Where was the acceptance of a contract requiring that? Microsoft just gave people a free upgrade.
PittleyDunkin 457 days ago [-]
I imagine the definition of "upgrade" depends on the needs of the customer. The merchant of the license is inherently unable to evaluate this. Installing software without explicit consent, especially not-functionally-equivalent-software, is inherently wrong.
causality0 457 days ago [-]
It's amazing to me that we're all so chill about a company in Redmond having root access to our PCs because they pinky-swear they will never misuse it.
ranger_danger 457 days ago [-]
And yet when you call it what it is (a backdoor) people get highly offended. Same thing with ubuntu snaps or really anything that updates automatically.
112233 457 days ago [-]
How exactly updating non-automatically would help you avoid vendor backdoors that could be placed in the software by a request from the vendor government?
ranger_danger 457 days ago [-]
If you or someone else inspect the update and find something malicious before the update is actually applied, I think that's useful.
For example look at how many "patch tuesday" update fails there have been... I think it's sometimes a good idea to not always apply new updates immediately for this and other reasons.
orf 457 days ago [-]
Right, but this is expensive and dumb so nobody is going to do it themselves.
And then you’re back to trusting an external third party, just slower and with greater expense.
ranger_danger 457 days ago [-]
I don't think it's dumb, I have been saved from disaster too many times to count, by just waiting a little bit after something new comes out, to see if other people start having problems that might affect me.
orf 457 days ago [-]
That’s a different thing entirely - waiting for a review of a product before purchasing is different from inherently untrusting the manufacturer of the product, as it may contain something malicious that is targeted at you.
ranger_danger 457 days ago [-]
I'm still only talking about updates. I didn't update xz for example, and I'm glad I didn't because it turned out to be compromised in certain versions.
orf 457 days ago [-]
Sure, or it could have left you vulnerable in other versions.
Waiting for others to hopefully discover targeted security vulnerabilities and only updating after an ad-hoc timeframe if nobody shouts “FIRE!” isn’t a security posture, it’s just terrible patch management.
ranger_danger 456 days ago [-]
I don't think things are always so black and white but I respect your opinion.
thro1 457 days ago [-]
Right. From the comments:
>Even better, legally if something is provided as a gratuity without any bargained-for exchange, then it is considered a gift as there is no basis in contract to support a claim that payment is due.
>Given that the existing software on the server may not work with the new server I'd start with this being an offence under the Computer Misuse Act and ask for damages.
>The proper procedure is Redmond sends its engineers to reinstall the original version - at its own cost - and presents its excuses to the customers that it fucked over.
>>Or make Windows 2025 a free upgrade to Windows 2022 licensors, just like how Win11 is free to licensors of Win10
Why the hell is Microsoft offering in-place OS upgrades of Windows Server in Windows Upgrade that are one-click "sure, why not, let me just break my license"?
Windows decided to ruin its desktop, but that's okay because the business servers are where the real money is at, and thankfully they'd never do anything to destabilise that customer base...
yonatan8070 457 days ago [-]
I'm not sure I understand what Heimdal actually does. Aren't updates handled by Windows Server itself?
rincebrain 457 days ago [-]
I believe Heimdal is supposed to provide patch management cross-platform, so similar to what RHN/WSUS/etc provide, but for all your platforms on one system.
Also, Microsoft has been aggressively removing the ability to control what patches you install, I assume because they don't test most combinatorics of possible patches running and people kept picking and choosing, so if you still wanted that level of control despite being told "don't do that", you would use a system like that.
mattsimpson 457 days ago [-]
We got an urgent notice today from our central IT group warning of this catastrophic screw up of epic proportions, and I could hardly believe it.
This is way worse than the Crowdstrike debacle.
Rendered at 13:38:13 GMT+0000 (Coordinated Universal Time) with Vercel.
Where was the acceptance of a contract requiring that? Microsoft just gave people a free upgrade.
For example look at how many "patch tuesday" update fails there have been... I think it's sometimes a good idea to not always apply new updates immediately for this and other reasons.
And then you’re back to trusting an external third party, just slower and with greater expense.
Waiting for others to hopefully discover targeted security vulnerabilities and only updating after an ad-hoc timeframe if nobody shouts “FIRE!” isn’t a security posture, it’s just terrible patch management.
>Even better, legally if something is provided as a gratuity without any bargained-for exchange, then it is considered a gift as there is no basis in contract to support a claim that payment is due.
>Given that the existing software on the server may not work with the new server I'd start with this being an offence under the Computer Misuse Act and ask for damages.
>The proper procedure is Redmond sends its engineers to reinstall the original version - at its own cost - and presents its excuses to the customers that it fucked over.
>>Or make Windows 2025 a free upgrade to Windows 2022 licensors, just like how Win11 is free to licensors of Win10
https://i.redd.it/xgk7t0sii3zd1.png
https://i.redd.it/4o92m0nwi5zd1.png
https://imgur.com/a/RvEx3yn
Also, Microsoft has been aggressively removing the ability to control what patches you install, I assume because they don't test most combinatorics of possible patches running and people kept picking and choosing, so if you still wanted that level of control despite being told "don't do that", you would use a system like that.
This is way worse than the Crowdstrike debacle.