Windows Update Restored: Fix Windows update on Windows 95, 98, ME, 2000, and XP
windowsupdaterestored.com
windowsupdaterestored.com
DECREASING LEVELS OF SECURITY:
1. Running Microsoft Windows.
2. Running out-of-support Microsoft Windows.
3. Running out-of-support Microsoft Windows and having it report itself to a server of unclear provenance and security (which could be efficiently indexing such insecure machines, and possibly even exploiting vulnerabilities during this simple interaction).
4. Running out-of-support Microsoft Windows and updating its system software from a server of unclear provenance and security (which could install malware, possibly even defeating any outdated vendor signing).
SUGGESTIONS:
* If your important science/medical/industrial/etc. equipment is stuck on ancient Microsoft Windows, probably you want to keep it airgapped and treat it gingerly, while planning to upgrade to more sustainable equipment (and hopefully it doesn't fail abruptly before convenient).
* If you're playing with Microsoft Windows for personal use, that's fine, but maybe consider whether you'd prefer to spend your time and energy instead learning and creating atop an open source software platform.
* For many business and personal purposes, Debian Stable is a good OS platform, and this is one installer for it: https://cdimage.debian.org/debian-cd/current/amd64/iso-dvd/
Old OT is actually pretty easy to take care of aside from sourcing replacements for some secret sauce PCI card that is no longer made. New OT blurs the line with IT in a really difficult way however, you can no longer rely on a dead simple airgap to solve your security concerns because everything and its mother wants to be on the internet.
Is Windows 11 with all of the default security settings really that insecure? Like Windows Defender, Windows Firewall, anything that needs admin needed you to click "yes, elevate to admin" through UAC
https://zerodium.com/program.html
Getting a Windows exploit is higher value than any linux exploit. Given how many servers use Linux, it makes me wonder if Linux 0 click are easier than windows.
There are a bunch of counters like 'there are too many distros', or 'a personal computer of a VIP is higher value than some corporations'. But I'm not sure its fair to include your point number 1.
I like to give people credit where its due, I imagine it took lots of work to make windows as secure as it is. (Giving Android OS the most credit for their 2.5M payout)
>Zerodium reviews, tests, validates, and documents all acquired vulnerability research then provides it to institutional clients as part of the
Zerodium only cares about shit their own customers want to target. They aren't trying to fund the entire world of software security.
Their customers in particular are select governments wanting exploits for their own use. You can sure as shit bet they already have specific targets in mind and what they use.
EDIT: For example, the forum software noted on Zerodium's list are popular for "blackhat" and "darkweb" forums from everything from card dump selling to malware. Many governments would love to get themselves a database dump with some user IPs. Conversely, this is why Discourse which is a major BB these days is missing as it's not popular in those circles.
It's a thin wrapper around Blink just like Chrome/Chromium. What is there to "hate"?
The endless fluff and clutter to clean up (Search bar appearing on desktop, sidebar foistware). The relentless marketing and push of adjacent services (Bing AI).
The passive-aggressive IE compatibility mode (unremovable nag banner to stop using IECM, your Legacy App URLs expire after 30 days for no good reason).
'turn it off'
I did. But its not intuitive, its some settings button that is semi-transparent. I literally had to google/bing it.
The inital setup was awful.
Then it opening all my links in edge was not okay. I'm signed in on firefox, I don't want things opening in edge.
I can't remember, I gave up after the whole BingGPT thing was a let down.
Plus sketchy companies like Zerodium major customers are nation-state actors who are primarily interested in data exfiltration and the application data stores themselves.
This is why its so valuable though.
Whereas a desktop often has users on it who enter banking details or corporate login credentials. Much juicier targets.
1. The Windows (end-)user base is much larger than Linux (not counting Android), so a Windows exploit enables more potential victims.
2. Windows has been the de-facto corporate OS for a long time, so a Windows exploit offers more high-value targets.
Like, I would not be surprised if there were issues trying to run an AGP or PCI video card.
There's probably a sweet spot where some hardware is old enough to have had all the major bugs worked out, but not so old that nobody bothers developing and testing it anymore.
And before anyone says I'm in danger by running unpatched Windows:
NO.
My threat model is such that the time lost and wasted from updates breaking shit is significantly greater than the dangers posed by hypothetical threats those patches ostensibly guard against. Updates are simply and literally not worth my time and concern compared to having systems that just work every day all year long.
