How to get people who installed a leaked build to stop using that build?
blogs.msdn.microsoft.com
blogs.msdn.microsoft.com
For some reason such emails made me feel like I was inside a tech cult. Guess my culture fit wasn't good enough...
Well, to be fair, I guess MS also utilizes these emails in addition to reverse psychology...
If you can't understand basic instructions such as not leaking internal, confidential info, you deserve to be fired.
Emails are supposed to be deterrence against further leaks by reinforcing the "company culture". (Whether they work, I have no idea.)
Almost nobody seemed to have any problem with it, so I guess it's just me. ¯\_(ツ)_/¯
I guess this sort of thing wouldn't happen today with the always-connected, always-phoning-home world we live in.
As someone who's never worked for a company that produces commercial software, I'm curious about what he's referring to.
The EULA will likely need to go through multiple iterations between local and partner lawyers before the language is agreed upon - so expediting is not always an option.
Greta: Mr. Reede, several years ago a friend of mine had a burglar on her roof—a burglar. He fell through the kitchen skylight, landed on a cutting board, on a butcher's knife, cutting his leg. The burglar sued my friend. He sued my friend and because of guys like you, he won. My friend had to pay the burglar $6,000. Is that justice?
Fletcher: No!…I'd have got him ten.
Probably the most famous case, Bodine v Enterprise High School, involved a teenager who fell through a painted over skylight while stealing (or redirecting to play basketball) a spotlight off the roof. Because of the fall he became a quadriplegic, he didn't really have much to lose suing the school district because, well, his life as he knew it was over. He had a lifetime of medical bills to pay and no way to earn an income.
There are definitely plenty of scam artists or leeches or whatever you want to call them abusing the legal system because it's easier than getting a real job, but don't underestimate the people backed into a corner by debt.
As said in Mr Robot, debt is the invisible hand that coerces us all
Debt: The First 5,000 Years
There are general principles of responsibility of property owners for dangerous conditions on the property that apply even when the harm done by them is done to trespassers (and regardless of the purpose of the trespass.) IIRC, these are largely common law principles, and older than the US.
Of course, they don't relieve any criminal liability for crimes committed by the trespasser on the property, or any civil liability for torts committed on the property, but if you are already on the hook for those and can't try to claim that you weren't the intruder, there's no reason not to try to pursue any colorable claim you have.
Bizarre!
In many US jurisdictions, not generally the case. The ones with a strong "castle doctrine" are notable because this is not the norm.
But, even so...
> So - if an intruder breaks in to your house, you can shoot him without repercussions
Your loose stair carpet was not created as a specific and immediate response to a particular unlawful act, and thus the relief from otherwise applicable legal liability attached as a result of self-defense doesn't apply to it.
Unless I'm misunderstanding your statement, it's actually the other way around. Most US states have a castle doctrine law of varying strength. Even the "gun-unfriendly" states like NJ, NY, and CA.
If you weren't the initial aggressor, and you are in your home with a licensed/legal firearm, you may shoot an intruder. Duty to retreat doesn't apply to your house...which makes perfect sense.
You're misunderstanding my statement. And/or considering only the duty to retreat and not the threat aspect of self-defense.
> Most US states have a castle doctrine law of varying strength.
Right, key part being "of varying strength"; but, AFAIK, very few have a strong castle doctrine law that would make "you can shoot an intruder without liability" generally true; IIRC, the most common version is the very weak form where being in your home basically just eliminates the obligation to flee if able in preference to using deadly force in self defense, but does not have an effect on the level of threat (both subjective and objective) which must be posed before using deadly force.
> If you weren't the initial aggressor, and you are in your home with a licensed/legal firearm, you may shoot an intruder.
Generally, "licensed/legal firearm" is irrelevant to self-defense analysis (whether in the home or otherwise).
It may or may not be "just fine" in general (e.g., it might violate building codes, etc.), but if you deliberately used it in a condition where you were legally authorized to use deadly force in self defense, you probably wouldn't be liable for that particular use.
Someone I know was away from home for an evening, and found the police at her door when she came back. Turns out some junky decided to break into her gardening shed to find something to force entry to the main house. Was so high he accidentally slit his wrist on the glass window he broke to climb inside the shed. Neighbours heard him cry and called the police.
Police told her she was very lucky he didn't die, as she was responsible for his well-being while breaking in.
In a related note, if you have a dog, you need a sign to warn burglers about it , as you have to safeguard anyone in your house, including burglars. If the sign talks about a dangerous dog, it means you knew the dog was dangerous and have a higher responsibility for injuries.
