28 ms·
Windows Update vs. My Router
- mjevans 4y agoHow about: 1) have a more robust update service with a clear point of connection. 2) more transparent, human readable, error messages. (This is the issue in step X, cannot connect to (location); check your firewall.)
- lazypenguin 4y agoYeah tons of pain would be saved with more transparent systems. If the poster knew WHY it was failing they wouldn’t have to guess.
- deleted 4y ago[deleted]
- notRobot 4y agoMan I love nerd blogging culture.
- blahgeek 4y agoI’m currently using a tplink wireless router running as AP mode (since I have another Linux box as the home gateway), but it would filter out all ipv6 router advertisement packets which entirely breaks ipv6 stateless configuration. Before this, I was using another netgear router that would randomly drop ICMP pings. The packed “features” in nowadays home routers really annoys me. I wish there’s some cheap “dumb wireless AP” products that does nothing other than switching packets.
- dsr_ 4y agoMost TP-Link wifi routers can run OpenWRT. That would solve your problem.
- Dylan16807 4y agoIs that still true? I got one semi-recently and there was no way to change the firmware. And the previous one required some trickery. Edit: I think DD-WRT won't get support for newer broadcom devices, and OpenWrt has no meaningful support for broadcom at all? On top of some issues with firmware locks from TP-link directly.
- dsr_ 4y agoHere's the list of 234 TP-Link models supported by OpenWRT: https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=tp-link https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=tp-link Maybe they made 300 models, or 500? I don't know. I have three in my house, all of which have 2.4 and 5GHz radios working in OpenWRT, connected by gig-e backhauls.
- Dylan16807 4y ago> Here's the list of 234 TP-Link models supported by OpenWRT How many of them have wifi 6 or later, though? I can't figure out how to use this site very well but I found https://openwrt.org/toh/views/toh_available_16128_ax-wifi https://openwrt.org/toh/views/toh_available_16128_ax-wifi and that only has one non-router device from TP-Link.
- gruez 4y ago>I wish there’s some cheap “dumb wireless AP” products that does nothing other than switching packets. Have you tried unifi? Their pricepoint is about the same as a mid range wireless router.
- Shared404 4y agoI've got an optiplex box running OpenBSD thats gonna get a PCI wireless card thrown in it when I get around to it. Doesn't get much dumber[0] or cheaper than that, assuming you buy the optiplex used. [0] Not actually dumb, but entirely controlled.
- wolrah 4y ago> I've got an optiplex box running OpenBSD thats gonna get a PCI wireless card thrown in it when I get around to it. Have you actually looked in to this path? 802.11ac support is basically brand new in OpenBSD and the drivers that support it don't support HostAP mode. In general the state of WiFi support across the BSD multiverse is pretty poor. I've wanted to be able to use pfSense/OpnSense boxes as all-in-one devices for years but it's always been so bad that it's better to just use a dedicated Linux device as the WAP.
- Shared404 4y agoI followed https://www.openbsd.org/faq/pf/example1.html https://www.openbsd.org/faq/pf/example1.html (Router guide) and did successfully build out a working box - except for a faulty wireless card. That card was old (and didn't support ac anyways), but I had it on hand so figured I'd try it. I've been too busy recently to properly research purchasing a new wireless card for this thing so far, though from what you've said I may wind up having to do something else. Maybe Alpine on this box, or a dedicated wireless AP.
- wolrah 4y agoI'm not saying it can't work, in fact up to 802.11n apparently works perfectly fine with the right hardware, but it's 2022 and 802.11ac is now "the past" with 802.11ax/WiFi6 as the current standard. As far as I'm aware none of the BSDs have any support for 802.11ax. If you want to build a BSD box that can also do wireless and don't really care about performance there's nothing wrong with that, but if your goal is something that functionally compares to retail hardware you're going to want to stick to Linux.
- throwaway742 4y agoI like TP-Link's Omada line of APs.
