Windows Update - How will it change your system?

Anonymous
2016-10-14T16:11:13+00:00

You need to make a decision about where you want to be with your system.

My advice is to change the Windows Update (WU) setting to never.

It really depends on where you want to be with your Windows 7 system.

Woody Leonhard has described the situation something like this.  Note, I am using my own words here and describing it from my own perspective:

http://www.infoworld.com/article/3128983/microsoft-windows/how-to-prepare-for-the-windows-781-patchocalypse.html

Group A:  Roll over and just let MS install what ever they wish on your computer and just don't worry about privacy and the spyware they will install.  With this option you leave WU as Delayed start, and set the WU setting at Recommended.  This is the easy way and requires no effort or concentration.  You just let happen what will.  This is essentially what you have with a Windows 10 system.

Group B:  Refuse to accept any updates except Security ones.  In that case you follow my initial recommendation and leave WU set at Never.  You get the Security only updates from the "catalog".   There is risk here in B.  You are trusting that MS will not put anything in that group that does things you do not want done. A sort of level of trust in MS that I am not sure they deserve.   Keep in mind that they have done the same thing with this set of updates they did in the main one.  It is all one agglomeration of whatever number of security updates they decide to put in it. 

Group C (AKA W): Shut down WU permanently and never again accept a Windows Update.  This group feels that the risk of MS changing their machine in unacceptable ways or even bricking it is greater than the risk of a hacker breaking in because some security patch was not installed.   I suspect that most people who even think about this topic will opt for this.  However since most people think of their computer like a potato peeler, they will not even think about this and things will just happen without them even knowing.  They will be Group A and won't even know it.

I am in Group W and would like to be in Group B.   It depends on whether I can find a satisfactory way for my 150 or so client machines to be updated.  They are average Joes and Janes.

Note that this may not apply to NON-Windows updates such as Office.  I am not sure how you can be in group B or W and do this, but I am working on it.

UPDATE November 19, 2016:

It now appears that B is an impractical strategy for 99% of users.  And, here is the reason why:  When an error is made in a security-only update, if the error turns out not to have a security affect, it may be corrected in a non-security update.  In that case if you were following B strategy, you would be left with an un-corrected defective update installed on your computer.  If you were extremely diligent and knew about it, you may be able to get the correction in specific cases.  This would entail an extreme amount of diligence that few would be willing or able to provide.

The new rollup style of updates that Microsoft is now providing to what we would call Group A, which include all kinds of updates (security and non-security), are cumulative.  That means if you miss a month or even more, it will not matter because by installing the latest month's rollup, you would be up to date.

NOTE well, that Security-only updates are NOT cumulative.  Which means if you miss a month, you may never get the missed updates.

So one strategy that you may wish to consider is following Group C, but still updating .net and Microsoft Office through Windows Update, but installing no Windows updates at all.  It would be advisable in this case that you stop using Internet Explorer because you would not be getting those updates, but instead use an alternative browser.

Then, after following this strategy for some time, if things take a turn for the worse, and you decide you made the wrong choice (Group C with .net an Office updates), you can easily shift to A by simply using the latest offered Rollup offered in Windows Update.

So, as things have evolved, it looks like the vast majority have really only two choices:  A as described above or C (modified as described above).  The good news is that if you follow the modified C strategy, you have a way back to the Microsoft way, that is easy to implement.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

247 answers

Sort by: Most helpful
  1. Anonymous
    2017-04-24T14:14:58+00:00

    The very first time you install those monthly roll-ups, you are group A.  The die will be cast at that point.  The only way to reverse that course will be to re-install Windows 7 and then apply updates very carefully, avoiding the roll-ups.

    The decision really is a trade off between two risks:

    • The risk that Microsoft will turn your computer into a data gathering beacon point that describes you in their database and leaves you with a junior under-priviledged kind of quasi Windows 10 system
    • The risk that your system will be infected because you had not applied some security patch.

    It is my opinion that Group B will gradually, if not already become more and more complicated, eventually making it impossible to manage.  I therefore have decided that Group C (W) is my choice.  I have ensured that I and my clients have a top notch AV program and use conservative principles in using the web.  I have encouraged my clients to begin using Chrome instead of IE.

    In fact, I have applied the security only patches for Oct, Nov, Dec, Jan and Mar.  Feb WU was called off by MS at the last moment, probably because of some screw up.  You will find the links to those specific updates at this site:

    https://www.askwoody.com/forums/topic/2000002-ongoing-list-of-group-b-monthly-updates-for-win7-and-8-1/

    I have also applied .net updates as they are generally agreed to not contain any of the MS spyware.

    I have refused MSRT because it is now loaded with MS spyware, and in fact is relatively useless anyway.

    I have applied Office updates up to, but not including March and April which are full of all kinds of defective Windows updates.

    I do not know if I will apply any future updates.  I am taking that one month at a time.  In any event, I will only apply updates when they are quite aged -- meaning at least one month old.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-04-24T09:08:26+00:00

    Hi CT,

    At the moment I'm set at Group B and still at odds wether I should accept the monthly rollups!

    Seems there's no real clear cut and certain way on what the best thing to do, might be!

    Guess its a matter of something like six of the one or half a dozen of the other?

    Regards,

    Derek

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2017-03-08T05:46:39+00:00

    I have decided,

    that none of the CCU (Combined Cumulative Updates) will ever be installed on my systems

    they can sit in the WUAU notification forever for all I care

    Group A people who call me for help,

    have been on: Never Check for updates since the beginning of the war on win 7 (1 year free 10 upgrade)

    now that the Free upgrade time it's expired

    I will move them to Notify only and have them only install

    MRT,

    MSO updates (if they have MSO)

    wait for approval on the the dot nut update(s)

    and hide the CCU

    because:

    Problem In Chair Not In Computer

    also everyone I help has IE nuked with the following:

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun]

    "1"="iexplore.exe"

    anything attempting to start IE generates the dialog:

    The operation has been cancelled due to restrictions in effect on this computer.

    Please contact your system administrator.

    because IE is actually where 95+% of the security holes come from:

    the update more information link usually points to a page that has some form of the following text

    ... authenticated / unauthenticated remote attacker ...

    well if yer not using IE then the hole can't be exploited

    see total "Security" updates for NT3.1 and NT3.5x without integrated IE is a very small number

    updates were usually functionality and bug fixes, not "Security" updates

    as soon as IE was integrated in NT4 and all subsequent OS versions

    the number of "Security" updates went through the roof

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-03-08T04:30:24+00:00

    In Windows 10, all Windows Updates are downloaded and installed automatically, you do not have the option to select which updates will be installed.

    With the following troubleshooter,  you can show or hide which Windows Updates will be installed.

    https://support.microsoft.com/en-us/help/3073930/how-to-temporarily-prevent-a-driver-update-from-reinstalling-in-windows-10

    Note: You have to disabled WU, and check for Updates manually otherwise all WU will be installed automatically without your awareness.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-03-06T00:55:38+00:00

    AFTER HOURS OF DEALING WITH BROKEN WIN-7 UPDATES  the POS won't boot after I removed Mcafee and the update hung again.

    Microsoft .. YOU OWE ME A WIN7 - BOOTABLE CD.

     What a pathetic, cancer ridden piece of crap.

    7 years of data - lost.

    Was this answer helpful?

    0 comments No comments