Replacing Windows 7 security updates with anti-virus?Does anti-virus/security software protect against NTFS ADS?How to list missing security updates for Windows servers?Anti Virus IntergrationSecurity Benefits in Replacing Windows Desktop Programs with New Windows Store Apps for Higher-Risk Uses?Comparing Anti-VirusWhat is problem with open source anti-virusHow secure is a virtual machine and free VPN?Chicken-and-egg-problem: What's the intended secure way of installing anti-virus software with online installers?AVG detects Kaspersky update files as infected (trojan, infected, malware)Real time Anti-virus communication with API hooks

Do I really need to have a scientific explanation for my premise?

Why would one plane in this picture not have gear down yet?

Reverse string, can I make it faster?

Good for you! in Russian

Should I tell my boss the work he did was worthless

Is Gradient Descent central to every optimizer?

Aliens englobed the Solar System: will we notice?

Peter's Strange Word

Is "history" a male-biased word ("his+story")?

Unreachable code, but reachable with exception

Time travel short story where dinosaur doesn't taste like chicken

Word for a person who has no opinion about whether god exists

Who deserves to be first and second author? PhD student who collected data, research associate who wrote the paper or supervisor?

Look through the portal of every day

Can someone explain what is being said here in color publishing in the American Mathematical Monthly?

They call me Inspector Morse

Examples of a statistic that is not independent of sample's distribution?

If the Captain's screens are out, does he switch seats with the co-pilot?

Extra alignment tab has been changed to cr. } using table, tabular and resizebox

How do I deal with a powergamer in a game full of beginners in a school club?

Why the color red for the Republican Party

What wound would be of little consequence to a biped but terrible for a quadruped?

Force user to remove USB token

How do you like my writing?



Replacing Windows 7 security updates with anti-virus?


Does anti-virus/security software protect against NTFS ADS?How to list missing security updates for Windows servers?Anti Virus IntergrationSecurity Benefits in Replacing Windows Desktop Programs with New Windows Store Apps for Higher-Risk Uses?Comparing Anti-VirusWhat is problem with open source anti-virusHow secure is a virtual machine and free VPN?Chicken-and-egg-problem: What's the intended secure way of installing anti-virus software with online installers?AVG detects Kaspersky update files as infected (trojan, infected, malware)Real time Anti-virus communication with API hooks













27















Microsoft has announced Windows 7 will no longer be receiving updates after January 14, 2020: Here.



I hate windows 10's forced updates and telemetry so I have always stuck with Windows 7, but it may be as good as dead after the lack of security updates.



Linus Tech Tips did a great video covering this issue: Here.



With this massive change I was wondering if anyone knew of the real impact this would have. Can third-party Anti-virus successfully substitute Windows 7 security updates after they are discontinued?



Right now I use Malwarebytes and AVG, and I feel as though this would be enough but this is something you have to be sure about.



With Windows Vista I feel as though this has already been studied but, I am not clever enough to google the right words. So I have turned to the amazing community here for solid answers.



Is Windows 7 being left 4 dead, or is Y2K coming back for round 2?










share|improve this question









New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.















  • 10





    Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

    – GrandOpener
    8 hours ago






  • 3





    the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

    – Trevor Boyd Smith
    5 hours ago






  • 1





    You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

    – starbeamrainbowlabs
    3 hours ago











  • I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

    – chiliNUT
    2 hours ago















27















Microsoft has announced Windows 7 will no longer be receiving updates after January 14, 2020: Here.



I hate windows 10's forced updates and telemetry so I have always stuck with Windows 7, but it may be as good as dead after the lack of security updates.



Linus Tech Tips did a great video covering this issue: Here.



With this massive change I was wondering if anyone knew of the real impact this would have. Can third-party Anti-virus successfully substitute Windows 7 security updates after they are discontinued?



Right now I use Malwarebytes and AVG, and I feel as though this would be enough but this is something you have to be sure about.



With Windows Vista I feel as though this has already been studied but, I am not clever enough to google the right words. So I have turned to the amazing community here for solid answers.



Is Windows 7 being left 4 dead, or is Y2K coming back for round 2?










share|improve this question









New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.















  • 10





    Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

    – GrandOpener
    8 hours ago






  • 3





    the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

    – Trevor Boyd Smith
    5 hours ago






  • 1





    You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

    – starbeamrainbowlabs
    3 hours ago











  • I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

    – chiliNUT
    2 hours ago













27












27








27


5






Microsoft has announced Windows 7 will no longer be receiving updates after January 14, 2020: Here.



I hate windows 10's forced updates and telemetry so I have always stuck with Windows 7, but it may be as good as dead after the lack of security updates.



Linus Tech Tips did a great video covering this issue: Here.



With this massive change I was wondering if anyone knew of the real impact this would have. Can third-party Anti-virus successfully substitute Windows 7 security updates after they are discontinued?



Right now I use Malwarebytes and AVG, and I feel as though this would be enough but this is something you have to be sure about.



With Windows Vista I feel as though this has already been studied but, I am not clever enough to google the right words. So I have turned to the amazing community here for solid answers.



Is Windows 7 being left 4 dead, or is Y2K coming back for round 2?










share|improve this question









New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.












Microsoft has announced Windows 7 will no longer be receiving updates after January 14, 2020: Here.



I hate windows 10's forced updates and telemetry so I have always stuck with Windows 7, but it may be as good as dead after the lack of security updates.



Linus Tech Tips did a great video covering this issue: Here.



With this massive change I was wondering if anyone knew of the real impact this would have. Can third-party Anti-virus successfully substitute Windows 7 security updates after they are discontinued?



Right now I use Malwarebytes and AVG, and I feel as though this would be enough but this is something you have to be sure about.



With Windows Vista I feel as though this has already been studied but, I am not clever enough to google the right words. So I have turned to the amazing community here for solid answers.



Is Windows 7 being left 4 dead, or is Y2K coming back for round 2?







antivirus windows-10 updates microsoft windows-7






share|improve this question









New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.











share|improve this question









New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









share|improve this question




share|improve this question








edited 8 hours ago









schroeder

77.4k30171206




77.4k30171206






New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.









asked 19 hours ago









TritiumCatTritiumCat

15226




15226




New contributor




TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.





