France orders Microsoft to stop tracking Windows 10 users
theverge.com
theverge.com
I understand text and voice data will be captured and sent if you use Cortana but that is pretty obvious, the same is true of Google, Bing, Siri, etc. [0]
What I want to know is when I put things at the lowest setting possible what do MS get and how often?
Edit: [0] I mean captured and sent for processing. I expect (perhaps wrongly) for it to be deleted from Microsoft's servers as soon as my request has been answered. Unlike Google which stores everything you say to Google Now for example.
Not really. I was surprised both by Google storing every voice recognition sample they've ever received, and I was also surprised that people weren't totally creeped out and outraged at discovering this. Most people admit to being a little creeped out, but get over it very quickly.
Most people don't know this, and I didn't expect it either. Having used voice recognition in the past (like, 8 years ago) they were just programs that worked very badly, but they were the state of the art back then. That they now upload everything ever is recent news to me.
It's not all "bullshit anti-{bigCorp} fairy tales" if it's something people genuinely didn't expect.
So basically random bugs can get your very private conversations recorded on servers that can be under the control of state agencies and disgruntled employees, possibly stored forever? That's a reason to freak out really.
I've had google search activate a few times by my wife watching TV in the background and once when it was sitting in front of my speakers while listening to a podcast. We've tried going back and replaying the same bits but can never get it to activate in the same place twice. Still, it is strange to be sitting there and suddenly have the Google mic pop up.
Is there an analogue for a piece of scotch tape over the webcam for the paranoid (Zuckerbergs) of the world?
What they do is to introduce a dedicated processor that listens for these keywords and that is supposed to wake the phone up on detection. The danger of course is having that processor activate the phone on keywords other than "OK Google". And it doesn't even have to be on purpose. As I said, my wife's phone detection is totally broken for some reason.
Voice sounds fine at 8kbps. Reduce it even further if all you need is to understand what's being said.
that at least does not really worry me. Google is very paranoid over who can access customer data from the inside.
Government access is way more of an issue IMO. I would be way more creeped out by somebody going over my whole gmail history than my searches (audio or not) though.
And yes I agree it is disturbing that so much is saved. I remember the first time I opened the audio recordings area in Google Dashboard and my jaw hit the floor at just how much it had captured. Thankfully you can delete it easily. Well delete it from view, I don't believe for a second it is truly gone.
All of the FUD and other misinformation from random people on YouTube is annoying. I just want a straight answer.
Do you still get telemetry data when it's run in a VM?
Yeah. Maybe another sign of Microsoft's increasing lack of relevance if no enterprising hacker cares to investigate it.
Sounds like an oversight by IT. On corporate/enterprise network the Windows 10 upgrade should be disabled through group policy.
Are we sure that the Enterprise version doesn't send anything ? Honestly I'd be ready to pay a premium for having an otherwise good OS respect my privacy.
There is currently no Microsoft-endorsed way to disable all telemetry, no matter how much money you pay, or which version of the software you buy.
I'm excited by France's decision. I hope the telemetry-free version of Windows 10 will be available outside of France, because I'd happily pay a bunch of money for it.
As it stands, I'm stuck on Windows 7 because I don't like the UI in Windows 8, and I'm not a fan of the telemetry in Windows 10. I've only run into a handful of apps that don't work because my OS isn't compatible with very new versions of DirectX/.NET, but these problems will only become more common with time.
I'm colorblind, and the flat design makes it very hard for me to figure out what's clickable. Things like borders, shadow, and shading provide valuable visual hints about which parts of the UI can be interacted with. I've heard that Windows 10 has walked back some of the more problematic design changes.
The whole "myth" of a performance boost probably started simply because they added a new startup mode in W8, called "Fast Startup", which is basically just partial hibernation. So even saying that it boots faster isn't correct; regular boot, sleep and hibernation are still just as fast as they were on W7.
As such, the "bullshit anti-Microsoft fairy tale stuff" is just as valid as whatever you believe that they send. Especially also under the connotation, that Microsoft does actually reserve the right to send anything they want in their Privacy Statement.
And we shouldn't treat privacy as "innocent until proven guilty". If they cannot provide a lower boundary where you have a guarantee that they respect it, then we should assume the worst.
Just because multiple things are possible in this case, that doesn't inherently mean all things are equally plausible. Otherwise we'd have to pretend that the lizard people conspiracy theory is as likely as anything else that has yet to be proven. Your premise drops the critical consideration of plausibility and declares all possibilities equal, no matter how fantastical.
