heavy especially on server 2016 (which is where I grabbed the numbers)
I have comparatively fewer 2012r2 machines but I can aggregate the numbers for those too if you like.
Reboots are good because they test that your OS still works and you can make observations about which update broke what. They should be fast and painless though.
I guess some folks just want to complain.
If the complaint is that "I can't skip arbitrary patches at will" then yeah that's not possible, nor should it be if you're aware of security concerns AT ALL.
Windows users have a long history of not willingly patching against vulnerabilities that are actively being used by attackers in the wild, and for very odd reasons. Those reasons can include complete ignorance of the vulnerability or the patch which fixes it, fear of a wide array of conspiracy theories (I've heard all of these that I care to hear in 1,000 lifetimes), fear of post-patch performance problems, fear of home-grown automation breaking, and a bazillion other reasons, nearly all of which are complete nonsense in practice.
I was very happy when Microsoft announced that they would force updates on most users, because my own experience and Microsoft's telemetry both agreed that if given an option, users simply will not patch their systems.
https://blogs.microsoft.com/blog/2019/05/28/enabling-innovat...
There's an interesting avenue for Microsoft to provide a ChromeOS-like experience, but with built in O365. This would cover the use cases of easily 95%+ of computer users (web+email+office).
That just leaves (simplifying a little) gamers, specialists (e.g. video+graphics editing), legacy enterprise app users and developers who need anything more.
I suspect if that were the case then Windows RT wouldn’t have been canned. I’m wondering what’s different now that makes this idea better. Marketing?
It took a concerted push in Windows 10 to remove most of the "seams" between UWP and Win32 (to the point where now you can even have UWP Islands inside of Win32 apps). We're also seeing years later the fruits of labor to better emulate Win32 on ARM in the latest Windows 10 on ARM builds.
Though now with Chromebooks gaining popularity they are in danger of being too late again even though now they have an answer to "Can this Windows run Win32 applications, too?" because Chromebook and the increased market shares of iOS and Android have left an increasing number of people wondering what they need Win32 applications for. (The rumors that Microsoft might not even brand whatever this "Modern OS" project is as "Windows" and it may not even refer to current Windows on ARM efforts seems to maybe imply that Microsoft really is too late back to this market that they tried to enter earlier.)
I am sure I had this conversation with you months ago, actually.
Not all businesses want or need enterprise-level IT management, and there are alternatives to having a full-time professional sysadmin that do not involve being the stereotype dumb user who forgets to apply security updates.
This article (which you clearly didn't read) makes no mention of this change happening to Windows 10, but a ChromeOS-like "Windows Lite" instead, and if you are capable of controlling Windows "tightly" then you would definitely know how updates can be managed in appliances or devices that run a version of Windows designed for those use cases.
Test and approve any updates you want to release.
Also in your case it would also be worthwhile to look into whether you shouldn't be using the LTSB branch of Windows.
That doesn't sound easy, although it also seems like an odd choice for an OS for a medical device.
Full-stack C# which grants me easy flexibility on what I want to happen client vs server-side, with near-native performance. I can drop a Safari shortcut on home screens for iOS, and an Edge link on desktops for Windows. If you wanted some sort of iOS specific behavior that you can only access from there, the application could be wrapped in a webview. It'll also be seamless to package it as an Electron app for Ubuntu support. I don't intend to go with Electron or put it in a native iOS app, just browser links for whatever platform they want to use, but there's plenty of flexibility.
This is a webapp-done-right in my opinion and really a PWA. Perhaps the path I've set out for myself would work for you. The application I work on is critical to the daily functions of a large business, but not "medical grade", so I may be able to work on the knife's edge a bit more.
Interesting, yeah I would think a chrome device, or android, iOS, some sort of base level secure focused linux might be a better place. Especially not 'home' flavors windows.
