windows 10 is (for me) worse than when i bought it. i get that some people wanted these updates, but i didn't. all i want is the software i paid for three years ago.
and yes, i recognize that this is a problem with all "evergreen" software (internet browsers in particular jump out). but choosing an OS is a commitment, moreso than any other type of software, and when you commit to windows 10 you have no way to know how that commitment will pan out a year or two later.
so anyway i'm back to `sudo dist-upgrade` and i'm pleased as punch about that.
You can delay them for a while. Is that the control you alluded to in the above comment? That doesn't sound like much control over anything, if anything it's just a temporary delay of the inevitable.
If the requirement is to run for month(s) without updates, I suspect a 'home' OS was the wrong choice.
I think for your typical home user required updates with the option to delay is very reasonable.
The scale of bad bot activity out there would be tremendous without requiring updates. We see enough security discussion oh HN to make that clear.
Even if your OEM won't sell you a Pro edition license, it's also easier than ever to move a Home SKU to a Pro SKU because it's a one-time $99 purchase in the Microsoft Store and an in-place software update.
Declining updates in general weakens herd immunity.
Pro does let you turn off the "Basic" telemetry that is mandatory on Home and that turns off "all" telemetry in the OS itself (you may still have to opt-out for some applications). Keep in mind that turning of "Basic" telemetry also turns of Windows Error Reporting and crash/BSOD telemetry, which can also weaken herd immunity.
Anti-telemetry and "update control" arguments kind of sound a lot like anti-vaxxer arguments.
No, declining security updates that are applicable in your situation and that actually work weakens herd immunity if the threat is contagious.
On my system, I'll be the judge of when that applies, not some external organisation, and certainly not an external organisation with a track record of both abusing an automatic update mechanism to push changes that their users don't want and pushing changes that break things.
Anti-telemetry and "update control" arguments kind of sound a lot like anti-vaxxer arguments.
Anti-vaxxer arguments are not grounded in science and evidence. They advocate not taking effective preventative measures by denying the existence of the harms those measures prevent.
Given that the risks from both bad updates and data leakage are well established, if anything I'd say the argument that we shouldn't care about controlling our own systems and uploads from them is the one analogous to anti-vaxxer reasoning.