Microsoft Edge records browsing history in InPrivate mode
betanews.com
betanews.com
Product: So Sue, how's the restore-session-after-crash feature going?
Dev: Great, just about done.
Product: So it's working for all sessions now? Fantastic!
Dev: Yep! Well, all sessions except private ones of course.
Product: ... so you haven't finished private sessions yet?
Dev: No, it's just that we don't store anything on disk for them, so there's nothing to restore.
Product: ...
Dev: ...
Product: Users don't know what "stored on disk" even means. They're going to be very upset if we lose their work after a crash, just because the session happened to be private. Maybe even more so.
Dev: But with nothing on disk, that would be impossible.
Product: You devs have such a fixed mindset. If I had a penny for every time I'd heard one tell me something was "impossible." So store what you need on disk, and ...
Dev: But history ...
Product ... and flag it so it doesn't show up in history or as a visited link. Wouldn't that work?
Dev: Well, kind of, but ...
Product: Great! So we have a solution. How long to get that coded up?
[Later] Product: "Impossible" laugh Hah!
However, its disingenuous at best that they didn't mention it anywhere.
I'm about to scan my butt to the CEO and type in the CSO's email address in the From field just to prove my point....
Everyone's supposed to have some fancy alphanumeric-with-special-characters password and sit there in front of the machine copying it in slowly from their LastPass. No, thank you.
Where else in a healthcare business can you implement those?
I mean, good story. 6 years ago it might have even been realistic for ms. These days, the middle level product manager who did that would rapidly find themselves on a high speed track to a new employer.
The Edge team isn't a bunch of faceless goons. Heck, a lot of them are really active in the browser development community and you can see they're trying really hard.
As much fun as it is to carry on the Slashdot tradition and make fun of every bug at MS as indicative of a toxic and stupid culture, maybe that's not entirely appropriate anymore.
I mean, it's not like Firefox and chrome haven't had bugs in this vein before. Hell, neither can fully protect repeatedly visited private urls on Android either.
But betanews wouldn't have very much to write about....
http://www.hanselman.com/blog/MicrosoftKilledMyPappy.aspx
Microsoft is thought of as this hugely evil company, but I don't know, maybe they are just as disorganized as every other company I've worked with and the product owner doesn't understand their customers all the time. The key is some comapanies I've worked for pivot fast and fix things they see as a mistake. Others try to bury and hide it.
Are they going to kill my pappy this time? I don't think so, but we'll see.
https://en.wikipedia.org/wiki/Halloween_documents
Hanselman's point was that they weren't as evil as you might think
Inside the private window, you can have multiple tabs; closing them and restoring them. Once you close the private window everything is gone.
Firefox is maintaining a window with tabs within it. So it can still keep your session info for each tab stored at the window level and restore it even after a tab is close.
This isn't true either. Log in to a site in one private window and then open another one. You'll be logged in in that one too.
Chrome's Incognito mode has the exact behavior of not supporting things like session restore and closed tab reopening. It's kind of annoying for those of us who occasionally use Incognito windows like a convenient transient separate profile (specifically "give me a different cookie jar because some site's login is broken"), but I think the loss of functionality is worth it given what the mode is actually /for/.
It makes me wonder though if it'd be worthwhile having a mode that gives you a separate cookie jar but keeps the browser settings otherwise identical (bookmarks, suggest, etc). I suspect the distinction is too subtle for most people however.
You can run both at once.
They've just started earning some trust and respect from the users and then this. Also, the Windows 10 privacy nebulosity. Why not just leave the user's privacy alone? There's still enough business with Windows itself. No need to be so greedy and try to compete with Google.
How shall I trust Microsoft enough to put my data on Azure? Or by a Windows 10 phone?
So stupid. What the hell did they want to do with private browsing data? Was it worth it?
Google has been very upfront on exactly how their business model works with users since day one. I don't find this comparison warranted.
http://www.pcworld.com/article/115692/article.html
EDIT: Quote > But Google is planning to scan e-mail and add advertisements that it thinks are relevant to the messages. Additionally, the Gmail privacy policy warns that messages, even if "deleted" by a user, may still be stored in the system, even long after users have closed their account--something that some privacy campaigners believe may be in conflict with U.S. and European data protection and privacy laws.
