Live data from Hacker News

Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

doublepulsar.com

31–40 of 109 posts

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#31
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

From the article: "There is a problem where some anti-virus vendors are using techniques to bypass Kernel Patch Protection by injecting a hypervisor which they use to intercept syscalls and make assumptions about memory locations — memory locations which are now changing with the Meltdown fixes."

Difficult situation for Microsoft. If you install applications which mess with the operating system in unsupported ways you can't expect your system to function correctly with automatic updates. On the other hand, users are likely not aware of what they have done and bricking millions of computers is also not good. Might for example cause a backslash when people stop updating their systems.

This sounds like a quick and dirty fix they put in place while figuring out what to do.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#32
post #4
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

You can’t just stop using AV software I’m told. The key is checked for everyone, including people with no AV. Contrary to the sensational headlines, it is implied to be a temporary measure. It’s not really clear whether you’d have to only do this manually once, or on every subsequent update.

If you do it once, it may be that your AV isn't compatible with the patch and will cause your system to bluescreen and maybe not even turn on, so no, you really shouldn't do that.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#33

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

The problem is that anti-virus software is not a normal application, it is a weird, very complex kind of parasite that burrows deep into the operating system. This means Microsoft must be very careful, lest the parasite unintentionally kill the host.

[deleted]

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#35
post #2

“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

I'll never understand why AV is a third party software solution. I don't buy an Audi and then go to some other company and buy ABS and seat belts. This is a MS issue and should be handled in house.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#36
post #10
post #9

Slightly OT if I may: Is there any reason to use anything else than Defender these days? Chrome+uBlock, good email security and update practices, Defender just in case, do we need more?

No, not that I am aware of. 3rd party AV are liabilities at this point. https://www.pcworld.com/article/3020327/antivirus-software-c...

Defender can be seen as merely being the lesser evil.

Consider CVE-2017-0290[0], which was caused by the MsMpEng process running a custom unsandboxed javascript interpreter with system privileges to evaluate untrusted code for maliciousness. Remotely exploitable over many unsolicited channels. Pretty much the worst kind of exploitability. Of course other AVs have done quite similar mistakes.

[0] https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#37

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

I'll never understand why AV is a third party software solution. I don't buy an Audi and then go to some other company and buy ABS and seat belts. This is a MS issue and should be handled in house.

>I'll never understand why AV is a third party software solution.

It has been first-party for many years - MSE was released 2009-09 per Wikipedia.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#38

I think at this time if you're on windows 10 you should really just use Defender. It works well, they are actively developing it, and the new white list based directory protection is kinda neat if you're scared of ransomware.

What feature are you talking about specifically?

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#39

Earlier quoted context omitted.

No, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')

I'll never understand why AV is a third party software solution. I don't buy an Audi and then go to some other company and buy ABS and seat belts. This is a MS issue and should be handled in house.

Maybe not a great analogy: ABS components and seat belts are, in all likely hood, manufactured by a third-party who specialises in such.

Re: Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set

#40

Earlier quoted context omitted.

I'll never understand why AV is a third party software solution. I don't buy an Audi and then go to some other company and buy ABS and seat belts. This is a MS issue and should be handled in house.

Maybe not a great analogy: ABS components and seat belts are, in all likely hood, manufactured by a third-party who specialises in such.

But I don't have to go get them installed myself. So it's Audi's problem, not mine.
Post reply on HN