{"id":15754,"date":"2019-07-11T02:30:03","date_gmt":"2019-07-11T10:30:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/07\/11\/news-9501\/"},"modified":"2019-07-11T02:30:03","modified_gmt":"2019-07-11T10:30:03","slug":"news-9501","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/07\/11\/news-9501\/","title":{"rendered":"New Windows 7 &#039;security-only&#039; update installs telemetry\/snooping, uh, feature"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/02\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Thu, 11 Jul 2019 03:16:00 -0700<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Back in October 2016, Microsoft <\/span><a href=\"https:\/\/www.infoworld.com\/article\/3128983\/how-to-prepare-for-the-windows-781-patchocalypse.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">divided the Win7 and 8.1 patching worlds<\/span><\/a><span style=\"font-weight: 400;\"> into two parts. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those who got their patches through Windows Update received so-called Monthly Rollups, which included security patches, bug fixes \u2013 and we frankly don\u2019t know what else \u2013 rolled out in a cumulative stream. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The folks who were willing to download and manually install patches were also <\/span><a href=\"https:\/\/web.archive.org\/web\/20161028123404\/https:\/\/blogs.technet.microsoft.com\/windowsitpro\/2016\/08\/15\/further-simplifying-servicing-model-for-windows-7-and-windows-8-1\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">given the option<\/span><\/a><span style=\"font-weight: 400;\"> of installing \u201csecurity-only\u201d patches, not cumulative; these were meant to address just the security holes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">&#8230;From October 2016 onwards, Windows will release a single Security-only update. This update collects all of the security patches for that month into a single update. Unlike the Monthly Rollup, the Security-only update will only include new security patches that are released for that month. Individual patches will no longer be available&#8230;. The security-only update will allow enterprises to download as small of an update as possible while still maintaining more secure devices.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019ve had lots of problems with the security-only patches in the intervening three years, with most of the difficulties tied to bugs created by the security-only patches that are fixed in Monthly Rollups.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those who use Windows Update to get their Win7 patches have been treated to all sorts of extraneous stuff, including the infamous snooping (or should I be politically correct and call it \u201ctelemetry\u201d?) patch<\/span><a href=\"https:\/\/www.computerworld.com\/article\/3289506\/patch-tuesday-problems-abound-server-2016-crashes-and-a-net-patch-goes-down-in-flames.html\"><span style=\"font-weight: 400;\"> KB 2952664<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Now comes word that the July security-only patch, KB 4507456, includes an unexpected bonus. Snooping, er, telemetry.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to an eagle-eyed <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/july-2019-patch-tuesday-has-arrived\/#post-1872865\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">anonymous tip on AskWoody<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The \u201cJuly 9, 2019\u2014<\/span><strong>KB4507456<\/strong><span style=\"font-weight: 400;\"> (Security-only update)\u201d is <\/span><strong>NOT \u201csecurity-only\u201d update<\/strong><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It replaces infamous <\/span><strong>KB2952664<\/strong><span style=\"font-weight: 400;\"> and contains telemetry. Some details can be found in\u00a0<\/span><a href=\"http:\/\/download.microsoft.com\/download\/5\/9\/1\/591534C3-E10D-427B-8889-69D20F36FBB5\/4507456.csv\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">file information for update 4507456<\/span><\/a><span style=\"font-weight: 400;\"> (keywords: \u201ctelemetry\u201d, \u201cdiagtrack\u201d and \u201cappraiser\u201d) and under<\/span><a href=\"http:\/\/www.catalog.update.microsoft.com\/ScopedViewInline.aspx?updateid=7cdee6a8-6f30-423e-b02c-3453e14e3a6e\" rel=\"nofollow noopener\" target=\"_blank\"> <span style=\"font-weight: 400;\">http:\/\/www.catalog.update.microsoft.com\/ScopedViewInline.aspx?updateid=7cdee6a8-6f30-423e-b02c-3453e14e3a6e<\/span><\/a><span style=\"font-weight: 400;\"> (in \u201cPackage details\u201d-&gt;\u201dThis update replaces the following updates\u201d and there is KB2952664 listed).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As <\/span><a href=\"https:\/\/www.askwoody.com\/2019\/microsoft-surreptitiously-adds-telemetry-functionality-to-july-2019-win7-security-only-patch\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">@PKCano explains<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Microsoft included the <\/span><strong>KB2952664<\/strong><span style=\"font-weight: 400;\"> functionality (known as the \u201cCompatibility Appraiser\u201d) in the Security Quality Monthly <\/span><strong>Rollups<\/strong><span style=\"font-weight: 400;\"> for Windows 7 back in September 2018. The move was announced by Microsoft ahead of time.