The only real way to address it without the mandatory updates was for the ecosystem to diversify; can't use a Windows exploit to compromise a Mac OS machine.
You can imagine why that solution was not on Microsoft's list of recommendations.
That would mean doing as much of the work as possible in the background in a way that doesn't impact the user and making sure the reboot where it actually gets activated doesn't take noticeably longer. It would also mean not doing things that are against the user's interest like moving things around, installing new ads or misfeatures, or breaking things.
I don't know anyone who hates or wants to disable Chrome updates, for example (I'm sure such people exist, but it's much less common than Windows updates), despite Chrome updating way more often than once a month.
Of course, overcoming the aversion people built over years because of past bad behavior is going to be hard, but forcing people against their will and making updates more disruptive isn't going to help with that aversion. People really dislike being forced to do something, even if they don't actually mind the thing itself that much.
Android does an A/B update and after a only slightly slow reboot is in the new version. It then does some optimization in the background that can have a slight performance impact.
NixOS must be the gold standard here. It downloads and completely installs the new version in the background then a regular-speed reboot is enough to be running the new system. (~10s on my system)
But Windows and macOS both have crazy slow update processes. When I had a mac for work I was dumbfounded by how slow the update process was. It regularly took >30min! Those machines are crazy fast, it seems like it could have written a TiB of data in that time so IDK what it is actually doing.
Point updates of macOS take 20+ minutes on an M1 Max with 32GB of memory and a blazing fast SSD. What could it possibly be doing?
Even iOS updates are a bit faster.
Is apple even interested in fixing this?
If memory serves: point-symbol optimizations to make code calls into The objective-C libraries performant.
Under The hood, objective-C really does use strings to reference library functions. So when the OS is updated, the string interning table is updated and all of the installed software has to have its string to symbol caches rewritten to account for the new API.
There are almost certainly better ways to do this but if I understand correctly, Apple inherited the existing solution without putting enough thought into how it would scale and now changing the solution would break an indeterminate amount of software depending upon the current implementation.
EDIT: a sibling comment jogged my memory; the thing I was doing a bad job of remembering was prebinding. https://opensource.apple.com/source/cctools/cctools-622.5.1/...
When a new version of the OS is installed, the OS re-runs prebinding for applications to the dynamic libraries they rely on because the dynamic libraries may have changed. The alternative is to have a big latency bump every time an app is launched for the first time as the caches are rebuilt on-the-fly.
(I think this is the step that used to be called "Making Your Macintosh Happy" during an install, but the veracity of that notion has fallen too far down the Google search hole for me to easily pull up a reference to confirm or deny it).
However, this exposes the real challenge. We cannot have informed consent without informed users. I think this problem will haunt us repeatedly in the future. We need users to know at least a little bit about their options. Only then can they make informed choices on what option to pick. This means people can't glaze over the details and not worry about them. This does not mean you have to be a computer wizard. You just need to know what you want and pick an option that is good for you. For example, I run this on Fedora:
sudo dnf offline-upgrade download -y && time sudo dnf offline-upgrade reboot
Any update requires a reboot.
However, I am ok with it because I am positive each update comes after a lot of testing.
More importantly, I am in control of when to run this update.
I can't accidentally run it because it requires my sudo password.I used to wonder why no corporation complains about Windows Update. Then I learned that virtually all companies use group policy to change Windows Update behavior to suit their organization. Therefore, this is a non-issue for them. Welp.
That also includes never crashing, which Microsoft has historically struggled with.
If you don’t reboot in an orderly way, then the machine crashes while the user is doing something, and when it restarts everything is different. “Don’t restart” is insufficient for good UX here.
You can still choose to reboot for every update. The point though is that it is a choice.
sudo dnf offline-upgrade download -y && time sudo dnf offline-upgrade reboot
It doesn't nag me at all other than ask me for my sudo password.
It is perfect.Here is what I understand about dnf offline-upgrade
> The process of restarting, applying updates, and then restarting again is called Offline Updates. Your computer boots into a special save-mode, where all other systems are disabled and where network access is unavailable. It then applies the updates and restarts.
https://fedoramagazine.org/offline-updates-and-fedora-35/
> With Windows, it's an almost-weekly, "Hey, update right now, because someone in another country is pwning all unpatched machines that aren't air-gapped from the internet."
I see. I feel like I don't quite understand the extent of the problem. In any case, I am not qualified to even attempt to propose a fix. My mode of thinking was Google Chrome and derivatives are able to slowly walk along with increasingly scarier visible warnings asking users to restart the web browsers but they don't (as far as I know) reboot the web browser while the user is still using it. Even Google Chrome OS didn't do that (well, it didn't back when I had my cr-48). When I updated Mozilla Firefox on my Fedora machine, existing tabs continued to work. New tabs would come with a warning for me to close Firefox and open it again. This is the kind of warning I was getting rid of with offline-upgrade.