New contributor





TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.






TritiumCat is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.







  • 10





    Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

    – GrandOpener
    8 hours ago






  • 3





    the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

    – Trevor Boyd Smith
    5 hours ago






  • 1





    You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

    – starbeamrainbowlabs
    3 hours ago











  • I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

    – chiliNUT
    2 hours ago












  • 10





    Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

    – GrandOpener
    8 hours ago






  • 3





    the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

    – Trevor Boyd Smith
    5 hours ago






  • 1





    You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

    – starbeamrainbowlabs
    3 hours ago











  • I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

    – chiliNUT
    2 hours ago







10




10





Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

– GrandOpener
8 hours ago





Without knowing your requirements, it's worth mentioning that if you really hate Windows 10, there are at least two other desktop OSes worth considering. Many developers actually consider one of the others to be superior for many tasks. Your mileage will vary depending on your use case. If you do have requirements that mandate Windows, you can at least become familiar with the Privacy and Diagnostics pages of the Settings app to disable most information sharing and telemetry.

– GrandOpener
8 hours ago




3




3





the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

– Trevor Boyd Smith
5 hours ago





the only way I know of to safely run a machine that runs an operating system that is end-of-life'd (i.e. no more updates/patches/bug-fixes)... is to run the machine on an air-gapped network or no network. and be very careful what files you transfer to the machine (files are transferred to the machine via physical media transfer).

– Trevor Boyd Smith
5 hours ago




1




1





You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

– starbeamrainbowlabs
3 hours ago





You may find that another operating system besides Microsoft Windows is more to your liking. Perhaps consider doing some research in this area if Windows 10 is not up your street.

– starbeamrainbowlabs
3 hours ago













I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

– chiliNUT
2 hours ago





I was stuck on windows 7 for a long time, the 3 things that got me past it to windows 10: Getting classic shell set up correctly, realizing windows 10 is not the dumpster fire that is Windows 8/8.1, and proper bluetooth audio support

– chiliNUT
2 hours ago










4 Answers
4






active

oldest

votes


















46














Nope.



After Microsoft discontinue security updates for a version of Windows there is not a safe way to run that version of Windows.



Some people will promote Virtual Patching where you have a external firewall scan all your traffic looking for patterns of traffic that look malicious. I would not trust that, and it requires a seperate non-vulnerable computer.



A number of vulnerabilities patched by Microsoft are not the sort that anti-virus are good at catching. In the most recent example Google announced a Chrome Bug plus Windows 7 bug that caused visiting a site to remotely execute arbitrary code, this was being used in the wild. After end-of-life Microsoft will not patch this type of bug. (https://www.zdnet.com/article/google-chrome-zero-day-was-used-together-with-a-windows-7-zero-day/)






share|improve this answer


















  • 16





    @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

    – James Trotter
    14 hours ago







  • 26





    @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

    – Luaan
    14 hours ago






  • 10





    @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

    – Brian Leishman
    10 hours ago






  • 7





    "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

    – mbomb007
    9 hours ago






  • 9





    @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

    – jpmc26
    6 hours ago



















21














No, anti-malware is not a replacement for security updates.



Neil Matz summarized the Fortinet's Q2 Global Threat Landscape report for 2017, noticing:




WannaCry and NotPetya targeted a vulnerability that had been
patched by Microsoft a few months earlier.



But it’s not just these high-profile attacks that target recent
vulnerabilities that are the problem. During Q2, 90% of organizations
recorded exploits against vulnerabilities that were three or more
years old. And 60% of firms experienced successful attacks targeting
devices for which a patch had been available for ten or more years!




You hate Windows 10's forced updates and telemetry. Using gpedit.msc you can can modify:



  • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates. It's still possible to choose 2 = Notify before downloading and installing any updates.



  • It's possible to get the feature updates only after they are actually ready (i.e. tested and complained by the end users). ... > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received:




    When Selecting Semi-Annual Channel (Targeted) or Semi-Annual Channel:



    • You can defer receiving Feature Updates for up to 365 days.



  • Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Allow Telemetry = 0 Security sends only a minimal amount of data to Microsoft. Too much? You can disable the DiagTrack: Connected User Experiences and Telemetry service.


Windows 10 was the first Windows with cumulative updates, which actually means less updates. Since October 2016 there has been no difference as Microsoft stopped individual updates for every supported Windows and currently all updates are in rollup model. (You can read more about servicing differences).






share|improve this answer




















  • 4





    Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

    – Overmind
    12 hours ago












  • I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

    – Esa Jokinen
    7 hours ago











  • I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

    – Esa Jokinen
    7 hours ago






  • 1





    Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

    – razethestray
    4 hours ago











  • Ok. Then one would need to edit the registry values those group policy settings alter.

    – Esa Jokinen
    4 hours ago


















4














There is no realistic substitute for software patches.



There are additional security measures one can take, but all of them have their limitations.



  • Antiviruses will not do a thing against attacks that do not write to disk. If an attacker hijacks a legitimate process in memory, it's open-season on your data. These kinds of attacks are becoming more and more common.


  • Firewalls and IDSes (of either the software and hardware variety) can catch malicious traffic that matches a signature. The slightest bit of customisation will defeat this.


  • All software measures rely on your core operating system being trustworthy. A core OS with security holes like Swiss cheese cannot be trusted.


  • Hardware measures rely on you having a spare machine with software that has a supported OS anyway.






share|improve this answer
































    1














    Windows 7 was released 10 years ago. Wanting to use win 7 now is the same as wanting to use win xp in 2013 (the year windows 8.1 was released), or wanting to use windows 95 in 2004. There were such guys in that era too, and we made fun of them at the time1. Technology is changing, you should learn to adapt if you want to succeed in this field. If you want to schedule your own update times or prevent some updates to install completely you can spend some more bucks for the pro version of windows 10, regarding telemetry I have bad news for you: there's also in windows 7, and the quantity of information can't be configured as in windows 10 so you keep the defaults, whether you like that or not.



