Remove anti-privacy, anti-security, and general nuisance “features” from Win 10
github.com
github.com
This is the first time in probably four years that I'm using Linux on my main desktop again, and it's been a pleasure. Things like SLI and dual monitors just work - I remember last time I had a Linux desktop these things were a nightmare. A surprising amount of my games on Steam (152 of 400) support Linux.
Zero regrets so far!
edit: Sorry, I didn't mean this to become a Linux bragging post. This looks like a great project! I appreciate the effort people are putting in to making W10 usable.
I'm honestly really surprised how smooth the transition was for me. I expected it to be a bit rough - I only did the install telling myself "I'll give this a go for a week or so" - but I really can't see myself moving back any time soon.
Even sleep works - and it works better than it ever did on OSX or Windows.
To make Fedora even remotely usable I had to un-Mac OS X it by installing a bunch of third party tweak tools and plugins because they took all of the major UI anti-patterns from OS X.
Any cursory glance of any Windows forum on the internet will show you that it is indeed not more usable than any of its competitors.
I've personally set up children and elderly people with Fedora and it's orders of magnitude better than Windows in these cases seeing as it's almost impossible for the average user to mess up.
Perhaps installing Fedora on your mac book was a headache, but have you ever tried to install OS X on non-apple hardware? It's worse than any other OS. If you bought Ubuntu certified hardware (as you did with Apple) you'd have no problem with Linux, so it's disingenuous to compare the two.
Sorry, but Windows isn't an OS for "normal" people, it's an OS people use because they have to for some reason (games, work). It doesn't "just work" and it's not miles ahead of any other OS, and certainly not more stable. I've had my Fedora desktop up for months at a time without anything crashing, this typically can't be said for Windows in my experience.
And you'll never see a problem like this on Windows - https://ask.fedoraproject.org/en/question/38845/graphical-de...
This isn't typical though. I've seen literally thousands of posts about how "every time I come over I have to fix my parents computer" and 99% of the time it's a windows machine.
>And you'll never see a problem like this on Windows
https://social.technet.microsoft.com/Forums/windows/en-US/5b...
http://windows.microsoft.com/en-us/windows7/why-is-my-screen...
https://social.technet.microsoft.com/Forums/windowsserver/en...
Pretty similar.
Maybe it's different for me because I'm from the east coast, but all of the people that I know running Windows at home are certainly normal. My wife, a teacher, is running a Surface Pro 3 which replaced her iPad + laptop. My dad (a retired plumber) runs Windows but my mom has a Macbook Air. Almost all of the college students in my family went with Windows on a laptop or a hybrid.
I have Fedora F21 running and it's probably the best performing Linux desktop that I've seen and the most usable (after taking away all of the OS X idioms of course), but unless the only thing you want to do is run Chrome more slowly than you could on Windows, then I wouldn't recommend it for normals (edit: because from what I've seen, it's generally a buggier environment than Windows. Now that could be mostly because I installed a bunch of buggy plugins for Gnome, but I also had hardware issues that Windows did not have).
Even people who are power users can only use Windows for games and some enterprise apps.
So you either don't use a computer at all or use Windows and sometimes OSX.
I could see some people needing office software, but the average user really can get by with LibreOffice.
I don't trust open systems either. I don't have the time to audit them. If I did, I wouldn't trust myself to catch everything. I don't trust "enough eyes make all bugs shallow" either.
Case in point: Canonical written "features" in Ubuntu, and OpenSSL bugs in general.
> why would you then, after performing these steps, trust the system that it really does what it says it does.
Don't trust: verify with wireshark? Alternatively, trust the people who wrote this to have run wireshark. Alternatively, "Trust but verify."
I generally trust Microsoft and FOSS to not be actively malicious on their own behalf.
I trust neither Microsoft nor FOSS to do their privacy due diligence, write perfect software, to be free of capitalistic or engineering pressure to add privacy harming features, nor to be free from subversion by state actors (NSA etc.)
What's your superior counter-proposal, under these conditions?
> The point is that you don't know, and you can never be sure.
Fundamental truth of computing, not "windows 10". I can't even trust the code I write myself to be free of security or privacy issues due to my own mistakes or lack of consideration.
> The solution is to either trust or not, switch or stay, there is no middle path, because any middle path implies some amount of non-trust.
I reject the thesis that trust is binary. Were I to accept it, I trust nobody - everyone is vulnerable to being subverted by blackmail, intimidation, making mistakes, etc.
Trust of system is also not the only factor influencing my use of a system. I trust a deeply buried cement brick more than any computer, but I can't use the web with it. I have very different trust needs for my bank servers, my workstation, my catstation, and my gaming console.
Don't put words in my mouth please.
I reject the thesis that trust is binary. Were I to accept it, I trust nobody - everyone is vulnerable to being subverted by blackmail, intimidation, making mistakes, etc.
You seem to be using a different definition of the word trust than I did. Everyone is vulnerable, does that mean you cannot trust anyone? No, you certainly can, that is the whole point of trust.
It's not my intent to. I'd ask that you clarify exactly how I have, if I have.
>> I reject the thesis that trust is binary. Were I to accept it, I trust nobody - everyone is vulnerable to being subverted by blackmail, intimidation, making mistakes, etc.
> You seem to be using a different definition of the word trust than I did.
