Every 30 minutes Windows 10 sends all typed text to Microsoft
translate.google.com
translate.google.com
Just try
https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...
I'm just saying, for us it's on par with your prisonplanet.com
Reminds me of the DRM FUD against Windows 7[1] and the fake benchmarks claiming that Windows 7 was eating up memory and was slow[2].
And they end up getting a lot of attention and page hits from sites like this, so it's a vicious cycle, with people repeating this 'information' to others.
[1] http://tech.slashdot.org/story/09/02/16/2259257/draconian-dr...
[2] http://www.zdnet.com/article/why-we-dont-trust-devil-mountai...
MS generated a great deal of FUD about for the linux desktop. And it's always been a favourite of the people who own america's politicians and news organizations.
That's how all that "marijuana causes brains damage" shit got its start. Dr. Heath, "The scientist," and I use that term quite loosely, who published the study, pumped marijuana smoke into breathmasks worn by monkeys. His monkey's suffered brains damage and started dying and he published his government funded study.
What he didn't publish were the details of his flawed methodology.
The monkeys were smoked up with the equivalent of 63 joints over a five minute period. The masks were air tight and the only thing the monkeys could breath was smoke.
He did that repeatedly for 90 days until the monkeys displayed symptoms of brain damage and began dying. Okay! Time to publish!
Playboy and Norml obtained the records via a federal info request and published the truth in 1986.
The monkeys' brain damage and deaths were caused by carbon monoxide poisoning and asphyxiation.
https://www.microsoft.com/en-us/privacystatement/default.asp...
I'm considering using a secondary computer (linux) for all of my personal internet activity and making my windows box purely game dev / gaming.
Took me a few weeks to completely replace my Windows workflow in OSX and Ubuntu but I'd say the broader perspective of knowing all three platforms when being a programmer is well worth the investment!
I'd have to say, Uncharted played a small role in this transition; I've been blown away by this series and they're not available for PC, so there :)
I personally just game on a Linux box (running Slackware, specifically). I don't get the best selection in the world, but most of the indie games seem to be paying attention to Linux/SteamOS, and said games tend to be the better ones anyway.
Do you own an Xbone? I hope not for your sake as Windows 10 is coming to that too.
(If I'm being pedantic, other consoles have used Windows in some way. I'm not sure about the Xbox 360 but IIRC the OS for the original Xbox was based on Windows 2000. The Dreamcast also had limited support for Windows CE, I don't think the main OS was based on it, but a few games used it).
> Windows 10, rather than residing as a static software program on your device, key components of Windows are cloud-based, and both cloud and local elements of Windows are updated regularly, providing you with the latest improvements and features. In order to provide this computing experience, we collect data about you, your device, and the way you use Windows. And because Windows is personal to you, we give you choices about the personal data we collect and how we use it.
Apart from the data we don't give you a choice about. And the choices we opt to ignore anyway.
"When you interact with your Windows device by speaking, writing (handwriting), or typing, Microsoft collects speech, inking, and typing information—including information about your Calendar and People (also known as contacts)—that helps personalize your experience. This information improves your device’s ability to correctly recognize your input, such as your pronunciation and handwriting. You can turn the Speech, inking, and typing setting (which is called Getting to know you) on or off in Settings.
Note: If you want to use Cortana, you must have Getting to know you turned on.
We also collect your typed and handwritten words to improve character recognition and provide you with a personalized user dictionary and text completion suggestions. Some of this data is stored on your device and some is sent to Microsoft to help improve these services. You can turn the Send Microsoft info about how I write setting on or off in Settings."
1. http://windows.microsoft.com/en-us/windows-10/speech-inking-...
ref: https://jonathan.porta.codes/2015/07/30/windows-10-seems-to-...
Also, it seems that Win10 ignores some of these settings: https://www.reddit.com/r/Windows10/comments/3gm1e3/what_wind...
I've no problem with them doing this sort of thing, but it must be opt-in rather than opt-out. Like you say, this isn't just about individual privacy concerns, it's about important legal obligations that people may unwittingly be violating if they use Windows 10.
I'd think that the security concerns would be functionally identical.
There are plenty of practice management cloud solutions with cloud storage support which are hipaa compliant.
Swinging back to topic: Microsoft has traditionally had a good rapport with the business / government space, so I'll be shocked if they don't already have a plan for addressing the need to protect private data. Maybe the enterprise solution version of Windows 10 will have this feature off by default?
