Windows 10 Enterprise telemetry network traffic analysis, part 1
voat.co
voat.co
> However, before more info is gathered, Microsoft’s privacy governance team, including privacy and other subject matter experts, must approve the diagnostics request made by a Microsoft engineer. If the request is approved, Microsoft engineers can use the following capabilities to get the information:
> Ability to gather user content, such as documents, if they might have been the trigger for the issue.
This means that Telemetry in Windows 10 is a built in backdoor that allows Microsoft to access your local files. That is disturbing. At minimum, explicit user consent should be required, i.e. a popup asking if you'd like to share a specific file with Microsoft.
Source: https://technet.microsoft.com/en-us/library/mt577208.aspx?f=...
It's on by default on all other versions.
Even if the US government were entirely trustworthy, other governments are not. Does Microsoft really want to be put in the position where they either have to face sanctions or turn over the data of somebody whose big crime is being the opponent of somebody powerful?
I look at patching almost like a public health issue. Vaccinations are important because they protect you and the people around you. Likewise, secure machines connected to the internet are good for the owner and everybody else on the internet.
I get what you are saying, but I think the forced patches on consumer machines is at least arguable. The forced collection of data seems less defensible to me.
> I have configured the DD-WRT router to drop and log all
> connection attempts via iptables...
I'd be more interested in seeing the result of letting the connections succeed while timing how long they stay open and how many bytes are sent/received. The fact that thousands of connections are opened is likely a result of retry mechanisms after the connections are dropped at the router. Perhaps the first thing Windows 10 does is let Microsoft know "this system has opted out of the following tracking: ..." so that connections to Windows Update, etc. don't end up logging additional information.I'd also like to see a similar comparison for an average desktop Linux installation, OS X installation, and so on.
I agree. I'd really like to see an analysis of Android and ChromeOS. I'm glad to see Microsoft in the spotlight over tracking and analytics as this is a subject that gets far too little scrutiny from the tech community.
Tracking practices are widespread in the industry. Take Chromebooks for example, they are now used in many US schools. The kids have no choice in using these laptops, it's the adults who make the decision to deploy them (and Google that heavily promotes their use). The privacy implications of an OS that requires sign-in and then tracks every app and website you use are horrendous. Yet there's barely any scrutiny from the tech community.
We really need to apply this analysis of Windows 10 to other operating systems, especially ones that we know track you by default.
To use ChromeOS you must sign in with your Google account. Although you can use it as a "guest", this will limit what you can do.
Once you are signed-in, Google knows which web apps you use, including when and how often you use them. It knows (and records) the websites you visit (unless you browse constantly in private mode). It even knows when you print to your desktop printer because print jobs are routed through Google's cloud print service first.
To repeat: none of this is anonymous since you must be signed into use the OS properly. A Google account = your name, date-of-birth, gender, location and (optional) phone number. In other words, some of your most private and personal details.
In my view, this all amounts to a privacy-invasive OS that tracks you by default.
When you turn on Location in your Android phone, every time there is a disclaimer (unless you turn the notice off). It says that Google will collect your location data. If you decline, your phone's GPS is useless. So, in order to utilize the hardware you bought, you are forced to give up your privacy.
This is the definition of "tracked by default". Is there any hardware feature that Windows does not allow users to access if you turn off all the tracking?
But GPS still works. GPS even works with the WiFi and mobile radios turned off. GPS works without the Google Apps installed, and without the WiFi location being enabled.
Edit: I read a bit about this. There is something called Google location history. It's on by default and tracks and reports your location to Google. You can turn it off (it's a bit non-obvious but not very much so). The wording is "Places you go with your devices will stop being added to your Location History map". So there, "tracked by default".
The data collection is active only in 'High accuracy' and 'Battery saving' modes. Both these modes are services, the phone asks Google servers "I see wifi with SSID ABC and MAC 0:1:2:3:4:5, where am I?" or "I see celltower of provider 0123, with id 456, where am I?".
In 'Device only' mode, your location is determined purely by the device hardware. If anyone, it's Qualcomm who knows about you, due to AGPS request.
Then there is a separate service, Location History, that can be turned off.