Article about privacy right there. I talk with people and they always say Google was forced into reviling they read people's gmail. Wasn't true.
The closest statements are mealy-mouthed ones along the lines of "we collect information about how you use our services and use that information to improve our services". Which is true of every single business in the history of the world.
> Our automated systems analyze your content (including emails) to provide you personally relevant product features, such as customized search results, tailored advertising, and spam and malware detection.
I think that statement is too general. From where I was sitting, it looked like people didn't think about privacy at all, and the only thing they were saying was "Holy shit, this is free!" Are you sure the people you tend to talk to are representative of the general population?
Your statement is did people care? That answer is if they did they wouldn't use Google services or FaceBook or most of the Internet.
http://www.infodocket.com/2014/04/30/privacy-google-no-longe...
https://news.ycombinator.com/item?id=11012392
They hid and lied about the facts about ad tracking of Education and Apps emails etc. until they were forced to testify about it in federal court and no one was clued into it. Once they got caught tracking and making money on it for many many years they rolled back some stuff. How is that clear communication?
Or how is that "Google has been very upfront on exactly how their business model works with users since day one." ?
I remember when people were scandalized by this, a minority in my circle but it was funny. Of course they were going to do that, what did they expect. I think Google is "evil" now for other set of reasons though.
That couldn't be further from the truth.
How many people know Google using location data from Android phones to track which physical stores users visit?
They were even mining paid Google Apps for Business accounts for tracking data.
From http://www.edweek.org/ew/articles/2014/03/13/26google.h33.ht...
Highlights:
"As part of a potentially explosive lawsuit making its way through federal court, the giant online-services provider Google has acknowledged scanning the contents of millions of email messages sent and received by student users of the company’s Apps for Education tool suite for schools. In the suit, the Mountain View, Calif.-based company also faces accusations from plaintiffs that it went further, crossing a “creepy line” by using information gleaned from the scans to build “surreptitious” profiles of Apps for Education users that could be used for such purposes as targeted advertising."
"A Google spokeswoman confirmed to Education Week that the company “scans and indexes” the emails of all Apps for Education users for a variety of purposes, including potential advertising, via automated processes that cannot be turned off—even for Apps for Education customers who elect not to receive ads. The company would not say whether those email scans are used to help build profiles of students or other Apps for Education users, but said the results of its data mining are not used to actually target ads to Apps for Education users unless they choose to receive them."
...
"Student-data-privacy experts contend that the latter claim is contradicted by Google’s own court filings in the California suit. They describe the case as highly troubling and likely to further inflame rising national concern that protection of children’s private educational information is too lax."
"Mr. Thiele said his district has used Google Apps for Education since 2008. Officials there have always been aware that the company does “back-end processing” of students’ email messages, he said, but the district’s agreement with Google precludes such data from being used to serve ads to students or staff members. As long as the company abides by those terms, Mr. Thiele said, “I don’t have any problem with it.” In an emailed statement provided to Education Week, Bram Bout, the director of Google Apps for Education, said that “ads in Gmail are turned off by default for Google Apps for Education and we have no plans to change that in the future.”" ... "Those plaintiffs in the California lawsuit allege that Google treats Google Apps for Education email users virtually the same as it treats consumer Gmail users. That means not only mining students’ email messages for key words and other information, but also using resulting data—including newly created derivative information, or “metadata”—for “secret user profiling” that could serve as the basis for such activities as delivering targeted ads in Google products other than Apps for Education, such as Google Search, Google+, and YouTube."
"The plaintiffs allege that Google has employed such practices since around 2010, when it began using a new technology, known as Content Onebox, that allows the company to intercept and scan emails before they reach their intended recipients, rather than after messages are delivered to users’ inboxes, regardless of whether ads are turned off."