If I need to comply with regulations or audits or I am the target of focused attacks, then yes the scales shift the other way. But as a general, and particularly personal, concern? No, updates are a waste of my time.
Linux is even worse because I don't even need to run updates for something to break and waste my time.
>If I need to comply with regulations or audits I hope you are not handling any customer info on such systems... or are you?!
There seems to be a deeper issue at play. I've seen it many times, even here on HN. So very few people actually know anything about information security, and if they do they only have horrifying misconceptions from god knows where. No wonder why there's so many data leaks when the responsible people have these attitudes.
It's the kind of re-evaluated outlook on life you only get as you grow older and you start witnessing more and more deaths and imminent deaths around you. I'm also dealing with cancer in the family (I'll spare the details), so my time really is too valuable for god damn software updates.
>I hope you are not handling any customer info on such systems... or are you?!
I'm not. Like I said, if my threat model actually incorporates the kind of threats that updates ostensibly protect against, the scales would weigh differently.
Would I keep business computers updated? Absolutely, if for no other reason than so I can make it all someone else's problem. I'm talking about my own personal computers.
On a flip side though, I've seen so many older folks loose so much time and undergo a lot of stress (which may be highly unwarranted for medical reasons) from having money stolen by banking malware, or more recently, good old phishing. It's like a vaccine, we endure a small pain to prevent a much greater one in the future.
Anyway, I hope you and your family does well!
Back in 2012 I was the Head of IT for an A series start-up with about 80 people and we ran almost all machines on Linux (mostly Ubuntu) and it worked like a charm. We scaled to about 400 people before switching to Chromebooks in 2015 for the vast majority of users. Our IT operations team never had more than 4 FTE at any point in time, which compares very favorably with any other company. This was possible because Linux environments are extremely easy to maintain for a trained IT staff and, obviously, because we mostly avoided the MS Office crapware (which was less crappy back then than it is today). Google Suite served us fine and the rest was custom web-based software.
Today I'm at a different company, no longer in the trenches, and use MS Windows machines for my work and there is not a single week going by without need to call tech support. Adding the counter-productive helpfulness of MS Office applications I sometimes think MS is paid by our competitors to destroy our productivity. That's a "stability vulnerability".
Er, this decade? How would setting resolution go badly today? (The closest thing I can think of is that once upon a time you could mess up CRTs with bad settings.)
Wrong.
Half way through, Debian seems to have lost[1] libcrypt.so.1, which everything important in the system relies on. Could no longer sudo (needs libcrypt) from the session I was logged into. Couldn't re-log in at all either over the network (ssh needs libcrypt) or locally (local authentication needs it too). Could not even get to single-user mode because init=/bin/bash didn't even work. I ended up having to boot from a liveCD, re-assemble the raid partition containing my root filesystem, and manually copy libcrypt into /lib/x86_64-linux-gnu/
All because I tried to upgrade Debian from 10 to 12, skipping a version, which, apparently you can't do anymore.
As much as I can't stand Windows and I grin-and-bear macOS, I've never had an experience even close to as bad as that on those systems.
And if you had bothered to read the Release Notes for bookworm: It's in there [2]. Also you are instructed that only upgrades from bullseye are supported, and to upgrade to bullseye first if you are running an older version.
Nobody else to blame for your fall.
[1] https://www.debian.org/releases/sarge/i386/release-notes/ch-... [2] https://www.debian.org/releases/stable/amd64/release-notes/c...
None of that changes the user-experience comparison with mainstream OS's or parent's point about Linux's "‘stability vulnerabilities’ where the user has to tread carefully". Linux is well known for being a sharp tool without safety guards. That, and the "RTFM" tone of the typical response to trouble, are some reasons why the Year Of The Linux Desktop is perpetually stuck somewhere in the future.
The second most recent was when Windows Store local repository become broken. Any attempt at resolving the issue failed using Windows provided tools. Yet again had to reinstall the OS and all applications.
This is the big reason why I prefer Linux over Windows any day of the week. Windows fix always seems to be the same, re-install OS and applications. Never had a problematic Linux installation that couldn't be resolved with a live CD / USB. Boot into live USB, mount encrypted partitions, chroot into environment, fix problematic package(s) or re-edit configuration files, reboot. No need to reinstall the OS and all applications.
