-
EstherD
AskWoody LoungerEarlier today Google Technology News was featuring an article on ZDNet that claimed MS Cloud Services outages “continue into week two” and Fox was reporting “Major Outlook outage causing nationwide email outages”. Maybe MS have their hands full with that? All hands on deck, or some such?
-
EstherD
AskWoody LoungerIt’s worse than you think. Read this article from ProPublica…
Inside TurboTax’s 20-Year Fight to Stop Americans From Filing Their Taxes for Free
Using lobbying, the revolving door and “dark pattern” customer tricks, Intuit fended off the government’s attempts to make tax filing free and easy, and created its multi-billion-dollar franchise
by Justin Elliott and Paul Kiel Oct. 17, 2019
1 user thanked author for this post.
-
EstherD
AskWoody LoungerIf a post is deleted for a rules violation, does the poster get any notification of that action? And is there any appeals process?
Why I’m asking…
Posted earlier tonight in Is there a way to cheat Pause Update? thread. My post seemed to be in the thread shortly after posting. Didn’t receive a notice of deletion, but post isn’t there now. Not listed in sidebar, either, so it doesn’t look like it was moved somewhere else.
Didn’t think my post violated any rules. Don’t think it was off-topic, either. But it was “pithy”, and a bit hasty, so it could have been perceived as such.
Should I just try again, but take a bit more time writing and say why I think what I’m posting is relevant to the topic, rather than just a rant?
Any help or insight would be appreciated. TIA…
— EstherD
-
EstherD
AskWoody LoungerThere’s lots that needs to be said on this issue. But my music program is going to end soon, and I’m not sure I want to stay awake long enough to finish writing this diatribe. But let’s begin and see how far we get.
BACKUPS
Yeah, great. With you and bbearren all the way on this one. Problem is… What you WANT to have is a backup that was made (and verified) within MINUTES of the time the update occurs, so you can be SURE you have captured EVERYTHING of value.
Under the current Win10 update regime you cannot do that because you typically do NOT have control over EXACTLY WHEN the update will occur. So the best you can do is an approximation… what the machine state looked like when the backup program was last run, NOT what the state of the machine was just prior to the update.
If you have to restore under a condition of approximation, then you have a rock and hard place choice to make: Abandon everything that didn’t make it onto the backup, or try to capture it from the failed system and merge it into the restored system. I’ve done both; NEITHER is acceptable to me. I want FULL CONTROL over updates. MY timeline, NOT someone else’s.
TELEMETRY
If I could be SURE that MS’s telemetry could actually do all the wonderful things you claim it can do for us, then yes, I would be in favor of it, too. But I do NOT believe it can. Or ever will.
In a former lifetime I did program development in a world-class scientific research lab. I once tried to write code that watched one of my programs run and gave me feedback on what went wrong. That’s a VERY HARD task. MUCH harder than writing the code itself. Perhaps impossible. As in NP Complete impossible. And I suspect Gödel himself might have a few words to say about the theoretical impossibility of doing it, too.
Why? Because the ONLY things your telemetry code can test for are things you already know to look for, and how to test for. But in order to do what you want MS’s telemetry to do that code has to watch for all the UNEXPECTED things that by definition cannot be predicted IN ADVANCE before you actually SEE them happen at least once.
Here’s another way to look at this. What MS is trying to do is analogous to trying to write a diagnostic program that runs within the OS. But writing diagnostic programs that REALLY and FULLY test hardware and/or software is well known to be a thankless and difficult task.
In that same former lifetime, my fellow engineers and I used to quip that our application programs were better at diagnosing failures of the DEC hardware we were running on than the diagnostic programs that DEC wrote and supplied to us.
We’d have a failure and call in a DEC FE. First thing he did was run the standard diag. Most of the time it would come up clean. But our app would crash consistently. And if we could get the FE to try a few board swaps, oftentimes the problem would vanish with one of them. And magically reappear if the original board was swapped back in. QED
But sometimes it wouldn’t, because the failure was intermittent. Then we would have to pare down our code until we found something that would repeatably provoke a failure. Once we knew EXACTLY what to look for, and how to tickle it, then AND ONLY THEN could we write a diagnostic that reliably demonstrated the fail.
How is that different than Win10 updates? If MS knew what was going to fail in a new patch, then they certainly could write telemetry code to test for that particular failure. But why would they do that, when they could more easily use that same insight to correct the problem in the patch BEFORE it shipped.