"While the allegations by the plaintiffs are explosive, it’s the sworn declarations of Google representatives in response to their claims that have truly raised the eyebrows of observers and privacy experts. Contrary to the company’s earlier public statements, Google representatives acknowledged in a September motion to dismiss the plaintiffs’ request for class certification that the company’s consumer-privacy policy applies to Apps for Education users. Thus, Google argues, it has students’ (and other Apps for Education users’) consent to scan and process their emails."
"In November, Kyle C. Wong, a lawyer representing Google, also argued in a formal declaration submitted to the court in opposition to the plaintiffs’ motion for class certification that the company’s data-mining practices are widely known, and that the plaintiffs’ complaints that the scanning and processing of their emails was done secretly are thus invalid. Mr. Wong cited extensive media coverage about Google’s data mining of Gmail consumer users’
>Mr. Wong’s inclusion of the following reference to the disclosure provided to students at the University of Alaska particularly caught the attention of privacy advocates: The University of Alaska (“UA”) has a “Google Mail FAQs,” which asks, “I hear that Google reads my email. Is this true?” The answer states, “They do not ‘read’ your email per se. For use in targeted advertising on their other sites, if your email is not encrypted, software (not a person) does scan your email and compile keywords for advertising. For example, if the software looks at 100 emails and identifies the word ‘Doritos’ or ‘camping’ 50 times, they will use that data for advertising on their other sites.” “The fact that Google put this in their declaration means we take it as true,” said Ms. Barnes of the privacy watchdog group EPIC. Google’s sworn court statements reveal that the company has violated student trust by using students’ education records for profit.”
From a Google filing in court about Gmail privacy:
>Indeed, “a person has no legitimate expectation of privacy in information he voluntarily turns over to third parties.” Smith v. Maryland, 442 U.S. 735, 743-44 (1979).
>it's "inconceivable" that someone using a Gmail account would not be aware that the information in their email would be known to Google.
You have a process that needs to work for, in its mindset, "all tabs," which tries to recover them after a browser crash. You have a different flag on these tabs which is supposed to signal that disk-writing and history are not stored. Sounds easy, but the reality is that there are probably dozens of parts of the code that could potentially write recoverable history. Cookies, cache data for images and resources, the normal history writing functions, those are all the obvious ones to check. The anti-crash feature? Yeah, I can see it being missed.
Yes, their security audits should have caught this, but don't call it an amateurish bug simply because it seems obvious in hindsight.
(Though to be entirely fair, this is also why I won't use Microsoft products. If a reporter hadn't called them out on it, would it ever have been fixed?)
Or do you think Stagefright on Android would have ever been fixed if the exploit wasn't publicly disclosed? The threat of public disclosure is the only thing security researchers have as leverage to get a company to do the right thing.
Their APIs work that way due to ineptitude.
As someone who has been a sysadmin for a decade in environments that are at least 50% MS, I can tell you that, yes, they can be that amateurish and usually are. In other words, Hanlon's razor.
Microsoft, even at its best, is definitely a 'wait for SP1 before putting in production' company. Now with Nadella, they're even worse, and Win10 was clearly rushed to stop the poor publicity of Win8. Win10 won't be fully cooked until 2017-2018 at this rate.
Also, history of this happening in Chrome and Firefox:
http://www.ghacks.net/2016/01/11/chrome-incognito-mode-leak/
https://bugzilla.mozilla.org/show_bug.cgi?id=709326
Lastly, you have to be a fool to think private modes save you from any kind of snooping. At best, they just make purging history easier. At worst, they give people a false sense of security. Your stuff is sniffable all down the line unless you're using a VPN or Tor.
You can watch it send many of the same signals.
EDIT: Very confused why this post was downvoted. The post above is clearly concerned about privacy and the topic is very relevant. It's also true, and trivially verifiable.
I'd like to think the latter, but the fact that Win 10 has had well documented privacy issues already, and the fact Microsoft is probably the most experienced and among the most well funded browser development companies in the world, I get a bit skeptical. A private mode that still writes history WebCache. Did they really overlook that?
This could be interpreted or viewed as just inadequately covering their tracks.
I said it was a bug in Microsoft's view and they are allegedly fixing it.