That's the same logic error that leads people to believe one roulette wheel spin influences the next, and that if you have two possibilities then the odds must always be 50/50 regardless of context.
What I meant was that any bullshit anti-Microsoft fairy tale stuff, which is not trivially disprovable as physically impossible or clearly illogical for Microsoft to do, is just as valid as whatever he/she believes. That is, as long as his/her beliefs are also within this same range of thinkable things that Microsoft could do, as otherwise those other claims would actually be more valid.
You can claim that Microsoft spying on their clients again¹ is a fantastical proposition all you want. It does not make it so.
1 - They were caught a few times doing that already, and even stealing IP.
Big data is huge and there is no end in sight as far as growth goes! Telemetry is a big success. And we're talking about regular usage now. Hospitals use new state of the art EMR software with all kinds of telemetry built it as well.
Why not Verizon? Why not NSA? Why not the traffic strips counting cars? why not the ticket guy @ the cinema?
Edit: US example, I have no idea how France government works. http://www.boilingfrogspost.com/2011/11/30/bfp-report-meet-t...
Apple; there's a toggle switch to turn off telemetry and it works. But it's also not a primary business operating system and doesn't hold the market capital the same way either.
If the country was running on apple products for mail, appointment making, meetings, and all national work was done on apple OS, then it would be open to the same scrutiny. But even so, they've been good about keeping their nose out of your operating system.
Because people post those to HN all the time.
Or not, because that's not as fun as bashing MS.
google.com 0.0.0.0So, why are you trying to include them?
Microsoft could easily demystify this by writing detailed document detailing what is being sent but unfortunately there isn't one. Even if it was, part of the outrage is that some most egregious options are opt-out and easy to miss if you are not technically inclined and just went through unintended upgrade.
https://technet.microsoft.com/en-us/itpro/windows/manage/con...
Most lists are open-ended, they will start with "such as" so you can't be sure there isn't anything more. Even then under basic level I fail to see why they'd need to take my IMEI number or device attributes of presumably every piece of hardware I connect to my computer.
Then there's another group of settings related to privacy, the most troublesome is "Send Microsoft info about how I write" which seems intentionally vague about what it does, but it's been suggested that it sends keystrokes to Microsoft and we know this feature is included in Windows due to this bit from privacy statement: "Microsoft collects and uses data about your speech, inking (handwriting), and typing on Windows devices to help improve and personalize our ability to correctly recognize your input."
I obviously have no more definitive insight than you, but it seems most people agree that this refers to inking. It's data about handwriting and character recognition. We can't say for certain that it doesn't include information about keystrokes and sentence structures/patterns, but it's the most obvious. Occam, Hanlon, and a bunch of other razor manufacturers and all that jazz.
https://technet.microsoft.com/en-us/itpro/windows/manage/man...
every mouse click, every letter typed, every program installed, timestamps of start/shutdown of every executable, serial number of every usb drive plugged in, etc etc etc
I've actually read the privacy policy that is linked from the Windows 8.1 operating system. It's pretty frighting what they collect. They're browser is basically spyware with the things it collects.
What I want to know is this:
If I use Chrome, or Firefox, are they still somehow collecting my browsing data?
I know that IE is actually built into the Windows operating system.
Actually seeing everywhere a local machine is sending data to is easy. Figuring out what it is sending is significantly harder if the traffic is encrypted in transit, which Windows 10 telemetry is.
Further, and something I don't see discussed as much, is their apparent ability to force through whatever "improvements" they want to this tracking via their now-impossible-to-fully-disable Windows Updates system.
Is it entirely unreasonable to expect them to use that for targeted delivery of payloads on "terror suspects" or what not? I realize that might be a bit in the tin-foil hat territory, but until proven otherwise, I feel like we need to assume that capability now exists.
When they ask if you want to share what you type or say with them, in order to improve the experience and for you to get more relevant suggestions or more accurate spell checking or whatever, they only focus on the positives.
But that's not enough. I want them to say that your delicate and private conversations might leak and be used for nefarious purposes by disgruntled employees, state agencies, hackers or future owners of that data, because that's the truth.
Much like how cigarettes packs have graphical warnings on them. I'd like that very much, because as an ex-smoker I can tell you that those work. But of course, it would hurt their business to admit it, so they'll never do it willfully.
Windows pretty much checks the box in term of complexity to the average user.
