Microsoft relaxes telemetry rule for PCs managed with Windows Update for Business

Credit to Author: Gregg Keizer| Date: Wed, 07 Aug 2019 13:12:00 -0700

Microsoft has quietly relaxed a rule that prevented privacy-first organizations from managing the Windows Update for Business (WUfB) service using group policies.

With Windows 10 1903, aka “Windows 10 May 2019 Update,” which debuted in late May, organizations no longer are required to set the “diagnostic data level” for their devices to “Basic” or higher.

That diagnostic data level is a multi-step categorization of what Microsoft pulls from Windows devices and sends to its own servers. Also dubbed “telemetry,” the data harvesting is used by Microsoft for a range of tasks, notably deciding when a specific PC receives a feature upgrade.

To read this article in full, please click here

Read more

Microsoft Patch Alert: Welcome to the Upside Down

Credit to Author: Woody Leonhard| Date: Tue, 30 Jul 2019 09:33:00 -0700

This month, Microsoft Patch Land looks like a stranger Stranger Things Upside Down, where Security-only patches carry loads of telemetry, Visual Studio patches appear for the wrong versions… and we still can’t figure out how to keep the Win10 1903 upgrade demogorgon from swallowing established drivers.

As we end the month, we’ve seen the second “optional” monthly cumulative updates for all Win10 versions — the 1903 patch was released, pulled, then re-released — and fixes for Visual Studio’s transgressions. There’s a kludge for getting the Win10 1903 upgrade to work. And BlueKeep still looms like a gorging Mind Flayer.

Win7 Security-only patch brings telemetry

Those of you who have been dodging Windows 7 telemetry by using the monthly Security-only patches — a process I described as “Group B” three years ago — have reached the end of the road. The July 2019 Win7 “Security-only” patch, KB4507456, includes a full array of telemetry/snooping, uh, enhancements.

To read this article in full, please click here

Read more

BlueKeep guides make imminent public exploit more likely

Credit to Author: Danny Bradbury| Date: Fri, 26 Jul 2019 11:40:12 +0000

A public exploit for Microsoft’s BlueKeep vulnerability is just days away. In fact, for those with deep pockets, it’s already here.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/ECYOzBCkJ4g” height=”1″ width=”1″ alt=””/>

Read more

Changing California’s privacy law: A snapshot at the support and opposition

Credit to Author: David Ruiz| Date: Thu, 25 Jul 2019 15:59:59 +0000

Before the California Senate returns from its summer recess, we look at the authors, supporters, opponents, and donors involved in an extended fight to change California’s privacy law, the California Consumer Privacy Act.

Categories:

Tags:

(Read more…)

The post Changing California’s privacy law: A snapshot at the support and opposition appeared first on Malwarebytes Labs.

Read more

New Windows 7 'security-only' update installs telemetry/snooping, uh, feature

Credit to Author: Woody Leonhard| Date: Thu, 11 Jul 2019 03:16:00 -0700

Back in October 2016, Microsoft divided the Win7 and 8.1 patching worlds into two parts.

Those who got their patches through Windows Update received so-called Monthly Rollups, which included security patches, bug fixes – and we frankly don’t know what else – rolled out in a cumulative stream.

The folks who were willing to download and manually install patches were also given the option of installing “security-only” patches, not cumulative; these were meant to address just the security holes.

To read this article in full, please click here

Read more