I'm not sure what you mean by the "covering their tracks" bit.
But wouldn't it be awesome, if all conspiracy theories were produced by a conspiracy of the tinfoil industrial complex?
I think so.
Remember: This is the company that took an end-to-end-encrypted communications platform (Skype) and completely turn it around into a mass surveillance platform by being the first to join PRISM. It's the same company that builds a full disk encryption system (BitLocker) that sends your encryption keys back to Microsoft's servers. And finally, it's the same company that pushed for an "always on" HD webcam and microphone bundled with an "always online" video game console.
Probably more that they never intended this mode to be secure.
It could be simply a bug that disabling the caches for private browsing didn't work as intended.
Of course, barring a whistleblower, we'll never know. Yay closed source software.
Also let's hope they aren't sending different headers like DNT etc. when in private mode, which would make fingerprinting a lot easier.
This allows us to move tabs across Windows. How would we do that with one session per tab or per window? Also what happens when user opens link in new incognito window?
But it does seem to be shared between all incognito tabs in all incognito windows (including in further new incognito windows) until you close all incognito tabs/windows. This is not necessarily what users expect. New incognito window should mean NEW && INCOGNITO!
Not that I would recommend a Microsoft browser when you want privacy; or their OS for that matter.
...like many other Windows 10 features. Like someone in Redmond thinking: oh let's have two control panels for several years and progressively move stuff from one to the other so that users can never become familiar with our UI!
Every time someone says that as though it's not the absolute correct thing for MS to do given it's standard home-user technical level/expectation I'm super confused. I would expect it to be possible to turn that off, but you can be damned sure that swathes of their users expect to be able to ring MS when they forgot their bitlocker key.
>it's the same company that pushed for an "always on" HD webcam and microphone bundled with an "always online" video game console.
They want you to always be able to use voice and gesture controls with your console - because if you have to stand up and press a button to turn the damned thing on then what's the value in half the functionality?
I'm confident MS are actually more interested in their profit margins than they are by any conspiratorial opportunities with the security services. Casting the latter as their primary motivation all the time is disingenuous.
I have to admit I'm lazy and still allow some stuff too. Making security both functional and comfortable is a really hard (impossible?) thing to do.
How do you even do this? It was hard enough to report a bug as an MSDN subscriber. I don't think they have a vast array of consumer support phone agents, or if they do they keep the number very quiet.
Not doubting you, but do you have references? I haven't heard much directly about this stuff since the NSAKEY saga.
Nation states are states which are also nationalities, with people generally sharing a common ethnicity and language. That's totally the opposite of the 'melting pot' of the USA.
http://www.oxforddictionaries.com/definition/english/nation-....
If a "bug" was intentional inserted into a code, then it's not a bug. It's a backdoor.
Source: A wild guess, but fuck those pricks anyway.
When evil and incompentent seem like your only options, it's time to search for an alternative.
I'll never buy anything from them again.
Regardless of the browser, "private mode" is kind of a misnomer. You're still hitting the websites and unless you're using Tor, this can be easily logged by whoever has control of the LAN/router.
The point of "private mode" is to avoid logging to browser history so that someone can't casually inspect what URL's a user has visited (eg, when hubby wants to visit websites that wifey doesn't approve of). The problem here is that MS is storing the browser webcache even in private mode and it is relatively easy to get to it?
If so, the solution is to publicize this issue and microsoft will likely fix the problem. Then hubby will need to worry about wifey interrogating the router.
It just seems like an oversight and not a big deal in terms of privacy and security.
PS - L2Tp/IPSec can be a "nightmare" to NAT traverse. OpenVPN is best for mobile applications.
It is not for me but it might be an option for a lot of companies that depend on older software for industrial automation etc.
Smooth GUIs doesn't matter too much there.
ReactOS has released special FOSDEM distribution of upcoming 0.4 version
This is... horrendous, how did they get such a basic feature that broken?
Hangouts, iOS, Win 10, and Android (on a Moto X) have all been surprisingly buggy for me. If there were a company that prioritized stability and QA over anything else, I'd certainly switch to that for my phone. I thought buying a Google-made or Apple device would solve that problem, but I was wrong.
But then I thought some more, and I don't know if any companies actually do this correctly.
Do companies exist that can deliver on projects at a fairly steady clip with teams that build solid products generally on time and within budget? Or are we all just floundering around, making buggy apps that take forever to release and don't solve any problems, except for the lucky few who can get everything to harmonize out of sheer statistical happenstance?
But whatever the reason or rational, every time a story breaks about another security exploit or privacy exploit I read that as a condemnation on our profession.
In other professions, part of the certification process is gaining a basic level of understanding of the ethics one is judged against when associating one's work with that of the larger trades group, guild, or association. Often it is well understood that, to some extent, the topic is simply being paid lip service. But,it is also understood that those ethics draw a bright line which those the association serves will not tolerate when openly crossed. Take for instance investment professionals. Everyone knows insider trading happens and it's not uncommon to put profit before fiduciary duty, but when those lines are openly or egregiously crossed it is not tolerated under threat that the understanding between the client and advisor that minor infractions will be tolerated will no longer be honored.
The software engineering profession lacks this basic ethical covenant with its customer. Just look at the utter lack of product warranties. Sure there are SLAs, but there are virtually no warranties. And it shows.
As software begins to function more and more as the linchpin of our society, this issue will morph from technical debt to an Achilles heel. We complain about anachronistic laws. What about anachronistic code? We complain about absurd laws. What about absurd code? It's just as dangerous.
What I'm trying to say is that if you're serious about finding issues no project/product is safe from you :)
[1] http://www.theinquirer.net/inquirer/news/2298553/chrome-for-...
I was going to report it, but by then version 44 was already available, and it fixed that bug.
But, well, if even Mozilla can make such mistakes, Microsoft surely can too.
[1] https://technet.microsoft.com/en-us/library/mt598226%28v=vs....
These privacy mechanisms should be far simpler, vetted for security, and ubiquitous. Consider the physically separate "secure element" chip on your phone that stores data in a way that nothing else can possibly reach, for example. It should be accepted practice in the software industry that your new app doesn't just get to invent some way of storing potentially-sensitive information; there should be a clear place to toss it in a vault under user control, where the user can see everything you have stored even if your application isn't open (e.g. OS X Keychain).
And yes, this is an argument again for open-source software. Proprietary secrets be damned, there's nothing special about a web browser anymore. The code should be visible so as many people as possible can ensure it is correct.
I wonder if it has something to do with the fact that they are tabs. Either way, I really miss private tabs in chrome-ish browsers. They were better for regular use than a separate window I think.
Chrome already supports multiple 'users' which fits nicely with what you describe.
https://vivaldi.com/ (they push a few new things, it's closed source.. and rather taxing on performance)
http://otter-browser.org/ (this is more or less a hobby project I'd say)
It is one of the few things IE gets better (and has for a long time) than Chrome or Firefox where a single OS-level user can have at most two distinct sessions at any given time: one private and one not. It can be very handy from a development PoV when testing multi-user workflows in your application.
One caveat: if the site/application uses saved cookies rather then those set to expire at the end of the current session they will still interfere with each other when opened this way as saved cookies (those with an explicit expiry date/time) are considered global (with respect to the OS user) rather than local to the browser session.
I've not checked if this feature has carried into Edge. The clients I support are so backward that I'll not need to test against that this decade!
Chrome has support for profiles and having multiple open at the same time http://imgur.com/GU33K43
Best of all, they're persistent, making them ideal to have distinct 'home' and 'work' profiles in Chrome.
I think those "tree tabs" extension would be great to separate these groups even visually. So each root node is a separate session for example.
... you are not already logged in?
... is that what you are saying?
Sure it's simplified but hardly convenient!
i.e. open that resource in one click.
Separating profiles into windows drastically simplifies the situation.
https://en.wikipedia.org/wiki/Vivaldi_(web_browser)
"Founded by Opera Software co-founder and former CEO Jon Stephenson von Tetzchner and Tatsuki Tomita.. the browser is aimed at staunch technologists, heavy Internet users, and previous Opera web browser users disgruntled by Opera's transition from the Presto layout engine to the Blink layout engine, which removed many popular features in the process. Vivaldi aims to revive the old, popular features of Opera 12 and introduce new, more innovative ones"
It’s not some side benefit, it’s the primary reason for private browsing to exist at all, at least as far a product manager (who actually understands and cares about what users actually want from their browser – so not actually a bad one) might be concerned.
That’s why I can absolutely understand how this kind of bug can creep in. The most important aspect of this feature (from the point of view of most people actually using the feature) is not that browsing leave absolutely no trace anywhere, the most important aspect is that browsing leave absolutely no trace where other users of the PC can see it†.
I’m consequently a bit confused why everyone is unpacking the big conspiracy guns. This seems like an easily understandable and completely plausible bug to me.
People often don’t use separate OS accounts (it’s often just not necessary) and even if they do they will often still share the PC from time to time (even if just for a brief moment) or just show something off for some other people.
During all those occasions the browser history could be visible, even if people aren’t really prying (autocomplete, frequently visited websites, …).
1. For desktop users, most of us aren't using Edge most of the time. Desktop systems are powerful and features matter more. The only time we use Edge is when some saved feature or history element is there.
2. For Windows Mobile, all 30 people using the platform have no choice but to use Edge. This bug is pretty important for them, as inPrivate mode has many more implications on a mobile device.
3. For Tablet and Surface Book customers, generally regarded as the "leading edge" customers & Microsoft's most robust product and software line? We use Edge and will probably keep doing so. Why? Because it's te only browser that gives a damn about efficiency. Chrome is quite fast, but is a monster on battery life. Firefox is quite slow (even without plugins). Edge gets very good speeds, generally good performance and compatibility, and doesn't trigger a battery dump spiral.
This is not a unique aspect of the Windows platform (Chrome can roast batteries on Mac OS X as well, and mobile/portable Linux's Power management story is not great either). but it's exacerbated by the new form factors Microsoft is shipping in its Surface line which can easily get >10h battery life with canny apps.
That is too painfully familiar. So much testing is "does the UI work?"
yes, blame the intern...
let's blame all the telemetry snooping in Windows 10 on a bunch of interns too ? it's like Microsoft can't hire professionals to develop its two main products . There is no benefit of the doubt, they know what they are doing.
Load an incognito tab, hit the button to return to the main screen, kill the app, then re-launch Chrome.
If you need forensically safe ways to surf, browser "porn mode" isn't your ticket.
For some OEMs, it's hard to even figure out how to clear this data out. I've seen, well... awkward moments during software pitches of mobile products on Android.
"We recently became aware of a report that claims InPrivate tabs are not working as designed, and we are committed to resolving this as quickly as possible."
Hee. You "recently became aware"? Dudes. This was coded in. It doesn't seem very likely that this was accidental or that you were unaware. The browsing history is getting directly written into the main web cache file, along with a special code that specifies it's from private mode. You just accidentally missed this?
I don't want to hate on Microsoft but they are making it hard not to. Edge could, no it should have been excellent but it has been out for 7 months now and the updates are minimal.
See you back inside the Matrix...
This is surprising because? I would rather switch Chrome and Firefox in this sentence.
or you may have Googled 'how to change the default search engine in Microsoft Edge'
what time is the super bowl?Also, IE is often used to download Chrome / Firefox after a fresh install..
Apple had a similar bug in Safari.
>Safari's Private Browsing Mode Saves URLs In an Easily Accessible File
http://lifehacker.com/safaris-private-browsing-mode-saves-ur...
Google had a similar bug on Chrome in Android
>Chrome for Android’s incognito mode saves some of the sites you visit
http://news.softpedia.com/news/incognito-mode-in-chrome-for-...
I find it curious that a huge deal is made out of Microsoft's missteps with over-the-top comments being modded up and same with the articles, but similar or worse things by, say Google or Apple are simply papered over and buried.
It's Slashdot all over again.
