10 ms·
Microsoft disables Windows Update when Meltdown/Spectre registry key isn't set
- gtirloni 9y ago“Customers will not receive the January 2018 security updates (or any subsequent security updates) and will not be protected from security vulnerabilities unless their antivirus software vendor sets the following registry key” Another incentive to stop using questionable AV software (since this was implemented because they can't get their act together).
- sergers 9y agoat initial patch release, not even all the well known had the registry key setting in place.... so its not just about questionable AV software when big corps considered "safe" (debatable) didnt have "their act together" either. there was a list posted yesterday on compatibility that is continued to be updated: https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?sle=true#gid=0 https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLp...
- sambe 9y agoYou can’t just stop using AV software I’m told. The key is checked for everyone, including people with no AV. Contrary to the sensational headlines, it is implied to be a temporary measure. It’s not really clear whether you’d have to only do this manually once, or on every subsequent update.
- JdeBP 9y agoThe questions and answers in Microsoft's own doco imply once. * https://news.ycombinator.com/item?id=16076660 https://news.ycombinator.com/item?id=16076660
- sambe 9y agoThat makes sense to me, but then why the need for AV to repeatedly set the key?
- cube2222 9y agoIf you do it once, it may be that your AV isn't compatible with the patch and will cause your system to bluescreen and maybe not even turn on, so no, you really shouldn't do that.
- sambe 9y agoIf you have no AV, you can be pretty sure that’s not an issue.
- LeifCarrotson 9y agoNote that one of the antivirus software vendors that does this correctly is, in fact, Microsoft Defender. If you haven't installed dodgy third-party AV, you're fine.
- koolba 9y agoWhich third-party AV isn't dodgy?
- lucb1e 9y agoclamav Unfortunately I have no reason to use it, though. I don't even know whether it's any good. But at least I know it's not dodgy!
- bitwize 9y agoIn terms of catching viruses that are out there in the wild, ClamAV is the least good antivirus solution. But hey, open source and completely auditable!
- verall 9y agoClamav (clamWin) will happily false positive and quarantine all sorts of files on a windows box, occasionally including required system files. I've tried it on 3 different boxes at different times over the past ~5 years and the amount of false positives was insane every time. I don't think its ready to be run on Windows boxes unless you are a power user willing to manually verify ~100 files are not actually malware.
- Feniks 9y agoMalwarebytes? Not really an AV I guess.
- tedunangst 9y agoYou're not fine if you've disabled Windows Defender.
- craftyguy 9y agoNo, another incentive to stop using Windows. 3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates, and Microsoft should not be relying on 3rd party applications to determine whether or not their customers receive critical OS security updates (and of all things, hilariously defaulting to 'no')
- untog 9y agoIt isn't relying on it - MS recommends people use Defender, which works fine. But unfortunately not everyone is doing that.
- mark-r 9y agoIronically Defender was preventing me from receiving Windows updates, so I had to turn it off. I assume that means I'm in a catch-22.
- craftyguy 9y agoSeems like the EU and/or the FTC would want to talk to microsoft about microsoft requiring microsoft's AV to be installed before microsoft will update the OS.
- untog 9y agoBut they don't - third party AV software can update the registry key.
- Arnavion 9y ago>3rd party applications should NOT be responsible for insuring that the OS can receive critical security updates It is because these (misbehaved) 3rd party applications do things that cause the mitigations update to make computers unusable. >and of all things, hilariously defaulting to 'no' It does not default to "no" since the default is to run MSE / Defender.
- JadeNB 9y ago
- Feniks 9y agoThe bane of open software: users can install any trash they want to.
- petecox 9y agoPerhaps one advantage of the walled-garden of Windows S. No virus checker needed if every piece of software is vetted by an online repository and everything runs in its own sandbox
- josefx 9y agoMicrosoft could at least pop up a nag screen every 15 minutes to notify the user that their AV software is crap and needs to be removed. The average user wont know that their AV is actively keeping their OS unpatched.