By giving me a 50+ pages brochure. Just like EULA's hide the nasty stuff among huge amounts of text.
Sure it's better than nothing, but still far from perfect IMO.
These are not font 6 footnotes in the terms and conditions.
Facebook has been doing this for a long time, to extremely high degrees of invasiveness. Google as well, and pretty much every single web startup in existence. Collecting data is how you compete in modern business.
If you think this Microsoft stuff is a big deal you should have another look at the entire foundation of modern tech.
My hope is that France can get Microsoft to just enable Telemetry 0 for all licenses, and that maybe they let us here in the US do it too.
You definitely can, Feel free to disagree, but many would argue the comparison is fair, especially considering a smart phone has replaced a desktop or a laptop for many people. But to say in such absolute terms the comparison is not appropriate is naive.
Looks to me like it's calling out people for their hypocrisy.
I'd argue that my phone is almost a lower common denominator than my computer. My phone knows my geographic location at virtually all times, has logged into most of my web accounts, handles all of my social contacts (definitely more than Facebook. But even people who primarily use Facebook likely use it mostly from their phone and not their computer).
If we want to care about this stuff, things need to change in very dramatic ways.
Absolutely & unequivocally. Hard part is, the technological means is baked into every modern SoC & NIC, huge amounts of money are being made from the 'big Data' industry created & the psychopaths are driving the bus. We survived just fine back in the Stone Age(pre-smartphone) and we can hold out for change($=vote). Principals often require certain sacrifices.
So what you gain in privacy vs private entities you lose with regards to the state having complete access to all of your online life.
234 people dying from terror attacks in France in the last 18 months is not a handful. Don't just dismiss their deaths so heartlessly as a "handful".
Shame on you.
I personally fear state powers much more than terrorism.
Or suicidal airline pilots...
Right, of course not.
It's not that you shouldn't care, it's that you should care in proportion to the seriousness. 234 death is fifteen days of 2014's driving fatalities.
Why do you hate the children so much that you don't care to save them except from movie-plot deaths?
Yes, it had a major impact on some people and their families and their pain is not to be dismissed lightly but on the other hand we should not give up our way of life to prevent these things from happening, especially when evidence supports that the new laws that are written after these events seem to do very little to actually further protect us.
While a little sensational I think the graphic in this article concerning the TSA in the US does a pretty decent job of summing up exactly what we've gotten from "enhanced" security in the US.
https://www.techdirt.com/articles/20120405/04390118385/tsa-s...
Medias usually have this balance in mind when they cover common crime. This balance goes totally out of the door when it is terrorism.
Edit: In addition, feel free to review another popular construct the FBI created soon after 9-11 to fan the flames of 'Fear Theater' by this 'extremist' group... a couple street thugs who had no potency beyond an FBI agent and promises of guns & bombs. How many trials did it take to convict some of them? Fear Theater works.
plus in french example, probably motivating some local young unhappy psychopats in muslim communities to help "with the cause" described above. goal? maybe civil war in france? more budget from saudi elites on jihad? don't know here.
if you look at all these acts through this logic, they don't look that bad, and they are truly a drop in the ocean of civilization of 7 billion. last year, in africa alone, 400,000 people died just from malaria, which is a lousy way to die just because you are poor. i don't see much emotions about these topics, yet numbers are shocking, every single time.
Apart from that and from rewarding people by getting a well paid job inside it, CNIL is useless since 1978.
I remember listening to my law teacher in IT school back in 2000 telling us that CNIL doesn't have the budget nor the will to ensure anything.
Well now it's 2016 the commission has a 20M€ budget so they have to justify it by having some existence in the media.
for those who reads french: http://www.20minutes.fr/societe/659250-20110126-societe-la-c... https://www.data.gouv.fr/s/resources/budget-de-la-cnil-1/201...
There is a saying which says if a product are free "you are the product". Microsoft made the upgrade to Windows 10 free a guess so that they can mine data about you and your habits. That data is valuable for marketing purposes.
Wireshark traffic dumps show a lot of data going to Microsoft telemetery.
I choose to say no to that data collection, instead wanting to keep a bit of privacy.
Have some security wiz MITM the Microsoft telemetry server with their own cert to inspect the data collection traffic?
EDIT: Just realized that since 16.04, Ubuntu no longer has online search results enabled by default in the Dash. Still though, play around with some of the settings!
