Showing posts with label fix. Show all posts
Showing posts with label fix. Show all posts

Friday, October 14, 2016

Microsoft's flawed update strategy


Let's talk about updates.  Specifically, lets talk about updates in the context of Windows 10.

When Microsoft launched Windows 10 it was supposed to be the cure-all to the Woes of Windows.  It was to be everything to everybody regardless of your chosen device.  It would be the gateway to what you wanted to do instead of the sandbox (or litter box) for the things you HAD to do.

When it works it can be all that.  Unfortunately, it really isn't.

I've listened to the pundits and Microsoft apologists for over a year now.  How they go on touting its merits while in the same breath decrying their frustrations.

Simply put, Microsoft can't be trusted with the power Windows 10 gives them.

I've had my own frustrations with it having seen my production machine blue screen for no apparent reason over a dozen times in the past year.  In the 3 years prior the same machine running Windows 7  may have done it twice.



I'm tired of constant updates churning in the background while I'm trying to do actual work.  Sick of waiting 15 minutes for a system shutdown because Windows decided it was time to do some housekeeping.

My eyes bleed at the sight of full event logs warning of failed telemetry connections.  All because I refuse to turn my daily workflow into an episode of The Truman Show.  Spybot Anti-Beacon takes care of that but the price is endless bitching.

My PC is not a lifestyle device, my data under my and nobody else's purview. I expect to control my own environment.  I have no use for Cortana.  Quite simply, I don't have the buying or search habits to make it or anything like it benefit me.  Meaning I have no reason to be so forthcoming.

Am I a troglodyte?  Hardly, I just prefer to not have Microsoft curating my search results or my computing habits for that matter.  Even if they do consider it a "Feature."

But Microsoft doesn't see it that way.

The best example is the update process.  It's common knowledge that Windows 10 has essentially taken away your ability to exercise any disposition of updates.  Even if they brick your device.

Take the recent update that disabled millions of webcams.  We've come to find out that it was all due to one lone Microsoft Engineer who took the unilateral action to remove a codec without bothering to pass it through Q&A.  ( Thurrott said that on Windows Weekly 487 BTW)

I appreciate employee empowerment and all.  It works great for the auto industry in fact most auto workers have the power to stop an entire assembly line if they see a problem.  What comes next is a structured process to address it.  

But nobody makes the ultimate call by themselves.  Unless they work for Microsoft that is.  Where one poorly executed update can be unleashed on millions of devices worldwide without as much as a peer review.

If you're using Windows 10 there's no doubt you've spent at least a few minutes observing the update process.  It's all very clandestine: even the event logs won't provide you any illumination as to what's going on.  You just sit and watch that screen, cross your fingers, and hope the update goes well as it reboots 2, 3, 5 times...



The latest atrocity?  The endless loop of death from KB3194496 that for many users will never install correctly without first manually applying an out of cycle patch ( <--that links to it BTW) 

We reap what we sow and the crop is a load of manure.  In the old days we could just simply uncheck the update once we found out it was problematic.  Today we have to beg the good graces of Microsoft to acknowledge the problem in the first place.  Meanwhile our workflows and production goes to hell while Microsoft whitewashes it's official response.

I could care less what Microsoft's "telemetry" is telling them about the severity of the issue.  If they can't get a patch right why should I trust their telemetry as an indicator of anything?

Laissez-faire may be great for Free Market policy wonks but it's got no place in a platform that 20% of the planet relies on to actually accomplish something.

The user base should demand that the next patch they release give us back control of the update process.  At this point it's obvious Microsoft can't be relied upon to do it themselves.  

Here's a proposition...

I'll meet you half way Microsoft.  Let the users curate their own patches but turn off Cortana or the Store while it's disabled.  

I think that's a fair compromise and for those invested in the Microsoft way of doing things, it would be a reminder to turn the updates back on when the inevitable storm has passed.




Thursday, April 2, 2015

Ghosts in the Malwarebytes



Just a quick note.  If you've just suffered a debilitating round of re-installing Office 2003 today ( C'mon now, at least a few of you still have to support it) I may know why.

At roughly 2PM PST on April 2nd 2015,  Malwarebytes released an update (4.2.6) for it's malware scanner  that falsely triggered a quarantine of Microsoft Office 2003 files for a supposed "Trojan.Agent.edt" infection.  The first victim is usually outlook.dll since it's part of Outlook client and the most used application of the suite.  

While the Fortune 500 IT guys may have nothing to worry about here, the rest of us just might.  In the "real" world to find an old version of outlook (like 2003) to be running alongside a newer version of the MS Office suite isn't uncommon.   More often than not small businesses opted to upgrade to a version of MS Office that didn't include Outlook.

That there were more versions of MS Office without it than with was either bad marketing or just a cruel joke.  Regardless, it means you as a small business IT guy or consultant can run into this issue.  

So here are those ingredients for pain again...

You need one part Microsoft Office 2003, one part Malwarebytes and one part bad update.

The fix?

Depending on whether or not the affected system had Office running today the fix is as simple as allowing the latest updates to install (4.3.x).

If, however, you received a feverish phone call toady from users convinced they were experiencing a "Virus!" there's an extra step.