Linux packaging system(s) are heaven compared to the Windows update hell-scale. Ever have to find a way to update the Root Certificates in order to install .NET Framework 4.7.2 offline on Windows 7 Embedded SP1 that is air gaped and has not had an update since the computers were shipped? Not fun.
oh man, I had my Windows install get into a weird state where trying to open 'Updates & Security' would just crash the Settings app altogether. Eventually I submitted a feedback hub report for it with a dump and tttrace (though that was a journey in and of itself) and in the meanwhile I actually managed to get updates installed via the PSWindowsUpdate powershell module. Alas, that still didn't fix the crashing Settings app. I had a friend at MS promote my feedback hub item to a bug who relayed the reason being that my copy of MusUpdatehandlers.dll was corrupt somehow. Ok, I guess I can try using sfc and dism to hopefully repair that. A couple rounds of that and all I learnt was I actually had a few more update related DLLs that were also corrupted. The real kicker being the copy in the store was also corrupted??
2022-05-25 16:40:41, Info CSI 00000226 [SR] Could not reproject corrupted file \??\C:\WINDOWS\System32\\updatepolicy.dll; source file in store is also corrupted
Anyways, I was too stubborn to just reinstall and got it fixed by grabbing an install.wim from an ISO that matched my install and telling dism to use that. The really dumb thing was i first tried to do the repair in offline mode pointing it at the install.wim for sources but turns out that's just not supported.
Instead you get some opaque failure message and it only mentions the fact that wasn't supported in a single line buried in the huge log file.1) doesn't even a domestic router block all inbound connections?
2) is there any evidence of unpatched remote vulnerabilities for windows 98?
https://unix.stackexchange.com/questions/111281/exploding-am...
Recommending Debian to the retrocomputing community is possibly the most tone-deaf thing I've seen today.
For everyone else: This project exists for the joy of the retro-computing community. No one in their right mind - retro-computing enthusiasts included - would ever recommend using any of these versions of Windows for anything other than amusement.
No, DOSBox is not always an alternative.
Retro enthusiasts are quite excited by this project. And for anyone wanting to rebuild an old PC running Win95 for fun, this is going to be a very helpful tool.
Michael MJD (YouTube) covered this yesterday in fact: https://www.youtube.com/watch?v=xbeqLmSVqvs
Saying you're free to have your hobby isn't tone-deaf.
If you're use for this project is personal enjoyment, have fun. If it's an important cog in your business, you should probably fix that.
It is. It's a community project that you can trust, or not. Debian also reports to servers of "unknown provenance" and updates itself from there.
Now, Debian has probably a lot more eyes on it than some Windows Update revival project, but some more niche distros have essentially the same problem.
> Recommending Debian to the retrocomputing community is possibly the most tone-deaf thing I've seen today.
archive.debian.org might be right up their alley
Open source does not address my need or desire for Windows, regardless outdatedness.
Seriously, it's annoying that fReE and oPeN sOuRcE are thrown around like they will solve all the problems in the world. Spoiler alert, they don't. Especially if that problem involves a practical need that most libertarian neckbeards wouldn't care about.
Yes I run Windows, and yes I happily run EOL Windows because they are required to run something reliably. And yes, I happily run unpatched Windows because updates break shit and waste my time compared to the dangers posed by hypothetical threats outside my practical threat model.
Something being free or open source does not in any way fundamentally address my needs and desires. No, Wine is not a panacea (unless we're talking about the drink). No, I'm not going to waste even more time getting Linux to work just so I can get on with life.
There are certain high seas where such things are plentiful.
If you don't want to go through the hassle of installing and then upgrading I'm also pretty sure you can upgrade one of the images in the wim offline using dism.
0: https://www.microsoft.com/en-us/software-download/windows10 (will serve you an iso directly instead of the media creation tool if you give it a linux user agent)
1: https://learn.microsoft.com/en-us/windows-server/get-started...
I do work on my windows machine, so doing anything illegal just gives me the opportunity to lose 1000x more money than if I just upgraded legally.
Because most of this list is not Native or Platinum.
Games on Windows just work.
Also, how well does VR work in Linux these days?
this loaded question should be directed towards the developers.
that any Windows game works on Linux at all, given Microsoft's record regarding interoperability, seems like a miracle.
If I had to make an equally loaded question I'd say, what OS are they using to host their game servers?
Of course you can purchase "enterprise" versions of Windows 11[0].