    To answer your question: there is no way an external small software house can patch vulnerabilities of a closed source operating system with the same efficacy as the operating system developer, the best they can do is work around known bugs by blocking features or scanning your activity for malicious patterns.
    This will slow your computer, and has bigger privacy concerns that the telemetry Microsoft gathers2.
    Also, as someone already said, there are vulnerabilities which can't be worked around outside of the operating system, so you'll keep them all.



    Relying on external protection for your outdated OS may lure you into a false sense of security and may work without issues for years (it is not like the operating system becomes insecure the exact day its support ends) but would require you to keep yourself informed on new security issues, whether they are severe, whether they affect your OS, whether they will stay unpatched and eventually determine whether you should finally leave your OS at one point. If you can afford that much time managing your installed OS just for privacy concerns you can definitely use it to install Linux and solve the issues you may encounter to the lack of certain apps in your usual workflow, it will pay off more in the future.



    Another thing that has not been said in other answers and I think affects security of an old operating system is that external app developers will eventually stop supporting it and releasing new version for it, so you may end up having old and buggy versions of apps such as browsers, which may be another surface of attack for exploiters.



    TLDR, only hassle comes with staying with Windows 7. The problems you thought Windows 10 has also affect Windows 7, and while up until now it may have been a preference choice for the old UI to justify using that operating system, from now on the technical problems which come with it will keep increasing, so stay away: either go to Win 10 or move to Linux




    1 there was arguably a reason for people to stay in an older operating system at the time, and that was the increased demand of computing power of the newer operating systems which prevented them to be installed on older machines. This is not true anymore, since Windows 10 requirements are exactly the same as the 10 year old windows 7.



    2 concern being data leakage and server vulnerabilities are more likely on a small company and more likely to be severe, because Microsoft has a much more experience in security gathered from failures accumulated along its 40 year of activity and enmity to various revolutionary hacker groups






    share|improve this answer


















    • 1





      The problem is in UI. How to accept such thing like the UI of Win10.

      – i486
      8 hours ago












    • Many orgs still use XP. Many orgs are forced to.

      – schroeder
      8 hours ago











    • Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

      – Doug O'Neal
      7 hours ago











    • @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

      – pqnet
      7 hours ago






    • 1





      @blankip: You can achieve the same safely with many currently maintained Linux distributions.

      – Esa Jokinen
      5 hours ago










    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "162"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: false,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: null,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    noCode: true, onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );






    TritiumCat is a new contributor. Be nice, and check out our Code of Conduct.









    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f205193%2freplacing-windows-7-security-updates-with-anti-virus%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    4 Answers
    4






    active

    oldest

    votes








    4 Answers
    4






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    46














    Nope.



    After Microsoft discontinue security updates for a version of Windows there is not a safe way to run that version of Windows.



    Some people will promote Virtual Patching where you have a external firewall scan all your traffic looking for patterns of traffic that look malicious. I would not trust that, and it requires a seperate non-vulnerable computer.



    A number of vulnerabilities patched by Microsoft are not the sort that anti-virus are good at catching. In the most recent example Google announced a Chrome Bug plus Windows 7 bug that caused visiting a site to remotely execute arbitrary code, this was being used in the wild. After end-of-life Microsoft will not patch this type of bug. (https://www.zdnet.com/article/google-chrome-zero-day-was-used-together-with-a-windows-7-zero-day/)






    share|improve this answer


















    • 16





      @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

      – James Trotter
      14 hours ago







    • 26





      @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

      – Luaan
      14 hours ago






    • 10





      @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

      – Brian Leishman
      10 hours ago






    • 7





      "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

      – mbomb007
      9 hours ago






    • 9





      @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

      – jpmc26
      6 hours ago
















    46














    Nope.



    After Microsoft discontinue security updates for a version of Windows there is not a safe way to run that version of Windows.



    Some people will promote Virtual Patching where you have a external firewall scan all your traffic looking for patterns of traffic that look malicious. I would not trust that, and it requires a seperate non-vulnerable computer.



    A number of vulnerabilities patched by Microsoft are not the sort that anti-virus are good at catching. In the most recent example Google announced a Chrome Bug plus Windows 7 bug that caused visiting a site to remotely execute arbitrary code, this was being used in the wild. After end-of-life Microsoft will not patch this type of bug. (https://www.zdnet.com/article/google-chrome-zero-day-was-used-together-with-a-windows-7-zero-day/)






    share|improve this answer


















    • 16





      @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

      – James Trotter
      14 hours ago







    • 26





      @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

      – Luaan
      14 hours ago






    • 10





      @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

      – Brian Leishman
      10 hours ago






    • 7





      "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

      – mbomb007
      9 hours ago






    • 9





      @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

      – jpmc26
      6 hours ago














    46












    46








    46







    Nope.



    After Microsoft discontinue security updates for a version of Windows there is not a safe way to run that version of Windows.



    Some people will promote Virtual Patching where you have a external firewall scan all your traffic looking for patterns of traffic that look malicious. I would not trust that, and it requires a seperate non-vulnerable computer.



    A number of vulnerabilities patched by Microsoft are not the sort that anti-virus are good at catching. In the most recent example Google announced a Chrome Bug plus Windows 7 bug that caused visiting a site to remotely execute arbitrary code, this was being used in the wild. After end-of-life Microsoft will not patch this type of bug. (https://www.zdnet.com/article/google-chrome-zero-day-was-used-together-with-a-windows-7-zero-day/)






    share|improve this answer













    Nope.



    After Microsoft discontinue security updates for a version of Windows there is not a safe way to run that version of Windows.



    Some people will promote Virtual Patching where you have a external firewall scan all your traffic looking for patterns of traffic that look malicious. I would not trust that, and it requires a seperate non-vulnerable computer.



