Live data from Hacker News

Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

doublepulsar.com

61–70 of 109 posts

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#61
post #47

Earlier quoted context omitted.

I'm not sure it's that difficult for Microsoft. Unless I misunderstand something, the requirement is on the antivirus systems already registered with Microsoft. They had half a year. MS could force vendors to patch their shit in a few weeks by giving them an ultimatum: in January, either you don't interfere with kernel patching, or we're showing your customers "you antivirus is stopping you from receiving latest secu…

They could, but this isn't just a technical issue it's also a legal and political issue where several AV vendors are currently suing MS in the EU for alleged anti-trust behavior. So the lawyers compromise everybody's security.

That's definitely one of the reasons to do it the way they have. But it's their choice. They chose to have a technical/security problem rather than a political/legal one. Or specifically they choose the customers to have a problem rather than themselves.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#62

My windows 10 machines will not receive the update automatically for some reason. I think it is because I had defender completely disabled via group policy since it interferes with some of my development activities surrounding node.JS. However I was able to install the security update manually from the Microsoft Windows update catalog download site. I did this after enabling defender briefly and updating it to ensure…

I'm real curious what kind of development you're doing with node.JS where Windows Defender causes trouble.

The real-time scanning slows down processes that access a large number of files, like code compiles in general and importing node modules in particular.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#63
post #59

Earlier quoted context omitted.

Symbiont. The word you're looking for is symbiont, not parasite. A symbiont lives in harmony with the host, exchanging something in exchange for the resource it consumes (in this case protection). A parasite just takes, and gives nothing back to the host. (Of course, let's ignore the obvious joke about some AV solutions like Symantec.)

Given your definitions, I'm pretty sure commercial AV is just parasites.

Yeah, the distinction between a symbiont and a parasite is mostly of degree, not kind, and AV software these days is increasingly being found on the blurry line between the two.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#64
post #47

Earlier quoted context omitted.

They could, but this isn't just a technical issue it's also a legal and political issue where several AV vendors are currently suing MS in the EU for alleged anti-trust behavior. So the lawyers compromise everybody's security.

that seems like a fairly questionable blame-shift for MS. If they don't have the guts to provide even that level of protection, yet more reason to shift away from them except for trivial things like gaming.

So if you edit the Kernel on your version of Ubuntu, then Canonical should be held responsible?

That seems like a crazy thought process. You're running software that modifies Window's internal functionality. The vendor knows it's unsupported. How can you blame the company who just made the platform you compromised?

Might as well set your root password to "password" and open it to the public then complain that the security is bad.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#65
post #43

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

Windows isn't going anywhere, if for no other reason than because Microsoft Excel is basically electronic paper to the business world -- and there is simply no adequate substitute for it. (No, neither OpenOffice Calc nor any of the Web-based offerings -- including Microsoft's own -- count.) Coping with Windows is a fact of life. Get used to it.

There's MS Excel (and office) for Mac and Wine supports Office 2013. The situation is getting better every year.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#66

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

The problem is that anti-virus software is not a normal application, it is a weird, very complex kind of parasite that burrows deep into the operating system. This means Microsoft must be very careful, lest the parasite unintentionally kill the host.

Typically, that would be called "a virus"

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#67
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

The bane of open software: users can install any trash they want to.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#68
post #11
post #7

Earlier quoted context omitted.

Which third-party AV isn't dodgy?

clamav Unfortunately I have no reason to use it, though. I don't even know whether it's any good. But at least I know it's not dodgy!

Clamav (clamWin) will happily false positive and quarantine all sorts of files on a windows box, occasionally including required system files. I've tried it on 3 different boxes at different times over the past ~5 years and the amount of false positives was insane every time.

I don't think its ready to be run on Windows boxes unless you are a power user willing to manually verify ~100 files are not actually malware.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#69
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

Note that one of the antivirus software vendors that does this correctly is, in fact, Microsoft Defender. If you haven't installed dodgy third-party AV, you're fine.

You're not fine if you've disabled Windows Defender.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#70
post #43

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

Windows isn't going anywhere, if for no other reason than because Microsoft Excel is basically electronic paper to the business world -- and there is simply no adequate substitute for it. (No, neither OpenOffice Calc nor any of the Web-based offerings -- including Microsoft's own -- count.) Coping with Windows is a fact of life. Get used to it.

[deleted]
Post reply on HN