For example Office 365 for Healthcare which is HIPAA compliant has probably quite a different privacy policy and out of the box authentication, encryption and right management settings than what you would get as an individual or even by buying Office 365 for business editions.
http://www.microsoft.com/en-us/health/products/office365/def...
Not saying that's right, but most companies that provide free/subsidizes consumer services including companies like Google tend to have quite a different SLA and service terms for corporate customers.
Android voice recognition might raise similar problems; the Google search engine less so. You can use Google Search without putting any protected information into it; OTOH, if an OS is capturing all of your typing and inking and sending it to another party, anything you do by typing or inking that involves protected information is being sent, so (in the HIPAA case) unless you have a BAA in place, and both parties have both the technical and administrative safeguards required under HIPAA, using it for PHI is going to involve regular illegal disclosures.
Windows 10 is harvesting and relaying every-fucking-thing you type on your operating system.
I will not waste my time to MITM SSL traffic and break down binary blobs to find out, whether it contains something I just typed. It sends out unwanted traffic when I type into start menu --> onus is on Microsoft to be transparent, what it sends out. And to allow user to disable that behavior.
The problem is that, by way of Windows 10 effectively having a keylogger installed, pretty much any EMR accessed via a Windows 10 machine is automatically insecure, since the data entered into said EMR is being sniffed and sent to a third party. If Microsoft experiences any sort of data breach, hospitals throughout the U.S. will be having a HIPAA/HITECH hell-day.
“Some of this data is stored on your device and some is sent to Microsoft to help improve these services. Data sent to Microsoft for product improvement is put through rigorous, multi-pass scrubs to remove sensitive or identifiable fields (such as email addresses, passwords and alphanumeric data) and strings are chopped into very small bits and stripped of sequence data to prevent the information from being identified or put back together.”
http://blog.laptopmag.com/windows-10-privacy-issues-exaggera...
It amazes me that this information isn't easier to find and I end up being the one defending Microsoft. I definitely recommend using Free Software only if you want to be absolutely sure of confidentiality.
In any event, during the installation process, you do see a screen where you can turn all this off. It's not off by default, but viewing these settings was part of my Windows 10 installation experience.
Otherwise wouldn't every commonly misspelled word show up incorrectly in spellcheck?
There is quite a bit of work in the field of speech recognition, too, and it's entirely possible to create a functional model without recording every user's voice and storing that information on a server. Even if they require speech samples, or samples from different languages, they should at least pay someone for that information.
I was disappointed when I learned that the voice recognition feature in Siri wasn't local to the phone.
Do you know what actual data is, and is not, sent to Microsoft as you use your device?
Even if you do, will you still know once Microsoft pushes a mandatory update and/or changes its 12,000 word terms of service?
The problem is that Windows 10 does not respect you having this turned off. It will send away your data, even if you turned off all the switches.
Don't you see this as a huge problem?
Various security measures rename sensitive fields into things that are basically random strings that are stored in a session. [e.g. Fields to change your password? They are set to something like 2ajefklaj23324rk]
There is also the issue of people who write erotica for fun. Or doctors writing down notes for patients.
So, has anybody ever audited build farms for Debian, Ubuntu, etc? Have we ever seen a breakdown of their income sources? How do you know that the binaries you install are built from the sources you can browse or download from the net?
Do you compile everything yourself?
For the situation I'm talking about where absolute confidentiality is required, the right way to do it would absolutely be auditing all code and compiling from source, assuming you're working in an organization that has that kind of capacity.
But for most cases, just dealing with an organization you trust is enough, whether they provide source or not.
Ah, good to know. Do you have any links to articles or discussions about this? Would like to learn more.
/LOL.
If so, that sounds unbelievably error prone. What if your password is of the "correct horse battery staple" form, rather than the standard unreadable scramble? It seems impossible to reliably distinguish that from other text. Does that mean that Microsoft then has your password? Even anonymized, that's a massive problem.
Passwords and the like are probably identified by the type of field they're entered into, as Windows forms and websites have explicit identifiers for passwords, and it would be easy not to record this. I think this analysis is more for things like analyzing the frequency of terms and which characters tend to follow other characters, but I don't have much more information, and I agree that there needs to be more shared about how this works.