    A number of vulnerabilities patched by Microsoft are not the sort that anti-virus are good at catching. In the most recent example Google announced a Chrome Bug plus Windows 7 bug that caused visiting a site to remotely execute arbitrary code, this was being used in the wild. After end-of-life Microsoft will not patch this type of bug. (https://www.zdnet.com/article/google-chrome-zero-day-was-used-together-with-a-windows-7-zero-day/)







    share|improve this answer












    share|improve this answer



    share|improve this answer










    answered 19 hours ago









    David WatersDavid Waters

    1,448713




    1,448713







    • 16





      @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

      – James Trotter
      14 hours ago







    • 26





      @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

      – Luaan
      14 hours ago






    • 10





      @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

      – Brian Leishman
      10 hours ago






    • 7





      "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

      – mbomb007
      9 hours ago






    • 9





      @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

      – jpmc26
      6 hours ago













    • 16





      @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

      – James Trotter
      14 hours ago







    • 26





      @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

      – Luaan
      14 hours ago






    • 10





      @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

      – Brian Leishman
      10 hours ago






    • 7





      "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

      – mbomb007
      9 hours ago






    • 9





      @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

      – jpmc26
      6 hours ago








    16




    16





    @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

    – James Trotter
    14 hours ago






    @TritiumCat I mean, Windows 10 is overall better than 7 so it really shouldn't be an issue.

    – James Trotter
    14 hours ago





    26




    26





    @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

    – Luaan
    14 hours ago





    @TritiumCat The forced updates aren't much different from what was used since Vista (and overall, updates are much less frequent). If you set the telemetry to Basic level (in Settings, no need for group policies etc.), the data being sent isn't much different from what was already sent in Windows XP. In the end, it's all about security and reliability - reporting crashes, hardware issues etc. Apart from the slippery slope arguments, there's little point in fearing the changes; the issues have been blown way out of proportion, and it's not like MS is the pioneer of these things either :)

    – Luaan
    14 hours ago




    10




    10





    @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

    – Brian Leishman
    10 hours ago





    @Luaan I can't wait till the "fun to hate Win 10" of the internet goes away, it's seriously over hyped how bad Win 10 is

    – Brian Leishman
    10 hours ago




    7




    7





    "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

    – mbomb007
    9 hours ago





    "there is not a safe way to run that version of Windows", not true. It's still safe to run outdated versions of Windows offline, without being connected to the Internet.

    – mbomb007
    9 hours ago




    9




    9





    @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

    – jpmc26
    6 hours ago






    @JamesTrotter I beg to differ. I miss the Windows 7 interface. The Control Panel replacements are clunky and much more limited; you often need to revert back to the old interface anyway, which is harder to access now. Accessing the shut down menu via keyboard is now much more difficult. The privacy settings are configured to send everything by default, so you have to hunt them all down. And the most annoying thing: forced reboots even if your programs are running, possibly making you lose work. The bottom line is that Windows 10 was not designed with serving the user as the priority.

    – jpmc26
    6 hours ago














    21














    No, anti-malware is not a replacement for security updates.



    Neil Matz summarized the Fortinet's Q2 Global Threat Landscape report for 2017, noticing:




    WannaCry and NotPetya targeted a vulnerability that had been
    patched by Microsoft a few months earlier.



    But it’s not just these high-profile attacks that target recent
    vulnerabilities that are the problem. During Q2, 90% of organizations
    recorded exploits against vulnerabilities that were three or more
    years old. And 60% of firms experienced successful attacks targeting
    devices for which a patch had been available for ten or more years!




    You hate Windows 10's forced updates and telemetry. Using gpedit.msc you can can modify:



    • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates. It's still possible to choose 2 = Notify before downloading and installing any updates.



    • It's possible to get the feature updates only after they are actually ready (i.e. tested and complained by the end users). ... > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received:




      When Selecting Semi-Annual Channel (Targeted) or Semi-Annual Channel:



      • You can defer receiving Feature Updates for up to 365 days.



    • Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Allow Telemetry = 0 Security sends only a minimal amount of data to Microsoft. Too much? You can disable the DiagTrack: Connected User Experiences and Telemetry service.


    Windows 10 was the first Windows with cumulative updates, which actually means less updates. Since October 2016 there has been no difference as Microsoft stopped individual updates for every supported Windows and currently all updates are in rollup model. (You can read more about servicing differences).






    share|improve this answer




















    • 4





      Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

      – Overmind
      12 hours ago












    • I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

      – Esa Jokinen
      7 hours ago











    • I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

      – Esa Jokinen
      7 hours ago






    • 1





      Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

      – razethestray
      4 hours ago











    • Ok. Then one would need to edit the registry values those group policy settings alter.

      – Esa Jokinen
      4 hours ago















    21














    No, anti-malware is not a replacement for security updates.



    Neil Matz summarized the Fortinet's Q2 Global Threat Landscape report for 2017, noticing:




    WannaCry and NotPetya targeted a vulnerability that had been
    patched by Microsoft a few months earlier.



    But it’s not just these high-profile attacks that target recent
    vulnerabilities that are the problem. During Q2, 90% of organizations
    recorded exploits against vulnerabilities that were three or more
    years old. And 60% of firms experienced successful attacks targeting
    devices for which a patch had been available for ten or more years!




    You hate Windows 10's forced updates and telemetry. Using gpedit.msc you can can modify:



    • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates. It's still possible to choose 2 = Notify before downloading and installing any updates.



    • It's possible to get the feature updates only after they are actually ready (i.e. tested and complained by the end users). ... > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received:




      When Selecting Semi-Annual Channel (Targeted) or Semi-Annual Channel:



      • You can defer receiving Feature Updates for up to 365 days.



    • Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Allow Telemetry = 0 Security sends only a minimal amount of data to Microsoft. Too much? You can disable the DiagTrack: Connected User Experiences and Telemetry service.


    Windows 10 was the first Windows with cumulative updates, which actually means less updates. Since October 2016 there has been no difference as Microsoft stopped individual updates for every supported Windows and currently all updates are in rollup model. (You can read more about servicing differences).






    share|improve this answer




















    • 4





      Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

      – Overmind
      12 hours ago












    • I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

      – Esa Jokinen
      7 hours ago











    • I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

      – Esa Jokinen
      7 hours ago






    • 1





      Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

      – razethestray
      4 hours ago











    • Ok. Then one would need to edit the registry values those group policy settings alter.

