I have a bit of a rant I need to get off my chest. Here's a little Op/Ed on my opinion of Microsoft's Update Philosophy.
The guys and gals over in Redmond have been busy little beavers for the last few weeks. It has apparently been confirmed that Microsoft has been "stealth patching" some NT based computers without the knowledge or consent of the user (this includes computers with XP and Vista on them) even if the user asked to be notified of updates. Basically, Microsoft has been placing software components on user systems (yours likely included) remotely and secretly (ok - "not very transparently") - regardless of whether you want the update or not.
Reporting from WindowsSecrets.com
Reporting from ZDNet.com
Reporting from InformationWeek.com
Microsoft responded in a typical, no apology, highly detailed, without any real detail, manner, via Nate Clinton:
How Windows Update Keeps Itself Up To Date
An interesting quote from Microsoft's Nate Clinton really goes to the heart of Redmond philosophy:
"One question we have been asked is why do we update the client code for Windows Update automatically if the customer did not opt into automatically installing updates without further notice? The answer is simple: any user who chooses to use Windows Update either expected updates to be installed or to at least be notified that updates were available. Had we failed to update the service automatically, users would not have been able to successfully check for updates and, in turn, users would not have had updates installed automatically or received expected notifications. "
Actually Nate, if I choose "Check for updates but let me choose whether to download and install them," or "Never check for updates," I pretty much expect that my machine will, "Check for updates but let me choose whether to download and install them," or, "Never check for updates." I mean, it's pretty clear what I expect. Really Nate, you don't need a committee to figure out what I or any reasonable person expects. Don't turn your psychic powers on - just respect my choice.
Oh, and by the way Nate, what is the bug in this multi-million dollar system that would have caused it to stop functioning entirely had you folks not slipped code onto the hard drives of many the consumer? What could possibly be so wrong with the update system that it required Microsoft to do this? We can only speculate I guess. Possibly Microsoft was securing the system so that no one could install software components without the user's knowledge or consent.
That would be a nice security feature. You know, the ability to actually control who puts files on your machine would be pretty "neat."
Until Microsoft comes clean about exactly what they can and cannot do remotely to their OS's, the privacy of our data is suspect. Users can not be sure that MS doesn't have, at minimum, backdoor write access to their systems - actually, they CAN be sure that MS has that access - it was just used. And, if this access falls into the wrong hands, what then? Or, now seeing how MS's philosophy actually works, when will they decide to stealth install a little .exe that catalogs my system's contents and phones home with them under the rationalization that it's to "meet customer expectations" and better serve me?
"Of course, for enterprise customers who use Windows Server Update Services (WSUS) or Systems Management Server (SMS), all updating (including the WU client) is controlled by the network administrator, who has authority over the download and install experience."
That language may quell the minds of some system admins who are wondering if their Windows networks are vulnerable to backdoor file installation by Redmond (or anyone else), unfortunately it does not address the real question admins are possibly wondering about. That question is, "They didn't, but could they?"
Oh, and BTW Nate, I was under the impression that as the administrator of my machines and network, that I had "authority over the download and install experience." Thanks for clearing that up for me.
Some users (and I suspect Microsoft) might point out that Windows users agree to an EULA that is more of a "use agreement" than ownership and Microsoft is within their rights to behave this way. I might point out to MS that I actually own my hard drive and the placement of files on it is at my discretion, not theirs.
"Before closing, I would like to address another misconception that I have seen publically reported. WU (Ed: Windows Update) does not automatically update itself when Automatic Updates is turned off, this only happens when the customer is using WU to automatically install upgrades or to be notified of updates."
Right....Like I believe you now. But, that's beside the point. What part of "be notified of updates before installing them" is failing to get through? Just as I start trusting you guys enough to actually be notified and choose, rather than going to the MS site and cherry picking, you decide to go and not notify me and not allow me to choose. Nice.
Linux Anyone?
/rant
Ah...I feel much better now. Hmm....where did I put that Ubuntu disk?
Chris Adcock on 20 September, 2007
http://www.hardwarelogic.com/Staff-Blogs/285.html





