Are you running Windows 7 or Server 2008? There are some important updates coming down the pike, and you need to install them if you want to keep gett
[See the full post at: Patch Lady: Preparing for Microsoft’s patch-security changes]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Patch Lady: Preparing for Microsoft’s patch-security changes
Home » Forums » Newsletter and Homepage topics » Patch Lady: Preparing for Microsoft’s patch-security changes
- This topic has 14 replies, 10 voices, and was last updated 5 years, 5 months ago.
AuthorTopicViewing 3 reply threadsAuthorReplies-
MrJimPhelps
AskWoody MVPApril 8, 2019 at 6:48 am #349734For years, Microsoft has continued to use SHA-1, assuming that the chances of a valid attack are small. Currently, Windows 10 supports both SHA-1 and the more secure SHA-2, but Win7 systems have supported only SHA-1. Later this year, however, things will change — Microsoft’s entire infrastructure and patching mechanisms will require SHA-2.
When Microsoft switches to SHA-2, there will be some old software what will no longer work, because it will be dependent on SHA-1. I predict that when this happens, there will be a lot of complaints that “Windows 10 broke my software”. That would be one way to look at it. But a more accurate way to look at it, in my opinion, is that you had some old software that the vendor refused to update to SHA-2, and now you are getting bit. In other words, it isn’t Microsoft’s fault, even though they will get blamed for it.
Same thing for SMB v.1. Windows 10-1809 defaulted to a newer version of SMB; there were likely those who blamed Windows 10, but in fact Microsoft was simply plugging a security hole; and it is easy to allow SMB v.1 if you want to.
Group "L" (Linux Mint)
with Windows 10 running in a remote session on my file server -
Seff
AskWoody PlusApril 8, 2019 at 9:34 am #349771Thanks for the article, Susan, most informative as ever. However:-
“I recommend you not install any of these SHA-related updates on the regular Patch Tuesdays (the second week of each month). Rather, add them at the end of the month to ensure they’re installed by themselves and that there’s no interference from feature and security patches.”
Isn’t that contrary to Microsoft’s recommendation (endorsed variously here with this month’s updates) that the SHA-related updates should be installed separately before the usual monthly quality rollup?
Just in the last few days I installed the March updates on both my Windows 7 x64 home desktops by hiding everything so as to be offered KB4490628 which I installed. Then I restored the hidden updates and installed KB4474419 followed separately by KB4489878 (quality rollup). Finally, on the one relevant machine I installed the 5 Important and checked Office 2010 updates, leaving the remaining Important but unchecked Office 2010 update untouched. I followed all appropriate “restart” prompts and left time between the different installations for things to settle down. It all went smoothly.
I hope we can get a clear recommendation in future months as to whether we have to go through this or some other somewhat tortuous procedure, or can simply install the updates in the sequence in which they are offered to us.
-
PKCano
Manager -
Seff
AskWoody PlusApril 8, 2019 at 10:46 am #349828Indeed PK, but both are considered together in Susan’s article with the conclusion – in the plural – that I quoted above, and with no suggestion that the two updates mentioned should be considered and installed differently from each other.
That is why I expressed the hope that there would be greater clarification in future months. There’s clearly confusion on Microsoft’s part in the way the updates are offered otherwise we would be offered the one that has to be installed first before being offered anything else, whereas it’s only when we have installed (or known to hide) all the others that we get offered the one that they say should have been installed first – that’s why I think that we should ensure maximum clarification each month as to how to proceed with these particular updates and any others like them.
-
PKCano
Manager -
LHiggins
AskWoody PlusApril 8, 2019 at 1:55 pm #349924OK a question. On my Win 7 laptop, I checked and was offered KB4474419 – which I installed. I rechecked and was then offered KB4490628, also installed.
Then, on my Win 7 desktop, I repeated the procedure and was offered KB4474419 and KB 4493132. Since KB 4493132 is the Win 10 nag update, I hid it, installed KB4474419 and then rescanned to get KB4490628. That never appeared – and Win Update says there are no other updates. I am Group A and pretty much just wait for Woody’s go ahead and install what he says it safe each month.
So – how will I be able to get KB4490628? Should I just download it directly since it isn’t offered – or wait till the end of the next update cycle and see if it is offered then?