As far as I understand it (IANAL), the legal theory is that breaking in and failing to safeguard the burglar are 2 unrelated crimes, which each deserve their own punishment/damages.
Otherwise I could break in somewhere, hurt myself (there is always a possibility) and sue the owner of the house. Unless the owner builds traps to severely injure anyone who enters the house even if there's no danger to residents, I cannot imagine a court deciding in favour of the burglar.
It may be different if you have a dog that is trained to injure/kill anyone who enters the premise. That could lead to a court case, e.g. if the dog injures a child who wanted to retrieve a ball from the garden and there was no warning sign.
Do you have any links for cases that were actually won by the burglar?
For instance if you break in a house while the owner is on holidays, and stay a few days, not only the owner would have to go to court for years to kick you out, but the owner is not even legally permitted to enter his own house until after the execution of the eviction, after all appeals have been exhausted.
...not just in the US!
Surely if the "leak" is the result of an employee acting unlawfully, i.e. maliciously leaking their employer's intellectual property in contravention of their employment agreement, then the leak does not constitute a disclosure.
If it did, then IP-based organisations would have an absurd level of exposure to the bad actions of any employee, and would have to impose equally absurd security measures - cavity searches at the exits, anyone? - on every employee with access to IP.
If you're talking about public leaks (rather than just private leaks to a few individuals), surely they're not that hard to find?
I wonder if you mean the leakers?
(for the record, I'm a moderator of a forum which discusses said "leaked builds of Windows"; and I help try to find and preserve those that leaked long enough ago such that they have almost disappeared)
No idea if a leaked build would count as shipping for these purposes, though.
But then I remembered that there are other countries in the world other than the USA. Those other countries have different rules! It's sometimes difficult for Americans to remember that, since we're so insular here. E.g. I haven't been out of the USA in probably about 25 years.
Although most of the anecdotes are historical, I hope he releases an updated version one day. There's so much computing history contained in his blog.
There's probably a point at which any more effort put into carrots (new features or wallpapers on official builds) and sticks (nag screens, watermarks, expirations, etc on old builds) just becomes more trouble than it's worth.
I like trying out leaked builds of programs or OSes as much as the next bored nerd but I can't imagine ever running something as primary OS on any machine I count on for anything. That stuff is for old computers that aren't being used or VMs.
Also, how does a user who doesn't upgrade notice a change in wallpaper which doesn't take place until after the upgrade? By looking at someone else's desktop which is running the release version?
What if the user has changed to a custom wallpaper, and doesn't remember what the original wallpaper of the leaked OS looks like?
The type of person who is downloading leaked pre-release builds in order to have the latest and greatest generally follows the latest news about new leaked builds.
I think that would get the message across quite effectively :)
"Super secret preview version of Windows X leaked! Download here!"
(...3 weeks later...)
"People trying Super secret preview version of Windows X get their hard drives wiped out! Was this Microsoft's plan all along? Please tell what you think!"
Everywhere? When they care for you when you're sick, drive you to sports practice, clean up after you and what not?
"Build 97241 contains a potentially fatal bug that could wipe your computer. If you are using Build 97241, please upgrade it to a more recent build or otherwise cease using this build immediately. We do not care how you acquired this build. We simply do not want you bricking your computer."
customer: I'm trying print and it just says "error"
me: It just says error?
customer: yes
me: Are there any other words or error numbers?
customer: yeah, it says "No printers are installed. Add a printer and try again"
me: facepalm
Their solution works because it communicates a lot while saying very little
I imagine in Windows' case, some enterprising individuals who don't know better will end up installing these builds on various computers, and you end up with a large group of users on the wrong build who:
1. Expect better quality than the pre-release build provides.
2. Blame Microsoft for their pre-release build breaking.
Raymond Chen also mentions a third case where the pre-release build messes up other parts of the network... so now you've got:
3. Somebody else blaming this guy for something he genuinely thinks is Microsoft's fault.
And then if you put out a warning message, it's typically ignored because the software is 99% working until catastrophic failure. And then you still get blamed by unreasonable users who then spread the word about how much you suck but conveniently leave out the "leaked pre-release build" part of the story. (If you sense some bitterness, yeah, I've had a few of my own experiences with much less consequential software.)
It's a lose-lose situation for Microsoft. I don't envy anybody in that position, regardless of the quality of the final finished product.
