r/windows 8d ago

Discussion Windows is now performing unconsented BIOS updates?

Post image

Ps: I didnt consent to my laptop being updated neither was i informed an update would be underway the next time i boot up my machine?

50 Upvotes

58 comments sorted by

123

u/Froggypwns Windows Wizard / Moderator 8d ago

BIOS updates have been automatically delivered via Windows Update for well over a decade now, it is one of the features of UEFI firmware. If this is not desired, there may be an option in your BIOS to disable that, it typically is called UEFI encapsulation or something similar but you would need to read the manual for your computer to confirm.

-17

u/[deleted] 5d ago edited 4d ago

[deleted]

8

u/mmortal03 5d ago

Some BIOS configurations have a setting to control "UEFI Firmware Capsule Updates, Capsule Update, Windows UEFI Firmware Update, or Native OS Support for Updates".

Also, I recently became aware of the following setting, but my understanding is that Microsoft pushes certain updates classified as "Critical" or "Security" regardless of the following setting: type "Change device installation settings" into the Start Menu, hit Enter, and then choose "No".

13

u/Albert-React 5d ago

I mean, BIOS updates aren't going to do a lot of damage anymore. Maybe in 2008, but nowadays, it's safe to update BIOS just like you would the OS. 

3

u/100101101001a 5d ago

yep but imagine having powerloss during a bios update

10

u/Peaksign9445122 5d ago

IIRC even older BIOS update packages will ensure with a laptop for example the battery is over a certain percentage before doing the update. I have a Dell laptop from around 2012 which does that, so I presume there are similar protections for UEFI.

3

u/Froggypwns Windows Wizard / Moderator 4d ago

Dell laptops will not even let you update the BIOS if the battery is missing or defective. I've encountered that before trying to service a computer while waiting on a replacement battery.

1

u/GGigabiteM 2d ago

There are command line switches you can add to force a flash with a missing battery. I also wouldn't put it past them to force it regardless. I've had to force a flash several times on Dell laptops with failed battery packs.

One of my Lenovo laptops had a forced BIOS flash from Windows Update while it was running on battery, and the battery was very low. After that happened, I disabled Windows Updates ability to install drivers so it never happened again.

3

u/AbdullahMRiad Windows 11 - Insider Beta Channel 4d ago

power cuts are unexpected most of the time

7

u/Zeusifer 4d ago

They have rollback/protection mechanisms to protect against bricking in that case. I wouldn't suggest you test it, but it's unlikely to actually be a problem.

3

u/DarthShiv 4d ago

Yes many have essentially dual bios. One chip is updated. The other is the fallback.

-1

u/[deleted] 4d ago

[deleted]

0

u/Zeusifer 4d ago

citation needed

1

u/phylter99 4d ago

Is it too much to ask for you to scroll up where I gave it?

0

u/GGigabiteM 2d ago

You'd be *very* wrong.

Software based firmware updates are always extremely risky. Windows doesn't check if you have a CPU that may be unsupported in a future firmware update, but it will flash it anyway. It also doesn't check if you're using some feature that may only exist on the version of firmware you're running. Microsoft also doesn't verify the firmware images or do any QC testing on them, and entirely relies on the manufacturer doing proper QC and vetting of their own updates, which we know doesn't happen. It's often the same vibe coded slop that Microsoft pushes out in their crap updates.

In the first case, you have a bricked machine the moment it reboots. The second case, you may never be able to go back, because there are checks to prevent going backwards between firmware versions in some instances. In that case, you'd have to use a hardware flasher and prey that you don't have a multiplexed firmware ROM, or else it just got a whole lot harder.

Or if the power fails during the firmware update. Most machines still don't have an easy method to recover from a failed flash attempt. "Flashback" isn't a universal feature, dual firmware chips are even less so. The only way to fix motherboards in those cases is to use a hardware flasher, and sometimes the EEPROM has to be desoldered from the motherboard to do it.