You type "the quick brown fox jumps over the lazy dog." You continue typing other stuff. 30 minutes later, there's a queue of random slices like: { "lazy dog", "chocolate donut", "brown fox" }. That gets encrypted and sent into a big pile of other data for a machine learning algorithm to develop better typing prediction.
I would like to know if that's the gist of it or if there are other things happening. Hopefully there will at least be a developer blog or something like that to better explain it.
> only "some"
99% is still "some". Regardless, since when is "some" keyloging acceptable?
> too much data
That depends on a lot of factors. Text is small and trivial compared to most stuff on the internet these days. How many kilobytes per day of text does the median windows user even type?
It would be even easier for MS to filter out stuff like video games (DirectInput?) to reduce the size.
> I think
Guessing is useless. What matters is the data going over the wire and what authorized MS to do in the future.
> there needs to be more shared about how this works
No, there needs to be explicit informed consent form the user.
Most people probably like all that, but I would like to see more robust privacy settings to easily disable tracking whenever it's desired.
You mean, like this?
# apt-get update && apt-get upgrade
Granted, running that isn't 'forced', but given that OSS users don't _actually_ analyze the code in their software, it's basically the same thing.
There's always a chance of something being slipped in later, no matter what OS you're on. Rampant paranoia and conspiracy theorizing does no one any good.
The problem of inspecting the code itself is a separate issue entirely, though at least in the area of Free Software that inspection is possiblea, and reproducible (deterministic) will simply the problem. Good luck doing the same with Windows (or any other closed software).
> Rampant paranoia and conspiracy theorizing
Now you're simply resorting to either insults (and/or wilful ignorance).
I think it's you that missed my point.
> people choose when (and if) they upgrade, for a variety of complex reasons
If they're running Gentoo, or maybe a small group of other distros, sure. Otherwise, people (on all operating systems) don't really do a lot of choosing at all. If updates are available, they generally run them. The only picking and choosing I've ever seen from the vast majority of people (including technical folks) is if they don't have the bandwidth/time to update a particularly large piece of software at the moment. Of course, they'll update it later when they are able.
> The problem of inspecting the code itself is a separate issue entirely, though at least in the area of Free Software that inspection is possible
Yes, it's possible, but it isn't done in practice, which is why I said it. That's the reason I said it's 'basically the same thing'. Whether you receive updates automatically or choose when to download them, you are still accepting what the distribution method gives you. There are FAR too many software packages out there for the average person to work out the logistics of reading accounts from early adopters of every single point release.
> Now you're simply resorting to either insults (and/or wilful ignorance).
It's not an insult. It's a factual statement. You claimed in your comment that a multi-billion dollar corporation who has a vested interest in keeping the good will of their customers (some of whom are corporate, some government, but the vast majority are consumers who look to them for help) would willfully send compromised software through forced updates in the future. If that isn't a conspiracy theory, I'd love to know what is.
Apparently you need to get out more, because you seem to have missed that "not upgrading" is so incredibly common that some major software packages (web browsers) and at least one operating systems have decided to force upgrades.
Also, do you really believe that all the IT departments in the world are running current versions of anything? There are entire industries that run "last year's" versions, who only upgrade after extensive testing.
> I'd love to know what is
Did you even read the thread you're replying to? You're knee-jerk application of the paranoid-style[1] ignores the fact that "It's in the privacy policy." There is not secret. MS is telling everyone they will send forced updates (which have already cause stability issues for some people). As for MS keeping "the good will of their customers", again, did your read this thread? Windows 10 has already forced various professionals to drop windows.
Also, "compromised" is your term, not mine. I'm sure any future update they push out will be buzzword compliant. The point is we don't know what future updates will bring, but you agree to run those future versions anyway.
--
Meh. I have better things to do than waste any more time on your distractions. If you want to be the apparatchik that refuses to believe MS would do anything malicious, that's your business.
[1] http://harpers.org/archive/1964/11/the-paranoid-style-in-ame...
Honestly it does not look like you wasted much time at all, you seem to have missed his point again.
I'd like to see precisely how they anonymize the data, and I'd also like to know what data it is.
If Microsoft was a known moral bastion who had perfect security might not be a problem. But it isn't and it doesn't, so there is only one response: NO!
(OK, there are more responses, but I'm not sure if they are allowed with HN's code of conduct.)
I'm fairly certain things under NDA won't go near Windows 10, even if anonymous the data is still leaked. Just like these things currently stay far away from 3rd-party services.