How does the telemetry code know to look for a particular profile failure mode when there are hundreds or thousands of ways that something can go wrong? Or identify a race condition that cannot even be defined let alone tested for? And again, if MS knew what to look for, a more straight-forward approach would be simply to FIX THE CODE, either in the OS or the patch, and be done with it. Writing yet more telemetry code gets you nowhere useful. It’s a REACTIVE strategy whereas what you really want is a PROACTIVE approach.
And don’t tell me “AI can do it”. Nope. Still have to train it. And if there’s a category missing from the training set, AI won’t help you find it. AI is good for finding exotic variants of things you already know something about, NOT for exploring the unknown. Which is what bad code is, because if you KNEW in advance it was bad, then you wouldn’t ship it until it was fixed. Or at least most competent programmers wouldn’t.
One final point. There are also fundamental limits on HOW MUCH telemetry you can gather before your telemetry becomes a drag on productivity. So even if you know what to look for, you may not be able to gather sufficient data to perform the needed analysis, because the computation required is so cpu- or disk-intensive that the user would immediately notice the slowdown.
Bottom line: NO, I do NOT believe telemetry BY ITSELF can now or ever will compensate for MS’s poor coding. Or make updating easier or safer for the average user or sysadmin.
And with that, I’m donning my flame-proof nightgown and heading off to bed…
— EstherD
19 users thanked author for this post.
rc primak,
Bengalensis,
Kranium,
LH,
OscarCP,
Lars220,
Charlie,
DriftyDonN,
woody,
SueW,
jburk07,
wavy,
Cybertooth,
phaolo,
zat_so,
Kathy Stevens,
Fred,
David F,
migongo
-
EstherD
AskWoody LoungerIt also causes “sfc” on Win7 to emit a cryptic error message, something about files it tried to restore but couldn’t, presumably because “sfc” also can no longer read the jscript.dll files after the workaround is implemented. Since the logfile generated by “sfc” is effectively unparsable by mere mortals, it is difficult to determine exactly what “sfc” is complaining about. Therefore, you may not want to implement this workaround if you rely on “sfc” to validate the health of your Win7 system.
-
EstherD
AskWoody LoungerAgree with your appraisal of EMET. Ran it on the family’s three personal laptops for about 5 years in the late-2000’s and early-2010’s. EMET never stopped anything nasty (though our AV’s caught a number of them during those years). Meanwhile, EMET was constantly throwing up false positives, usually just after every new release of Chrome or Firefox. Got to be too much of a maintenance headache, so I ripped it out.
Currently using Malwarebytes Pro as our AV and anti-malware tool of choice, with Win7 Defender turned off. Highly recommended.
1 user thanked author for this post.
-
EstherD
AskWoody LoungerOctober 22, 2019 at 6:57 pm in reply to: Rings within Insider Rings – where you end up, nobody knows #1988426Silly question: “Could Microsoft possibly make this any more complex?”
Obvious answer: “Of course they can!”
So don’t give them any ideas. Or excuses! -
EstherD
AskWoody LoungerAre you sure you mean JAVA rather than Javascript?
The two technologies are NOT the same, but they are often confused with one another.
Javascript is built into all browsers. Most websites require Javascript to render correctly.
JAVA is a browser PLUGIN from Oracle that you have to install (and update) manually. Very few sites need JAVA. Notable exceptions are a few science-based sites, which use JAVA to compute things like star maps and satellite tracking. Personally, have never seen JAVA required by any banking and/or e-commerce sites.
If you have JAVA installed, it will have its own control panel and appear in the list of installed programs. Javascript does not do either of these things.
-
EstherD
AskWoody LoungerLast time I checked, which was admittedly about 5 years ago, you could stop the scanning, but you could NOT uninstall / disable the low-level code that implemented it. So it’s there, ripe for the pickin’, whenever someone has the incentive to figure out how to exploit it.
1 user thanked author for this post.
-
EstherD
AskWoody LoungerIf MS were supplying a “clean” patch just for the BlueWho family of vulnerabilities, then I would agree with you: Waiting to patch would be foolhardy. However, that is NOT the case; the BlueWho patch is bundled with all manner of unrelated stuff. Consequently, the risk calculation is NOT as simple as you make it out to be. A prudent sysadmin needs to balance the risk of leaving BlueWho unpatched with the risk of patching quickly and then taking one on the chin because of some other so-called “fix” that is buried in the same patch file. And I do mean BURIED, since MS seems loath to tell us EXACTLY what change(s) are present in any given patch. That makes testing VERY difficult, and impossible to do with any degree of confidence, since it becomes a complete guessing game as to what must be tested to feel some assurance that the patch won’t adversely affect production systems. And don’t tell me that unexpected interactions are highly unlikely. What about the recent “Visual Basic” fiasco? Or the early Spectre/Meltdown patches, which actually made the systems on which they were installed LESS secure than if those systems hadn’t been patched at all? If “side-effects” like that were predictable, then why didn’t MS catch (and FIX) them during design, implementation or testing? If not, then my point is proven: Fools rush in whereas prudent sysadmins tread slowly and lightly. QED
1 user thanked author for this post.