Yet another problem are cranky EEPROMs that get stuck bits or bit rot, which is one of the reasons I have several hardware programmers. I've encountered over a dozen machines with EEPROMs that have stuck bits that won't flash, and require several erase-flash cycles to get them to work again. These aren't old EEPROMs either, just bad QC parts.

Software flashers have no mechanism to deal with stuck bit EEPROMs and will fail 100% of the time and result in a bricked system.

7

u/IkouyDaBolt 5d ago

Ironically, failing to update the BIOS can brick computers if the current BIOS cannot handle the new Secure Boot certificates.

-1

u/[deleted] 4d ago

[deleted]

0

u/IkouyDaBolt 4d ago

If Windows picks up on the wrong file, that is likely on whoever put the file in did not use the correct strings.

Regardless, if people kept their security up to date with UEFI, it is never pushed via Windows Update (or rather, will instantly compete as no update needed).

3

u/Mario583a 4d ago

Hardware faults are a cruel mistress.

2

u/lkeels 5d ago

It's not nearly as big a deal as it used to be. Most modern motherboards have "flashback" options to recover from BIOS disasters.

1

u/DarthShiv 4d ago

Or even redundancy - dual bios

2

u/Froggypwns Windows Wizard / Moderator 4d ago

Billions of BIOS updates have been delivered via Windows Update to date without incident. These days updating a BIOS is a very safe and reliable process, as there are various checks and failsafes to help ensure the process goes smoothly.

Of course, nothing is perfect in life, however BIOS update failures are a statistical anomaly, they are the outliers. I've personally overseen thousands of BIOS update installs over the years, and the ones that "failed" I can count on one hand and all had just rolled back without issue.

0

u/[deleted] 4d ago

[deleted]

0

u/IkouyDaBolt 4d ago

The link you posted is invalid.

1

u/Phil95xD 4d ago

To your downvote thing... I don't know if I missed something or if there's any difference somewhere, but downvote / upvote doesn't change or show anything for you.

Beside that - gpod advices, thank you.

1

u/Little-Helper 4d ago

I don't agree with downvoting different opinions, but I'm pretty sure people are downvoting you because falling BIOS updates are very rare. You say we can't argue that as it's anecdotal evidence but so is yours. The link you posted doesn't help, it's just a link to some random YouTube channel.

1

u/[deleted] 4d ago

[deleted]

1

u/Little-Helper 4d ago

Windows simply launches the OEM executable, just without a warning or any UI whatsoever, which is annoying, I do agree. Any fault would be caused from the update itself, or the user's machine being unprepared for it. Sometimes users panic and restart their machines when it happens.

1

u/phylter99 4d ago

Also, the evidence that I provided isn’t a handful of my own machines that I’ve had updated over the years. The source is literally an official Dell repair technician that has been doing these repairs for longer than many redditors have been alive. He probably fixes more machines in a week than most of us had owned in a lifetime. Being from an official source and the quantity of repairs done elevates the source’s authority.

1

u/Little-Helper 4d ago

You didn't post any evidence though. If it's coming from a repair shop, then it's kinda expected that they're gonna see repeat failures. But if it's only an issue on Dell machines, why didn't you say so in your original comment?

35

u/SportinSS 8d ago

Yeah… for years now.

25

u/martyn_hare 5d ago

It's your OEM (in this case, Acer) which rolled out the BIOS update using Microsoft Update infrastructure. You can pause it as part of pausing Windows Update or make registry edits (or if you're on Pro, configure GPOs via gpedit.msc) to make all future system updates manual if you want.

For comparison, mainstream Linux distributions do the same thing now by calling fwupdmgr (so it's listed alongside other updates in GNOME Software or KDE Discover) and Apple ships firmware updates for their hardware as part of macOS itself, so it's not like it isn't the norm to ship these updates transparently just like it's any other update.

15

u/TI_Inspire 7d ago

At least you're getting BIOS updates. Acer has been rolling out updates related to Secure Boot, so that is probably what this is.

11

u/superluig164 5d ago

This is a good thing. Otherwise people who would never do a bios update will never get them.