Just because other companies/products have similar bugs doesn't make this bug or Microsoft any less asinine.
So... where are the threads about the bugsI linked? Why were they not voted up so highly on HN? That was my only point about the story selection and how getting tech news from only HN can cause a blind spot.
HN was a community of Silicon Valley startup founders. Though because of its title, more and more nerds switched over from Reddit/Slashdot/Digg. Until early 2015 HN was mainly inhabited from Linux and MacOS people. But Microsoft invaded HN around their Build 2015 conference in May 2015. Nowadays a lot of sock puppets and fanboys with MSFT background are on HN and try to downvote everything slightly not so pretty. Nowadays "Show HN" is already a bit off-putting with cynical comments and harsh critics. HN certainly needs better voting-ring and paid sock puppet detection - hint: they are only active in certain timezones and mainly on a weekdays.
The question is what HN want to be. I visit HN for startup news and occasionally open source news. Who in the right mind would use vendor lock-in mediocre expensive licensed software for a startup? Although, I am okay with Windows 7, I hate Win8/10 with a passion because MSFT turned to a mean company again (bad ModernUI, don't care about consumer anymore at all, privacy debacle of Win10, turns everything to SaaS, evil license changes). And therefore would welcome to see less MSFT sock puppets and less FUD on HN. Remember HN used to be a group of very intelligent people, burn them once and we will remember that forever, burn them twice... you know, better stop that right now.
Huh, I bet that's the US/Pacific timezone. What an astounding correlation you've stumbled upon[1]
> less FUD on HN
So it's FUD only if it's not anti-MS FUD?
There was plenty of anti-MS FUD on Slashdot.
http://tech.slashdot.org/story/09/02/16/2259257/draconian-dr...
http://mobile.slashdot.org/story/13/03/17/1914209/microsoft-...
http://news.slashdot.org/story/10/02/21/2329249/windows-7-me...
Do you think the above stories and comments are FUD or not?
Eventually the biased story selection by editors, circlejerk, echo chamber and biased moderation got so bad that the site pretty much died. Do we want that to happen on here as well?
>I visit HN for startup news and occasionally open source news
Then perhaps just move past the other posts you're not interested in, like the HoloLens or Open Sourcing of .NET and other libraries announcements which are definitely 'Hacker News' material.
Or spend more time on other places like /r/linux etc.
>Who in the right mind would use vendor lock-in mediocre expensive licensed software for a startup
That's totally your opinion, it works for some companies like StackOverflow.
>less FUD on HN
Can you link me to some of this FUD you're talking about?
While I can attest that HN has always had a significant amount of startup stuff, that was nowhere near the entirety of the site.
I remember when the front page was filled entirely with Erlang articles, for example, and I'm damn sure no more than a tiny fraction of HN was using or considering Erlang for production at that time.
Nor is it now. Speaking of Erlang, there have been three Joe Armstrong articles on the front page in the last week.
That makes it seem worse, not better.
By the way, their bit above about how the HN community makes a 'huge deal' out of Microsoft criticisms while Google and Apple get off, etc. etc., and accusations of voting bias on HN (e.g. https://news.ycombinator.com/item?id=11014741) —all that is highly characteristic of this person or persons. So is their use of HN not only to promote Microsoft but also to bash its competitors, something I predict you'll see if you look through the submission history of this one.
So, a call to all upstanding HNers: if in the future you see accounts that comment like that, it might be a good idea to email us at hn@ycombinator.com so we can investigate. But please don't accuse people on the site itself—that undermines civility, and shouldn't be done without strong evidence. (And let's not forget that HN has many legitimate users who use and like Microsoft products. I'm pretty sure kogir is no astroturfer.) When we do have strong evidence, we act immediately to protect the integrity of this site.
When we discovered this astroturfing campaign in 2013, and saw for how long they'd been plaguing HN, pg said that it made his blood boil. Well it makes my blood boil now.
We detached this subthread from https://news.ycombinator.com/item?id=11011322 and marked it off-topic.
Someone probably knows or can pretty easily find out what you've been doing.