Since Flash update is now bundled with Windows Updates it means that Edge users will be using vulnerable Flash for one more month, wow :/
The "Disable Falsh" button is under Advanced Settings on Edge. Switched it off and I barely notice anything is missing these days.
Microsoft’s February security update release delayed to March
31–40 of 53 posts
Re: Microsoft’s February security update release delayed to March
#32Re: Microsoft’s February security update release delayed to March
#33One foreign government organisation must be hacked this month, but NSA doesn't have enough time, so they asked MS to delay patches.
Not saying the NSA doesn't influence Microsoft or others to withhold patches, but seeing the invisible hand of the NSA everywhere is not helpful for determining and criticizing when they do influence things. People seem to be able to suspend their critical thinking too easily whenever the NSA can be invoked.
Re: Microsoft’s February security update release delayed to March
#34I don't get it. So because of one issue, they're not going to deliver any other security patch either?
There are speculations that Windows Update itself could be broken: http://www.computerworld.com/article/3170633/microsoft-windo... https://www.askwoody.com/2017/what-happened-to-the-february-...
Now they distribute all patches in one month together, so they possibly limited themselves to "all or nothing" also for one platform.
But regarding all platforms, they only had the choice of releasing all platforms delayed: e.g. one or two weeks or the whole month. If the issue is not trivial, as probably isn't, the whole month alternative wins.
Re: Microsoft’s February security update release delayed to March
#35Earlier quoted context omitted.
This is a somewhat unpleasant semi-misconception. You can , indeed, update everything but the kernel without rebooting. In fact, I suspect you could even replace the kernel image and the modules while they're running (but this will certainly break any attempt to load modules at a later point without rebooting first). (Edit: most distributions choose to keep the old image along in case the new one breaks. It's relativ…
If memory serves, Microsoft cannot actually do it, due to differences in file system semantics. In Windows, it's not possible to replace a file that's in use.
Re: Microsoft’s February security update release delayed to March
#36Earlier quoted context omitted.
It has nothing to do with cumulative updates. They push once a month because back in the day they pushed whenever they had an update, and enterprises really hated that because it meant that sometimes 1000s of computers were all out of commission running updates at the same time. So MS and the enterprises agreed on a specific day of the month that updates would get pushed, so that the enterprises could plan accordingl…
enterprises really hated that because it meant that sometimes 1000s of computers were all out of commission running updates at the same time. If a computer has to go out of commission for a security update, you are doing it wrong (as an OS vendor). Doing cumulative updates is only band-aid. The real solution is make the OS modular and reliable enough to replace/restart components while it is running.
Having said that, is is nice to be able to fully update an OS, including kernel, whilst running, but ultimately it is just a matter of abstraction levels and marketing.
Re: Microsoft’s February security update release delayed to March
#37One foreign government organisation must be hacked this month, but NSA doesn't have enough time, so they asked MS to delay patches.
I wish people thought a bit more critically when invoking NSA conspiracies in these matters. If the NSA was the primary cause, wouldn't it be much easier to simply silently exclude those specific unwanted updates from an otherwise regular Patch Tuesday, instead of having Microsoft announce very publicly and vocally that something is 'off' in this patching round? Not saying the NSA doesn't influence Microsoft or other…
Re: Microsoft’s February security update release delayed to March
#38Earlier quoted context omitted.
I wish people thought a bit more critically when invoking NSA conspiracies in these matters. If the NSA was the primary cause, wouldn't it be much easier to simply silently exclude those specific unwanted updates from an otherwise regular Patch Tuesday, instead of having Microsoft announce very publicly and vocally that something is 'off' in this patching round? Not saying the NSA doesn't influence Microsoft or other…
It was a joke.
Re: Microsoft’s February security update release delayed to March
#39I don't get it. So because of one issue, they're not going to deliver any other security patch either?
Windows 10 already worked like that, last fall they started doing the same for older OS'es.
See: https://blogs.technet.microsoft.com/windowsitpro/2016/08/15/...
Re: Microsoft’s February security update release delayed to March
#40Earlier quoted context omitted.
It was a joke.
Poe's law I guess then, sorry about that. You didn't make it easy to see, judging by the serious responses you got!
Yup, I'm surprised too ;) At least it shows how much respect MS and NSA have now.