Have Microsoft overstepped the Mark regarding Security issues, and may have produced a really dangerous one themselves? :o
Let me explain (rewind a bit)
Microsoft have started using a new download method on Broadband using the Broadband modem offline, while the Computer is running (and not logged in...)
I noticed this on the last Microsoft security update (at the scheduled time) which I logged off then returned later showing about 25% of the latest patches loaded on the yellow shield icon in the taskbar by the clock
I logged on later and checked again was up to 30% Thought may be "trickle loading" during idle periods (like SETI updates)?
I logged off again and this new warning message was displayed (after shutting down AOL) about Do Not turn the computer off while the updates were loading...
So Microsoft are accessing our computer regardless of being online or Not, so long as A) the BB connection is Hooked up and B) The computer is Running.

Very Clever Microsoft...
But with you banging the Drum hard over preventing Security breaches, this is a massive "Own Goal" that might backfire on you Big Time?! :o
What if somebody could emulate this method of moving data, Just 1 trojan would be moved by this method would get in theory onto ALL the connected BB computers connected up, not talking several dozen on a single ISP link, but perhaps several million collectively! Bypasses browser Maybe also Firewall security... Going back to Boot sector type viruses? :eek: :o :(
Historically Microsoft started the remote connection Link where you could take control of another computer on a 1 to 1 basis ... Now there are many clones (most of the Illegal kind)
all doing the same thing (some better than the Microsoft version)
I think Microsoft's Latest bit of "Cleverness" will bring down the Broadband Internet unless they take Immediate action to rectify this gaping Loophole. :eek:

Your comment?

Dani AI

Generated

Short summary for context: observed Windows retrieving updates while no user was logged in and worried that the mechanism could be abused to push malware. correctly pointed out that a proper firewall/router helps — that advice is still the right starting point. What you saw is almost certainly the automatic-update client running as a background service (it initiates outbound downloads). That is not the same as Microsoft "remotely connecting" into your machine on a push basis.

Why an update-based mass-infection is unlikely: update packages are validated by the client before installation. To make millions of PCs accept a malicious update an attacker would have to either break Microsoft’s update-signing or convince each client to use a rogue update server (for example by hijacking DNS or compromising a corporate WSUS). Those attacks are much harder than ordinary worm propagation. That does not mean there is zero risk — supply-chain and server compromises are real threats — but they require a very different attack vector than a simple “trickle download” exploit.

Practical steps to reduce exposure (complements ’s points):

  • Keep Automatic Updates enabled but set them to a schedule or to “download and notify” if you want more control.
  • Use a hardware NAT/router and enable the OS firewall to block unsolicited inbound traffic.
  • Home users: run up-to-date AV/anti-malware and keep backups.
  • Small/enterprise: use WSUS or another internal update server and enforce update sources with Group Policy.
  • If unsure what happened, inspect the update history and the WindowsUpdate log (or Event Viewer) to see which component downloaded/installed what, and avoid powering off while an install is applying (that message appears because partial installs can corrupt the OS).

The core defense is layered: patch promptly, restrict inbound access, validate update sources, and keep backups.

Recommended Answers

All 3 Replies

I'm not sure what you're saying here, Answerpooler. The concept of broadband is that the PC is continually online whilst in operation. You've mentioned "shutting down AOL", but the actual connection of the PC to the modem must be disabled to have your system isolated. I've not had experience with AOL, but for other ISPs I've had experience with, their software does not completely disable the connection to the internet.

In fact, for the PC I'm logged in with at present, which is connected to ADSL via a gateway/router, there is not even an 'Internet connection' icon available for me to disable. I'd need to access the router and disable the connection, or else disable the LAN connection, for the PC to be disconnected from the internet.

Of course updates will download whilst I'm not using my email client or my web browser. All my programs can access the internet as well, should they need to. That's part of the concept of broadband internet - an 'always connected' PC which can extend its functionality by way of access to data elsewhere.

Thanks Catweazle
I follow what you are saying (despite not being a tech person) But the question is a valid one... What if somebody learnt how to use this method? It would only take less than 5 minutes work to upload a nasty to all the "always on" computers

That is why, Answerpooler, if you have a Broadband connection you should always at least have the 'Internet connection firewall' enabled, preferably a more comprehensive Firewall program running, and ideally a hardware firewall sitting between your PC and the internet.

I personally, for ADSL, use a combination modem/router/firewall unit. They can be purchased for only a few dollars more than an ADSL ethernet modem, and anyone who has ADSL should be using one, regardless of whether they are networking PCs together or not! It's the safest way to be connected!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.