Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

No. If you sold cars and realized that there were some buttons you could push on the AC unit that would cause it to catch fire, you wouldn’t remotely shut off my car to perform the repairs while I was driving down the highway.

The customers who “need” patches have a business to run, and forcing their computer to reboot in the middle of the workday for some service that may not be exposed at all on their network would be a good reason to avoid Microsoft products for said customer.



If Windows Server has been developed in such a way that a patch would just randomly reboot in the middle of the day or if anything would just reboot it unknowingly to the ops team then this is an OS problem and a reason why Windows Server is unfit to be used for servers rather than a patch problem.

A patch should be released as soon as possible and the OS should make it possible for the OPs team to install a patch at their own convenience and then there is no reason to withhold a patch ever. Sounds like a fundamental Windows issue and not a business practise issue.


I fundamentally disagree with your point of 'a patch should be released as soon a possible'.

A patch releases the fix, but by necessity also puts a bright target on the vulnerability it fixes by providing the information on potential exploitable vulnerabilities in the system being patched. From that moment on it is a race between reverse engineering exploit writers and system maintainers to get their work done first.

Having coordination and predictable planning where possible allows companies to include security maintenance into the workload, rather than to have to constantly scramble and react to unforeseen and unpredictable wildfires.

It is not about 'convenience', it is a component of a mature security process.


Security by obscurity. Surely the information on the vulnerability is already out there by the time the patch is released?


No, not necessarily. That's the point of those disclosure timelines.


Security by obscurity can work just fine when it's a two week extension on a bug that has existed for years.


But it never ends at two weeks. Time and time again the vendors will put it off for years if you let them.


I'm defending monthly patches here, not giving vendors extra time.


> If you sold cars and realized that there were some buttons you could push on the AC unit that would cause it to catch fire, you wouldn’t remotely shut off my car to perform the repairs while I was driving down the highway.

I'm just gonna leave this here.

https://www.theverge.com/2019/1/31/18205774/nio-ota-update-t...

Okay, so this instance was likely human error, but the manufacturer should make it very difficult for you to get yourself into this situation. I'm counting the days until one of the many new EVs on the road is force-updated (i.e., for something like a recall due to malfunctioning brakes), causing the car to become unavailable when the owner needs it.


Are there actually businesses who just use the normal windows updater? (Ignoring smaller businesses without IT departments for a second). I assumed the forced patching at boot/reboot was a consumer version thing? A unforeseen update from microsoft can just shut down your business?


Whilst servers are in a different category, multiple Windows Updates have changed the way updates work. Look at the Dual Scan situation[0]. People who had central management applied one update and suddenly found desktops also accepting updates from the Internet.

Then you've got the fact that "Professional Edition" was once a perfectly fine solution for businesses, but suddenly the ability to properly control updates like you suggest required Enterprise Edition. These aren't the only issues.

There's always someone who points out that if you have basically unlimited free time you can stay on top of all of it, but at the end of the day a lot of businesses still find surprise updates happening. I just got a sales call for a third party business product with the tagline "Disable Updates automatically applying (Yes, REALLY!)" as a listed feature.

Finally you can top it all off with the BYOD trend, where people often expect to run their own machines without management software.

[0] https://www.thewindowsclub.com/dual-scan-windows-update


Thanks for the insight


The same line of reasoning applies to IT departments as well, though. If you force corporate IT departments to spend all their time installing your daily updates, the cost of ownership of your product for the company goes way up and the department heads will start looking for cheaper alternatives. Exceptions could surely be made for critical vulnerabilities, especially those being exploited in the wild, but this is a low-severity DoS. As another commenter said, if you made this an off-schedule hotfix you would have to do it for basically every bug.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: