Microsoft Admits Windows 10 Automatic Spying Cannot Be Stopped
forbes.com
forbes.com
If you read their link "detailed data"[0] you can see there is an issue but you can also see that the level of invasion is low with most telemetry disabled.
This article links to that, but then ignores that author's conclusions (that it is a relatively light level of privacy invasion) to draw this conclusion:
> So how concerned should users be about Windows 10’s default data collection policies? I would say very.
But the author's articles are only really pro-Apple and anti-Microsoft, just look at their back catalogue [1]. They've written about Windows 10 problems weekly for months, getting more and more inflammatory each time.
So how concerned should readers be about the author's obvious bias? I would say very.
[0] http://arstechnica.co.uk/information-technology/2015/08/even...
Regardless of their history, something along the lines of "We will invade your privacy and you can't disable it, but the level of invasion is low, and you have no choice but to trust us on this" doesn't sound reassuring to me.
I don't want to go there, but one can easy question if you have pro-Microsoft tendencies (or even sponsored by Microsoft ), because we're talking about invasion of user privacy at the hands of a corporation, and just because it's a "low-level of invasion [that can't be turned off]" doesn't make it OK for users, be it Microsoft or Apple.
It's fine if your expectations are less rigorous; you simply aren't part of the article's intended audience.
Mods, can we get this link swapped out with a less biased one? I'm okay with Microsoft's telemetry stance hitting the front page, but I want it from a better source.
How can you justify using Windows for enterprise work if due to new policies you can't be assured you can keep anything you work on secret? I am not willing to keep the possibility open of sharing my competitive advantages with whomever is in bed with Microsoft's management to capitalize on my ideas. Can somebody please tell them to get back to their senses and become trustworthy again?
Do I need a dedicated NUC running super-secured *BSD/Qubes filtering out traffic towards known Microsoft servers while using Windows 10?
Same here. It's very annoying that they're trying to force a major upgrade. I don't like Windows 10 - I don't like its frankenstein UI and I don't like its privacy implications and I find myself in the odd position of having to jump through hoops to keep it off my PCs.
Before that head into Control Panel > Windows Update > Change Settings
Oh, btw: if you have let Automatic Updates run until now it's probably best to do a fresh reinstall of Windows 7 or Windows 8, because they retrofitted almost all of Windows 10 telemetry services in those operating systems in a series of "updates" released around August.
Which gave me enough reasons never to trust any update from Microsoft ever again.
If you are big enough to get the enterprise version, everything apparently can be tweaked. But there are a lot of tiny businesses that order a PC from Dell, install some software for their vertical, and then do little more than regularly install updates. My old dentist was a two person operation. They aren't going to get the enterprise version yet they need to handle medical and billing records securely.
Either I'm totally misinformed, or the professional version of Windows isn't suitable for many professionals. I'd be happy if somebody could explain why it's the former.
I also wish Microsoft were more transparent about the data that is sent to them. Why is a machine with all the options set with privacy in mind still in constant contact with Microsoft?
I don't see why they don't just add the option to disable that with appropriate labeling, though, if nothing else to satisfy the more vocal, privacy-concerned folks.
If you are wrong and Microsoft suffers a breach, your defense for HIPAA violations has to be better than "but I trusted Microsoft!"
> I would think that MS is only transmitting enough data to keep the machine running and virus free
I don't think that's true. It uploads what you type, your calendar, contacts, etc... so that things like Cortana work better. What makes me nervous is that even if you turn off all the Cortana things that you can, Cortana is still always running. Plus, how often to business users use Cortana?
Your last point basically contradicts the first one, IMHO, because you have an OS that itself becomes a giant spyware. You don't know what MS is doing with all that data. The could very well resell them to 3rd parties, give it to states, ...
And the "you can't turn that off" is obviously by design. You can't turn off a spyware.
Some of us poor software users don't always like one or both of these things, and client-side software is great at avoiding them: you choose when to install newer versions, and whether the software talks to the developer. Sadly, companies are figuring out how to "cloud up" client-side software with forced updates [1] and always-on telemetry, and Microsoft is jumping on the bandwagon in a big way. Maybe reverse firewalls will catch on like browser ad blockers have; probably not, but there's always a chance.
[1] http://www.forbes.com/sites/gordonkelly/2015/07/17/windows-1...
If Win10 improved on this, that is good news.
Is there anyone in MS management here who can explain how and why this is supposed to be a customer winning idea, and how it won't launch a stampede towards OS X and Linux?
"Okay, so we do the spying thing with everything you type. But - scout's honour - we don't do it all that much. Honest!"
Corporate dementia is becoming more and more of a problem in enterprise scale IT. HP, Yahoo, Apple, Oracle, IBM, and Google all suffer from it to varying degrees.
But MS appear to be trying to win a special best-in-class award for it.
--
PSA: For people with Windows 10 installed, I've found the following tool quite useful in shutting down the large amount of information collected and transmitted.
Unless they see an actual reduction in revenue and fewer people using their platform, this problem is only going to get worse.
[1] operant conditioning (Skinner )
In this case, I'm picking my battle.
MS are free to spy on me playing X-COM, but they won't be getting anything else...
the former was fixed by buying a cheap PCI-E soundcard and passing it through (line-in'ed to the primary soundcard), and the latter by twiddling some QEMU flags, as NVIDIA want you to buy the $4000 quadro... my next card will be AMD, who don't do this sort of BS.
now it's all sorted it works like a dream, you wouldn't know it's in a VM.
2) If you are always going to rank playing games as more important than spyware, then you're an easy mark. If you aren't willing to make a few sacrifices to invest in your future, then you're made your decision. Why do you care about spyware if games are more important?
The costs of leaving are only going to get worse with time. I recommend paying these costs now instead of waiting for the problem to get worse.
I wiped Windows nine months ago and installed Arch. The only things I missed were Dark Souls and Insurgency.
I found out a week ago that Dark Souls runs like butter in Wine, and Insurgency just got native Linux support the other day. I am a happy Linux gamer.
As for the titles that choose to avoid supporting my operating system, well I guess I won't be supporting them with my dollars.
I have a RAT5 mouse and am X-55 Rhino HOTAS for Elite: Dangerous and as far as I am aware, there are no drivers for these under Linux.
I use my Windows machine for gaming only, whereas the rest of my computing is split between my MacBook and iPad.
2 is actually a decent reason to try to change, given that Valve is trying to get more venders to SteamOS it might just be start to make a difference.
It's not even remotely comparable to what MS is doing with Windows.
And any idea why MS is acting this way? Certainly offering a hidden opt-out registry key would satisfy a lot of customers, and not impact the telemetry data in a meaningful way. For Office, they literally discarded/sampled the telemetry data as it was simply too much to use.
Gateway firewalls are much less susceptible to malicious modification this way, and IMO are the best way to protect yourself from this type of corporate spying in general.
Comodo is pretty good.
But, I see some hypocracy in criticizing companies like Microsoft and Google about the danger of private information being leaked. What about github repos, data on AWS, etc.? Most people seem willing to trust those companies.
I believe that companies like Microsoft and Google will immediately fire any employee caught improperly accessing user information.
We also trust our doctor's office and our bank with critical information.
I trust Microsoft and Apple to a large degree because I believe that their interests and my interests are aligned. I trust Google and Facebook, as sellers of data for advertising, less.
In the last five years I have gone through two "phases" where I used Linux on my laptops almost exclusively - for privacy and control reasons. The problem is both times I was a bit less productive during the periods when I used Linux. Personal efficiency trumps some of my concerns over privacy, especially given that the NSA and other intelligence agencies around the world record most of what we all do anyway.
The one and only place that things like keystroke logging are mentioned in the privacy policy is in the context of interacting with Cortana and the related search service, where the phrasing is similar to "things you enter here get sent to us, and we log those things."
The vast majority of the Windows 10 privacy concerns are mitigated by turning off the Customer Experience Program stuff and never turning on Cortana.
Why?
What's the need for key strokes to be logged rather than just a complete edited search term sent to a server. Why does anyone need to know which keys I press on my computer?
There are a lot of examples in the past too. Arbitrarily limiting 32-bit consumer versions to just 4 GB RAM. Letting just one user having an interactive login in the same time. Not having remote desktop server in consumer versions.
Microsoft, please just make one version of Windows. If you must, make a separate server version. But please stop this segmentation madness.
From a tech support perspective, the decision makes sense. Most target consumers probably aren't going to have enough RAM to hit the limit, but are going to notice and complain when their computers become extra-crashy. I may well have made the same decision.
> I disagree that the 4GB RAM cap is entirely arbitrary. Guess how many GiB of memory you can address with 32 bits? 4.
That's completely irrelevant. You could still simultaneously a lot of processes each taking up to 3 GB RAM individually. All that matters is that different processes and drivers could utilize whole installed physical memory range. 2.5-3.5GB limit was already an issue in Windows XP era, when computers started to commonly have 4GB or more. 32-bit Windows XP could have handled up to 64 GB RAM just fine.
> Then consider that Microsoft discovered that some drivers became unstable when addressing more than 4GiB of RAM.
I've heard this one often, but never seen any concrete examples of drivers with such problems. What are these drivers actually? What kind of bugs? Say DMA buffers? Well, if the developer was incompetent enough to set 4GB max DMA buffer bit for PCI[e] hardware that can't address 4GB+... All other memory buffers would have mapped behind 32-bit pointers anyways, regardless of where they actually are in physical memory. You seldom deal with direct mapping even in kernel mode drivers.
For example, how about drivers that use PASSIVE_LEVEL functions at DPC or higher? Should they not trigger IRQL is less than equal blue screen as well? Buggy drivers are buggy drivers, period.
> complain when their computers become extra-crashy
Why would their computers be extra crashy? Windows 2003 server versions worked just fine with very much the same drivers without any crashing. Why would Windows XP have been any different?
By the way, I have written Windows kernel mode drivers.
What a crock.
All you have to do is care enough to install a proper gateway firewall that can intercept and block these requests before they leave your network.
Companies will only encroach more and more on your privacy all the while telling you there's nothing wrong and it can't be disabled and that its just a little bit of your privacy [that they're forcibly stealing].
Stop being complicit in it and do something about it. You'll feel much better about everything when you do.
I just made the switch to Linux full time after all this Win10 privacy bullshit. Been Linux full time for 4 months with no problems, never going back to Windows.
I started by configuring it to block everything by default and white listing the traffic I wanted to allow. Most systems will log dropped or anomalous traffic so its very easy to work out what traffic needs to be allowed when some new game's multiplayer features don't work as expected. And as an added bonus you learn a lot about networking at the same time, possibly opening up new career opportunities.
It might not be for everyone but if you value your privacy you owe it to yourself to explore your options. I suggest the Sophos UTM if you're just starting off, the UI is very friendly and helpful.
http://www.sophos.com/en-us/products/unified-threat-manageme...
Satya Nadella
He seems even more tone-deaf than most CEOs, e.g. his comments about women asking for a raise in pay.So, here's the delicate question: is this cultural? He's originally "not from around here", but he's lived in the USA for at least 25 years.
In contrast, Tim Cook seems to have staked out the opposite ground, i.e. that user privacy matters.
"I believe men and women should get equal pay for equal work. And when it comes to career advice on getting a raise when you think it’s deserved, Maria’s advice was the right advice. If you think you deserve a raise, you should just ask."
He also said "[I] Was inarticulate re how women should ask for raise. Our industry must close gender pay gap so a raise is not needed because of a bias"
So you've made a conclusion because he said something that was wrong and silly. I would go as far so say that it's a big leap of faith that you've drawn, or that you're trying to be inflammatory on purpose.
Now it would be more accurate to say that Microsoft is seeing how much money Facebook and Google make from knowing people's secrets.
Making it about one guy and his cultural background is a bit stupid, in my opinion.He is what, Indian? does it influence its way of thinking, maybe. Does that dictate Windows 10 strategy? no. This guy was mostly unknown before he becomes CEO of Microsoft, I always thought Sinofsky would take Balmer's job. My point is, MS board chose a rather "unknown to the public" and more discreet guy to represent MS in order to change the image of the brand. Which worked. Who came up with that new business model, we don't know, Nadella certainly vetted it though.