- ArchOversight 4y ago> I wish there’s some cheap “dumb wireless AP” products that does nothing other than switching packets. I don't know how cheap you are talking about... but TP-Link has their Omada line-up of devices, including WiFi 6 AP's that are just that, access points. No router, no filtering, just SSID's and ability to drop traffic onto various VLAN's (with radius for auth if you want). They are fantastic. They are rock solid and since they don't do anything but be an AP they are never rebooted or run out of memory for state tracking and the like.
- 3np 4y agoGL.iNet Cirrus (GL-AP1300). Runs forked OpenWRT out of the box but you can flash it with a clean upstream as well. (Some other of their devices have issues when running vanilla OpenWRT - this particular model seems fine so far) If you want even more "dumb" and DIY you could look at something like a PCEngines APU or similar, but it sounds like you want to spend less time and effort on your APs, not more. I am surprised about everyone recommending TP-Link. They used to be decent but I have recently helped people set up some of their more recent models and they're atrocious- especially but not only Deco. All kinds of issues and weird behavior (I recall one with dozens of pages over multiple years in their support forum, with no fix in sight) In particular, across the range they go more towards "intelligent"/"smart"/cloud+app for management, which is the opposite of what parent is asking for. TP-Link is one of the worst offenders here - going the Ubiquiti direction but poorly executed. Any OpenWRT/DD-WRT/Linux compatibility is accidental. Ubiquiti Unifi AC Pro is also nice on its own. IIRC it works without using any of their software and can be managed through web. I guess it may not classify as cheap, though.I don't have any experience with their AP Lite,maybe it's worth a look as well?
- nicolaslem 4y ago> I’m currently using a tplink wireless router running as AP mode This is the problem right there. Don't buy consumer network equipment. It is tempting because it is cheap but I personally always end up regretting it. Spend a bit more for the entry-level business line and keep your sanity. TP-link actually has a pretty decent line of small business switches and APs.
- hhh 4y agoI don’t understand why this person is using network controls to deny access to Microsoft services. There’s plenty of reason to allow Windows update to download outside of some corporate VPN (especially for remote users, why use bandwidth over the VPN?) when you control which updates are installed via WSUS. I by no means mean any ill will to the author, and appreciate the post, but I do feel critical of the approach. I would have to understand the why more than is apparent in this blogpost to sympathize. Especially when this configuration is for another person as mentioned at the top. Are they aware of all rules being applied? This sounds like a home environment, which to me signals that these rules would have also killed updates for personal devices, potentially leaving them vulnerable. If you truly need control over Windows Update like this, you should be using the controls exposed to you (WSUS, group policy, etc.) If it’s a choice that the end user has made, acknowledging that domains used by Windows are being blocked by a firewall and this may cause erratic or nonfunctioning behavior for Windows I see no problem. It is likely my own experiences and opinions, but I personally believe this is using the wrong tool for the job, using a sledgehammer to drive a screw. I’ve had to deal with things like this at my work, with firewall rules being completely invisible to end users, and it just costs money and causes frustration at something that can be completely transparent and easy to access.
- sjtindell 4y agoHonestly it feels a little like blog posts I read titled “X software is full of bugs” and then the first line is “so I installed X on my custom Arch Linux setup…”. Sure, not ideal, but the conclusion might not quite match the playing field.
- shkkmo 4y ago> I don’t understand why this person is using network controls to deny access to Microsoft services. The person who wrote the article, wrote it about trying to get windows updates working. >> in this case, I was trying to restore Windows Updates.
- 3np 4y agoAnd the conclusion was to remove the block they had previously put there.
- RajT88 4y agoWhile it is not as discoverable as it should be, it is documented: https://docs.microsoft.com/en-us/windows/deployment/update/windows-update-troubleshooting https://docs.microsoft.com/en-us/windows/deployment/update/w...