-
EstherD
AskWoody LoungerThe term should be “pwned”, not “owned”. (Google it.)
Quick explanation:
If you NEVER reuse the SAME password on multiple websites, then there is nothing to see here.
However, if you DO reuse passwords, then you should STOP that practice. You should probably also consult Troy Hunt’s “Have I Been Pwned” website (see link in earlier post) for details about why that’s a BAD IDEA, and whether or not you are currently at risk, because some miscreant has stolen a hash of your favorite password from some site and cracked it so it can be used on another site, e.g. your bank or credit card account.
— EstherD
1 user thanked author for this post.
-
EstherD
AskWoody LoungerJuly 29, 2019 at 1:16 pm in reply to: Even though there’s a BlueKeep exploit for sale, it doesn’t work very well – doesn’t propagate, for example #1896407Any evidence that BlueKeep is exploitable if RDP / remote access is turned OFF? I haven’t seen any, though I freely admit to not having looked very hard recently.
It’s easy to do. Doesn’t even require hand-to-hand combat with the registry. Seems to me that turning this feature off should be on everyone’s security ToDo list. (Except for those who KNOW that they need to use it, of course.)
-
EstherD
AskWoody LoungerJuly 29, 2019 at 1:04 pm in reply to: Apple’s revelations about keeping/scanning Siri recordings demand a response #1896402 -
EstherD
AskWoody LoungerYears ago, boot problems like those described here could often be fixed by replacing the CMOS battery. Sometimes the cure was as simple as removing the battery, cleaning the contacts and putting it back (no actual replacement needed). HTH… EstherD
1 user thanked author for this post.
-
EstherD
AskWoody LoungerApril 18, 2019 at 4:47 pm in reply to: To block the latest zero day, instead of removing Internet Explorer, just short-circuit access to MHT files #552405Was doing this on a per-user basis by clicking “Browse” and then following the Yellow Brick Road to C:\Windows\Notepad. Clicking the disclosure triangle in “Other Programs” definitely speeds up the process considerably. Thanks, Karen!
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
1 hour, 18 minutes ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
2 hours, 45 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
1 hour, 26 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
2 hours, 3 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
59 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
4 hours, 53 minutes ago -
AskWoody at the computer museum
by
Will Fastie
19 minutes ago -
Planning for the unexpected
by
Susan Bradley
16 minutes ago -
Which printer type is the better one to buy?
by
Bob99
3 hours, 3 minutes ago -
Upgrading the web server
by
Susan Bradley
1 hour, 28 minutes ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
20 hours, 33 minutes ago -
Creating a Google account
by
DavidofIN
19 hours, 18 minutes ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
1 day, 1 hour ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
1 day, 12 hours ago -
AI *emergent misalignment*
by
Alex5723
1 day, 14 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
20 minutes ago -
Trouble signing out and restarting
by
Tech Hiker
14 hours, 36 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
1 day, 22 hours ago -
Problem running LMC 22 flash drive
by
Charlie
21 hours, 12 minutes ago -
Outlook Email Problem
by
Lil88reb
21 hours, 18 minutes ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
1 day, 4 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
1 day, 21 hours ago -
Nearly 1 million Windows devices targeted in advanced “malvertising” spree
by
bbearren
1 day, 21 hours ago -
Windows 11 Insider Preview build 27808 released to Canary
by
joep517
2 days, 22 hours ago -
Windows 11 Insider Preview Build 22635.5025 (23H2) released to BETA
by
joep517
2 days, 22 hours ago -
Sysprep issue
by
Evit
2 days, 22 hours ago -
Android Security Bulletin—March 2025
by
Alex5723
3 days ago -
23h2: PIN TO START randomly available on right-click
by
dataman1701
3 days, 1 hour ago -
Microsoft Defender
by
agoldhammer
3 days, 6 hours ago -
New Laptop-Another ?
by
PeachesP
3 days ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.