-
DrBonzo
AskWoody PlusApril 8, 2019 at 2:13 pm #349928I, personally, try to do as little updating through Windows Update as possible. I’m Win 7 Pro, sp1, x64, Group B. I just download the Service Stack Updates from the catalog and manually install them. That makes it an ‘exclusive install’, as required (make sure you’ve done any required reboots from any previous patch installs and make sure to reboot if required after the SSU install – although I don’t remember a reboot being required). No fuss, no muss, works great, no resultant system issues.
1 user thanked author for this post.
-
LHiggins
AskWoody PlusApril 8, 2019 at 2:30 pm #349933Thanks! Guess I’ll reboot to be sure there are no issues and go ahead and download that one. Glad it worked fine! I have no issues on the laptop, which did get both of those this morning – but for some reason, the desktop isn’t showing KB4490628. Weird!
ETA – Just noticed the DEFCON has changed to 2 – so maybe I’ll wait till next month for it – LOL!
-
-
-
-
-
shirlswoody
AskWoody PlusApril 8, 2019 at 4:20 pm #349959First time here. Don’t know quite how to use this, and I apologize if I’m in the wrong place!! But here is my question. I have win7 on a laptop, and have never been offered KB4474419. Is there a reason that it has not appeared when MS offers its updates?? I have never searched out an update, so is it okay if I go online and download it? And install it?? (I have installed 4490628.)
-
PKCano
Manager
-
-
PerthMike
AskWoody PlusApril 8, 2019 at 9:29 pm #350022Which brings up an interesting question.
If I deploy a fresh install of Windows 7 after July/September, will it still be able to get to Windows Update to (at the very least) download the patches to update itself to the new SHA2 patch? I assume the minimum would be SP1, a pile of Servicing Stack updates and then 4484071? Or will Windows update just break altogether for PCs that are freshly built?
I guess it’s a good thing I always keep WSUSOffline up to date with a set of patches.
No matter where you go, there you are.
Viewing 3 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Help with WD usb driver on Windows 11
by
Tex265
9 minutes ago -
hibernate activation
by
e_belmont
59 minutes ago -
Red Hat Enterprise Linux 10 with AI assistant
by
Alex5723
4 hours, 47 minutes ago -
Windows 11 Insider Preview build 26200.5603 released to DEV
by
joep517
7 hours, 51 minutes ago -
Windows 11 Insider Preview build 26120.4151 (24H2) released to BETA
by
joep517
7 hours, 53 minutes ago -
Fixing Windows 24H2 failed KB5058411 install
by
Alex5723
11 hours, 3 minutes ago -
Out of band for Windows 10
by
Susan Bradley
12 hours, 36 minutes ago -
Giving UniGetUi a test run.
by
RetiredGeek
19 hours, 34 minutes ago -
Windows 11 Insider Preview Build 26100.4188 (24H2) released to Release Preview
by
joep517
1 day, 3 hours ago -
Microsoft is now putting quantum encryption in Windows builds
by
Alex5723
1 day, 1 hour ago -
Auto Time Zone Adjustment
by
wadeer
1 day, 7 hours ago -
To download Win 11 Pro 23H2 ISO.
by
Eddieloh
1 day, 5 hours ago -
Manage your browsing experience with Edge
by
Mary Branscombe
9 hours, 55 minutes ago -
Fewer vulnerabilities, larger updates
by
Susan Bradley
20 hours, 51 minutes ago -
Hobbies — There’s free software for that!
by
Deanna McElveen
4 hours, 45 minutes ago -
Apps included with macOS
by
Will Fastie
2 hours, 37 minutes ago -
Xfinity home internet
by
MrJimPhelps
1 day ago -
Convert PowerPoint presentation to Impress
by
RetiredGeek
1 day ago -
Debian 12.11 released
by
Alex5723
2 days, 4 hours ago -
Microsoft: Troubleshoot problems updating Windows
by
Alex5723
2 days, 8 hours ago -
Woman Files for Divorce After ChatGPT “Reads” Husband’s Coffee Cup
by
Alex5723
1 day, 11 hours ago -
Moving fwd, Win 11 Pro,, which is best? Lenovo refurb
by
Deo
22 minutes ago -
DBOS Advanced Network Analysis
by
Kathy Stevens
3 days, 1 hour ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
2 days, 15 hours ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
13 hours, 32 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
2 days, 20 hours ago -
Some advice for managing my wireless internet gateway
by
LHiggins
2 days, 3 hours ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
1 day, 5 hours ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
3 days, 13 hours ago -
Sometimes I wonder about these bots
by
Susan Bradley
1 day, 1 hour ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.