top 50 comments

sorted by: hot top controversial new old
[–] 295 points 2 years ago* (17 children)

Since rolling back to the previous configuration will present a challenge, affected users will be faced with finding out just how effective their backup strategy is or paying for the required license and dealing with all the changes that come with Windows Server 2025.

Accidentally force your customers to have to spend money to upgrade, how convenient.

  • source
  • hideshow 17 child comments
  • [–] 80 points 2 years ago (10 children)

    Since MS forced the upgrade, you should get 2025 for free. That would probably be really easy to argue in court

  • source
  • parent
  • hideshow 10 child comments
  • [–] 69 points 2 years ago (9 children)

    Ah, but did you read the article?

    MS didn't force it, Heimdal auto-updated it for their customers based on the assumption that Microsoft would label the update properly instead of it being labeled as a regular security patch. Microsoft however made a mistake (on purpose or not? Who knows...) in labeling it.

  • source
  • parent
  • hideshow 9 child comments
  • [–] 93 points 2 years ago (8 children)

    Then it's still on Microsoft for pushing that update through what is essentially a patch pipeline

  • source
  • parent
  • hideshow 8 child comments
  • load more comments (7 replies)
  • [–] 95 points 2 years ago (12 children)

    Misleading title. It was installed by a third-party updater, Heimdall, but MS labeled a Windows 11 update wrong.

  • source
  • hideshow 12 child comments
  • [–] [S] 119 points 2 years ago (7 children)

    They labelled an OS version upgrade as a security update.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 27 points 2 years ago (5 children)

    Yet another reason to not do auto-updates in an enterprise environment for mission-critical services.

  • source
  • parent
  • hideshow 5 child comments
  • [–] [S] 41 points 2 years ago (4 children)

    In an enterprise environment, you rely on a service that tracks CVEs, analyzes which ones apply to your environment, and prioritizes security critical updates.
    The issue here is that one of these services installed a release upgrade because Microsoft mislabelled it as security update.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 2 years ago (3 children)

    Should still be doing phased rollouts of any patches, and where possible, implementing them on pre-prod first.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 11 points 2 years ago*

    Pre-prod is ideal, but a pipe dream for many. Lots of folks barely get prod.

    We still stagger patching so things like this only wipe some of the critical infrastructure, but that still causes needless issues.

  • source
  • parent
  • load more comments (1 reply)
  • load more comments (4 replies)
    [–] 87 points 2 years ago (9 children)

    I'm truly, totally, completely shocked ... that Windows is still being used on the server side.

  • source
  • hideshow 9 child comments
  • load more comments (1 reply)
    [–] 46 points 2 years ago (2 children)

    It must have been the same fun as when back in 2012 (or 2013?) McAfee (at least I think it was them) identified /system32 as a threat and deleted it :)

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 36 points 2 years ago (25 children)

    Do system administrators still exist? Honest question. I was one of those years ago and layoffs, forced back to office bullshit drove me away

  • source
  • hideshow 25 child comments
  • [–] 17 points 2 years ago (9 children)

    There are dozens of us (working for MSPs because in house doesn't pay as well and companies are cheap and want to outsource that cost center)!

  • source
  • parent
  • hideshow 9 child comments
  • [–] [S] 30 points 2 years ago (8 children)

    I switched from an MSP to a unionized in-house position, doubled my salary and my days of paid time off.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 9 points 2 years ago (3 children)

    I worked for a classic MSP a while back, barely lasted 3 months. Such a toxic environment, tons of pressure to spread yourself thinner and thinner.

    It was one of those places where you were expected to be there an hour early, stay an hour late, and work through your lunch.

    Even though that's illegal, it was never explicit, just one of those, wink wink type things. But the workload was always so heavy, you couldn't stay on top of everything unless you were working 50+ hours a week.

    And of course, all salary, no overtime or double time for weekend work.

    I do internal IT now, much better. Trying to get my own one-person shop going to eventually be fully self-employed. Actually, it would be really cool to become a worker-owned co-op, but that's still a faint dream.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (3 replies)
  • load more comments (4 replies)
  • load more comments (5 replies)
    [–] 35 points 2 years ago (1 child)

    I know this has nothing to do with my home computer, but this just further affirms my decision to switch to Linux earlier this year.

  • source
  • hideshow 1 child comment
  • [–] 33 points 2 years ago (5 children)

    When the OS becomes the virus

  • source
  • hideshow 5 child comments
  • [–] 7 points 2 years ago (4 children)

    When reading comprehension is limited to the title.
    MS mislabeled the update
    Heimdal (apparently a patchmanagement) auto-installed the falsely labeled update.

    If OP (this was reported by a Redditor on r/sysadmin) and their company is unable to properly set grace periods for windows updates I can't help them either.
    IMHO you are supposed to manually review and release updates either on a WSUS or the management interface of your patching solution.
    Not just "Hehe, auto install and see what happens".
    And if you do that shit, set a timeout for 14 days at least for uncritical rated updates.

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (4 replies)
  • [–] 20 points 2 years ago (6 children)

    Hate to be that guy but if you automatically patch critical infrastructure or apply patches without reading their description first, you kinda did it to yourself. There’s a very good reason not a single Linux distribution patches itself (by default) and wants you to read and understand the packages you’re updating and their potential effects on your system

  • source
  • hideshow 6 child comments
  • [–] 15 points 2 years ago (1 child)

    Many distros (at least Ubuntu) auto-installs security updates, and here a mislabeled "security update" was auto-installed. This is not the fault of the sysadmins.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 7 points 2 years ago

    here a mislabeled "security update" was auto-installed.

    To be fair, you would have to read all the way to the first paragraph to get this information from the article. Hard to blame people for not knowing this critical bit of information when it was buried so deep

  • source
  • parent
  • load more comments (3 replies)
    [–] 17 points 2 years ago (1 child)

    You thought you were in control?

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 12 points 2 years ago

    Crowdstrike moment

  • source
  • [–] 10 points 2 years ago (2 children)

    Meanwhile I've still got customers who are running CentOS 6.

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 9 points 2 years ago

    "Labeling error"

    Lol, okay.

  • source
  • [–] 7 points 2 years ago

    Of all the people MS doesn't want to piss off.

  • source
  • load more comments
    view more: next ›