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">With the July 2019-07 <\/span><strong>Security Only<\/strong><span style=\"font-weight: 400;\"> Quality Update <\/span><strong>KB4507456<\/strong><span style=\"font-weight: 400;\">, Microsoft has slipped this functionality into a <\/span><strong>security-only patch<\/strong><span style=\"font-weight: 400;\"> without any warning, thus adding the \u201cCompatibility Appraiser\u201d and its scheduled tasks (telemetry) to the update. The package details for KB4507456 say it replaces KB2952664 (among other updates).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Come on Microsoft. This is not a security-only update. How do you justify this sneaky behavior? Where is the transparency now.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Windows guru @abbodi86 has looked at the internals of the patch and <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/july-2019-patch-tuesday-has-arrived\/#post-1872928\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">concludes<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Disabling (or deleting) these schedule tasks after installation (before reboot) should be enough to turn off the appraiser<\/span><\/p>\n<p><span style=\"font-weight: 400;\">MicrosoftWindowsApplication ExperienceProgramDataUpdater<\/span><span style=\"font-weight: 400;\"><br \/><\/span><span style=\"font-weight: 400;\">MicrosoftWindowsApplication ExperienceMicrosoft Compatibility Appraiser<\/span><span style=\"font-weight: 400;\"><br \/><\/span><span style=\"font-weight: 400;\">MicrosoftWindowsApplication ExperienceAitAgent<\/span><\/p>\n<p><span style=\"font-weight: 400;\">but it\u2019s best to wait until next month to see if the Security-only update comes clean<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I\u2019ve found no indication that the Windows 8.1 Security-only patch has been similarly subverted.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Debate among patch cognoscenti <\/span><a href=\"https:\/\/www.askwoody.com\/2019\/microsoft-surreptitiously-adds-telemetry-functionality-to-july-2019-win7-security-only-patch\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">rages<\/span><\/a><span style=\"font-weight: 400;\">. Some feel that Microsoft is justified in adding telemetry to the last vestiges of Win7 \u2013 due for the scrap heap in January. Most see a fundamental deceit at play, with yet more Windows snooping software getting installed without forewarning or consent\u2026, this time in a \u201cSecurity-only\u201d patch for heaven\u2019s sake.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security veteran Dr. Vess Bontchev <\/span><a href=\"https:\/\/twitter.com\/VessOnSecurity\/status\/1149003884284846085\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">put it simply<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I have officially stopped updating my Win7 machine. I no longer trust Microsoft&#8217;s updating process. I&#8217;ll protect it from any existing and future vulnerabilities with my other defenses, as well as I can.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Even if Microsoft\u2019s motives are clean as the driven snow, I find it difficult to justify this kind of contempt for Windows 7 customers. Unfortunately, with just six months of support left for the old OS, it seems unlikely that any regulatory body will take MS to task.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Join the debate on <\/span><\/i><a href=\"https:\/\/www.askwoody.com\/2019\/microsoft-surreptitiously-adds-telemetry-functionality-to-july-2019-win7-security-only-patch\/\" rel=\"nofollow noopener\" target=\"_blank\"><i><span style=\"font-weight: 400;\">AskWoody<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3408496\/new-windows-7-security-only-update-installs-telemetrysnooping-uh-feature.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/02\/windows_security_safety_protection_encryption_locks_thinkstock_831741980-100749419-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Thu, 11 Jul 2019 03:16:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Back in October 2016, Microsoft <\/span><a href=\"https:\/\/www.infoworld.com\/article\/3128983\/how-to-prepare-for-the-windows-781-patchocalypse.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">divided the Win7 and 8.1 patching worlds<\/span><\/a><span style=\"font-weight: 400;\"> into two parts. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those who got their patches through Windows Update received so-called Monthly Rollups, which included security patches, bug fixes \u2013 and we frankly don\u2019t know what else \u2013 rolled out in a cumulative stream. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The folks who were willing to download and manually install patches were also <\/span><a href=\"https:\/\/web.archive.org\/web\/20161028123404\/https:\/\/blogs.technet.microsoft.com\/windowsitpro\/2016\/08\/15\/further-simplifying-servicing-model-for-windows-7-and-windows-8-1\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">given the option<\/span><\/a><span style=\"font-weight: 400;\"> of installing \u201csecurity-only\u201d patches, not cumulative; these were meant to address just the security holes.<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3408496\/new-windows-7-security-only-update-installs-telemetrysnooping-uh-feature.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10516,714,10525],"class_list":["post-15754","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-microsoft","tag-security","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15754"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15754\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15754"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}