I don't care how good your data gets anonymized; time and again, it's been shown that anonymized data can be fingerprinted and de-anonymized over time.
Whether or not this is happening, this should raise legitimate concerns with people who are considering, or who have already upgraded to Windows 10.
http://localghost.org/posts/a-traffic-analysis-of-windows-10
Doesn't look like the original source of the info is very trustworthy, will need other people to verify this.
If true, however, it is very problematic and of questionable legality (e.g. unintended HIPAA data disclosures etc).
Apparently people will have to start to invest in configuring outbound firewalls on their network to prevent various phone-home operations.
And of course there is no word from the horse's mouth (Microsoft) at all on ANYTHING related to this. Silence is always worrying.
You don't need to bust open the codebase itself to figure out what comms are occurring. You can stage your own MITM attack against yourself with a couple of home made SSL certificates and a router you have the ability to install your own software on.
Look at the context to decide if someone is using it to imply something is bad/evil/scary, in this case you cannot draw that conclusion. The OP is clearly just using it instead of italics.
Unless you can just install a local certificate and proxy it.
It's all "for your security", of course.
Linux, through Ubuntu, is (IMO) now ready for the prime time.
Guess I'll stick with 8.1 for now even though it is shit.
I have been able to put Unity on the back-shelf because it's just a hobby for me. I have been experimenting with Phaser / PIXI / P2 + ScalaJS in the meantime while I wait for the Editor to come to Linux, which will hopefully happen in the near future [1].
As for actually playing games, a surprising amount of the ones I try have been ported over to Linux already. For the rest, I use Steam Live Streaming from a Windows 7 box which works pretty well. Steam can even stream non-Steam games (blizzard ones for example). I tried using it to stream the Unity Editor, but it was just too clunky for my tastes.
1: http://blogs.unity3d.com/2015/07/01/the-state-of-unity-on-li...
It's not ready for home users, it's not ready for most businesses, it's not ready for anyone except a small number of users.
I'm sure the argument will come that most home users only need a web browser, so the software selection isn't a problem, but at that point you might as well just use Chrome OS and get something that actually works.
Audio still doesn't work on my installation. It can work if I kill Flash or pulseaudio---sometimes---or if I restart my browser or entire machine---sometimes. But it's an atrocious state of affairs to expect end-users to debug basic functionality like that, and they end up having to because there isn't a "Geek Squad" local-service ecosystem to take a malfunctioning Linux machine to (with your own customized distro install) where they can just "make it work."
It's not just a software problem---it's an ecosystem problem. Both in terms of the service / support sector and in terms of the software creation sector (the fact that there isn't just one answer to "How do I do audio on Linux" is absolutely maddening to someone used to writing software on a Mac / Win monoculture [http://braid-game.com/news/2008/08/misc-linux-questions/]).
Once it gets increased adoption more niche and paid for software will naturally migrate.
I say this as a Linux hating Windows lover who lasted 3 hours before reverting Win 10 back to 8.1 on my gaming machine and changing my wifi password, and I plan to never go to Win 10 or any Windows products again.
If it's not ready for a seasoned software engineer, it's definitely not ready for my mom.
"Go to Start, then select Settings > Privacy > General, and then turn Send Microsoft info about how I write to help us improve typing and writing in the future on or off."
Does anyone know if this stops Windows 10 from sending typing data across?
NOTE: Not that I condone what Microsoft is doing, just a little hypocritical to think that big bad Microsoft is doing anything new in the industry, especially when the products you guys are talking about jumping ship to, have the same problems. This is nothing new
It's just so ridiculously stupid and it's as if it's funny.
Nope. You're making assumptions based on nothing.
I have an issue with both (or any) companies doing it, as do many other people.
I don't even use Google search anymore, and I certainly don't want my Windows searches consulting Bing.
I would bet cash money that this is false. There is more than one type of person on HN. If you interpret the actions of multiple people as if they were a monolithic entity, of course they're going to seem contradictory.
No, if this is true it is massively different. This article claims that Microsoft is keylogging everything for keywords; this is not in the same universe as one app sending data for search results. Did you not rtfa?
to put it as simply as I can - wrong behavior is wrong, and it's good to not be OK with it. just because other assholes in the block are doing it too doesn't make it any more right.
do you see anything wrong with that statement?
And besides, these things tend to come in waves. I've read basically the same comment about Google ad Apple here: "Why is everyone picking on Google and giving MS a free pass? They've done much worse!" "Why is everyone hating on Apple? Android has most of the same problems too!"
