{"id":17692,"date":"2020-02-10T12:30:09","date_gmt":"2020-02-10T20:30:09","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/02\/10\/news-11427\/"},"modified":"2020-02-10T12:30:09","modified_gmt":"2020-02-10T20:30:09","slug":"news-11427","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/02\/10\/news-11427\/","title":{"rendered":"Patch Tuesday\u2019s tomorrow. Verify you have &#039;Pause Updates&#039; enabled"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security5-100734739-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Mon, 10 Feb 2020 12:13:00 -0800<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Remember the frenzy after last month\u2019s Patch Tuesday? How everybody and his twice-removed cousin \u2014 even the N forkin\u2019 SA\u00a0\u2014 told you to get patched immediately because of this big, spooky <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3514350\/patch-tuesday-aftermath-the-nsa-crypt32-threat-is-real-but-not-yet-imminent.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Crypto API security hole<\/span><\/a><span style=\"font-weight: 400;\"> that was supposed to bring down\u00a0 Windows As We Know It, like, right now?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Guess what. <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3518439\/the-perils-of-shouting-fire-in-a-crowd-of-pc-patchers.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">It never materialized<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To its credit, Microsoft never said the Chain of Fools\/CurveBall CVE-2020-0601 fix was a \u201cCritical\u201d patch. That didn\u2019t keep most of the increasingly echo-like Windows blogosphere from crying, \u201cFire!\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you prefer to wait and see if the latest Windows patches turn to dreck, there are a few simple steps to take right now.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The last free, pushed Win7 patches arrived a month ago. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you paid for Win7 Extended Security Updates\u00a0\u2014 yes, <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3519609\/it-s-not-too-late-to-get-an-extended-security-update-license-for-windows-7.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">even a business of one can get them<\/span><\/a><span style=\"font-weight: 400;\">\u00a0\u2014 you\u2019re due a patch tomorrow. One little problem: We haven\u2019t seen the patch and don\u2019t know absolutely, for sure, how it\u2019ll arrive.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you haven\u2019t paid for Win7 Extended Security Updates, we also don\u2019t know what the morrow will bring. Windows 7 already has one manually downloadable patch to fix the bad patch last month (which introduced the \u201cStretch\u201d black wallpaper bug) and I expect we\u2019ll see a patch at some point to fix the <\/span><a href=\"https:\/\/www.askwoody.com\/2020\/win7-error-you-dont-have-permission-to-shut-down-this-computer\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">\u201cYou don\u2019t have permission to shut down this computer\u201d bug<\/span><\/a><span style=\"font-weight: 400;\">. For now, there\u2019s nothing pressing. See Patch Lady Susan Bradley\u2019s <\/span><a href=\"https:\/\/www.askwoody.com\/2020\/patch-lady-podcast-reminder-backup-your-windows-7\/\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Feb. 9 podcast<\/span><\/a><span style=\"font-weight: 400;\"> for more details.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I suggest you keep your powder dry by following the usual steps: Click Start &gt; Control Panel &gt; System and Security. Under Windows Update, click the &#8220;Turn automatic updating on or off&#8221; link. Click the &#8220;Change Settings&#8221; link on the left. Verify that you have Important Updates set to &#8220;Never check for updates (not recommended)&#8221; and click OK.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019ll watch for any goofiness and alert you, as usual.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re using <\/span><strong>Windows 8.1<\/strong><span style=\"font-weight: 400;\"> (believed by many to be the most stable version of Windows currently on offer), click Start &gt; Control Panel &gt; System and Security. Under Windows Update, click the &#8220;Turn automatic updating on or off&#8221; link. Click the &#8220;Change Settings&#8221; link on the left. Verify that you have Important Updates set to &#8220;Never check for updates (not recommended)&#8221; and click OK.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Not sure which version of Win10 you\u2019re running? Down in the Search box, near the Start button, type About, then click About your PC. The version number appears on the right under Windows specifications.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you\u2019re using Win10 1803 or 1809, I strongly urge you to move on to Win10 version 1903. Microsoft released it (to some consternation) in May of last year. It had a shaky start before plunging into a four-patch debacle in September\/October, but now appears to be relatively stable. There are detailed step-by-step instructions for moving to Win10 1903 in &#8220;<\/span><a href=\"https:\/\/www.computerworld.com\/article\/3513399\/why-and-how-im-moving-win10-production-machines-to-version-1903.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Why \u2014 and how \u2014 I\u2019m moving Win10 production machines to version 1903<\/span><\/a><span style=\"font-weight: 400;\">.