So I blocked egress TCP port 80 today.

First casualty: Windows Update

#infosec #networking #Win10

https://mastodon.social/media/7-u94iUuujlH8v4a8YI

@lattera 'Your Microsoft account requires attention...'
@lattera right, WU downloads use port 80, because they're not only signed but hashes for said files were already obtained via a TLS-encrypted request
@slipstream Yup. Just kinda sucks for someone like me who wants to force encrypted comms.