      – Esa Jokinen
      4 hours ago













    21












    21








    21







    No, anti-malware is not a replacement for security updates.



    Neil Matz summarized the Fortinet's Q2 Global Threat Landscape report for 2017, noticing:




    WannaCry and NotPetya targeted a vulnerability that had been
    patched by Microsoft a few months earlier.



    But it’s not just these high-profile attacks that target recent
    vulnerabilities that are the problem. During Q2, 90% of organizations
    recorded exploits against vulnerabilities that were three or more
    years old. And 60% of firms experienced successful attacks targeting
    devices for which a patch had been available for ten or more years!




    You hate Windows 10's forced updates and telemetry. Using gpedit.msc you can can modify:



    • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates. It's still possible to choose 2 = Notify before downloading and installing any updates.



    • It's possible to get the feature updates only after they are actually ready (i.e. tested and complained by the end users). ... > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received:




      When Selecting Semi-Annual Channel (Targeted) or Semi-Annual Channel:



      • You can defer receiving Feature Updates for up to 365 days.



    • Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Allow Telemetry = 0 Security sends only a minimal amount of data to Microsoft. Too much? You can disable the DiagTrack: Connected User Experiences and Telemetry service.


    Windows 10 was the first Windows with cumulative updates, which actually means less updates. Since October 2016 there has been no difference as Microsoft stopped individual updates for every supported Windows and currently all updates are in rollup model. (You can read more about servicing differences).






    share|improve this answer















    No, anti-malware is not a replacement for security updates.



    Neil Matz summarized the Fortinet's Q2 Global Threat Landscape report for 2017, noticing:




    WannaCry and NotPetya targeted a vulnerability that had been
    patched by Microsoft a few months earlier.



    But it’s not just these high-profile attacks that target recent
    vulnerabilities that are the problem. During Q2, 90% of organizations
    recorded exploits against vulnerabilities that were three or more
    years old. And 60% of firms experienced successful attacks targeting
    devices for which a patch had been available for ten or more years!




    You hate Windows 10's forced updates and telemetry. Using gpedit.msc you can can modify:



    • Computer Configuration > Administrative Templates > Windows Components > Windows Update > Configure Automatic Updates. It's still possible to choose 2 = Notify before downloading and installing any updates.



    • It's possible to get the feature updates only after they are actually ready (i.e. tested and complained by the end users). ... > Windows Components > Windows Update > Windows Update for Business > Select when Preview Builds and Feature Updates are received:




      When Selecting Semi-Annual Channel (Targeted) or Semi-Annual Channel:



      • You can defer receiving Feature Updates for up to 365 days.



    • Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Allow Telemetry = 0 Security sends only a minimal amount of data to Microsoft. Too much? You can disable the DiagTrack: Connected User Experiences and Telemetry service.


    Windows 10 was the first Windows with cumulative updates, which actually means less updates. Since October 2016 there has been no difference as Microsoft stopped individual updates for every supported Windows and currently all updates are in rollup model. (You can read more about servicing differences).







    share|improve this answer














    share|improve this answer



    share|improve this answer








    edited 16 hours ago

























    answered 18 hours ago









    Esa JokinenEsa Jokinen

    2,323617




    2,323617







    • 4





      Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

      – Overmind
      12 hours ago












    • I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

      – Esa Jokinen
      7 hours ago











    • I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

      – Esa Jokinen
      7 hours ago






    • 1





      Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

      – razethestray
      4 hours ago











    • Ok. Then one would need to edit the registry values those group policy settings alter.

      – Esa Jokinen
      4 hours ago












    • 4





      Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

      – Overmind
      12 hours ago












    • I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

      – Esa Jokinen
      7 hours ago











    • I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

      – Esa Jokinen
      7 hours ago






    • 1





      Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

      – razethestray
      4 hours ago











    • Ok. Then one would need to edit the registry values those group policy settings alter.

      – Esa Jokinen
      4 hours ago







    4




    4





    Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

    – Overmind
    12 hours ago






    Your answer is too generic. That does not work in W10Home, for example. Also, all the W10 part is not relevant to the topic. Also, cumulative updates are kind of a service pack. Difference is, they mostly break things instead of fixing them.

    – Overmind
    12 hours ago














    I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

    – Esa Jokinen
    7 hours ago





    I agree that part isn't completely on-topic on this site, but it tries to help OP with the (XY) problem. This kind of myths should be challenged. There's still too many out there thinking XP is the best Windows, for similar reasons.

    – Esa Jokinen
    7 hours ago













    I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

    – Esa Jokinen
    7 hours ago





    I don't really play with home editions, but I suppose Select when Preview Builds and Feature Updates are received is the only one that doesn't work on them, right?

    – Esa Jokinen
    7 hours ago




    1




    1





    Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

    – razethestray
    4 hours ago





    Home doesn't have gpedit.msc. But you are exactly right - sticking with old versions is really a very bad security practice. I have adjusted to Win10 with all the settings you suggest and find my terrible soon to be replaced Win7 machine at work quite troublesome now.

    – razethestray
    4 hours ago













    Ok. Then one would need to edit the registry values those group policy settings alter.

    – Esa Jokinen
    4 hours ago





    Ok. Then one would need to edit the registry values those group policy settings alter.

    – Esa Jokinen
    4 hours ago











    4














    There is no realistic substitute for software patches.



    There are additional security measures one can take, but all of them have their limitations.



    • Antiviruses will not do a thing against attacks that do not write to disk. If an attacker hijacks a legitimate process in memory, it's open-season on your data. These kinds of attacks are becoming more and more common.


    • Firewalls and IDSes (of either the software and hardware variety) can catch malicious traffic that matches a signature. The slightest bit of customisation will defeat this.


    • All software measures rely on your core operating system being trustworthy. A core OS with security holes like Swiss cheese cannot be trusted.


    • Hardware measures rely on you having a spare machine with software that has a supported OS anyway.






    share|improve this answer





























      4














      There is no realistic substitute for software patches.



