In addition, I refuse all "security quality rollups", except for .net.
CT -- By ".net", do you mean .NET Framework? Just want to be sure I'm not missing anything.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
You need to make a decision about where you want to be with your system.
My advice is to change the Windows Update (WU) setting to never.
It really depends on where you want to be with your Windows 7 system.
Woody Leonhard has described the situation something like this. Note, I am using my own words here and describing it from my own perspective:
Group A: Roll over and just let MS install what ever they wish on your computer and just don't worry about privacy and the spyware they will install. With this option you leave WU as Delayed start, and set the WU setting at Recommended. This is the easy way and requires no effort or concentration. You just let happen what will. This is essentially what you have with a Windows 10 system.
Group B: Refuse to accept any updates except Security ones. In that case you follow my initial recommendation and leave WU set at Never. You get the Security only updates from the "catalog". There is risk here in B. You are trusting that MS will not put anything in that group that does things you do not want done. A sort of level of trust in MS that I am not sure they deserve. Keep in mind that they have done the same thing with this set of updates they did in the main one. It is all one agglomeration of whatever number of security updates they decide to put in it.
Group C (AKA W): Shut down WU permanently and never again accept a Windows Update. This group feels that the risk of MS changing their machine in unacceptable ways or even bricking it is greater than the risk of a hacker breaking in because some security patch was not installed. I suspect that most people who even think about this topic will opt for this. However since most people think of their computer like a potato peeler, they will not even think about this and things will just happen without them even knowing. They will be Group A and won't even know it.
I am in Group W and would like to be in Group B. It depends on whether I can find a satisfactory way for my 150 or so client machines to be updated. They are average Joes and Janes.
Note that this may not apply to NON-Windows updates such as Office. I am not sure how you can be in group B or W and do this, but I am working on it.
UPDATE November 19, 2016:
It now appears that B is an impractical strategy for 99% of users. And, here is the reason why: When an error is made in a security-only update, if the error turns out not to have a security affect, it may be corrected in a non-security update. In that case if you were following B strategy, you would be left with an un-corrected defective update installed on your computer. If you were extremely diligent and knew about it, you may be able to get the correction in specific cases. This would entail an extreme amount of diligence that few would be willing or able to provide.
The new rollup style of updates that Microsoft is now providing to what we would call Group A, which include all kinds of updates (security and non-security), are cumulative. That means if you miss a month or even more, it will not matter because by installing the latest month's rollup, you would be up to date.
NOTE well, that Security-only updates are NOT cumulative. Which means if you miss a month, you may never get the missed updates.
So one strategy that you may wish to consider is following Group C, but still updating .net and Microsoft Office through Windows Update, but installing no Windows updates at all. It would be advisable in this case that you stop using Internet Explorer because you would not be getting those updates, but instead use an alternative browser.
Then, after following this strategy for some time, if things take a turn for the worse, and you decide you made the wrong choice (Group C with .net an Office updates), you can easily shift to A by simply using the latest offered Rollup offered in Windows Update.
So, as things have evolved, it looks like the vast majority have really only two choices: A as described above or C (modified as described above). The good news is that if you follow the modified C strategy, you have a way back to the Microsoft way, that is easy to implement.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
In addition, I refuse all "security quality rollups", except for .net.
CT -- By ".net", do you mean .NET Framework? Just want to be sure I'm not missing anything.
Thanks ElderN, funny cartoon.
But my desktop is a Dell dual-xeon box from 2003. Still great except for WinUpdate problems.
S
This is based on the fact that Microsoft stopped all development work on Windows 7 Dec 31, 2014. I therefore presume that any NON-security update is not for the improvement of Windows 7, but for some other purpose. I believe that purpose to be that of installing telemetry tracking software and preparing the system to be "upgraded" to Windows 10.
...
My thinking is further supported with the idea that Windows 7 is a 9 year old OS and likely had most security bugs taken care of AND the observation that 18% of PCs accessing the Internet today are using XP which has not had an update in more than 2 1/2 years.
====================================================
You might be right, Canadian. This looks like it could work - but then the question is for how long. What we are really dealing with here is a software company gone rogue. Microsoft has simply gone rogue. For me, that's really the bottom line. They are doing things now that really get under my skin.
The last update from Microsoft I ran, which was labeled as "Required," lead to a pixelated spider running across my screen. I don't use my box to download tons of code. I don't use this box for anything other than two commercial grade client/server applications and MS Office.
Other than some Firefox browser plugins when are all reported as keenly coded and non-malicious, I simply don't put this machine in constant harms way by downloading everything in sight. I always run a clean box. That spider got my attention and now the inability to shut down after yet another Microsoft "Required" update, pretty much was the straw the broke the camel's back.