Did any of the earlier discussion about what I do and don't trust Microsoft & FOSS with seem on the right track?
> Everyone is vulnerable, does that mean you cannot trust anyone?
It means I cannot trust in an absolute, binary fashion, of 100% certainty that it will not be misplaced. I can only trust that they'll probably do the right thing (tm).
> No, you certainly can, that is the whole point of trust.
EDIT: Added context now that new lines have shown up. Also added replies.
Oh come on. Canonical did not hide what they were doing, and enabled an option to disable it in the first place. You could try finding better examples than that.
Did Microsoft? This is news to me if so, and I'd be interested in reading up on any sources for this you might have.
> and enabled an option to disable it in the first place.
Microsoft added several options to disable things. While I certainly agree that those options have some gaps and/or are outright bugged, I'm not convinced there's any difference in intent or motivation, which is the bigger factor to me when it comes to trust of character.
Yup, I completely agree. I trust both of them.
But I don't trust third-party programs made for Windows because I always have to un-check something just to not get some junk program attached to its installation. I've never encountered with a single such request since I made the switch to Linux two or three years ago.
[1] That's one of the reasons some of us promote Free Software instead of Open Source.
It used to be that only the smartphone knew your location, what you type, who you are, who you are emailing, etc. The difference now is that desktops and laptops running Windows 10 do too.
This seems to upset people, but the same people were/are OK with using smart phones. I don't get it, of course I don't use smart phones either and have no plans to use Windows 10. But when all my Android and iPhone friends complain about Windows 10, I just scratch my head and wonder these things.
desktop computer (also laptops) know your location, what you type, who you are (sort of), who you are emailing, etc. and it has been so for a while but it used to be third party software, websites, governments, corpo or malware that would collect and use this data.
Cell phones are tracking devices you can use to make a phone call, people using those devices doesn't mean they are ok with the surveillance that come with it.
When your friends complain they're complaining that the surveillance is creeping its way back into an OS.
Additionally, Apple is very clear which what they collect and what gets sent to Apple. They go through it when you set your iOS or Mac OS X device up. It's not hidden in some "advanced setup" link.
Most of them are also for useful features, it's just that they are all talking over the wire and potentially exfiltrating user information. I don't think that people realize how much data is sent around all of the time.
Here is a non-exchaustive list just to give an idea:
* locationd -> gs-loc.apple.com:443
* apsd -> .push.apple.com:80,443,5223
* mapspushd -> .ls.apple.com:80
* UserEventAgent -> :80
* ntpd -> time.apple.com
* ocspd -> :80,443
* ...
I didn't put all services. Notice that some data is not even encrypted.
I don't think this is the case. People have complained about that too and personally I take a lot of precautions to protect my data.
Pretty much every reddit thread on the subject has a top comment akin to "Who cares? everyone else is doing it", and your comment seems to be a more well thought out version of the same sentiment.
We've known for a while the NSA is abusing our technology and working with large corporations to spy on us, but at this point there is almost no way around it except to stop using technology (and even then you can be spied on by other sophisticated equipment like drones).
I don't really think this is any type of excuse or justification. Just because people have no control over the spying doesn't mean people like it or are "okay" with it. The only other option is to give up most technology and stop participating in the world, which is absurd.
This kind of irrational paranoia is extremely common amongst tech people, especially on HN. I can't think of anything that could slow down progress more than fear of transparency. Yet I can't blame these people because they clearly don't know better.
I regularly try to have discussions around the benefits of transparency and the unsustainable nature of privacy, but it's such a touchy subject that it inevitably gets buried.
After all you and I will need to leave auto-updating on default in order for the OS to stay safe in Internet context. Which effectually means that MS can enable/replace all of these services at any given time. I get that trusting closed source code is always iffy but trusting closed source software that -intentionally- sets out to monitor and document your every move seems a less than optimal path to walk. Will stay on Windows 7 for now and if no better offering comes along from MS I will move to a Linux solution (or even OSX if my privacy stands a better chance of being protected than on Windows). Sad in a way cause I'm fundamentally fine with Windows from a work perspective, it gets stuff done for me.
Meanwhile disabling UAC so you can run a pile of batch files off the Internet sounds like a terrible idea to me.
[1] https://github.com/dfkt/firefox-tweaks/blob/master/firefox-t...
[2] https://github.com/pbiggar/firefox-tweaks/commit/635779c7939...
I know i can just read the code, but i'm not skilled enough with windows to know if there's something else snuck in there or not.
There are blog/post links in various comments in these files, I should note.
I'm not sure how documentation would help with the "might sneak something in" issue either. If anything, if you're feeling paranoid / reasonably cautious, you should ignore the documentation in favor of documentation you source yourself - if you can't trust the author to write the commands, you can't trust the author's documentation of the commands either.
The solution is that someone trustworthy vouches for the files.
I think that in this particular case you can trust the random bat file more than Microsofts official binary blob OS.
Aside from the obvious risks of downloading and immediately executing internet code, which are indeed risks but of course we all accept them on a regular basis...
... and aside from the mildly more subtle risks that the HTTP server is doing something sinister, e.g. with browser-agent, and so you're not getting the code you think you're getting...
... even aside from these issues, curl-and-pipe-to-sh is dangerous because of its failure modes.