      There are additional security measures one can take, but all of them have their limitations.



      • Antiviruses will not do a thing against attacks that do not write to disk. If an attacker hijacks a legitimate process in memory, it's open-season on your data. These kinds of attacks are becoming more and more common.


      • Firewalls and IDSes (of either the software and hardware variety) can catch malicious traffic that matches a signature. The slightest bit of customisation will defeat this.


      • All software measures rely on your core operating system being trustworthy. A core OS with security holes like Swiss cheese cannot be trusted.


      • Hardware measures rely on you having a spare machine with software that has a supported OS anyway.






      share|improve this answer



























        4












        4








        4







        There is no realistic substitute for software patches.



        There are additional security measures one can take, but all of them have their limitations.



        • Antiviruses will not do a thing against attacks that do not write to disk. If an attacker hijacks a legitimate process in memory, it's open-season on your data. These kinds of attacks are becoming more and more common.


        • Firewalls and IDSes (of either the software and hardware variety) can catch malicious traffic that matches a signature. The slightest bit of customisation will defeat this.


        • All software measures rely on your core operating system being trustworthy. A core OS with security holes like Swiss cheese cannot be trusted.


        • Hardware measures rely on you having a spare machine with software that has a supported OS anyway.






        share|improve this answer















        There is no realistic substitute for software patches.



        There are additional security measures one can take, but all of them have their limitations.



        • Antiviruses will not do a thing against attacks that do not write to disk. If an attacker hijacks a legitimate process in memory, it's open-season on your data. These kinds of attacks are becoming more and more common.


        • Firewalls and IDSes (of either the software and hardware variety) can catch malicious traffic that matches a signature. The slightest bit of customisation will defeat this.


        • All software measures rely on your core operating system being trustworthy. A core OS with security holes like Swiss cheese cannot be trusted.


        • Hardware measures rely on you having a spare machine with software that has a supported OS anyway.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited 8 hours ago









        schroeder

        77.4k30171206




        77.4k30171206










        answered 8 hours ago









        520520

        1512




        1512





















            1














            Windows 7 was released 10 years ago. Wanting to use win 7 now is the same as wanting to use win xp in 2013 (the year windows 8.1 was released), or wanting to use windows 95 in 2004. There were such guys in that era too, and we made fun of them at the time1. Technology is changing, you should learn to adapt if you want to succeed in this field. If you want to schedule your own update times or prevent some updates to install completely you can spend some more bucks for the pro version of windows 10, regarding telemetry I have bad news for you: there's also in windows 7, and the quantity of information can't be configured as in windows 10 so you keep the defaults, whether you like that or not.



            To answer your question: there is no way an external small software house can patch vulnerabilities of a closed source operating system with the same efficacy as the operating system developer, the best they can do is work around known bugs by blocking features or scanning your activity for malicious patterns.
            This will slow your computer, and has bigger privacy concerns that the telemetry Microsoft gathers2.
            Also, as someone already said, there are vulnerabilities which can't be worked around outside of the operating system, so you'll keep them all.



            Relying on external protection for your outdated OS may lure you into a false sense of security and may work without issues for years (it is not like the operating system becomes insecure the exact day its support ends) but would require you to keep yourself informed on new security issues, whether they are severe, whether they affect your OS, whether they will stay unpatched and eventually determine whether you should finally leave your OS at one point. If you can afford that much time managing your installed OS just for privacy concerns you can definitely use it to install Linux and solve the issues you may encounter to the lack of certain apps in your usual workflow, it will pay off more in the future.



            Another thing that has not been said in other answers and I think affects security of an old operating system is that external app developers will eventually stop supporting it and releasing new version for it, so you may end up having old and buggy versions of apps such as browsers, which may be another surface of attack for exploiters.



            TLDR, only hassle comes with staying with Windows 7. The problems you thought Windows 10 has also affect Windows 7, and while up until now it may have been a preference choice for the old UI to justify using that operating system, from now on the technical problems which come with it will keep increasing, so stay away: either go to Win 10 or move to Linux




            1 there was arguably a reason for people to stay in an older operating system at the time, and that was the increased demand of computing power of the newer operating systems which prevented them to be installed on older machines. This is not true anymore, since Windows 10 requirements are exactly the same as the 10 year old windows 7.



            2 concern being data leakage and server vulnerabilities are more likely on a small company and more likely to be severe, because Microsoft has a much more experience in security gathered from failures accumulated along its 40 year of activity and enmity to various revolutionary hacker groups






            share|improve this answer


















            • 1





              The problem is in UI. How to accept such thing like the UI of Win10.

              – i486
              8 hours ago












            • Many orgs still use XP. Many orgs are forced to.

              – schroeder
              8 hours ago











            • Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

              – Doug O'Neal
              7 hours ago











            • @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

              – pqnet
              7 hours ago






            • 1





              @blankip: You can achieve the same safely with many currently maintained Linux distributions.

              – Esa Jokinen
              5 hours ago















            1














            Windows 7 was released 10 years ago. Wanting to use win 7 now is the same as wanting to use win xp in 2013 (the year windows 8.1 was released), or wanting to use windows 95 in 2004. There were such guys in that era too, and we made fun of them at the time1. Technology is changing, you should learn to adapt if you want to succeed in this field. If you want to schedule your own update times or prevent some updates to install completely you can spend some more bucks for the pro version of windows 10, regarding telemetry I have bad news for you: there's also in windows 7, and the quantity of information can't be configured as in windows 10 so you keep the defaults, whether you like that or not.



            To answer your question: there is no way an external small software house can patch vulnerabilities of a closed source operating system with the same efficacy as the operating system developer, the best they can do is work around known bugs by blocking features or scanning your activity for malicious patterns.
            This will slow your computer, and has bigger privacy concerns that the telemetry Microsoft gathers2.
            Also, as someone already said, there are vulnerabilities which can't be worked around outside of the operating system, so you'll keep them all.