1. I don't use my smartphone for work. I have to use Windows for work, and some of this is dealing with confidential information.
2. I don't use my smartphone to write sensitive documents. I use my PC to write all kinds of documents, some of them sensitive and confidential.
3. I am not aware of my Android smartphone or tablet sending all my typing to the cloud. If this is so in Android I'd like to learn about it, same as if it's true for Windows. I wouldn't be comfortable with it.
That's why I use Debian. And hope they do the right thing.
To just give one example, if typed passwords are sent them passwords typed into Chrome are sent, if only the password manager is synced then that only impacts IE or Edge users.
Source: https://www.microsoft.com/en-us/privacystatement/default.asp...
(Click "Learn More" under "Personal Data We Collect")
It is just part of the new trend, that everything runs in the cloud somehow.
Do you type passwords and other private information directly into GDocs? What about other things you type on your keyboard?
There's a difference between knowingly entering information into a 'cloud' system, and having a core OS collecting all keystrokes.
Of course! Why on earth would I trust passwords in some random third-party password locker when I can instead store them in a heavily-secured Drive doc behind the one account I have with a regular password rotation schedule and two-factor authentication?
It's where I keep my bank account numbers and last will and testament too. ;)
For example, in another HN submission where someone posted a tool to delete/disable tracking services and add ip lists to the hosts file, a user has reported startup errors. To me this indicates Windows 10 is trying to communicate even during boot without the users knowledge! That's a big deal in my book... I don't know about yall.
The one reason I have suffered the slings and arrows of Windows so long is for gaming purposes, more recently because I wanted to release my hobby side-project, a game in Unreal Engine 4, on Windows and so I have kept one of my computers on Windows 8.1.
Last night that machine was compromised, and despite my fairly extensive malware fighting abilities, I couldn't get rid of it. That means a complete wipe and only moving data over that I must have, and not trusting that data, not to mention never trusting the HDD again (going to have to throw it away). I also question my bios, so I'll need to flash bios too.
I run three main computers, Windows on a Asus laptop, OSX on a Mac Air, and Linux/DragonFlyBSD dual boot on a Macbook Pro 2014. I think Windows 10 just might be the excuse I need to push myself completely away from the MS ecosystem. I've been talking about it for years, but the power of their tie-in is not to be trifled with.
I also fear for the state of linux in the same way though. At >10 million lines of kernel code, I think the many eyes theory has a weakness, namely that complex and huge codebases are antithetical to the many eyes theory working. that's why I personally think the future of computing will be in code simplicity and pairing down existing codebases. A good example of a try at this is Minix 3. <10k loc. (of course lacks many features).
That's also why, even thought I'm a huge GPL/GNU guy, I am increasingly leaning towards the top down ecosystem of the BSD's.
I think there are a lot of fundamental issues in personal computing that many of us just ignore and don't want to discuss because the implications of the conclusions could be uncomfortable. I think it's time for those of us who are considered power users to start having this difficult discussions more often and in more public ways.
Here's Antilogger: https://www.zemana.com/AntiLoggerFree Please avoid the new version, as it's probably weakened by ICs. I'm sure an older copy is lying around the net somewhere.
This is such nonsense. It is like saying 'Hey, there is no problem with living in a glass house where everyone can see you go to the bathroom, you can just put up some curtains.'
Your first link looks like it's just a pack of local policies, so I suppose there's some value, if that's the case, for people who don't want to go through with learning how to set that up.
Regular electronics consumers are not going to buy a Thinkpad with FreeBSD on it, and then house the laptop in a Faraday cage to airgap it. It. Does. Not. Happen.
Nobody said it would but "regular electronics consumers" also aren't reading this thread and don't have much to do with the post you're replying to.
`oca.telemetry.microsoft.com.NSAtc.net`
If you want a Windows 10 without Cortana, simply disable the sound card during installation (BIOS or physically).
This is not a solution, but a workaround for those having no other choice. Tested with Windows 10 Pro N.
Why not at least consider it? I run Arch + GNOME3 on my desktop and I haven't had any insurmountable problems, nor any that would be easier to solve in Windows.
