Live data from Hacker News

Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

doublepulsar.com

21–30 of 109 posts

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#24
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#26

My windows 10 machines will not receive the update automatically for some reason. I think it is because I had defender completely disabled via group policy since it interferes with some of my development activities surrounding node.JS. However I was able to install the security update manually from the Microsoft Windows update catalog download site. I did this after enabling defender briefly and updating it to ensure…

I'm real curious what kind of development you're doing with node.JS where Windows Defender causes trouble.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#27
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

It isn't relying on it - MS recommends people use Defender, which works fine. But unfortunately not everyone is doing that.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#28
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

>3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates

It is because these (misbehaved) 3rd party applications do things that cause the mitigations update to make computers unusable.

>and of all things, hilariously defaulting to 'no'

It does not default to "no" since the default is to run MSE / Defender.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#29
post #27

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

It isn't relying on it - MS recommends people use Defender, which works fine. But unfortunately not everyone is doing that.

Ironically Defender was preventing me from receiving Windows updates, so I had to turn it off. I assume that means I'm in a catch-22.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#30
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

The problem is that anti-virus software is not a normal application, it is a weird, very complex kind of parasite that burrows deep into the operating system. This means Microsoft must be very careful, lest the parasite unintentionally kill the host.
Post reply on HN