Creative Communities of the World Forums

The peer to peer support community for media production professionals.

Activity Forums VEGAS Pro OT: Stopping Windows from installing updates

  • John Rofrano

    August 27, 2015 at 11:12 am

    [Bob Peterson] “The issue is whether or not your machine is connected to the internet. If it is, you would be foolish in the extreme to skip security updates. That is one of the ways that Sony was penetrated. Machines that were internet connected, but which had not been updated to close well known, open holes.”

    It’s important to note that your computer is most likely not “on the Internet” the way the Sony servers were. You cannot, for example, host a web site on your desktop because more than likely, you are behind a router that has a hardware firewall built in to prevent such access. If the IP address on your computer starts with 192.168.x.x or 10.x.x.x you are using a non-routable IP that is not accessible from the Internet. If, however, your computer is directly connected to the Internet, you should run out and buy a router with a hardware firewall to hide behind.

    I was not advocating that you never apply updates, but rather that you turn off automatic updates and only allow updates to happen when you have a full backup of your system to revert back to in case things go wrong.

    ~jr

    http://www.johnrofrano.com
    http://www.vasst.com

  • Bob Peterson

    August 27, 2015 at 3:00 pm

    The article I read said that it was more than just the servers which were used for entree. It talked about user PCs which were penetrated in various ways to gain access to the servers through internal computers connected to their network. I recently encountered a PC which was so infested with viruses, key loggers, and other nasties (a malware program counted over 600), that the malware had established its own partition on the hard drive. The user could not access that partition, but, after the OS was reinstalled from HP supplied discs, that partition was gone. Incidentally, the PC was owned by an elderly woman who is a retired missionary. I don’t think she ever engaged in the sorts of activities that are known for installing malware.

    If there is no need to be concerned, then we are all wasting huge amounts of time and energy. However, I am far too cautious to take chances in this area. Just a few passwords may be sufficient to give me a huge financial problem. I fully agree on the need for regular backups so that things can be backed out.

    Another thought. I am even more appalled with Sony security’s negligence if their problem existed solely due to failures to update necessary software on their servers. That is truly inexcusable although it does fit the image in the article where the security area left unattended PCs accessible to anyone who walked in off the street.

  • John Rofrano

    August 28, 2015 at 2:01 am

    [Bob Peterson] “If there is no need to be concerned, then we are all wasting huge amounts of time and energy. However, I am far too cautious to take chances in this area.”

    It’s important to note that I am referring the risk of delaying Windows updates that fix OS vulnerabilities when you have a hardware firewall in your router. If you already have viruses and malware on your computer then you are definitely at risk already and Windows updates aren’t going to help you.

    The first line of defense is using a plug-in like Web of Trust (WOT) in your web browser. This will alert you to malicious sites so that you can surf safely to begin with. It has a great rating system that tells you if Google results are good web sites or bad ones.

    ~jr

    http://www.johnrofrano.com
    http://www.vasst.com

  • Bob Peterson

    August 28, 2015 at 2:15 am

    John, surely you know that I do not think that existing viruses can be removed by Windows updates. I am, indirectly, pointing out with my example that a PC behind a fire wall is not thereby protected from all malware. Malware can still penetrate in several different ways. I am talking about updates that plug holes in programs which can be exploited by the malware seeking to take up residence. Surely you are aware that this problem is real and exists although I do think that Apple people sometimes assume that they no longer have to be concerned about such things. In my experience, many Apple fans think that Apples are not vulnerable to malware. IMHO, that is a huge mistake to make.

    Since you did not respond to my point on PC security being a significant part of the fiasco at Sony, I’m glad that we now seem to agree on that point. Or, perhaps we have agreed to disagree. I can, if you wish, search for the fairly detailed article I read on that subject. I think I saw it in the WSJ, but I would not swear to that. It was written by some of the security consultants who talked to Sony both before and after the penetration.

  • John Rofrano

    August 28, 2015 at 2:37 am

    Yes I understood your point. I think we are talking about two different types of exploits so allow me to elaborate (because I think we agree):

    One type of exploit is to attack a server that has not been patched. This requires that the server be visible from the Internet. If your PC is behind a firewall and a router which has assigned it a non-routable IP address, then it cannot be seen and cannot be attacked in this way. So you don’t have to worry about these sorts of attacks to your PC.