- josephcsible 4y ago> Kids can not bypass family-friendly DNS servers by hard coding other DNS servers into their computing devices. The router rules :-) Remember, if you can do this to your kids at network level, then your ISP or government can do it to you at network level too.
- belltaco 4y agoI'm confused. Who put those domains used by Windows Update in the router DNS blocklist? Is it the author since he said he configured it? If so, why is he blaming the user's employer company for it? And did he put them in to block Windows updates on purpose like he said he wanted to at the end? Wouldn't that block Windows Updates on all computers at home for that user? Why would a large company want to route what could be gigabytes of Windows updates per computer through the corporate VPN for 100K+ employees thereby slowing down the corporate VPN introduce lag into remote desktop connections and VOIP calls/screenshares, and potentially paying a lot more in bandwidth fees?
- RajT88 4y agoWindows updates (some? Not all?) come down over port 80. That rubs security folks the wrong way. There is extra validation (chiefly, digital signatures) which protect against MITM attacks, but some still think the bandwidth is worth the risk mitigation.
- belltaco 4y agoIt changed recently I think https://www.onmsft.com/news/microsoft-update-catalog-uses-https https://www.onmsft.com/news/microsoft-update-catalog-uses-ht...
- RajT88 4y agoAh, did not realize! A year back I was exposed to a white paper under NDA explaining the security posture. Also, the PM's had mentioned changes were underway. Normally it is not under my purview, hence why I did not realize the recent change.
- deleted 4y ago[deleted]
- willcipriano 4y agoI can see why "watson.telemetry.microsoft.com" was added. Id block that too if I saw it on my network.
- mr_toad 4y ago> Not forcing microsoft.com and windowsupdate.com to use the corporate VPN sure seems like an oversight to me. I imagine that some enterprises don’t want or need to have that data traversing their VPNs, it’s not sensitive data and their networks are probably busy enough with back to back teams calls.
- pixel16 4y agoFYI windows update for business is now a thing And it uses direct public access to microsofts cdn to push updates set via polices in intune or memcm. It could be the case here and it's usually used by msft customers to avoid clogging vpn with patching bandwidth Source: Msft employee https://docs.microsoft.com/en-us/windows/deployment/update/waas-manage-updates-wufb https://docs.microsoft.com/en-us/windows/deployment/update/w...
- svnpenn 4y agoI disabled Windows Updates two years ago, right after I installed Windows 10. Never gonna turn them on. Fuck you Microsoft. Read too many horror stories. Not updating. Dont ask me. https://github.com/WereDev/Wu10Man https://github.com/WereDev/Wu10Man
- josephcsible 4y agoIf you don't trust Windows Update, then you shouldn't run Windows at all, because Windows without updates is full of major security holes.
- svnpenn 4y agoIn my opinion, Windows Update is essentially malware. Ive been running without updates for years, even since Windows 7. Works fine.
- josephcsible 4y agoIt works fine in the same way that a car with no seat belts and air bags does.
- exodust 4y agoReminds me of the pro-vaccine memes likening vaccines to seat belts. An incompatible, overly-simplified emotive analogy for both vaccines and windows updates. It's almost like you believe your world to be threatening and dangerous without Microsoft's software rules to keep you safe.
- 0xcoffee 4y agoIt is because there is decades of history of unpatched devices being used as vectors for ddos, entrypoints for horizontal movements inside a secure networks etc. If you pay attention to the Ukrainian conflict, you will see that the cyber-warfare is going strong (especially in the energy sector), and the internet is indeed a 'threatening' place. Just because you don't consider yourself an interesting target doesn't mean you won't be compromised. Yes it's unfortunate that MS packages both bug fixes and 'features' in their update process. But as other comments have said, it is better then to migrate away from Windows to another OS which you can keep up to date. There are many layers to a good defense, but for a regular consumer, simply keeping devices up to date is a low effort way of reducing attack surface area. I wouldn't run any unpatched device with internet access, be it windows, linux, anything. I recommend the book "This Is How They Tell Me the World Ends: The Cyberweapons" for a non-technical but interesting read about this topic.
