Windows Update - How will it change your system?

Anonymous
2016-10-14T16:11:13+00:00

You need to make a decision about where you want to be with your system.

My advice is to change the Windows Update (WU) setting to never.

It really depends on where you want to be with your Windows 7 system.

Woody Leonhard has described the situation something like this.  Note, I am using my own words here and describing it from my own perspective:

http://www.infoworld.com/article/3128983/microsoft-windows/how-to-prepare-for-the-windows-781-patchocalypse.html

Group A:  Roll over and just let MS install what ever they wish on your computer and just don't worry about privacy and the spyware they will install.  With this option you leave WU as Delayed start, and set the WU setting at Recommended.  This is the easy way and requires no effort or concentration.  You just let happen what will.  This is essentially what you have with a Windows 10 system.

Group B:  Refuse to accept any updates except Security ones.  In that case you follow my initial recommendation and leave WU set at Never.  You get the Security only updates from the "catalog".   There is risk here in B.  You are trusting that MS will not put anything in that group that does things you do not want done. A sort of level of trust in MS that I am not sure they deserve.   Keep in mind that they have done the same thing with this set of updates they did in the main one.  It is all one agglomeration of whatever number of security updates they decide to put in it. 

Group C (AKA W): Shut down WU permanently and never again accept a Windows Update.  This group feels that the risk of MS changing their machine in unacceptable ways or even bricking it is greater than the risk of a hacker breaking in because some security patch was not installed.   I suspect that most people who even think about this topic will opt for this.  However since most people think of their computer like a potato peeler, they will not even think about this and things will just happen without them even knowing.  They will be Group A and won't even know it.

I am in Group W and would like to be in Group B.   It depends on whether I can find a satisfactory way for my 150 or so client machines to be updated.  They are average Joes and Janes.

Note that this may not apply to NON-Windows updates such as Office.  I am not sure how you can be in group B or W and do this, but I am working on it.

UPDATE November 19, 2016:

It now appears that B is an impractical strategy for 99% of users.  And, here is the reason why:  When an error is made in a security-only update, if the error turns out not to have a security affect, it may be corrected in a non-security update.  In that case if you were following B strategy, you would be left with an un-corrected defective update installed on your computer.  If you were extremely diligent and knew about it, you may be able to get the correction in specific cases.  This would entail an extreme amount of diligence that few would be willing or able to provide.

The new rollup style of updates that Microsoft is now providing to what we would call Group A, which include all kinds of updates (security and non-security), are cumulative.  That means if you miss a month or even more, it will not matter because by installing the latest month's rollup, you would be up to date.

NOTE well, that Security-only updates are NOT cumulative.  Which means if you miss a month, you may never get the missed updates.

So one strategy that you may wish to consider is following Group C, but still updating .net and Microsoft Office through Windows Update, but installing no Windows updates at all.  It would be advisable in this case that you stop using Internet Explorer because you would not be getting those updates, but instead use an alternative browser.

Then, after following this strategy for some time, if things take a turn for the worse, and you decide you made the wrong choice (Group C with .net an Office updates), you can easily shift to A by simply using the latest offered Rollup offered in Windows Update.

So, as things have evolved, it looks like the vast majority have really only two choices:  A as described above or C (modified as described above).  The good news is that if you follow the modified C strategy, you have a way back to the Microsoft way, that is easy to implement.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

247 answers

Sort by: Oldest
  1. Anonymous
    2016-10-15T15:37:45+00:00

    Just to clarify... My original post is here:

    http://www.infoworld.com/article/3128983/microsoft-windows/how-to-prepare-for-the-windows-781-patchocalypse.html

    I don't have Canadian Tech's responsibility for 150+ machines. I'm just a "Dummies" kind of guy, posting on AskWoody.com 

    And we who are "Dummies" appreciate it!  We really do want to learn more about this contraption, no matter what super-tech people (who already know about it) think.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-10-16T06:13:48+00:00

    For people who go with Windows 10 and want to lock it down tight to prevent all the spyware and telemetry, what resources are out there that would show us what all to disable? I'm sure everything is enabled by default and disabling this and that would probably take lifetime to accomplish. Of course, we still have the same problem with the WU situation.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-10-16T09:01:54+00:00

    For people who go with Windows 10 and want to lock it down tight to prevent all the spyware and telemetry, what resources are out there that would show us what all to disable? I'm sure everything is enabled by default and disabling this and that would probably take lifetime to accomplish. Of course, we still have the same problem with the WU situation.