Yes, exactly as I mentioned. And it is on by default.
Source: Little Snitch and the log files on my OS X systems.
Or route them to an internal system with a promiscuous HTTP server that gives a 200 response to any request. One could then parse the logs to see which URLs were being requested.
> The only way to turn Telemetry data full off is to use Local or Group Policy (and an Enterprise SKU, to be fair), as documented by Microsoft publicly. You cannot disable telemetry using the UI in Windows.
It's a very good read in general, have a look.
I ended up using O&O ShutUp10, a free app with a simple on/off interface for a bunch of Windows privacy-related settings, including telemetry.
There are other apps, and ways to block specific domains and IP to prevent Windows from calling home. It's staggering to see just how many part of the OS actually report information.
Some references:
http://answers.microsoft.com/en-us/insider/forum/insider_win...
http://superuser.com/questions/972501/how-to-stop-microsoft-...
http://www.majorgeeks.com/files/details/destroy_windows_10_s...
Some of these could be Windows checking if it is connected to the internet, NTP, malware filters, certificate revocations, windows update, ...
You can't really expect to install a computer switch off one setting and expect it to not connect to anything in 2016.
For what it's worth, I have Windows 10 Home and Pro as well as Windows 7 on several machines, and according to my router Windows 10 is only slightly more talkative than 7. I think that is mostly the Windows Store and Cortana stuff. The dreaded telemetry from 10 has already been backported to 7 and 8/8.1, so it's better to say "Windows tracks you" rather than "Windows 10 tracks you".
With Windows 10, you cannot avoid that.
It even highlights separate issue, that automatic forced updates are a bad thing.
For now, yes. In the future that may change, just as it did when the Windows 10 update changed from "optional" to "recommended" and the installation began without user interaction.
When you combine that with Microsoft's truncated support life cycle for 7 and 8.1, you end up feeling forced to move to 10 one way or another. I'm not saying that Windows 10 is a bad OS (indeed, I enjoy it on my gaming PC and my Stream 7 tablet, and it has been a huge performance boost to my wife's PC and laptop). I'm just saying that any pretense of "Microsoft would never say one thing and do another" is null and void at this point.
I used to have strictly manual updates set up. Yes, past time. One day I've had to hide KB3035583 one time too much, so now I'm getting used to El-Capitan.
This includes 2 workstations. In fairness, my /etc/resolv.conf points to recursive cache servers on my vpn, but I do log all my DNS queries. The only log entries are for things I ask for and Firefox trying to dial home.
A side-effect of being able to view the 'telemetry' packets is that one could also modify the packets on the way out.
http://arstechnica.com/security/2013/11/smart-tv-from-lg-pho...
With encrypted connections, you won't know what data it's sending, and if MS's treatment of security in other areas in previous versions of Windows is any indicator, the certificates will also be hardcoded so it's very difficult to MITM. Good for stopping everyone else from spying on you, but really bad when it stops you from knowing what data your own machine is sending.
Edit: Found this: https://systemoverlord.com/blog/so-is-windows-10-spying-on-y...
' maybe almost all, you need DNS. I dont know any way of letting applications use DNS selectively, its all or nothing :(. This forces you to let svchost.exe talk outgoing 53 udp.
Also, I think if Microsoft is actually worried about losing those users, it would choose not to subvert the firewall.
I suspect the kinds of organisations operating these tools would consider that "working as intended" in most cases, but if it interferes with the enterprise-grade configuration and update management tools then that could be an issue for them.
I use a third party firewall with all the known telemetry domanins added to a block list.
If anything, Windows 10 makes "a lot of assumptions about what the end user does or does not want"... and that script is just a different set of assumptions, perhaps ones that users would agree more with.
You could argue that anything is "legitimately useful functionality", while someone else would say it's privacy-invading spyware.
???? What are you talking about? Everything it does is pretty bog-standard troubleshooting in the PC tech space. chkdsk, sfc, rebuild the DISM store, run some anti-virus engines, etc.
Source : their About page https://voat.co/about
Ha. So if Windows 10 was designed by a VW engineer you could expect it to behave perfectly reasonably.