            Relying on external protection for your outdated OS may lure you into a false sense of security and may work without issues for years (it is not like the operating system becomes insecure the exact day its support ends) but would require you to keep yourself informed on new security issues, whether they are severe, whether they affect your OS, whether they will stay unpatched and eventually determine whether you should finally leave your OS at one point. If you can afford that much time managing your installed OS just for privacy concerns you can definitely use it to install Linux and solve the issues you may encounter to the lack of certain apps in your usual workflow, it will pay off more in the future.



            Another thing that has not been said in other answers and I think affects security of an old operating system is that external app developers will eventually stop supporting it and releasing new version for it, so you may end up having old and buggy versions of apps such as browsers, which may be another surface of attack for exploiters.



            TLDR, only hassle comes with staying with Windows 7. The problems you thought Windows 10 has also affect Windows 7, and while up until now it may have been a preference choice for the old UI to justify using that operating system, from now on the technical problems which come with it will keep increasing, so stay away: either go to Win 10 or move to Linux




            1 there was arguably a reason for people to stay in an older operating system at the time, and that was the increased demand of computing power of the newer operating systems which prevented them to be installed on older machines. This is not true anymore, since Windows 10 requirements are exactly the same as the 10 year old windows 7.



            2 concern being data leakage and server vulnerabilities are more likely on a small company and more likely to be severe, because Microsoft has a much more experience in security gathered from failures accumulated along its 40 year of activity and enmity to various revolutionary hacker groups






            share|improve this answer


















            • 1





              The problem is in UI. How to accept such thing like the UI of Win10.

              – i486
              8 hours ago












            • Many orgs still use XP. Many orgs are forced to.

              – schroeder
              8 hours ago











            • Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

              – Doug O'Neal
              7 hours ago











            • @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

              – pqnet
              7 hours ago






            • 1





              @blankip: You can achieve the same safely with many currently maintained Linux distributions.

              – Esa Jokinen
              5 hours ago













            1












            1








            1







            Windows 7 was released 10 years ago. Wanting to use win 7 now is the same as wanting to use win xp in 2013 (the year windows 8.1 was released), or wanting to use windows 95 in 2004. There were such guys in that era too, and we made fun of them at the time1. Technology is changing, you should learn to adapt if you want to succeed in this field. If you want to schedule your own update times or prevent some updates to install completely you can spend some more bucks for the pro version of windows 10, regarding telemetry I have bad news for you: there's also in windows 7, and the quantity of information can't be configured as in windows 10 so you keep the defaults, whether you like that or not.



            To answer your question: there is no way an external small software house can patch vulnerabilities of a closed source operating system with the same efficacy as the operating system developer, the best they can do is work around known bugs by blocking features or scanning your activity for malicious patterns.
            This will slow your computer, and has bigger privacy concerns that the telemetry Microsoft gathers2.
            Also, as someone already said, there are vulnerabilities which can't be worked around outside of the operating system, so you'll keep them all.



            Relying on external protection for your outdated OS may lure you into a false sense of security and may work without issues for years (it is not like the operating system becomes insecure the exact day its support ends) but would require you to keep yourself informed on new security issues, whether they are severe, whether they affect your OS, whether they will stay unpatched and eventually determine whether you should finally leave your OS at one point. If you can afford that much time managing your installed OS just for privacy concerns you can definitely use it to install Linux and solve the issues you may encounter to the lack of certain apps in your usual workflow, it will pay off more in the future.



            Another thing that has not been said in other answers and I think affects security of an old operating system is that external app developers will eventually stop supporting it and releasing new version for it, so you may end up having old and buggy versions of apps such as browsers, which may be another surface of attack for exploiters.



            TLDR, only hassle comes with staying with Windows 7. The problems you thought Windows 10 has also affect Windows 7, and while up until now it may have been a preference choice for the old UI to justify using that operating system, from now on the technical problems which come with it will keep increasing, so stay away: either go to Win 10 or move to Linux




            1 there was arguably a reason for people to stay in an older operating system at the time, and that was the increased demand of computing power of the newer operating systems which prevented them to be installed on older machines. This is not true anymore, since Windows 10 requirements are exactly the same as the 10 year old windows 7.



            2 concern being data leakage and server vulnerabilities are more likely on a small company and more likely to be severe, because Microsoft has a much more experience in security gathered from failures accumulated along its 40 year of activity and enmity to various revolutionary hacker groups






            share|improve this answer













            Windows 7 was released 10 years ago. Wanting to use win 7 now is the same as wanting to use win xp in 2013 (the year windows 8.1 was released), or wanting to use windows 95 in 2004. There were such guys in that era too, and we made fun of them at the time1. Technology is changing, you should learn to adapt if you want to succeed in this field. If you want to schedule your own update times or prevent some updates to install completely you can spend some more bucks for the pro version of windows 10, regarding telemetry I have bad news for you: there's also in windows 7, and the quantity of information can't be configured as in windows 10 so you keep the defaults, whether you like that or not.



            To answer your question: there is no way an external small software house can patch vulnerabilities of a closed source operating system with the same efficacy as the operating system developer, the best they can do is work around known bugs by blocking features or scanning your activity for malicious patterns.
            This will slow your computer, and has bigger privacy concerns that the telemetry Microsoft gathers2.
            Also, as someone already said, there are vulnerabilities which can't be worked around outside of the operating system, so you'll keep them all.



            Relying on external protection for your outdated OS may lure you into a false sense of security and may work without issues for years (it is not like the operating system becomes insecure the exact day its support ends) but would require you to keep yourself informed on new security issues, whether they are severe, whether they affect your OS, whether they will stay unpatched and eventually determine whether you should finally leave your OS at one point. If you can afford that much time managing your installed OS just for privacy concerns you can definitely use it to install Linux and solve the issues you may encounter to the lack of certain apps in your usual workflow, it will pay off more in the future.



            Another thing that has not been said in other answers and I think affects security of an old operating system is that external app developers will eventually stop supporting it and releasing new version for it, so you may end up having old and buggy versions of apps such as browsers, which may be another surface of attack for exploiters.



