Answer the question
In order to leave comments, you need to log in
Blocking windows and mac updates?
В связи с сложившейся ситуацией надо обезопасить себя и свою работу от возможных блокировок со стороны разработчиков операционных систем. Думаю самым надёжным способом будет блокировка по dns именам. Так как можно можно сразу и для всех блокирнуть адреса обновлений. С точки зрения подсетей тут помему менее надёжно. Вот и вопрос. Кто заморачивался подскажите какие адреса для этого используются или как лучше реализовать сию возможность?
Answer the question
In order to leave comments, you need to log in
At one time I solved the reverse problem.
It was necessary to close everything except updates ...
http://windowsupdate.microsoft.com
http://*.windowsupdate.microsoft.com
https://*.windowsupdate.microsoft.com
http://*.update.microsoft.com
https://*.update.microsoft.com
http://*.windowsupdate.com
http://download.windowsupdate.com
http://download.microsoft.com
http://*.download.windowsupdate.com
http://wustat.windows.com
http://ntservicepack.microsoft.com
http://stats.microsoft.com
https://stats.microsoft.com
To score, all these manufacturers know how to block bypassing "updates".
1) block all network traffic (both incoming and outgoing)
2) specifically allow access to the network only to the applications you need.
Under Windows, this can all be done using the standard firewall, but add-ons like WFC, simplewall, or tiniwall seriously simplify the task.
Theoretically, this is natural does not eliminate the possibility of backdoors, but a long-term (about a month) observation of the experimental sandbox did not reveal any illegal traffic.
It seems to me that with a higher probability, devices located on the territory of the Russian Federation will be disconnected from updates.
To score: the power of action gives rise to the power of reaction. Devices will be blocked - a bunch of masters will immediately appear, who will reflash and fix everything for you for a penny. Why waste nerves in advance?
They have access to the system even without it. Apple has it so exactly
And today a button arrived on Windows with updates disabled for 2 years - an urgent update ... the question is how))
So think for yourself))
I just have a program. Update switch. How the service works
Block dns names on the gateway. There is a list of them on the internet.
For poppies - no way, they have a permanent connection to the Apple. For Windows - I don’t know, unless I cut off the Internet :) But I think it will soon become irrelevant, because a general exodus to linux will begin. Yes, it will be uncomfortable, scary, dumb, dreary and without beautiful pictures. But there will simply be no other choice.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question