&#8221;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you insist on sticking with Win10 1809 (thrice bitten, thrice shy, eh?), you can block updates by following the steps in <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3487687\/patch-tuesday-s-coming-protect-your-machine-by-pausing-updates.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">December\u2019s Patch Tuesday warning<\/span><\/a><span style=\"font-weight: 400;\">. Be acutely aware of the fact that Microsoft won\u2019t be handing out any more security patches for 1809 Home or Pro after the May Patch Tuesday.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In version 1903 or 1909 (either Home, Pro, Education or Enterprise, unless you\u2019re attached up an update server), if you <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3516497\/get-the-january-2020-patch-tuesday-patches-installed.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">followed my instructions last month<\/span><\/a><span style=\"font-weight: 400;\">, you already have &#8220;Pause Updates&#8221; set so patching resumes near the end of February (screenshot).\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Not sure if you\u2019re sufficiently paused? To check, using an administrator account, click Start &gt; Settings &gt; Update &amp; Security. If you\u2019re paused until the end of the month or so, you don\u2019t need to do anything. That\u2019ll give you three weeks after Patch Tuesday to see if there are any bad bugs.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On the other hand, if pause is set to expire before the end of February, or if you don\u2019t have a pause in effect, you should set up a patching defense perimeter that keeps patches off your machine for the rest of this month. Using that administrators account, click the &#8220;Pause updates for 7 days&#8221; button, then click it again and again, if necessary, until you\u2019re paused out into March. (If you have a partial pause already in effect, you may need to click &#8220;Resume updates,&#8221; then reboot.)<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For those of you who have been wondering about the \u201coptional, non-security, C\/D Week\u201d KB 4532695 patch for Win10 1903 and 1909, it\u2019s there, but you shouldn\u2019t install it. For weeks I\u2019ve been wondering why I didn\u2019t see KB 4532695 offered on my 1903 machines as an additional update to \u201cDownload and install now.\u201d <\/span><a href=\"https:\/\/www.askwoody.com\/forums\/topic\/are-you-running-win10-version-1903-could-you-check-something-out-for-me\/#post-2137670\" rel=\"nofollow noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">@abbodi86 on AskWoody.com <\/span><\/a><span style=\"font-weight: 400;\">finally figured it out: If you\u2019re running Win10 1909, you\u2019ll see KB 4532695 offered as an additional update, as one would expect. But if you\u2019re running Win10 1903, you have to have a specific combination of hidden and blocked patches before the optional\u00a0KB 4532695 is offered.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Don\u2019t be spooked. Don\u2019t be stampeded. And don\u2019t install any patches that require you to click \u201cDownload and install now.\u201d They\u2019ll be minimally tested and available soon enough.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If there are any immediate widespread problems protected by this month\u2019s Patch Tuesday\u00a0\u2014 a rare occurrence, but it does happen\u00a0\u2014 we\u2019ll let you know here, and at AskWoody.com, in very short order.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">We\u2019re at MS-DEFCON 2 <\/span><\/i><a href=\"https:\/\/www.askwoody.com\/2020\/ms-defcon-2-make-sure-windows-is-locked-down-in-preparation-for-the-feb-2020-patches\/\" rel=\"nofollow noopener\" target=\"_blank\"><i><span style=\"font-weight: 400;\">on AskWoody<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.<\/span><\/i><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3526448\/patch-tuesdays-tomorrow-verify-you-have-pause-updates-enabled.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2017\/09\/windows_patch_security5-100734739-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Woody Leonhard| Date: Mon, 10 Feb 2020 12:13:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Remember the frenzy after last month\u2019s Patch Tuesday? How everybody and his twice-removed cousin \u2014 even the N forkin\u2019 SA\u00a0\u2014 told you to get patched immediately because of this big, spooky <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3514350\/patch-tuesday-aftermath-the-nsa-crypt32-threat-is-real-but-not-yet-imminent.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">Crypto API security hole<\/span><\/a><span style=\"font-weight: 400;\"> that was supposed to bring down\u00a0 Windows As We Know It, like, right now?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Guess what. <\/span><a href=\"https:\/\/www.computerworld.com\/article\/3518439\/the-perils-of-shouting-fire-in-a-crowd-of-pc-patchers.html\" rel=\"noopener\" target=\"_blank\"><span style=\"font-weight: 400;\">It never materialized<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3526448\/patch-tuesdays-tomorrow-verify-you-have-pause-updates-enabled.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10516,714,10525],"class_list":["post-17692","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-microsoft","tag-security","tag-windows"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17692"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17692\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17692"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}