I agree with my parent comment though. Updates are too bloated. Windows updates should be very fast with a modern processor (Intel eighth gen, AMD equivalent or greater), enough memory, and a fast SSD. Even DNF which has a very renowned reputation (at least among Fedora users) of being slow, is pretty reliably fast. I think the point that my parent comment was making was make people not dread rebooting their machine. My thought was
1. educate the users why reboots are essential 2. allow the users to postpone reboots indefinitely
However, I don't know what to say if there is an active remote command exploitation in the wild. It is important to get the update to the user before the exploit. However, that goes against everything I've said so far. I guess this leads us to the status quo. Those who have the know-how to use group policy can opt out of certain Windows Update behavior. The rest can either learn to do this: and set up their own Windows Update server? Periodically check CVE and gate update releases? Not sure how it works...
The reason I hesitate and say automatic reboot should be OPT-IN is sometimes I like to do some simple long running task like stitch photos I took into a video using ffmpeg. It can take hours on a slow laptop processor. It would really suck to do something like that and come back to see the computer rebooted itself.
Chrome updates approximately every month unless there is a security issue that has to be pushed out faster.
That's basically not possible in some cases. Not all of us are on super-fast broadband, even in places that are nominally 'first world'. The _best_ my parents can get is 8Mbps on DSL. Every time an update starts auto-downloading, you know immediately because all other connections grind to a halt.
(Now why a minor point update security fix for Monterey is 1.6GB I have no idea. But presumably that's not something Apple is capable of/interested in fixing)
That would be me for one. I hate it when google sneaks in privacy reducing preferences that are automatically turned on. I like to occasionaly go through settings to see what has changed and was surprised when an update showed up a whole host of new active features.
Why on earth should usb ports on my laptop be automatically exposed to any web page that demands it? Chrome can do that now. And not just usb/serial/midi ports, and motion sensors, chrome has also enabled 'presence' (a way for sites to know when you're actively using the browser). I found that creepy.
More software companies need to get on board with the idea of having a separate maintenance branch and "next version" branch. Too many of them just develop on trunk and every time you update for bug fixes and security, you get all the other crap their developers have been working on too.
Too many instances of installed Linux distros breaking because some foo relied on some bar that the distro declared should work fine but must have slipped through the testing cracks somehow. Or I'd gone off-book on some custom project or other because it relied on library versions that weren't in the distro, then I forgot I did that and updating the distro libs broke my project.
I basically never run the apt updates these days.
Just to be clear, this isn't an argument that as a result updates should be forced.
However the issue that I've had was my Terminal App shutting down by itself, I thought it was a crash but it turns out it was because the Windows Store decided to update it.
Now that is complete BS! How can a store arbitrarily decide to update an app while it is still running without asking, without waiting? Even Steam waits to download and update games for when you're not playing one. If it ever did the same thing as what the Windows Store does then there'd be a riot for sure. I guess that it means the Windows Store is just not being used by people at all.
For those interested the "fix" for not having Terminal app restart for an update is to download the MSI package, extract it to a directory, and run it from there. That's directly from the Developer's words on Github.
What we see, of course, is exactly what the twitter thread posted mentions: some "dickweasel" hijacked the update system to push crapware or do something user-hostile for purposes completely unrelated to what the user would want.
James Williams discusses this in his book "Stand Out Of Our Light", and likens it to a GPS that takes you off to places that you never wanted to visit in the course of (maybe) getting you to your intended destination. Of course, you arrive late, if ever, and burned way more gas (or battery) than you needed. But the GPS got you to drive by a specific set of billboards that they wanted you to see.
If you set your internet connection to "metered" it exposes an option to disable automatic updates.
https://www.tenforums.com/tutorials/139722-turn-off-download...
It's when they try to launder in a bunch of "feature" updates (i.e. more spyware, more crapware) with needed security updates.
They force the user to make a decision: Do I skip this update and avoid having new "features" from crippling my machine, or do I download the update to prevent my machine from being hacked?
If vendors really gaf, they would make is so that you could download needed security updates w/o the rest of the garbage. But then they couldn't force more malware on you.
In other words, it's only reasonable to expect security updates for a certain length of time and not indefinitely.
That is the perfect update story. Everyone loves it: the users aren't having their workflows upended, the developers are able to push updates regularly for security problems and the like, the only loser is the graphics designer who got hired because daddy owns the company and needs to constantly re-design the user interface to justify their job. (seriously, people in companies that do this kind of shit, what is it with re-designs? Why?)
As things stand today, I only trust updates from community driven open source software projects. With exceptionally few exceptions, commercial software seems to offer the guarantee of delivering undesirable payloads.
But I promise you there is never any kind of Machiavellian multi-year plan to condition people for upcoming bad behavior. Most of the things we do screw up are from lack of foresight; we are definitely not strong enough at long range planning to run psyops on customers.
I’d be interested to know what the actual story at MS was for this. I think the executives there in the past demonstrated pretty good decision making. Here’s[1] someone claiming something about PM’s thinking they knew better than users and maybe there is some hidden OKR incentive driving that reasoning, but my weak understanding is that that person wasn’t really involved in what happened so I don’t know how true it is.
[1] https://twitter.com/danluu/status/1504567911565824000 nitter: https://nitter.fly.dev/danluu/status/1504567911565824000