            TLDR, only hassle comes with staying with Windows 7. The problems you thought Windows 10 has also affect Windows 7, and while up until now it may have been a preference choice for the old UI to justify using that operating system, from now on the technical problems which come with it will keep increasing, so stay away: either go to Win 10 or move to Linux




            1 there was arguably a reason for people to stay in an older operating system at the time, and that was the increased demand of computing power of the newer operating systems which prevented them to be installed on older machines. This is not true anymore, since Windows 10 requirements are exactly the same as the 10 year old windows 7.



            2 concern being data leakage and server vulnerabilities are more likely on a small company and more likely to be severe, because Microsoft has a much more experience in security gathered from failures accumulated along its 40 year of activity and enmity to various revolutionary hacker groups







            share|improve this answer












            share|improve this answer



            share|improve this answer










            answered 8 hours ago









            pqnetpqnet

            24715




            24715







            • 1





              The problem is in UI. How to accept such thing like the UI of Win10.

              – i486
              8 hours ago












            • Many orgs still use XP. Many orgs are forced to.

              – schroeder
              8 hours ago











            • Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

              – Doug O'Neal
              7 hours ago











            • @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

              – pqnet
              7 hours ago






            • 1





              @blankip: You can achieve the same safely with many currently maintained Linux distributions.

              – Esa Jokinen
              5 hours ago












            • 1





              The problem is in UI. How to accept such thing like the UI of Win10.

              – i486
              8 hours ago












            • Many orgs still use XP. Many orgs are forced to.

              – schroeder
              8 hours ago











            • Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

              – Doug O'Neal
              7 hours ago











            • @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

              – pqnet
              7 hours ago






            • 1





              @blankip: You can achieve the same safely with many currently maintained Linux distributions.

              – Esa Jokinen
              5 hours ago







            1




            1





            The problem is in UI. How to accept such thing like the UI of Win10.

            – i486
            8 hours ago






            The problem is in UI. How to accept such thing like the UI of Win10.

            – i486
            8 hours ago














            Many orgs still use XP. Many orgs are forced to.

            – schroeder
            8 hours ago





            Many orgs still use XP. Many orgs are forced to.

            – schroeder
            8 hours ago













            Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

            – Doug O'Neal
            7 hours ago





            Third alternative is to go with macOS. Also, if the OP wants to hang onto his operating system for years he'll have a problem with any OS. REL/Ubuntu/Debian/whatever will give you anywhere from a year to maybe 7 years of support. Not the 10 years that he already has on Win7.

            – Doug O'Neal
            7 hours ago













            @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

            – pqnet
            7 hours ago





            @i486 This is a personal preference, which I admitted is still relevant as of now, but I argue it's going to become more and more outweighed by the technical discrepancies with a supported OS as Win7 becomes older and buggy and not updated anymore.

            – pqnet
            7 hours ago




            1




            1





            @blankip: You can achieve the same safely with many currently maintained Linux distributions.

            – Esa Jokinen
            5 hours ago





            @blankip: You can achieve the same safely with many currently maintained Linux distributions.

            – Esa Jokinen
            5 hours ago










            TritiumCat is a new contributor. Be nice, and check out our Code of Conduct.









            draft saved

            draft discarded


















            TritiumCat is a new contributor. Be nice, and check out our Code of Conduct.












            TritiumCat is a new contributor. Be nice, and check out our Code of Conduct.











            TritiumCat is a new contributor. Be nice, and check out our Code of Conduct.














            Thanks for contributing an answer to Information Security Stack Exchange!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsecurity.stackexchange.com%2fquestions%2f205193%2freplacing-windows-7-security-updates-with-anti-virus%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Best approach to update all entries in a list that is paginated?Best way to add items to a paginated listChoose Your Country: Best Usability approachUpdate list when a user is viewing the list without annoying themWhen would the best day to update your webpage be?What should happen when I add a Row to a paginated, sorted listShould I adopt infinite scrolling or classical pagination?How to show user that page objects automatically updateWhat is the best location to locate the comments section in a list pageBest way to combine filtering and selecting items in a listWhen one of two inputs must be updated to satisfy a consistency criteria, which should you update (if at all)?

            Тонконіг бульбистий Зміст Опис | Поширення | Екологія | Господарське значення | Примітки | Див. також | Література | Джерела | Посилання | Навігаційне меню1114601320038-241116202404kew-435458Poa bulbosaЭлектронный каталог сосудистых растений Азиатской России [Електронний каталог судинних рослин Азіатської Росії]Малышев Л. Л. Дикие родичи культурных растений. Poa bulbosa L. - Мятлик луковичный. [Малишев Л. Л. Дикі родичи культурних рослин. Poa bulbosa L. - Тонконіг бульбистий.]Мятлик (POA) Сем. Злаки (Мятликовые) [Тонконіг (POA) Род. Злаки (Тонконогові)]Poa bulbosa Linnaeus, Sp. Pl. 1: 70. 1753. 鳞茎早熟禾 lin jing zao shu he (Description from Flora of China) [Poa bulbosa Linnaeus, Sp. Pl. 1: 70. 1753. 鳞茎早熟禾 lin jing zao shu he (Опис від Флора Китаю)]Poa bulbosa L. – lipnice cibulkatá / lipnica cibulkatáPoa bulbosa в базі даних Poa bulbosa на сайті Poa bulbosa в базі даних «Global Biodiversity Information Facility» (GBIF)Poa bulbosa в базі даних «Euro + Med PlantBase» — інформаційному ресурсі для Євро-середземноморського розмаїття рослинPoa bulbosa L. на сайті «Плантариум»

            Вунгтау (аеропорт) Загальні відомості | Див. також | Посилання | Навігаційне меню10°22′00″ пн. ш. 107°05′00″ сх. д. / 10.36667° пн. ш. 107.08333° сх. д. / 10.36667; 107.0833310°22′00″ пн. ш. 107°05′00″ сх. д. / 10.36667° пн. ш. 107.08333° сх. д. / 10.36667; 107.083337731608Vinh AirportVinh airport facelift improves serviceвиправивши або дописавши їївиправивши або дописавши їїр