I know some folks working with some medical stuff and they've all since moved off of windows onto Linux, not an easy move, but windows just didn't make sense as their software moved into more of an "embedded" (not sure if anyone uses that term anymore) type setup than a desktop connected to a machine like it used to be.
They certainly do. There's an entire industry that builds control software for network-connected devices. These days you probably run an embedded web server and/or provide a network-accessible control protocol over something like TCP or UDP with separate software/app that runs locally on the user's device. Then on the back end you link to whatever functionality the device has rather than just storing everything in a database as a typical CRUD application would. There's a wide range of tools available for things like putting together a minimal Linux base and cross-compiling your code as well.
That’s what I would do now. Much easier to build up a device from components than trimming down Windows 10.
If we're destined to become mindless, media-fed automatons, I at least want my self-driving flying car in return.
try installing security updates only. try denying a specific update. try freezing you installation at a specific build number. try running a machine unattended for a month without it rebooting. and next time you update, check your settings. chances are good that something, somewhere, got silently reset to defaults.
the only option for personal windows 10 installations (i.e. non-enterprise) is to blacklist the windows update service. and with each update, you have to find a new way of blacklisting the service. the settings allow for some changes -- you can defer certain types of updates for up to one month -- but eventually microsoft _will_ push new updates to your device and they _will_, if needed, reboot your PC.
windows 10 is (for me) worse than when i bought it. i get that some people wanted these updates, but i didn't. all i want is the software i paid for three years ago.
and yes, i recognize that this is a problem with all "evergreen" software (internet browsers in particular jump out). but choosing an OS is a commitment, moreso than any other type of software, and when you commit to windows 10 you have no way to know how that commitment will pan out a year or two later.
so anyway i'm back to `sudo dist-upgrade` and i'm pleased as punch about that.
You can delay them for a while. Is that the control you alluded to in the above comment? That doesn't sound like much control over anything, if anything it's just a temporary delay of the inevitable.
If the requirement is to run for month(s) without updates, I suspect a 'home' OS was the wrong choice.
I think for your typical home user required updates with the option to delay is very reasonable.
The scale of bad bot activity out there would be tremendous without requiring updates. We see enough security discussion oh HN to make that clear.
Even if your OEM won't sell you a Pro edition license, it's also easier than ever to move a Home SKU to a Pro SKU because it's a one-time $99 purchase in the Microsoft Store and an in-place software update.
Declining updates in general weakens herd immunity.
Pro does let you turn off the "Basic" telemetry that is mandatory on Home and that turns off "all" telemetry in the OS itself (you may still have to opt-out for some applications). Keep in mind that turning of "Basic" telemetry also turns of Windows Error Reporting and crash/BSOD telemetry, which can also weaken herd immunity.
Anti-telemetry and "update control" arguments kind of sound a lot like anti-vaxxer arguments.
No, declining security updates that are applicable in your situation and that actually work weakens herd immunity if the threat is contagious.
On my system, I'll be the judge of when that applies, not some external organisation, and certainly not an external organisation with a track record of both abusing an automatic update mechanism to push changes that their users don't want and pushing changes that break things.
Anti-telemetry and "update control" arguments kind of sound a lot like anti-vaxxer arguments.
Anti-vaxxer arguments are not grounded in science and evidence. They advocate not taking effective preventative measures by denying the existence of the harms those measures prevent.
Given that the risks from both bad updates and data leakage are well established, if anything I'd say the argument that we shouldn't care about controlling our own systems and uploads from them is the one analogous to anti-vaxxer reasoning.
s// I thought new versions of windows were a thing of the past. Aren't we now just all supposed to be on "windows" with everything forward of today being an update rather than a new OS? We aren't supposed to talk of any sort of "new modern windows OS". This should be described as a potential future update, not a new OS, because there will never be a new 'version' of windows. //s
That is his point. Even on the VM I run on my macbook for work, there is always a background task running. Windows Defender, Windows Update, a bunch of incoherently named things... the list goes on.
...Also, nice trick statement at the end - Windows Update is always running!