That is a fair question. However, it all depends on your personal use case and because of that Linux just isn't an option for most people. If you value gaming you can fine tune wine till the cow comes home ... it will never feel (always) right. If you're into music production Linux gives you another "screw you!" Then, there is this huge amount of software for which it seems as if Linux offers reasonable alternatives. But if you really consider what a user actually wants Linux doesn't cut it. For example, Word could be replaced with Libre Office or (my personal favorite) an intriguing combination of markdown and pandoc. If, however, Word is what you want to use (even though I do not understand that) then every click that is different poses as a minor frustration that together with all the other minor frustrations adds up to a huge disappointment.
I haven't but I worry that some VSTi plugins might not work.
For example: https://www.winehq.org/pipermail/wine-bugs/2012-January/3072...
It's so bad that I believe it's unethical to offer it for download as working software because people with work to do on short timescales (as I had) may choose to rely on it and then get screwed.
If you are a Hacker, you will be overwhelmed by the great amount of development tools that are much easier to handle than on any other system.
There are very few reasons nowadays not to use Linux.
procmon: strace.
tcpview: netstat, wireshark.
They're all pretty easy to use.
However, I think it's very important to understand, and go into it with the mindset as follows:
You're not going to have the same programs. You'll have similar programs and very good alternatives (Photoshop/GIMP, 1Password/KeePass, etc.)
Once I realized that I probably shouldn't try to shoehorn a program written for only a specific OS into what I was doing, I found the experience much better.
Sure, some of the alternatives aren't as good. If you really need them, then you should re-evaulate why you're switiching.
GIMP is to Photoshop what mspaint is to GIMP.
Never said that one was better than the other, just that there are alternatives. :)
Again, if one really, really needs Photoshop, then they need to evaluate how much they want to change Operating Systems.
It's an alternative in some restricted circumstances. Calc.exe is an alternative to Wolfram Mathematica. People who didn't just pirate Photoshop probably don't use the small subset of functionality that GIMP provides because if they were they'd be using GIMP before switching to Linux.
This is not actually a selling point to a lot of people. Some people just want a device to work, and not have to worry about it.
> There are very few reasons nowadays not to use Linux.
One should use the right tool for the right job. Sometimes, that's just not Linux.
Windows 10 is excellent. We moved our all-mac company (~20 developers) off Macs and onto Windows over the past year, because Apple no longer supports the high end. We do GPGPU programming, and you can't plug a high end NVIDIA card into a MacPro. (The Mac Apologists will say you can, but you can't -- not in any useful performant reliable way.)
But I play too many videogames to run it as my primary machine.
and let's not forget the whole corporate global space, where Exchange+Office suite rules unchallenged. whenever i try to see some excel in what gmail has for previews, i cry and run away (and those are simple excels out there, without any complex scripts for example).
Could you explain why you wouldn't consider Linux for the desktop? Wine isn't horrible, if you want Windows compatibility, and it offers a huge range of functionality otherwise. It's the best platform for compiling and running stuff, for sure.
Microsoft appears to be in the business of trying to build a fully-functioning virtual assistant. If they're solving that problem with big data, they need a full stream of the user's behavior to operate on. But the tradeoff---an actual, working virtual assistant---could very well be worth it to people for whom that personal information is not worth hiding from a corporation with no vested interest in undermining their customer base by irresponsibly divulging that data.
If anything's sad, it's that we live in a world where some people do not have the freedom to treat their private info so loosely. That's a true tragedy, because there will increasingly be technologies they can't take advantage of.
I assume the same sort of stuff is happening on Ubuntu today, but I stopped using Ubuntu on the desktop/laptop when this came out and started using Debian instead.
but regardless, they've lost too much respect/credibility for including it in the first place, so I wouldn't trust them in general.
edit: just wanted to mention that when I first installed ubuntu I forgot to disable the feature, performed some very innocuous searches, and was shown loads of porn results from Amazon. That alone makes the feature completely worthless and frankly dangerous (depending on the environment that you're using ubuntu in).
1.) No Internet access (the default)
2.) Route through Tor
3.) Route via VPN to a server at home and out through my broadband connection (I trust my broadband ISP slightly more than my mobile network provider). This protects me on untrusted WiFi networks too.
[edit] I wish I didn't have to do all this, but the smartphone OS market doesn't give me non-leaky OS options in the same way that the Desktop market does.
Luckily Cyanogenmod supports my phone. I will attempt the installation soon. Any piece of advice, or something you would like have known when at my situation?
edit: nm, based on the other downvotes in this thread I'm guessing zealots at this point.