I have a question. I have 8 windows 7 computers (and counting), the majority of which I use either for homeschool or an English school program that I am trying to start in Mexico. My question is this: would it be better to let the computers which I do not use for personal things (email, banking, online purchases etc) get updates from Microsoft in order to have the security updates? I use Norton antivirus (perhaps there is something better? I like their child monitoring "norton family" though it sometimes fails) I was trying to follow B but I see that that is no longer a plausible option. I am the family "tech" but I don't have any real training, just hit and miss learning. I don't want to have these other computers updated to where my older programs fail to work. Does that mean that I should stick to group C and trust Norton to take care of the rest? I have installed the spybot, but only on this computer, where I do most of my personal online work. Thanks for any advice you can give, and for sharing these solution postings. You have helped me a great deal. Thanks!
Windows Update - How will it change your system?
You need to make a decision about where you want to be with your system.
My advice is to change the Windows Update (WU) setting to never.
It really depends on where you want to be with your Windows 7 system.
Woody Leonhard has described the situation something like this. Note, I am using my own words here and describing it from my own perspective:
Group A: Roll over and just let MS install what ever they wish on your computer and just don't worry about privacy and the spyware they will install. With this option you leave WU as Delayed start, and set the WU setting at Recommended. This is the easy way and requires no effort or concentration. You just let happen what will. This is essentially what you have with a Windows 10 system.
Group B: Refuse to accept any updates except Security ones. In that case you follow my initial recommendation and leave WU set at Never. You get the Security only updates from the "catalog". There is risk here in B. You are trusting that MS will not put anything in that group that does things you do not want done. A sort of level of trust in MS that I am not sure they deserve. Keep in mind that they have done the same thing with this set of updates they did in the main one. It is all one agglomeration of whatever number of security updates they decide to put in it.
Group C (AKA W): Shut down WU permanently and never again accept a Windows Update. This group feels that the risk of MS changing their machine in unacceptable ways or even bricking it is greater than the risk of a hacker breaking in because some security patch was not installed. I suspect that most people who even think about this topic will opt for this. However since most people think of their computer like a potato peeler, they will not even think about this and things will just happen without them even knowing. They will be Group A and won't even know it.
I am in Group W and would like to be in Group B. It depends on whether I can find a satisfactory way for my 150 or so client machines to be updated. They are average Joes and Janes.
Note that this may not apply to NON-Windows updates such as Office. I am not sure how you can be in group B or W and do this, but I am working on it.
UPDATE November 19, 2016:
It now appears that B is an impractical strategy for 99% of users. And, here is the reason why: When an error is made in a security-only update, if the error turns out not to have a security affect, it may be corrected in a non-security update. In that case if you were following B strategy, you would be left with an un-corrected defective update installed on your computer. If you were extremely diligent and knew about it, you may be able to get the correction in specific cases. This would entail an extreme amount of diligence that few would be willing or able to provide.
The new rollup style of updates that Microsoft is now providing to what we would call Group A, which include all kinds of updates (security and non-security), are cumulative. That means if you miss a month or even more, it will not matter because by installing the latest month's rollup, you would be up to date.
NOTE well, that Security-only updates are NOT cumulative. Which means if you miss a month, you may never get the missed updates.
So one strategy that you may wish to consider is following Group C, but still updating .net and Microsoft Office through Windows Update, but installing no Windows updates at all. It would be advisable in this case that you stop using Internet Explorer because you would not be getting those updates, but instead use an alternative browser.
Then, after following this strategy for some time, if things take a turn for the worse, and you decide you made the wrong choice (Group C with .net an Office updates), you can easily shift to A by simply using the latest offered Rollup offered in Windows Update.
So, as things have evolved, it looks like the vast majority have really only two choices: A as described above or C (modified as described above). The good news is that if you follow the modified C strategy, you have a way back to the Microsoft way, that is easy to implement.
Windows for home | Previous Windows versions | Windows update
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
247 answers
Sort by: Most helpful
-
Anonymous
2016-12-08T16:29:25+00:00 -
Anonymous
2016-12-08T15:59:45+00:00 Anti-Beacon may help. I am just trying it my self. I am troubled by the fact that is seems like beta software that has not been updated in a long time. Not sure Malwarebytes intends to follow through with this.
B is not practical for normal users. It is only practical for IT people who can dedicate a lot of time to staying up with it. It is very complicated because of the many errors made in updates and the fixing of them subsequently. My conclusion is that Microsoft will never make it possible for normal users to use this strategy.
Hence, I am in the C or W category, as describe in my posting. I have described the situation in some detail to my 150 client computer base and explained that I would support either A or C and asked them to make a decision. So far every single one who has made a choice, chose C. Only about 25% have chosen so far.
-
Anonymous
2016-12-08T13:05:04+00:00 Hi CT,
Thanks for all your input, very much appreciated.
Can I have your comments please on a modified A strategy: Allow automatic windows updates but install and run Spybot Anti-Beacon to disable all telemetry spyware.
First Question: Wouldn't this be a lot less hassle for an individual user like me, keeping the system updated AND secure (without the MS spyware issue) ?
Second Question: Regarding your November 19 Update on this thread: You were previously on a transition from C to B for all your users, but your latest update seems to suggest that B could bring trouble to your Win7 system. So are you moving back to C again?
-
Anonymous
2016-12-07T23:19:45+00:00 I believe Firefox is the best, but beware. There are a lot of add-ons that can prove troublesome. Chrome is intrusive too, but there are opt outs. You do not have to use Gmail to use Chrome or even have a Google sign in or ID.
If you do not update (C), then you do not get IE updates. If you use one of the others, you will get their updates through their individual channels.
Experts consider IE to be the most insecure of the lot and Firefox to be the most secure. You do have to keep IE working because it is actually part of Windows 7 and it may not operate correctly without it.
-
Anonymous
2016-12-07T22:58:10+00:00 No. I do not expect to stay off the Internet. I will however break my decades long love of IE for Chrome. Chrome will be updated constantly by Google.
I suspect that Windows 7, after 7 years is pretty much cleaned up. There may be bugs in the future which will prove to be unsafe, but I will take my chances with that because I think those chances are less likely than Microsoft making a mess of the PC that I know and love.
It is important to understand that Google Chrome and Firefox are applications. I can choose to use them or not. Windows in an OS which I have no real choice but to use.
Most of my clients will never buy another PC! Certainly not one based on Microsoft software. They instead will use other devices.
Only one far-fetched chance of this changing -- the failure of Windows 10 and likely the top guys at MS.
This is probably a dumb question but does it matter what browser we are using when we are still using Windows 7? I mean the two are connected? lol Ok, I'm naive.
(BTW, I have had so many issues with IE & Chrome so I really had no choice but to start using Firefox in the last year.) From what I've read Chrome is more invasive collecting private data as any browser.