The "infected" office files will be in the quarantine (under the History tab) of the Malwarebytes application.  Select their associated check boxes and simply click "Restore" and answer in the affirmative to any questioning prompt.

You should update the Malwarebytes signature files first, BTW, so that you don't end up in chasing your tail in an endless circle of restoration/quarantine.

The quarantine process removes but does not damage files so their restoration requires no further action to return your MS Office 2003 applications to full functionality.

Follow the steps above and you can consider this bullet dodged.


Check out the video below to see the steps in action!


Friday, March 13, 2015

Are you FREAKed out yet?


So maybe you heard about the latest round of security nightmares that plague what everyone thought was secure web traffic.

A few months back it was a serious security flaw in OpenSSL known as HeartBleed that sent webmasters scrambling.  Then came a left field sucker punch when it was discovered that all an attacker needed to do to compromise your entire server (not just a website) was to insert some code that a BASH prompt would respond to. 

Encryption be damned if you have root access to the server!

Which brings us to the latest security gaffe, otherwise known as a Freak attack...

This one has its roots in the earliest implementations of web security.  Back in the days when the U.S. government was so paranoid about not being able to clandestinely snoop on your encrypted communications that they enforced a ban on strong encryption ( aka: stuff they couldn't break.) It was deemed "export-grade" encryption which was just a fancy name for "weak."

They did it by forcing SSL to downgrade its encryption bit strength when traffic left the U.S. thus allowing easy surveillance of all "suspicious" (meaning all) traffic.

Well, as we know from the Snowden leaks there's not much need to worry about borders anymore.  The U.S. has monitoring bases worldwide now.  Besides, the juicy fruit of of the spy game is gathered from far less hardened sources these days.  Just bug a German chancellor's phone and you've got all the dirt you need on the EU.

But let's get back to the problem at hand. 

There are still remnants of this "backdoor" in SSL and because of it millions of websites are vulnerable to compromise using relatively simple "man in the middle" attacks that utilize the facilities of weak encryption still present in SSL implementations.

The worst part is that the problem exists on both the client (aka: your browser) and server sides.  A compromised client and a compromised server are a marriage made in heaven. 

So what's the solution?  Pretty much the same as always.  Keep abreast of security news and patch, patch, patch!  Which is why there were so many Internet Explorer security patches this week.  Open SSL will have a patch available too.

If you'd like to dig a little deeper the following site will let you test both your browser and your favorite SSL secured websites.



Do it now.

Wednesday, August 20, 2014

Microsoft's Bloody Tuesday

Originally published on Kupeesh as Fear and Loathing of a Microsoft Patch



Poor Microsoft, it's been a tough couple of years for the software giant as it's gone through management upheavals, a failed operating system and a lackluster foray into the mobile market.

It seems they just can't catch a break...

That doesn't preclude them, however, from breaking things.

Case in point.  Last week's round of "Patch Tuesday" updates was filled to the brim with security and operating system fixes that millions of Windows PC's dutifully installed via automatic updates.

Normally keeping an operating system up to date is a good idea if you want to keep the bad guys out of your stuff.  But what do you do when the supposed good guys blow up your computer?

That's a question thousands of Windows users are asking as they now find themselves between the rock of Internet security threats and the hard place of a botched update.  

Even longtime Microsoft watchers like Paul Thurott (Windows Weekly, Winsupersite) can only answer with, "That's a tough one."

The patch causing so much trouble is a seemingly innocuous update to the Russian Ruble currency symbol in the windows font library (KB 2970228).  Apparently some users are experiencing everything from screwed up fonts to Blue Screens of Death (BSOD) after its installation.  As a workaround Microsoft is currently advising users to remove it and 3 other updates (KB2982791,KB2975719,KB2975331) that contain the offending code.  In addition, the download description pages for the affected update patches have had their download links removed while Microsoft, "investigates the issue."

Windows 7 and 8 are arguably the most robust operating systems Microsoft has ever produced.  So the return of the BSOD nemesis from the days of Windows XP is going to raise some eyebrows.  BSOD's only arise when a core operating system function has failed beyond recovery.  

That's something we thought we left behind when the house of cards that was Windows XP finally shuffled off the stage.  So with so much progress, how could Microsoft allow an obviously unvetted update to be distributed on platforms from Server 2003 to Windows 8.1.

Yes I know, Microsoft, unlike Apple, doesn't control every variant of hardware that runs their software.  But it's for exactly that reason that one would think their update policy would err on the side of caution.  That goes double in a week that also saw major outages of the company's Azure cloud services.

Instead Microsoft seems bent on releasing new products (patches included) like automakers release new cars.  But operating systems aren't Chevy's and rushing new products to market always leaves something to be desired.  Just ask GM about taking shortcuts in a process for proof.

So what's the answer when a strategy of "rapid release" seems to rule the day.  Unfortunately it's "Caveat Emptor," Buyer Beware.  Microsoft appears committed to shooting out software patches and asking questions later.  So for now, you may just want to switch those automatic updates to "manual" and wait a week after Patch Tuesday to install those non-critical updates.


In this case the cure was worse than the disease.