"One question we have been asked is why do we update the client code for Windows Update automatically if the customer did not opt into automatically installing updates without further notice? The answer is simple: any user who chooses to use Windows Update either expected updates to be installed or to at least be notified that updates were available. Had we failed to update the service automatically, users would not have been able to successfully check for updates and, in turn, users would not have had updates installed automatically or received expected notifications. That result would not only fail to meet customer expectations but even worse, that result would lead users to believe that they were secure even though there was no installation and/or notification of upgrades. To avoid creating such a false impression, the Windows Update client is configured to automatically check for updates anytime a system uses the WU service, independent of the selected settings for handling updates (for example, “check for updates but let me choose whether to download or install them”). This has been the case since we introduced the automatic update feature in Windows XP. In fact, WU has auto-updated itself many times in the past."
quote: The point is you can turn off WU if you want
quote: This is not stated anywhere in the WU process, and that is why it is news.
quote: If Windows Update is "updated" automatically, than the system has a possible security flaw which would allow a malicious user to update windows update with code to auto update occasionally with malicious patches.
quote: The admin has control over WU patches with the current program. This is not necessarily true if the program is updated to give it new capabilities (including malicious ones).
quote: I think most would agree that forcing an update on users is a bad idea.
quote: I think you are labeling this as FUD more because you don't like my editorials than a valid technical assessment of its content.
quote: Update software is particularly security critical and in my mind should never override the user in updating its mechanics.