Live data from Hacker News

Microsoft’s February security update release delayed to March

blogs.technet.microsoft.com

31–40 of 53 posts

Re: Microsoft’s February security update release delayed to March

#31
post #25
post #16

Since Flash update is now bundled with Windows Updates it means that Edge users will be using vulnerable Flash for one more month, wow :/

The "Disable Falsh" button is under Advanced Settings on Edge. Switched it off and I barely notice anything is missing these days.

True, but for the 90% of users of Edge that aren't technical, going into advanced settings and disabling flash is probably beyond their abilities.

Re: Microsoft’s February security update release delayed to March

#32
post #17

One foreign government organisation must be hacked this month, but NSA doesn't have enough time, so they asked MS to delay patches.

What do you base that on? Faith? :)

Previous leaks :)

Google is in relationship with NSA

Yahoo let them tap their cables

Now it's MS turn

Re: Microsoft’s February security update release delayed to March

#33
post #17

One foreign government organisation must be hacked this month, but NSA doesn't have enough time, so they asked MS to delay patches.

I wish people thought a bit more critically when invoking NSA conspiracies in these matters. If the NSA was the primary cause, wouldn't it be much easier to simply silently exclude those specific unwanted updates from an otherwise regular Patch Tuesday, instead of having Microsoft announce very publicly and vocally that something is 'off' in this patching round?

Not saying the NSA doesn't influence Microsoft or others to withhold patches, but seeing the invisible hand of the NSA everywhere is not helpful for determining and criticizing when they do influence things. People seem to be able to suspend their critical thinking too easily whenever the NSA can be invoked.

Re: Microsoft’s February security update release delayed to March

#34
post #30
post #22

I don't get it. So because of one issue, they're not going to deliver any other security patch either?

There are speculations that Windows Update itself could be broken: http://www.computerworld.com/article/3170633/microsoft-windo... https://www.askwoody.com/2017/what-happened-to-the-february-...

I've followed the links. The argument "if the patch is broken on, for example, Windows 10 but not on Windows 7 they could still release for Windows 7" is wrong: once the patches for Windows 7 are available every criminal can investigate them and then apply the results to the unpatched (delayed) 10 systems. So it's either all platforms or none.

Now they distribute all patches in one month together, so they possibly limited themselves to "all or nothing" also for one platform.

But regarding all platforms, they only had the choice of releasing all platforms delayed: e.g. one or two weeks or the whole month. If the issue is not trivial, as probably isn't, the whole month alternative wins.

Re: Microsoft’s February security update release delayed to March

#35

Earlier quoted context omitted.

This is a somewhat unpleasant semi-misconception. You can , indeed, update everything but the kernel without rebooting. In fact, I suspect you could even replace the kernel image and the modules while they're running (but this will certainly break any attempt to load modules at a later point without rebooting first). (Edit: most distributions choose to keep the old image along in case the new one breaks. It's relativ…

If memory serves, Microsoft cannot actually do it, due to differences in file system semantics. In Windows, it's not possible to replace a file that's in use.

Your memory is serving you incorrectly.

* https://news.ycombinator.com/item?id=11415366

Re: Microsoft’s February security update release delayed to March

#36
post #3

Earlier quoted context omitted.

It has nothing to do with cumulative updates. They push once a month because back in the day they pushed whenever they had an update, and enterprises really hated that because it meant that sometimes 1000s of computers were all out of commission running updates at the same time. So MS and the enterprises agreed on a specific day of the month that updates would get pushed, so that the enterprises could plan accordingl…

enterprises really hated that because it meant that sometimes 1000s of computers were all out of commission running updates at the same time. If a computer has to go out of commission for a security update, you are doing it wrong (as an OS vendor). Doing cumulative updates is only band-aid. The real solution is make the OS modular and reliable enough to replace/restart components while it is running.

I could just as easily argue the opposite: If your operations can't handle individual system reboots you are doing it wrong. Rebooting and even rebuilding entire systems are not bad things in my book. In any case saying that this needs to be dealt with solely at the OS layer does not make sense to me.

Having said that, is is nice to be able to fully update an OS, including kernel, whilst running, but ultimately it is just a matter of abstraction levels and marketing.

Re: Microsoft’s February security update release delayed to March

#37
post #33
post #17

One foreign government organisation must be hacked this month, but NSA doesn't have enough time, so they asked MS to delay patches.

I wish people thought a bit more critically when invoking NSA conspiracies in these matters. If the NSA was the primary cause, wouldn't it be much easier to simply silently exclude those specific unwanted updates from an otherwise regular Patch Tuesday, instead of having Microsoft announce very publicly and vocally that something is 'off' in this patching round? Not saying the NSA doesn't influence Microsoft or other…

It was a joke.

Re: Microsoft’s February security update release delayed to March

#38
post #37
post #33

Earlier quoted context omitted.

I wish people thought a bit more critically when invoking NSA conspiracies in these matters. If the NSA was the primary cause, wouldn't it be much easier to simply silently exclude those specific unwanted updates from an otherwise regular Patch Tuesday, instead of having Microsoft announce very publicly and vocally that something is 'off' in this patching round? Not saying the NSA doesn't influence Microsoft or other…

It was a joke.

Poe's law I guess then, sorry about that. You didn't make it easy to see, judging by the serious responses you got!

Re: Microsoft’s February security update release delayed to March

#39
post #22

I don't get it. So because of one issue, they're not going to deliver any other security patch either?

Microsoft stopped distributing individual patches, all updates are now rolled up into one package. Therefore, if one patch causes issues, none of them can be released.

Windows 10 already worked like that, last fall they started doing the same for older OS'es.

See: https://blogs.technet.microsoft.com/windowsitpro/2016/08/15/...

Re: Microsoft’s February security update release delayed to March

#40
post #38
post #37

Earlier quoted context omitted.

It was a joke.

Poe's law I guess then, sorry about that. You didn't make it easy to see, judging by the serious responses you got!

>judging by the serious responses you got!

Yup, I'm surprised too ;) At least it shows how much respect MS and NSA have now.

Post reply on HN