topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday December 13, 2024, 2:51 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Poll

Stealth updates - right or wrong?

Right
Wrong
Don't Know
Don't Care
Buy me a beer, vodka or cranberry

Last post Author Topic: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF  (Read 28865 times)

Carol Haynes

  • Waffles for England (patent pending)
  • Global Moderator
  • Joined in 2005
  • *****
  • Posts: 8,069
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #25 on: September 14, 2007, 09:34 AM »
I have the same feeling about Windows Secrets and the demise of the LangList. I used to read both and LangaList was the one I read just about every word of. I still have a subscription but I don't think I will be renewing when it expires. I also really object the growing amount of blatant advertising in the paid for version.

Ralf Maximus

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 927
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #26 on: September 14, 2007, 11:24 AM »
Setting aside the Windows Secrets tendency to "cry wolf" occasionally, I still feel they're right to make noise about this item.  Keep in mind that the real issue here is not that Microsoft is downloading updates without our permission (though that pisses me off no end)... rather it's the amount of information they publish about what it *is* they're downloading.

Zero.  In fact, they're being evasive.  ANYONE twiddling files on my PC without permission is cause for alarm; being told nothing about what was changed is even worse.  It's not hard to describe technical changes in simple english, so why aren't they?  The possiblilities are disturbing.

If a stranger sneaks into your house in the middle of the night and "fixes" your plumbing for you, wouldn't that bother you?  Wouldn't you be concerned that they might've helped themselves to the beer or maybe installed one of those terrible 1.3 gpf toilets because THEY think it's necessary?

Wouldn't you rather they asked first? 

And in fact they DID ask, and you said "no updates to the plumbing please" but they came and did it anyway.

Even if MS publishes a complete spec for what was changed in the wau*.* files, I'd still like an explanation of the process.  Why the subterfuge?

Darwin

  • Charter Member
  • Joined in 2005
  • ***
  • Posts: 6,984
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #27 on: September 14, 2007, 12:39 PM »
I also really object the growing amount of blatant advertising in the paid for version.

Yes this is getting on my nerves as well... Perhaps an e-mail campaign to them is in order?

Ralf - great analogy re: the plumbing! You've summed up my feelings exactly, and far better than I could have to boot!  :Thmbsup:

PhilB66

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 1,522
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #28 on: September 14, 2007, 01:02 PM »
What I find worrisome is that users' security tools (FW, Intrusion Detection etc.) did not alert/prompt about this stealth install.

BinderDundat

  • Supporting Member
  • Joined in 2007
  • **
  • default avatar
  • Posts: 31
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #29 on: September 27, 2007, 12:10 AM »
The stealth updates work because the update program is a "trusted" program.  I am having second thoughts about that.  Also, I recently noticed a web site that was being contacted at bootup that appears to be some web content provider called Akamai (the dotted web addresses are hardly logged at all in google, so I had to do a whois to find any reference to them).  I still don't know who has contracted out their services to Akamai, because the initiator only showed as scvhost.  Trustworthy they may be, but I don't like strangers accessing my system - and possibly different ones from time to time - these guys are doing this work on contract from someone.  I have some questions about how secure their systems, software and personnel are.  If I had to guess, it might be M$, just because they have a history of unloading anything to do with servicing customers.  It seems a bit high-handed when they "loan" you the software, and then give any service company access to your computer.  I begin to wonder if I want to have software on my computer that makes my security system look like a seive (I am making a bit of a leap here, but whoever is giving this kind of access without my permission is looking for trouble).

terribleterryc

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 17
  • Mile High Denver Member since 2007
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #30 on: September 27, 2007, 01:44 AM »
Anyone who has had their operating system shut off when they were relying on it can attest to the ensuing panic and sense of helplessness.  This has occurred to me three times recently on visa and xp systems.  All were legal but I made errors in partitioning and repair.  Lost one system entirely.  If you make a mistake with Linux you just start over.
My thought here, I think, is that the complete LOSS of control over a major investment really makes one think about how much control and potential control MS  has over our lives.

CleverCat

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 1,164
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #31 on: September 27, 2007, 02:28 AM »
I like to see my updates and what they are... ;)

I have it set that way for that reason.

justice

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 1,898
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #32 on: September 27, 2007, 04:02 AM »
AFAIK, It's an update to ensue compatibility with the update service, which seems to suggest that not installing means the update functionality (manually or automatic) won't work for you...
There would be a lot more complaints if the update procedure broke, so therefore i voted RIGHT in this case. It's the right thing to do. There's no privacy problem and it makes sure things keep running. Noone would not want to install it, everybody needs it, therefore not having it is not an option.

f0dder

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Posts: 9,153
  • [Well, THAT escalated quickly!]
    • View Profile
    • f0dder's place
    • Read more about this member.
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #33 on: September 27, 2007, 04:31 AM »
BinderDundat: Microsoft have been offloading to akamai for quite a while now.

justice: it's still a wrong thing to do when you have turned off automatic updates. "keep working"? The right solution would be to update the windows-update components once needed.
- carpe noctem

Ralf Maximus

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 927
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #34 on: September 27, 2007, 12:39 PM »
BinderDundat: If by "trusted" you mean the Windows firewall or ZoneAlarm or something, then you are correct.  However, the wa* files Microsoft updates have no special "trustworthiness" assigned to them by the operating system.  Windows Update could potentially change ANYTHING on your PC, and they have demonstrated the ability to do so without notifying the user.

Justice: So long as Microsoft ONLY twiddles the mechanism that interfaces with the update servers, then I agree.  I am not protesing the maintenance of files Windows needs to update itself; in fact I avail myself of Windows Update periodically to get the recommended patches.  That's only common sense.

