3 ms·
Although its not much of a hurdle (as MS provide the hurdle too) don't modern large scale MS-based IT systems still rely on a local controller to push updates?
by ErrantX 9y ago
Although its not much of a hurdle (as MS provide the hurdle too) don't modern large scale MS-based IT systems still rely on a local controller to push updates? This used to be the case with domain controllers a few years ago.
- danarmak 9y agoThey can if they want to. It's called WSUS - Windows Server Update Services. But all it amounts to is a glorified local mirror and central point for pushing updates. You still don't know what individual updates do, still can't cherrypick individual fixes out of monthly rollups, still can't install some update without installing they prerequisite updates. And, like you pointed out, you can't fully trust the WSUS software, which also talks to Microsoft to update itself. WSUS might delay or stop an attacker who takes over the MS distribution channel from publishing an update telling all target computers to shut themselves down right now. But a smarter attacker will distribute a time bomb as part of a legitimate update, that people will install for legitimate reasons, and that will be triggered after enough computers have installed it. The trigger may not even come via the Windows Update channel. And to quote, "there's another theory that states that this has already happened."