Between Dell, Gateway and Microsoft, I have no more hair left. The quality has been Ford-like, teetering on the brink of being Chrysler-like. I think it is time for a Toyota, or a Volvo type computing experience in my world. I don't know if I will ever reach that high with Apple and the Mac, but I'm going to give it a shot.
This is what happens with innovation is stifled. Competition is weakened, diversity is limited and when the problems come, they hit harder than necessary. I lost a week's worth of work. That means a weeks worth of revenue potential gone. I could invest in another "PC" but I'd only be stacking tolerances and making matters worse.
I've gotten a lot done in the PC world, but at the expense of enormous frustration over the years. I worked in technology. I cut my tech teeth at Oracle, back when they were only a $2 billion company. I know Enterprise Software and I've seen the headaches that Microsoft has caused untold numbers of corporations and business models out there. The massive headache that Microsoft has issued in this world has been enormous and I've witnessed it from the inside of Fortune 100 and Global 1000 types of entities.
I'm just done. I've had it. I can't take anymore. If I go through a catastrophic loss like this one more time, I'm going to find the nearest bridge and jump. I can't do this anymore. I'm tired. I'm exhausted on Microsoft.
Around here, we call our ISP Comcrap. The company name is Comcast. Microcrap seems to work for me at this point. It think they are approaching Comcast levels of absurdity.
Maybe it is time for me to give the Mac a fair shot. I've been Mac biased and against it for real business use for years. I've always had a prejudice against Macs for getting real work done for eons. Times have changed and maybe I need to change with them.
I'm told that Macs are not what they used to be 25 years ago. I had the first Tandy TRS-80 Model Computer. That was the first mass produced "PC" for home use by Tandy and I learned BASIC on that tiny little box. I'm no novice user. So, when someone like me has to pull their hair out just to get their machine to shut down, or just to get it "updated" with patches, that's a big problem for the company that is supposed to be providing the solution.
It is a shame that when I think of Microsoft, I now think of companies like Ford, GM and Chrysler. Once upon time, they were dragon slayers - the best of the best. Once upon a time, Microsoft gave a damn. I don't think they give a damn anymore.
I just think it is time for a Toyota 4Runner Limited. It may be old school, but it works like a horse and it climbs over anything. I hope that is what I get with a Mac.
This is probably a dumb question but does it matter what browser we are using when we are still using Windows 7? I mean the two are connected? lol Ok, I'm naive.
Yes, it does matter.
Your browser is the very "window" (no pun intended) some sites use to track your browsing patterns. They can know where you have been, what you have seen and what you have downloaded. They can know what you clicked on, how much time you spent after you clicked and what site you visited when you left. Your browser does a lot to help make this a reality and so does your OS. Of course, your ISP "knows all" so to speak when it comes to your browsing habits and patterns.
Both "A" and "B" above are tedious to have to do each time you boot-up and browse. However, in lieu of local DNS changes and if you can afford it, simply do all your browsing through a VPS or VPN connection using a solid remote desktop connection to the Hosted box. You'd still want to use Ghostery, AdBlock Plus and Self Destructing Cookies on the remote instance of Firefox. In fact, you could even use the Geolocator Add-On for Firefox to specify a truer location WHEN using a VPS or VPN.
Yes. How you browse the web and what you use to browse with can/might matter.
Taco, may I suggest a strategy I have been using for more than a year now with no problems:
After the W7 SP1 install, running WU, you are offered around 200 updates. I accept all updates that are NOT Windows except for the Malicious software removal tool (which now carries telemetry). I then conditionally accept updates listed as recommended but not labeled specifically security. If the issue date of the Windows Update that is Recommended, but not Security is before January 1, 2015, I accept it. If after, I hide the update. I accept NO optional updates.
This is based on the fact that Microsoft stopped all development work on Windows 7 Dec 31, 2014. I therefore presume that any NON-security update is not for the improvement of Windows 7, but for some other purpose. I believe that purpose to be that of installing telemetry tracking software and preparing the system to be "upgraded" to Windows 10.
In addition, I refuse all "security quality rollups", except for .net.
My strategy is based on the idea that I feel it is much more likely my system will be turned into a sort of junior Windows 10 machine pumping private information to Microsoft servers, than the risk that a hacker could break into my system because I had not applied a patch.
My thinking is further supported with the idea that Windows 7 is a 9 year old OS and likely had most security bugs taken care of AND the observation that 18% of PCs accessing the Internet today are using XP which has not had an update in more than 2 1/2 years.
Consequently, I have not seen a single problem on any of my 150 client computers since I began this strategy. We have no Windows Update problems.