Even if it was today and such a note was published on the Internet, do you think that people who use leaked builds--in at least semi-production settings even--would see that note, much less actively seek it out?
1. Download a preview build because you want "the latest and greatest".
2. Build is full of horrible bugs.
3. Microsoft needs to employ psychological tricks to get you to download the next preview build, as you cling to the previous one with both hands.
The imperative is that these machines can screw up the network they are connected to, so they’re affecting other machines. Generally, people don’t look kindly when a Windows system starts screwing up a network.
https://blogs.msdn.microsoft.com/oldnewthing/20160906-00/?p=...
Crackers will bypass any kind of protection or change anyway.
So you have all these people who bought Lumia phones, enjoying 30 GB of cloud storage, 15 of them acquired with the phone purchase.
Cut it down to 5 GB with an announcement in a blog post, and watch the customers leaving in droves.
Problem solved.
I was horrified when I learned about the state of our datasets. The only reliable features are the ones that are exposed to the customers on the website, because when they're broken people can actually see them.
They are practically always worth a read, by the way. I'm a huge fan of the blog.
The first Preliminary Development Kit had an "Under Construction" wallpaper. The second one had the same wallpaper but tiled. Beta 1 had a different "Under Construction" wallpaper.
Of course, after PDK1 leaked far and wide, MS implemented some serial protection in PDK2 up to beta 2 (different from the one in the RTM; however the RTM's setup has remnants of it). Given that the leakers were involved with the warez scene, however, the skilled reversers that the builds were passed to easily found the backdoor that had been put in so that those on MS' internal network didn't have to enter the serial, and just patched a few bytes in the setup to abuse that.
The interesting part of this serial was that it was in two parts. One part was the "beta site ID" and half of the "password"; if this was valid, but the second half of the password wasn't, setup would appear to continue... until the point it would copy files, upon which it errored out with a message "General error 57, please contact your beta administrator".
This misdirection was discussed at the time, with some people believing the error at face value. This continued with the foundation of communities to preserve and discuss such builds several years onwards. The last half of the password was the hex form of the first 16 bits of an MD4 hash (this code was written in around autumn 1993!) of the beta site ID, the first half of the password, and... a string inside the setup that was used as the titlebar text for the error message, which would be something like "Microsoft Chicago Preliminary Development Kit 2, November 1993".
This part of the serial algorithm was finally reverse engineered, and a key generator made....in 2014.
Afterwards, some early Internet Explorer 4.0 builds were discovered. They used the exact same serial algorithm as the early Windows 95 builds. And had the exact same "MS internal" backdoor.
(Um, I think I may have just ruined one of Raymond Chen's future blog posts.)
What do I mean? I no longer use iPhone because I installed a beta iOS. When the official build came out, I kept "checking for updates" but I never got an update. One day, Apple remotely killed my phone.
Manually updating to the production iOS would be fine; but remotely disabling my phone without warning was not acceptable. This is why I refuse to buy an iPhone.
If you're savvy enough to manually upgrade to a beta OS (which comes with tons of warnings) you should be savvy enough to then update to the production release and get all the associated further updates. That's a really bizarre reason to refuse buying an iPhone.
...and didn't know what I was doing, nor did I read the well-documented warnings that are printed in multiple places. Then when things went down exactly as Apple warned me, multiple times, I went on the Internet to complain about it.
What warnings? Apple tells you up front that you can't upgrade to release from beta, you'll need to load it via iTunes or Xcode. Apple also warns that betas expire. And because "beta" is not "release", when Apple quits putting out betas, there is no "update" to update to. (How this currently works with public betas, I know not.)
Not sure about iOS, but for OS X public beta user are on the beta update channel even after release. If user happen to apply for OS X 10.11 Public Beta, then user will continue to receive beta for 10.11.1, 10.11.2, and so on, but not 10.12 Public Beta. To go back to release channel, user will need to switch off the beta update channel in System Preferences.
iOS Public Beta, on the other hand, seems to go directly from beta to release, per FAQ (Developer Beta seems to be different story, though):
> To get a shipping release of iOS on your iPhone, iPad, or iPod touch, you can simply install the final version of the software you are testing when it appears in Software Update.
People would just remove it. If you can't remove it, then don't buy devices that are crippled in this way.
Which is exactly why they (still!) plaster it with warnings to that effect. If you want to avoid any headaches the advice has always been to use multiple devices and keep the beta off your day to day device.
It is quite likely the project Raymond is talking about is Longhorn, as a few pre-'reset' builds were leaked in quick succession.