    You are talking about malware that exploits vulnerabilities and I agree that both PC and Mac users need to be careful about these but the first line of defense is to not be tricked into downloading the malware in the first place. That’s all I was pointing out. Once you download the malware you have bigger problems.

    As for Sony, I don’t know enough about the incident to comment but you are correct that a good way to infiltrate a server is by planting malware on a PC that’s already behind the firewall within the network via a malicious email or something. I’m guessing that’s how Sony got breached and your point was that a server could be attacked from within and I agree.

    More often than not, malware is not exploiting a bug in the OS that has not been patched… It is exploiting the end user who gets tricked into installing a program that is stealing their identity via a key logger without any OS vulnerability exploits at all. 😉

    ~jr

    http://www.johnrofrano.com
    http://www.vasst.com

  • Bob Peterson

    August 29, 2015 at 3:39 am

    I’m sure you know this to John, but I think the point is worth making. Malware can invade a PC if it can exploit a vulnerability in a program which is running on a PC. It is not always dependent on tricking the user into downloading and running it. It can lurk on an otherwise legitimate, but infected site, exploit the vulnerability, and install itself. Things like Flash or Java are a bit notorious for such weaknesses. Windows itself has this type of vulnerability within its many programs which is why security updates need to be applied to protect against attack.

  • John Rofrano

    August 29, 2015 at 1:33 pm

    I can’t argue with anything you have said Bob. This is why using a plug-in like Web of Trust is so important because you never know when a web site can be infected.

    That being said, you have to balance that against the possibility of Microsoft messing up your computer with their updates and you missing a client deadline. I’ve had Microsoft do this several times. I’ve never had malware on my computer. I will err on the side of not updating until I’m at a point where I can afford downtime from Microsoft updates.

    What started this thread is the fact that Microsoft just issued an update to Windows 10 that broke a lot of people’s computers. I can’t take that chance. I understand that Windows 10 Home doesn’t allow you to turn off updates while Window 10 Pro does. That’s an argument right there that anyone using Windows 10 in production should buy the Pro version.

    BTW, major corporations turn off Windows updates by default. They do not risk the fact that Microsoft can cause applications on their computers to not work. Instead they test each update and then release them at a later date once they know they are working. That’s all I’m suggesting that you do as well. If it’s good enough for the Fortune 500, it should be good enough for your business.

    ~jr

    http://www.johnrofrano.com
    http://www.vasst.com

  • Wayne Waag

    August 29, 2015 at 3:46 pm

    [John Rofrano]

    I understand that Windows 10 Home doesn’t allow you to turn off updates while Window 10 Pro does.

    Apparently, there are several ways. This article explains how to disable automatic updates in Windows 10 Home.

    https://gadgets.ndtv.com/laptops/features/how-to-disable-windows-10-automatic-updates-728049

    I haven’t upgraded to Windows 10 and haven’t tried it. This link was originally posted in a thread on the Vegas Pro forum.

    wwaag

  • Bob Peterson

    August 30, 2015 at 12:35 pm

    John, I think all that is true although I had not read about these problems with Win 10. I read your comment discouraging an update from Win 7 to Win 10, and I absolutely agree with you. I would not touch Win 10 with a 10 foot pole at this point. I have better things to do than spending time trying to install a major upgrade to Windows, and I’m not inclined to spend the money replacing hardware which may be rendered useless by it.

  • John Rofrano

    August 30, 2015 at 2:37 pm

    [Bob Peterson] “I have better things to do than spending time trying to install a major upgrade to Windows, and I’m not inclined to spend the money replacing hardware which may be rendered useless by it.”

    Exactly! I don’t see any reason for a Windows 7 user to upgrade. Not a single one. There are almost no new features and certainly none that you “need”. Let’s face it, Windows 10 was release purely because Windows 8 was such a dog with it’s crippled Desktop and Metro interface and Windows 10 is really fixing what was “wrong” instead of bringing something “new”.

    Unfortunately for Microsoft, all the things that were wrong in Windows 8 that Windows 10 fixed, don’t even exist in Windows 7 so why would a Windows 7 user upgrade to Windows 10? For Windows 8 users it’s a needed fix. For Windows 7 users I just don’t see the need to upgrade. As Bob pointed out, there’s just no payback for all the effort.

    ~jr

    http://www.johnrofrano.com
    http://www.vasst.com

Page 2 of 3

We use anonymous cookies to give you the best experience we can.
Our Privacy policy | GDPR Policy