What's more, anyone can purchase most of Microsoft's offerings for ~USD$1000[1].
[0] https://www.microsoft.com/en-us/d/windows-11-pro/dg7gmgf0d8h...
That's just not true. cf. the link I posted[0].
Anyone can buy a Visual Studio Developer Subscription (formerly "Technet Library" and "MSDN" packages) (USD$1199.00) without an enterprise agreement with Microsoft. I've used it for many years and will continue to do so.
And you don't need to renew it either (I'll generally do so every 5-7 years to get access to the latest stuff, but it's not necessary or required), especially since the software isn't "in the cloud" so you can have most of Microsoft's products (workstation and server) on local media.
But if you think I (and the Microsoft subscription page) don't know what I'm talking about, feel free to ignore me. It's no skin off my nose. In fact, it's about time for me to go and do (for the fourth or fifth time) what you say I can't do. Thanks for reminding me!
[0] https://visualstudio.microsoft.com/vs/pricing-details/
Edit: Fixed typo. added missing words.
I recently purchased a Windows 10 Enterprise key from a website called "RoyalCDKeys" for under $4. It worked to upgrade my Windows 11 installation.
Basically any reseller will work but only if they use a payment processor other than PayPal. PayPal will only end in misery and your money being lost.
A year or three ago, my uncle (mid-50s, telco IT manager, started on a Commodore in the 80s) decided he'd try Mint instead of upgrading from Windows 7. He got it installed and running, and decided he wanted to burn an audio CD.
His install of Mint didn't come with any application to accomplish this. He got something recommended installed easily enough, but it only supported FLAC, not his MP3s. So he removed that and got some different CD burning software that did support his MP3s, but was set to Finnish by default. He got enough Finnish translated to get it changed to English, and then ran into some sort of driver/support issue for his particular CD burner.
At that point, he did the free upgrade to Windows 10 and then burned his CD in less total time than he'd spent not burning a CD via Mint.
https://wiki.gnome.org/Apps/Brasero
https://linuxmint-installation-guide.readthedocs.io/en/lates...
I can't speak for Linux Mint, but last few times I tried to use Brasero it was issue after issue after issue with some kind of lower level driver thing. I installed the missing libraries, still nothing. Tried searching for a fix and found nothing that could resolve my issue with Brasero. I installed K3B and it just worked, so that is what I do now.
Possibly the parent poster's uncle ran into something like this and gave up instead of trying a KDE application?
Every time I unlocked that phone it would bother me.
That, a slower response time(might have been due to animations), not having widgets, and some buggy official apps like the podcast app, and I bailed from iPhone pretty quick.
I admittedly was so excited to unbox and give Apple all my personal information. Weird.
It was common in the Windows XP days for many users to never install updates and it really contributed to Windows's reputation for being incredibly insecure. Forcing updates became the only option to ensure Windows users remain secure.
It definitely was after 2011.
Windows 3.1, 95, 98, Me are less easy to emulate.
Note that that seems to have impacted the preservation of old games and programs. Plenty of dos games are all over the web and still quite popular, yet most stuff from the Win 9x era has almost entirely vanished due to the difficulty of running it on modern hardware.
Archivists take note - if you want something to live for a long time, it needs to be easy to emulate. And in turn, that means it needs to be both very common, and have simple API's so someone in the future can be bothered to make and maintain an emulator.
The tricky part is that this applies even if you're using a VM. I learned the hard way that Windows 98 isn't compatible with Ryzen CPUs, even through VirtualBox. I had to try again on another PC with an older Intel CPU.
[0] https://github.com/JHRobotics/patcher9x
[1] https://blog.stuffedcow.net/2015/08/win9x-tlb-invalidation-b...
how do archivists have a say in this?
Also, some archivists have the choice to convert media. For example, rather than storing a Wordperfect document, perhaps it is best to convert to PDF. Rather than storing the ROM of an 80's arcade machine, or the whole machine, perhaps it is best to store an MPEG video of a playthrough. Rather than storing the data on a floppy disk in a filing cabinet, perhaps it is best to store the data on a server which will be kept up to date? Well resourced archives might be able to implement emulators - but then the question remains how should that be done - Is it okay to have a PDP11 emulator that runs on dos, emulated by dosbox in windows XP, emulated again by virtualbox on Windows 11?
A big part of being an archivist is making decisions of what to keep, what not to keep, what form to keep it in, and when to convert it.