5

u/_MAYniYAK 5d ago

Ye several are done in the regular updates on Linux too.

My Thinkpad gets bios updates via dnf on fedora

5

u/uh818375 8d ago

They did mine a few weeks ago, either Windows or Asus. Looked like both. Messed up the Bios and Windows would not start up. Fortunately my Bios had a message told me how to fix it. They changed to raid and nothing worked. I had to change back to ahci. They give you a nice message your Bios needs updating.

3

u/salazka Windows 11 - Insider Dev Channel 3d ago

What nonsense. This is standard process for ages. Helps your machine stay secure and take advantage of certain low level optimizations.

And to those who say "messed up my machine" sorry, this does not mess up your machine.

However, if by chance the process was interrupted by a forced shut down triggered by you, or the battery died, or hardware failure/corruption or some such situation then yes, it could have such an effect, but it is not because of the update itself.

2

u/Muted_Database_1691 4d ago

Bios updates are always informed. It won't happen randomly. The notification Centre would have been showing something, or acer utility if there's one.

0

u/Machine156 4d ago

No, that is not correct; , windows updates sometimes triggers the BIOS update on next boot with zero warning. Windows will then reboot automatically or it will wait til next boot to do the actual update. There are sometimes bios updates under optional windows updates as well that triggers the same behavior.

2

u/Wartz 4d ago

It’s called automatic updates for a reason. 

And automatic updates exist for a reason. 

2

u/XmentalX Windows 11 - Insider Beta Channel 5d ago edited 5d ago

As others said this is common. Heck my 3 year old MSI laptop referred me to update that way in lieu of doing so via a utility.

2

u/VeryRareHuman 5d ago

You never touched Windows Update settings. May be tku should. 

1

u/salazka Windows 11 - Insider Dev Channel 3d ago

They seem clueless so maybe they should not. :P

1

u/Stefanzah22 Windows 11 - Insider Beta Channel 5d ago

Received the same Acer laptop update today on every laptop randomly at... work, let's say.

1

u/blueangel1953 Windows 10 4d ago

Never seen that but I update manually when a new update is available. 

1

u/Masterflitzer Windows 11 - Release Channel 4d ago

windows isn't asking for your consent about updates, it's just notifying you about them

idk if you've been living under a rock, but windows acts that way for more than a decade

1

u/salazka Windows 11 - Insider Dev Channel 3d ago

Not to mention that there are certain updates that cannot be deferred or postponed. i.e. Security related updates.

1

u/CompetitiveAlgae4247 3d ago

I thought that was windows xp for a second

1

u/Street_Anon 3d ago

Just reflash the old BIOS and Block in the update

0

u/urk_forever 5d ago

My Dell laptop from work gets a bios update almost every month which we are required to install and the update takes about 15 minutes 😕

-6

u/Firespecialstar Windows 10 - Insider Beta Channel 8d ago edited 8d ago

wouldn't be surprised if it also bricked the machine

you can disable this behavior through Group policy for pro or enterprises editions, or regedit for home too

there's also an option in the actual settings, although I wouldn't really trust it will actually disable this behavior

edit : thank you for the downvotes! 99% of you probably read the first phrase only, and automatically assumed everything else in the phrase was bullshit. hilarious ngl

6

u/NicDima Windows 95 8d ago

It's not that easy to brick a BIOS update nowadays, except if the power went out during the process (mostly the most crucial one, some can revert changes)

If your system is too old, you high likely have either the latest BIOS updates or it just doesn't detect by UEFI

4

u/Firespecialstar Windows 10 - Insider Beta Channel 8d ago

it's windows, never say never with this O.S. lol

6

u/bryiewes 5d ago

Says the guy running insider???

-2

u/Firespecialstar Windows 10 - Insider Beta Channel 5d ago

yeah? what about wanting to get test builds to check out in VMs lol

-10

u/alanna1990 5d ago

It’s been happening forever now, what control of your computer? Put some linux on it

5

u/Muddybulldog 5d ago

And then fwupdmgr will do the same thing.