Live data from Hacker News

Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

doublepulsar.com

101–109 of 109 posts

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#101
post #66

Earlier quoted context omitted.

The problem is that anti-virus software is not a normal application, it is a weird, very complex kind of parasite that burrows deep into the operating system. This means Microsoft must be very careful, lest the parasite unintentionally kill the host.

Typically, that would be called "a virus"

No. "Symbiote," likely; "parasite," perhaps. "Virus," not at all.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#102
post #96

Earlier quoted context omitted.

You could still get the reboots without updates ... which is what I've been getting for a few weeks now on a cheap tablet: loads update, reboots in the night, update fails. Rinse, repeat. (I don't care, an update took down the sound last year. For all I know the next one will make the gizmo totally malfunction ... MS don't care for that cheapo segment either, the wanton demands for disk space are astounding, and they…

Throw Enterprise LTSB on old/low spec hardware. Thats my preferred Win10: stable, bloat free and it only gets the updates beta tested by the regular users.

"Windows 10 LTSB is only available as part of Windows 10 Enterprise. And Windows 10 Enterprise is only available to an organization with a volume licensing agreement, or through a new $7 per month subscription program."

Seriously? An OS of which you need an obscure, hard-to-get version, special messing around in power tools, and still might break randomly? This role reversal happening in the last 10 years is sad, really.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#103
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

> Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

The default is to use the 1st party product, Windows Defender, which defaults to 'yes'.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#104

Earlier quoted context omitted.

Yes, http://www.bromium.com adds next level security to Windows environments.

I don't think your comment should be downvoted, but Bromium also adds a revolting lag, clumsiness and instability.

Indeed but if you need security it’s a good solution.

I must have upset the hive mind by sharing a link. Oh well, hopefully someone finds value here.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#105

Earlier quoted context omitted.

There's a lot of confusing information out there as you have found out. This link helps clarify the steps needed. https://doublepulsar.com/important-information-about-microso... Pay specific attention to the dataflow. Registry keys have to be set in a certain order in order for a) the patch to download and install and b) actually enable. If there is not a BIOS fix (I'm in the same boat as you), the other hope is that…

Seems like Intel has released updated microcode: https://news.ycombinator.com/item?id=16111433 but sadly no mention of what Windows users are supposed to do.

At this time, nothing other than update BIOS.

My Windows systems are VMs so I updated to the latest ESXI release (as of yesterday) which includes microcode. See https://www.vmware.com/us/security/advisories/VMSA-2018-0004...

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#106
post #95

Wow using a hypervisor to inject below the kernel to avoid KPP is nuts. Never knew the AVs did that. What are they going to do when Microsoft begins to use Hyper-V to enforce CredGuard[1]? [1]: https://blogs.technet.microsoft.com/ash/2016/03/02/windows-1...

Turns out nested virtualization is a thing. Jesus.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#107

Earlier quoted context omitted.

I haven't used anything other than Defender (and the Microsoft tool that predated it, can't remember the name) in ages. I've never had any issues.

Microsoft Security Essentials?

Yep, that's the one.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#108
post #46

Do I have to do anything if I'm just using Windows Defender?

Nope, Windows Defender has already set the registry key, and you should be good to go. For the rest of you, there is a good public document[0] that is being regularly updated on the status of each of the AV products out there. [0] https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLp...

Does Microsoft Security Essentials fall under Windows Defender for the purposes of this article?

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#109
post #66

Earlier quoted context omitted.

The problem is that anti-virus software is not a normal application, it is a weird, very complex kind of parasite that burrows deep into the operating system. This means Microsoft must be very careful, lest the parasite unintentionally kill the host.

Typically, that would be called "a virus"

Can a virus make its host dependant on it?
Post reply on HN