Microsoft Provides Details On "Silent" Update

Nate Clinton a program manager for Windows Update has posted the details on the "Silent" update from Windows Update that had been reported this week.  The bottom line is that Windows Update does perform a silent update in the event it it needs to update itself. Which makes sense.  The reasoning is that they must update Windows Update itself periodically to ensure it operates reliably. Why is it updated if they have opted to not install without notfication? The logic there is that if someone opt back into the service they should actually be able to use it. Which is a good thing, right? I applaud them for the disclosure, but here is what I think still needs to happen:

1.) No silent updates - If there is a need to update the Windows Update service use the Windows update engine and display the usual balloon notifications, etc. unless they ahve chosen a full silent install for all updates. Allowing silent updates will only breed paranoia and can lead to nothing but bad publicity.

2.) Public disclosure before any updates - Post a press release or security bulletin as well as make available an opt in email notification system for home users that will notify anyone prior to any update to the Windows Update service.

3.) Define the exact files that are involved in an update and make it publicly available. Not sure if this is already there but if this hasn't been done use Windows Service hardening to specify only the above files can be touched via the service.

(edited for innacuracies..my bad)

What do you think? Any more you can think of?


Posted Sep 13 2007, 06:39 PM by Josh Phillips

Follow Me on Twitter

Did you enjoy this article? If yes, then subscribe to our RSS 2.0 feed or

Comments

JoeM wrote re: Microsoft Provides Details On "Silent" Update
on 09-13-2007 7:36 PM

I personally think this is fine, as long as it does not update the system or other updates without my permission.

Josh Phillips wrote re: Microsoft Provides Details On "Silent" Update
on 09-13-2007 8:10 PM

I think its ok, if you have opted into a silent install, as long as there is discolure.  The major problem i see is the people who ask to be notificed of upates before insalling them aren't given any notfictaion of updates.  I am sure none of them were properly warned that microsoft still could update their systesm without their knowledge.  I think they also need to publisize updates becaue I want to know when to expect it so i don't  get all worked up thinking some virus is trying to exploit the update service.

JoeM wrote re: Microsoft Provides Details On "Silent" Update
on 09-14-2007 7:33 AM

I agree, then why don't people get all upset about google and Apple software, which do the same thing but force everything on the user.

Maybe MSFT could be a comment in the change settings, in the Windows update,  that "Windows/Microsoft update will auto update itself and does not download any updates for the OS unless the user specifies"

Josh Phillips wrote re: Microsoft Provides Details On "Silent" Update
on 09-14-2007 7:51 AM

I am sure they will think of some disclosure method, but they may have already lost a bunch of goodwill and now people might be disabling autoupdates altogether out of paranoia.

balloon » Microsoft Provides Details On "Silent" Update wrote balloon » Microsoft Provides Details On "Silent" Update
on 11-15-2007 5:31 AM

Pingback from  balloon » Microsoft Provides Details On "Silent" Update

Windows is a registered trademark of Microsoft Corporation.
Powered by Community Server (Non-Commercial Edition), by Telligent Systems Themed By nb development