I would rather recommend either Ubuntu GNOME, if you want a rather unconvential, but highly integrated, highly user-friendly interface, or Linux Mint Cinnamon, if you want a cleaned up Windows-like interface, or Kubuntu, if you want a Windows-like interface which just smothers you in options, tweaks and customizability.
However they are nowhere in mobile (and search), and desktop is the only source they have for user data. The thought of getting left behind in the data mining race by Google and Facebook must be a real concern, and they will do anything to keep up.
I suppose the LinkedIn takeover has changed this somewhat, but LinkedIn alone will not put them on terms with Google/Facebook.
Did you pay for Ubuntu?
I just tried logging in with my pin.
After a handful of tries I was given a string to enter before I could try again. I did that. After another try I got told to restart the device before I could try again.
So it doesn't look like 10 tries and locked out forever, but rather increasing penalties for incorrect attempts. Which is fine.
oh and my pin is 6 characters long.
If they don't have this right why should we believe them about any of their other claims?
> Microsoft: so enterprise customers will be able to completely turn off telemetry if they choose[1]
Which is it, Microsoft?
[1]: http://www.techrepublic.com/article/windows-10-now-lets-you-...
What is the wire format of the telemetry data? How do I access the UI that tells me exactly what telemetry has been sent to Microsoft?
Companies like this will continue on and consider things like this simply the cost of doing business.
Kind of like banks. They don't give a fuck.
Since then, I like the EU commission. As long as they can bend the master plans of dominating US companies.
However, I don't see how the forced Windows upgrade didn't lead to a requirement to reimburse every user of their stripped Windows 8 license.
That said, who cares. I've hardly seen anyone use uBlock Origin, Ghostery or Privacy Badger. OTOH, people love tools [1] that read your email and notify about due bills and the like.
[0] https://twitter.com/darylginn/status/590664399041519617
[1] Google Now
Microsoft, then Android, please ;)
And even so, lots of people have software that isn't compatible with Macs (or Linux for that matter).
I'm honestly curious what would happen if MS decided one day to jack up their Windows license costs to, say, $1000 per copy. Or what about $500? Would their revenue go up or down? Obviously, some people would switch to something else, a bunch more would just stick with what they have, but people do buy new computers now and then, and businesses are always refreshing. Combine this with "updates" to existing Windows versions to make them slower and slower and slower (like iOS does) to force people to get new versions of Windows, and it seems to me MS would probably make a lot more money by gouging customers as much as they can.
Enterprise/Volume Licensing, SMB Licenses, Educational Licences (Students and Teachers), Developer Licensing (MSDN), Microsoft @ Home (buying considerably discounted licenses through your employers) and OEM licenses for retailers and system builders...
Since Windows 7 the vast majority of the windows licenses that are not VL are cooked into the machine (stored in the BIOS) and are effectively non-transferable (OEM lic's were never transferable, but now there is no sticker with a key anymore).
If microsoft decided to charge 1000% for the retail the majority of the licensing programs would be immune, OEM's/System Builders would love it (can rack up the prices since Windows is so expensive now), and pretty much none of the normal users would care/be affected by it directly.
Heck, I think they have even more room to screw their customers with the Enterprise licensing, not only for Windows but all their other enterprise products too. What are big businesses going to do, suddenly switch to Apple? Obviously, they couldn't do this overnight, but they could certainly jack up their enterprise license costs to 5x when they come up for renewal. They'd probably want to avoid doing this too much for some things where there's actually competition (like with SQL Server: businesses might switch to Oracle), but with Windows, MSDN, etc., they could. Where are customers going to go?
What counts as "excessive"? Apparently whatever someone at CNIL thinks is excessive. I can imagine that Microsoft learning what apps you download is inevitable given their reputation based malware detection scheme: no way for that to easily work except by IE checking in with Microsoft to find out if a program is known malicious or not. And figuring out if a program is actually interacted with or not seems like a pretty good signal to determine if a new, unknown program is a silent botnet or not.
"4-PIN limit is insecure, because there's no limit on the number of accesses" is exactly the kind of bureaucratic central-planning nonsense that France has so many problems with. You do not need absolute counted limits on a password/PIN system to make it secure. You just need to take other steps to make brute forcing infeasible, like throttling the rate of attempts. Why is CNIL attempting to micro-manage the code for the Windows authentication systems, something they are clearly not qualified to do? The details of Microsoft's security system is their concern alone: if users dislike the way Microsoft do it, then they have other alternatives they can easily switch to.