- medlazik 9y agoSlightly OT if I may: Is there any reason to use anything else than Defender these days? Chrome+uBlock, good email security and update practices, Defender just in case, do we need more?
- 0xfeba 9y agoNo, not that I am aware of. 3rd party AV are liabilities at this point. https://www.pcworld.com/article/3020327/antivirus-software-could-make-your-company-more-vulnerable.html https://www.pcworld.com/article/3020327/antivirus-software-c...
- the8472 9y agoDefender can be seen as merely being the lesser evil. Consider CVE-2017-0290[0], which was caused by the MsMpEng process running a custom unsandboxed javascript interpreter with system privileges to evaluate untrusted code for maliciousness. Remotely exploitable over many unsolicited channels. Pretty much the worst kind of exploitability. Of course other AVs have done quite similar mistakes. [0] https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
- lima 9y agoNo, there isn't. Antivirus only protects against known threats anyway, and Windows Defender works fine for that.
- jdc0589 9y agonot the free consumer kind. Some business/enterprise stuff is useful (e.g. eset), but thats not helpful to the average consumer.
- godzillabrennus 9y agoYes, http://www.bromium.com http://www.bromium.com adds next level security to Windows environments.
- 9y ago
- hungerstrike 9y agoMy windows 10 machines will not receive the update automatically for some reason. I think it is because I had defender completely disabled via group policy since it interferes with some of my development activities surrounding node.JS. However I was able to install the security update manually from the Microsoft Windows update catalog download site. I did this after enabling defender briefly and updating it to ensure that the registry key was written.
- Avery3R 9y agoYou could have also just manually created the registry key
- inetknght 9y agoI'm real curious what kind of development you're doing with node.JS where Windows Defender causes trouble.
- Arnavion 9y agoThe real-time scanning slows down processes that access a large number of files, like code compiles in general and importing node modules in particular.
- inetknght 9y agoI haven't noticed Windows Defender causing significant slowdowns for processes which access lots of files except when it does a full system scan (which is not often). Even then, it's only barely noticeable.
- serf 9y agoI've disabled defender due to high CPU usage on machines that had to slice mpegs into jpegs with near constant work. The machine was slicing up 11 channels of 24fps videos into jpegs, so 264 jpegs/s at 720p and 24 bit color. I've had friends and coworkers that have hit the same CPU issues with big git repos and defender. It seems like Defender has problems with getting hit with tons of small files in quick succession, but really I know very little about it.
- discreditable 9y ago> The compatibility registry key exists for a reason. I know. I can also see it’s a messy hacky fix. But it needs an end of life date I couldn't agree more. As I've been devising a patching plan over the past few days I couldn't help but wonder "how long will I have to do this"? My hope is that in future OS releases (say, Windows Client/Server 1803) the mitigations will be default-on for clean installations (minimally).
- photon-torpedo 9y agoSo finally there's a way to disable updates on Windows 10... ;)
- kabdib 9y agoYeah, had me confused for a while. Easy to set with a group policy, though. Still, could have been better communicated.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- cube2222 9y agoI think at this time if you're on windows 10 you should really just use Defender. It works well, they are actively developing it, and the new white list based directory protection is kinda neat if you're scared of ransomware.
- zengid 9y agoDo I have to do anything if I'm just using Windows Defender?
- graystevens 9y agoNope, Windows Defender has already set the registry key, and you should be good to go. For the rest of you, there is a good public document[0] that is being regularly updated on the status of each of the AV products out there. [0]https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLpzAtckQxYiuirADzf3cL42FQ/htmlview?usp=sharing&sle=true https://docs.google.com/spreadsheets/d/184wcDt9I9TUNFFbsAVLp...
- Multicomp 9y agoDoes Microsoft Security Essentials fall under Windows Defender for the purposes of this article?