But MS has demonstrated their ability and willingness to deliver updates DESPITE MY REVOKING PERMISSION TO DO SO.  I opted out, they did it anyway.  Doesn't matter if the patch was necessary or not, it's frikkin rude to shove software onto my PC without telling me.  May even be illegal, since most states prohibit unauthorized tampering with data systems.  And no, the EULA does not shield such intrusion; there is plenty of legal precedent protecting computer users.

But here's the kicker: I don't even believe it's necessary.  When you login to the Windows Update website, what's the very first thing that happens?  You get a small update to your "Installer" and THEN you get to the scanning-your-pc phase.  If updates to the wa* files are necessary, then that's the logical place to perform maintenance.  I would bet real money that they *are* updated there, also, just in case your machine hasn't been online in awhile and the stealth updates never installed.  Not everyone has a 24/7 connection.  Note that the Windows Update website works fine even on machines freshly installed from CD without any patches at all.

So it's rude, possibly illegal, potentially dangerous, damages the user's trust in MS, and finally: UNNECESSARY.

All for what?  Microsoft's response continues to be evasive, addressing only WHAT was stealth-modified, but not why.  Yes, we know those are Automatic Update engine files, and it'd be nice if everyone was 100% in sync all the time with the latest micro-update.  But why do it this way, using stealth and sneakiness?  If told up front what was being changed and why, I doubt any reasonable user would object.

So again, Microsoft, why?

Carol Haynes

  • Waffles for England (patent pending)
  • Global Moderator
  • Joined in 2005
  • *****
  • Posts: 8,069
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #35 on: September 27, 2007, 01:34 PM »
It gets even better - according to the WindowsSecrets newsletter today the updates have broken Windows XP's abilitlity to use the "Repair Install" facility from the CD. If you do this all goes well until you try to update your repaired installation and then there are 80 updates that will not install because MS has deregistered various WU files during the update and they aren't repaired back to a known state properly!

Brilliant!

You can read the article here: http://windowssecret...m/comp/070927#story1

There are also instructions on how to fix the problem if required!
« Last Edit: September 27, 2007, 01:39 PM by Carol Haynes »

PlayPhil

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 24
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #36 on: September 27, 2007, 06:38 PM »
Hmm, according to my log files during this time I did not get these seriptitious updates...

In my Hosts file when WGA first started this (XP) nonesense quite a few months ago, I restored a just prior Image Backup and I added the following...

# Resent MS Joe Bob's wgatray.exe phoning home
# 192.168.0.1      is used to test connectivity to the host computer & can't be used
# 192.168.253.*    Not tested
#         So, max it up into the TOP unused Host IP
192.168.253.253      stats.update.microsoft.com      # primary
192.168.253.253      statsupdate.microsoft.com.nsatc.net   # also resolves to...
# /Resented :)

wurx4me....
Phil

bassclarinetl2

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 31
  • MIS -- Management on Steroids
    • View Profile
    • WillSoft
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #37 on: October 03, 2007, 03:42 PM »
I like to see my updates and what they are... ;)

I have it set that way for that reason.

Me too.  Even if I end up installing all of them, i still like to know what is going on.
-No one instrument is more important than the other.  All are needed for the band to play.

Carol Haynes

  • Waffles for England (patent pending)
  • Global Moderator
  • Joined in 2005
  • *****
  • Posts: 8,069
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #38 on: October 15, 2007, 11:44 AM »
It get's better and better - now updates are being installed that force a reboot without user consent even when WU is completely disabled.

See http://blogs.zdnet.com/microsoft/?p=832 and the discussion that follows.

If you want to completely disable Windows Update so that you have control over what is going on there are two posts in the discussion which are a really useful overview. The second one is particularly helpful as it only shows how to disable (and re-enable for manual checks) WU without affecting other components:

http://talkback.zdne...3925&start=-9911
http://talkback.zdne...3961&start=-9911

Ralf Maximus

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 927
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #39 on: October 15, 2007, 12:41 PM »
It would be nice to have a little hootchie to turn this stuff on/off easily with a click.

Mmmmm... coding snack?

Carol Haynes

  • Waffles for England (patent pending)
  • Global Moderator
  • Joined in 2005
  • *****
  • Posts: 8,069
    • View Profile
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #40 on: October 15, 2007, 01:06 PM »
It's easy to do that - just create two batch file called WU_On.bat and WU_Off.bat and then edit them with a text editor and add the relevant commands to each.

Then you just need to double click the batch file to switch off and on (assuming Admin status).

You can automatically stop the relevant processes using:

SC STOP <svc_name>

eg. SC STOP waauserv

will stop the "Automatic Updates" service (just go in to START>Run>Services.MSC and double click on the service you want to identify and the service name is as at the top)

sc.gif

To start it again just use SC START <svc_name>
« Last Edit: October 15, 2007, 01:13 PM by Carol Haynes »

Ralf Maximus

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 927
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Microsoft patches applied - EVEN WHEN AUTOUPDATE IS OFF
« Reply #41 on: October 16, 2007, 10:39 PM »
I did it!  Presenting my first contribution to DC: WAU Whacker.

A simple utility to start or stop the Windows Automatic Update process (WUAUSERV) via the WMI interface.  Requires VB6 runtimes (XP users already have them), tested on XP SP2.  Not tested on NT, 2000, or Vista.

If you have the Updates service disabled, and try to start it via Whacker, it will grind its gears for about 5 seconds as it tries to start the service, but will eventually give up.

Please report feedback, bugs, etc.
« Last Edit: October 16, 2007, 10:50 PM by Ralf Maximus »