There is no consensus - some archives knowingly keep data and software that they have no way to open/run, in the hope someone might bother in the future. Others keep dependency tables to ensure that they always have some combination of hardware and software to run/open any stored material.
Future people will have better solutions to all these problems, and every bit of effort we put into organising our archives today is effort taken away from collecting more bytes.
For some hardware, the number of people who can make it work has already diminished a lot. You can gather some of the knowledge today, “future people” won't be able to. What's the use of collections of data that can't be used?
You can technically get Windows 9x software running in a VM, but not without laggy video/audio in my experience.
[1]: https://www.catalog.update.microsoft.com/Search.aspx?q=SP3+X...
Wikipedia:
> Windows Update was introduced as a web app with the launch of Windows 98 and offered additional desktop themes, games, device driver updates, and optional components such as NetMeeting. Windows 95 and Windows NT 4.0 were retroactively given the ability to access the Windows Update website and download updates designed for those operating systems, starting with the release of Internet Explorer 4.
Otherwise, in the 95 era, I believe you'd likely be finding out through a software vendor or otherwise that a certain fixpack from Microsoft might fix an issue and you should go grab an update then.
Oofda. That can't have been an accident.
Anything else would have been a direct fix package - such as the DCOM95 OLE Update, DUN 1.4, or Winsock 2 -- things that you only installed if you needed something that used those functions, and often would become bundled with the software anyways because users might not have been given those updates out of the box.
There was at least one XP-era update CD that I do recall - the Windows Security Update 2004 contained patches for 98 through XP and was available by mail from Microsoft.
"Critical Update Notification Utility (initially Critical Update Notification Tool) is a background process that checks the Windows Update web site on a regular schedule for new updates that have been marked as "Critical". It was released shortly after Windows 98."
Unfortunately, the citation for that is no longer active on MS's site, and the archive.org version no longer works either.
https://en.m.wikipedia.org/wiki/Windows_Update#Critical_Upda...
— Those who knew how to enable those features probably checked update sites and news sites manually often enough.
— Almost all software had to bundle required components and updates anyway. Games came with DirectX version 5/6/7/8/9 installers, IE version 4/5/6 installers provided important system components, acting as semi-service-packs for 9x systems… and, of course, Visual Studio library dependencies.
Windows Update Restored (purportedly) does.
(Sent from a ThinkPad x41 running Windows XP)
Quite a lot of (DOS based but not only) tools and programs (particularly any low-level one and - generally speaking - games) that run just fine in Windows 95 won't work on NT 4.00/2000 and later, and they as well won't in ReactOS.
Struck me as a bit unsafe?
BTW this also exists or did exist for "Fix Windows Update on Windows XP, Vista, Server 2008, 2003, and 2000"
Usually ATMs run in their completely own network with heavy access controls limiting access even if the physical location is compromised.
[1] If you can get into the innards you can probably just, you know, grab the cash (beware of dye bombs though).
JFYI, there is a dedicated thread on MSFN.ORG for these sightings:
https://msfn.org/board/topic/176692-windows-xp-spotter-the-c...
Atm's and public signage (airports, metro and similar) are still common enough.
Couldn't they collect and systematically 'slipstream' every patch and fix that would exist on Windows Update into a "Final Edition" ISO?
Or is the scope broader than a naive reading of the headline, and non-OS packages (drivers, third party software) were also relayed through WU?
> This website requires a minimum of Internet Explorer 5.0 or above, but we recommend Internet Explorer 5.5. To download Internet Explorer 5.5, Click Here
> http://windowsupdaterestored.com/en/aboutwindowsupdaterestor...
The submission is the literal website used for the updates. You use it by browsing the website like any other website.
You figured out how to use HN without much hand-holding, I'm sure you can figure out how to use this website as well :)
Edit: There is even a video explaining how to use the website, not sure what more you could ask for? https://www.youtube.com/watch?v=pbWa_tlC-3I
I was expecting one would need to tweak the registry or plug some custom DNS entries to get the updates running.
Even the final official build of Firefox that supported Windows XP will break on websites like Github, where a Releases page will never finish loading, and never let you download any files. But the New Moon build on that website (28.10) will work.
(Don't forget to install uBlock Origin and a current fork of uMatrix)
Discussions of those builds can be found in relevant threads on relevant forums.
that's the bit that left me gobsmacked