rcon:
We're looking into better alternatives and agreed that changing timeout for all services is not the right way, but it did provide temporary relief as we were learning more.
All of the binaries are signed with authenticode and for strong names. There are a few other "workarounds" but the gist of the issue is that the binaries have been signed with different certificates because one of the certificates in the signing process had expired.
We are also working on a public KB article and will be updating the blogs soon.
An alternative to modifying/creating individual application exe .config files is to modify the machine.config instead. That will work but does disable it across the board.