- mesofile 9y agoIt's worth noting that Windows Update may also fail to apply the Meltdown/Spectre patch if other conditions aren't met. Some are mentioned on the KB page [1] but they don't mention another common scenario, which is that if your system firmware is not ready to accept the update, Windows Update will not apply it, and _it won't tell you_ that it's not applying it -- it will simply say 'Your device is up to date'. I had to dig around to find a page [2] that had some useful instructions allowing me to find out what the actual status of my Windows install was. I'm grateful to the author of that page, they provided critical info that neither Microsoft nor my machine's manufacturer did. I wish I could say that it boggles my mind that they could be so hushmouthed on the subject of a vulnerability this severe. Of course, my OEM (Lenovo) has not released an update for my Windows laptop (Yoga 900) since 2016, and as of today their support page [3] on Meltdown/Spectre does not indicate that they plan to do so. I'm posting this partly in anger/despair, partly in the hope that I'm wrong and that someone will pop up to comment and tell me there's a fix. There is a Linux BIOS for this machine but it's old and I don't know if it will actually address this issue. [1] https://support.microsoft.com/en-us/help/4056892/windows-10-update-kb4056892 https://support.microsoft.com/en-us/help/4056892/windows-10-... [2] https://www.bleepingcomputer.com/news/security/list-of-meltdown-and-spectre-vulnerability-advisories-patches-and-updates/ https://www.bleepingcomputer.com/news/security/list-of-meltd... [3] https://support.lenovo.com/us/en/solutions/len-18282 https://support.lenovo.com/us/en/solutions/len-18282
- Arnavion 9y ago>It's worth noting that Windows Update may also fail to apply the Meltdown/Spectre patch if other conditions aren't met. >... if your system firmware is not ready to accept the update, Windows Update will not apply it, and _it won't tell you_ that it's not applying it -- it will simply say 'Your device is up to date'. The update enables mitigations for Meltdown regardless of firmware. You need updated firmware for updated CPU microcode to mitigate Spectre. >I had to dig around to find a page [2] that had some useful instructions allowing me to find out what the actual status of my Windows install was. All this is transparently revealed when you run `Get-SpeculationControlSettings`, which is mentioned in the update guidelines, eg https://support.microsoft.com/en-us/help/4073119/ https://support.microsoft.com/en-us/help/4073119/
- unstatusthequo 9y agoFinally a fix for forced reboots!
- B1FF_PSUVM 9y agoYou could still get the reboots without updates ... which is what I've been getting for a few weeks now on a cheap tablet: loads update, reboots in the night, update fails. Rinse, repeat. (I don't care, an update took down the sound last year. For all I know the next one will make the gizmo totally malfunction ... MS don't care for that cheapo segment either, the wanton demands for disk space are astounding, and they refuse to use their own exFat format on additional storage. Truly ready to ascend to Oracle level, they are.)
- Feniks 9y agoThrow Enterprise LTSB on old/low spec hardware. Thats my preferred Win10: stable, bloat free and it only gets the updates beta tested by the regular users.
- Piskvorrr 9y ago"Windows 10 LTSB is only available as part of Windows 10 Enterprise. And Windows 10 Enterprise is only available to an organization with a volume licensing agreement, or through a new $7 per month subscription program." Seriously? An OS of which you need an obscure, hard-to-get version, special messing around in power tools, and still might break randomly? This role reversal happening in the last 10 years is sad, really.
- j-c-m 9y agoAnother consequence of this is that windows will disable updates when you do not have any anti-virus software running as well.
- ENOTTY 9y agoWow using a hypervisor to inject below the kernel to avoid KPP is nuts. Never knew the AVs did that. What are they going to do when Microsoft begins to use Hyper-V to enforce CredGuard[1]? [1]: https://blogs.technet.microsoft.com/ash/2016/03/02/windows-10-device-guard-and-credential-guard-demystified/ https://blogs.technet.microsoft.com/ash/2016/03/02/windows-1...
- ENOTTY 9y agoTurns out nested virtualization is a thing. Jesus.