- collsni 4y agoUhh why would a large corp spend the money on windows update bandwidth when they could just split the traffic? Not sure about this article. Issue was on the enduser.
- peppermint_tea 4y agoto control the releases of patches with a windows server update services (wsus) so the you can test the patches and make sure it does not break user network connectivity https://arstechnica.com/information-technology/2016/12/microsoft-windows-10-dhcp-broken-update/ https://arstechnica.com/information-technology/2016/12/micro... but yeah, I agree from the bandwidth perspective
- 3np 4y ago> This time I looked at Web Blocking, the blocking of domains accessed with HTTP and HTTPS. Anyone knows how this works, especially for HTTPS? I imagine it doesn't MiTM TLS so SNI..? > The disadvantage of DNS is that it blocks one computer at a time. It can not block facebook.com the way Web Blocking does. With DNS you have to block abc.facebook.com and def.facebook.com and anything.you.want.facebook.com individually. This isn't true. You can block domains with arbitrary rules - what you're looking for here is easy enough in any DNS server I ever worked with. Maybe there is such a limitation with this particular interface but that distinction should be clear.
- jve 4y agoYeah, not sure how this would work over HTTPS without proxy or rogue cert. With proxy, you can use HTTP CONNECT proxy : computer provides domain (SNI) and proxy can make allow/deny decision. If allowed, establishes a blind tunnel where packets flow without further inspection.
- Thorrez 4y agoSNI has nothing to do with proxies. Essentially all HTTPS connections provide SNI, regardless of whether there's a proxy or not. A MITM can sniff the SNI. There's a draft standard to encrypt the SNI. I don't think it's been widely adopted.
- Anunayj 4y agoSNI is part of the Client Hello part of TLS, (it's needed so the server can decide the appropriate SSL certificate to reply with), and since this happens at start of TLS handshake, it's transmitted in plaintext. Many Firewalls (and even my ISP), terminates the connection here if the domain is the blocklist. Since it's part of SSL negotiation, and unrelated to the actual HTTP query, in some cases you can find another (non blocked site) on the same server, send that SNI for TLS handshake, and then do the http request on the correct host to bypass stuff like this. (This technique is called domain fronting [1]). Unfortunately big CDNs like Cloudflare stopped allowing this because it's non-standard. There is a proposal for Encrypted Client Hello (and therefore Encrypted SNI) being worked on right now: draft-ietf-tls-esni-14 [2], till then using VPN/Web proxies are the only effective way of getting around these restrictions. [1] https://en.wikipedia.org/wiki/Domain_fronting https://en.wikipedia.org/wiki/Domain_fronting [2] https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ https://datatracker.ietf.org/doc/draft-ietf-tls-esni/
- Terry_Roll 4y agoIf the functionality doesnt exist, the code doesnt exist, so you have to write it yourself.
- elktea 4y agoWhy would you put yourself through this
- ukoki 4y ago> The advantage is that the blocking is total. Web Blocking only blocks HTTP and HTTPS. DNS blocks all protocols. eh, DNS is an address lookup service. It doesn't block anything. 1. Install any of the many "virtual hosts file" addons in Chrome/Firefox. (or simply edit /etc/hosts if you're on Unix) 2. Use one of the many online dig GUIs to find the the IP address for, say, blockedsite.com (eg https://toolbox.googleapps.com/apps/dig/ https://toolbox.googleapps.com/apps/dig/) 3. Access blockedsite.com in the browser without any DNS lookups
- Anunayj 4y agoeven better use DNS over HTTPS/TLS.
- dadarecit 4y agoTldr prod.do.dsp.mp.microsoft.com settings-win.data.microsoft.com sls.update.microsoft.com watson.telemetry.microsoft.com ctldl.windowsupdate.com These five domains/subdomains can block Windows Update