I suspect Microsoft may do what other big companies do and simply ignore CNIL completely. They can only hand out relatively small fines and it's easy for big companies to just pay them off to make them go away. Their rulings have a long history of being completely unreasonable so it's usually the easiest path.
All evidence seems to suggest that the French are not big fans of the free market, because that would create winners and losers.
"Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés" is quite specific about collection & processing of personal data. A good example of what falls foul of this legislation: logging everything for unspecified purposes to cross-tabulate it with other unspecified records in case it might be useful in some way (which might not be in the user's direct interest) within an undetermined timeframe, without letting the user know about it precisely nor letting him opt out.
CNIL is annoying and their enforcement is spotty for lack of budget (so they have to focus on landmark cases) - but their actions are well grounded in legislation and actually protective of people.
> I suspect Microsoft may do what other big companies do and simply ignore CNIL completely
Please do that - I'm off to fetch some popcorn !
Oh, that's not good enough? Well now you are back to what I said: it's simply central planning nonsense where a regulator makes up rules on the fly.
I have seen no evidence that CNIL or indeed other bodies like them protects people from anything. Please show me one, completely unambiguous case of someone who was clearly suffering whose suffering was rectified by CNIL forcing some change to a privacy policy somewhere. And I mean really has a problem, not some emotional airy-fairy feeling that they'd prefer things to be different, I mean concrete, quantifiable issues: like monetary loss.
There is no need for popcorn. I think the biggest fine CNIL can usually hand out is like 300,000 EUR or something. Just pay it Microsoft and get on with things.
That should be obvious: any data the user hasn't given their specific informed consent to be collected. How is this even in question?
No, hiding blanket statements in a privacy policy is not specific consent, and dissembling about spyware details in an vague or misleading option description is not an informed choice. This is how you bring bad regulation to an industry; if businesses cannot police their own ethics, event laws will be written to fix the problems.
> malware detection scheme
Not everyone uses that, and there are other ways to implement malware detection that are not privacy leaks.
> Microsoft learning what apps you download
Or run, or interact with...
> good signal
...which then claim is a good thing. Microsoft (or anybody else) can ask the user if they would like to track that specific data.
> they have other alternatives
The cost to change platforms - which may include replacing an existing investment in software - can be large. Forcing a Hobson's Choice on users indicates it's time to open up another antitrust investigation.
Governments: "Collecting data without informing people is bad"
Companies: "OK, we inform users what is collected in our privacy policy"
Them: "Nobody reads them. Make sure they opt in."
Companies: "OK, we have put up an interstitial that asks people to opt in after showing a summary of what is collected."
Them: "Still not good enough. Ask specifically for everything."
Companies: "..... we list specifics in the privacy policy. That's what it's for. And we ask people to agree to it when they sign up."
Them: "Too late. Pay us a big fine"
This is a stacked deck. Nobody providing user services on the internet can ever win this game, ethics has nothing to do with it. There are no standards and nothing is ever considered sufficient. Badly thought out, vague and rambling approaches to privacy laws are how you get cookie popups everywhere. Makes no sense!
Data collection and storage must be...
* Off by default and opt-in.
* Completely granular.
- For what is collected.
- For what collected data may be used for.
* Agreeing to one form tracking or data collection cannot cascade to another.
* Preference for sharing/selling data to 3rd parties must be off by default and opt-in.
* A users preferences on your service must extend to 3rd parties.
* Must have a non-persistence option. (i.e. data is only stored for the minimum amount of time required to render the service)
* Tracking can be discontinued at any time at the users request.
* Deletion commands must be honored in a reasonable time frame.
* Deletion commands must be propagated to all 3rd parties.
* Agreeing to tracking or any data collection cannot be a requirement for use of a service.
* User must be allowed to view and acquire all data collected about them.
* Cannot be misleading or place any undue burden on a user attempting to exercise their rights.
What the more extremist privacy advocates fail to realise is that if they applied their same principles to a physical shop they'd be demanding that all employees be blindfolded. And then if someone walks through the door drunk and passes out after vomiting on the floor, those employees would have no idea that people were silently walking in off the street before suddenly spinning on their heels and leaving again. Yet who wants vomit-encrusted shopping, in the name of privacy extremism that virtually nobody cares about anyway?
So tell me about all those alternative OSes that can run all the same applications that run on Windows.
Before someone suggests it, running a Linux distro + Wine is not an easy switch by any stretch of the imagination.