    Try Spybot’s Anti-Beacon for Windows. Anti-Beacon is specifically designed to block Microsoft’s telemetry gathering, which puts it in a different category from the application-level privacy settings. While it’s far from the only tool in use to lock down Windows 7 thru 10, it’s one of the few produced by a known software house (Spybot is also responsible for Spybot Search and Destroy). I recommend giving it a look if you want to further control what Windows does and doesn’t share about you in the future. Be advised that if you choose to block Bing URLs, you won’t be able to access the search engine at all (the option to block Bing is in the “Optional” tab.) I have used it and it is simple, straight forward and easy to enable/disable individual settings.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-10-16T11:45:14+00:00

    I installed the Spybot Anti-Beacon to see what it does comparing a before and after of registry settings and some other things.

    Note that SAB was designed for Windows 10 but runs on 7 and does about what I expected.

    All the things SAB does you can just do yourself.

    SAB adds some Windows 10 Policyy adjustments that will have no effect on Windows 7 because those Policies do not exist in 7 but adding a few registry entries for Policies that Windows 7 doesn't know about isn't going to hurt anything.

    SAB disables the known data collection Scheduled Tasks but some of those (not all) may already be disabled if you opt out of CEIP.

    SAB blocks a bunch of Microsoft telemetry IP addresses using the Windows Hosts file.  This doesn't hurt anything if those sites don't even exist (some don't even ping).  SAB inserts a comment that they are for Windows 10 but including them on Windows 7 shouldn't and doesn't seem to hurt anything.

    After some poking around I see some other adjustments involving a couple Services.  SAB will optionally disable Remote Registry but not another Service I read about called Diagnostic Tracking Service.

    For example right away this looks like it should be disabled and is mentioned in other places on the Internet:

    There is also one additional Policy that SAB doesn't disable but could.  It may not matter if the rest of the stuff is turned off or disabled but why not disable it too.

    SAB disables Policies for Office but none of that may be necessary if all the little collection engines are turned off.

    Some adjustments may be redundant if turning off one thing disables other things but why not just go ahead and disable everything you can find.

    That got me to wondering what is the "issue" with the Windows 7 updates...

    Can somebody define "the issue"?

    Can somebody define "the situation"?

    Is it that we are looking for a way to totally (or as totally as we can understand) disable all of data collection and telemetry parts of Windows 7?

    If that is the case I am thinking of putting together in one place information that I have gathered from Woody, Spybot, and other places so that one can just follow the process all at once or a little at time.

    There are also KBs to uninstall, but most of us have probably already done that.

    There are some Policy setting adjustments to enable (to turn things off).

    There are Scheduled Tasks to disable but they (but not all) may already be disabled if you opted out of CEIP.

    There are some Services to disable.

    The trouble is even if you do all this stuff how will you be able to tell if it is working or not?  There doesn't seem to be an activity log to see when/how this data collection takes place so there still could be that something we don't know about has been missed.

    Since there is no Policy editor on some versions of Windows - a registry import will add/adjust the missing policies.

    I've did all this three days ago with no ill effects and the adjustments are trivial and make sense but who knows if have I gotten them all and how can I be sure I didn't miss anything?

    Everything I have done can be undone too if some problem comes up later.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-10-16T15:43:09+00:00

    Thank you ElderN.  That is great work.  I have just installed Spybot Anti-beacon myself on a test machine.  It is simple to install.  My concern is will it cause other problems?   I would like to consider installing this on all of my clients' computers.  I am really looking forward to gathering more information on this product.

    Questions:

    • Do you need to keep it installed, or does just the act of installing it make all these changes (they call it immunize)  and then you don't need SAB any longer?
    • There is a "portable" version that does something different and I'd like to understand that better.

    Was this answer helpful?

    0 comments No comments