Fix Windows 10 Privacy
modzero.github.io
modzero.github.io
Any amount of service toggling and hosts file stuffing will not suffice. It just screams ignorance. As a software developer you should understand that plugging holes in a black box is a futile effort. All these tools are doing is giving a false sense of privacy, that the next update will undo by flipping a switch or installing a new service.
If you think the OS is violating your privacy, stop using it or remove it from the Internet. Or both. It's the only way.
Edited to add: If you actually like Windows (I do), just switch to the Enterprise Edition and dial Telemetry down to "Security". Here is an explanation of what little is then shared, and how to even further minimize your footprint: https://technet.microsoft.com/en-us/itpro/windows/manage/con...
Edit to address the availability of the Enterprise Edition: If you are not able to get it via your $JOB, a valid key from MSDN surplus shouldn't be more than $50 if you look around. Of course you'd then be bending the EULA in your favor, but hey, since Microsoft is spying on everyone against their will I think it is fair game, right?
Either you accept that using Windows means Microsoft exercises arbitrary and unrestrained control over your system, or you don't use Windows.
Edit: To address your edit, aren't you trusting their black box and using a different tool to accomplish the same? Also, not everyone has access to Windows 10 Enterprise.
Also they block things that can be used in a good way, like recognition of ink pen, yeah you don't want Microsoft can improve then how they will improve it? and they will complain why this pen don't recognize anything, the solution will be to use ccleaner to do more mess because we all know the script that BOOST windows performance...
Ah darn. So I guess that means the “Off”¹ option never made it into the release version of Windows 10 Enterprise… ️
――――――
---
https://technet.microsoft.com/en-us/itpro/windows/manage/con...
The lowest telemetry setting level supported through management policies is Security.
[Security Security data only. 0]
Information that’s required to help keep Windows, Windows Server, and System Center secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender.
The Security level gathers only the telemetry info that is required to keep Windows devices, Windows Server, and guests protected with the latest security updates. This level is only available on Windows Server 2016, Windows 10 Enterprise, Windows 10 Education, Windows 10 Mobile Enterprise, and Windos IoT Core editions.
• Microsoft removed the already existing capability to completely turn off Telemetry for some reason, or
• the “Off” label wasn’t accurate in the first place, so Microsoft changed it to something less misleading
In any case, it seems like Microsoft has no plans to include a way to fully turn off telemetry on Windows 10 Enterprise anytime soon³.
As for your inquiry, unfortunately, I haven’t seen a more in-depth analysis of what being sent than the one at the link you’ve posted (although it actually does go into a bit more detail than just the part you’ve quoted here). There is this⁴, although it’s just a list of hostnames and IP addresses; there was no packet inspection done, so it doesn’t make it clear what’s actually being sent.
――――――
¹ — http://arstechnica.com/information-technology/2015/08/window...
² — http://i.imgur.com/ubCQrWk.png
³ — http://www.forbes.com/sites/gordonkelly/2016/02/11/microsoft...
The only way is a total firewalling of all Windows services from the internet, including dnscache.
Its the same reason why people who dislike and tries to block advertisement don't simply stop consuming contents that contain advertisement. They don't want to turn into hermits that live on a mountain away from the web, TV, mail, email, radio, billboards, milk cartons, the sky, and practically everywhere where a company can stick a advertisement on something. It is an imperfect solution to an imperfect world.
It's quite understandable given the different objectives and budgets of the two, but I think for most average users this is a deal breaker for switching.
Is there any room in your opinion for people who love Windows and think it's better than any other OS that is currently available? Because that's why I stick with it, despite having some very minor issues...
Also, the reason that I don't switch to a Free and open source OS for my desktop is because they all suck. They're slower and clunkier than Windows and they don't have the features that I want.
All of my Windows issues were solved by simply toggling features via Settings and Group Policy though. I think there is one setting that you need the Enterprise version to toggle and that is Telemetry. However, you can disable that service manually too - http://www.thewindowsclub.com/windows-10-telemetry/ Of course disabling Telemetry causes you to lose Cortana, the Windows Store and any use of your Microsoft Account - but I don't use any of that crap anyway and anyone who does want to use that stuff wouldn't care about the basic Telemetry data that gets collected, which is detailed here - https://privacy.microsoft.com/en-US/windows-10-feedback-diag...
I really don't understand how something that can run on less than a Pi can feel slower on consumer hardware than something that requires beefier specs.
For example, I never have to wait for my file manager to open. Not half a second.
Secondly, though Microsoft details the telemetry, its encrypted before the user can see it. You have to trust a company, that have a habit of bending over backwards for the US's clandestine organisations. It can't be verified.
For example, all of the browsers run slower and are klunkier on Linux.
I'm with you on the telemetry. I just disabled it via the registry though. That option works on all editions of Windows unless I'm mistaken... which I very well may be since I did not go to very far lengths to verify that my machine is not sending back anything. However, I am not worried about US clandestine operations because there's nothing I can do about them anyway. They are into everything around you, not just Windows.
In my opinion the greatest threat is not spying on you. The thing you should be worried about the most is psychological warfare. They are not supposed to be running psychological operations on US soil, but it's so obvious that nobody follows that rule. TV, movies, news...all of them are used to program people. Honestly, there's nothing you can do about that either unless you are seriously rich and very well-informed.
Spying leads to manipulation, true. But my fear is based on not living in the US. And disabling regkeys doesn't stop 5gb of telemetry going to MS a day. Which I find just a tad excessive.
Then again, the main reason for running Windows instead of Linux is because you want stuff to just work. Once 'buy Windows' becomes 'go looking on the gray market in the hope of finding something unsupported that might or might not actually work when you try to install it' the value proposition relative to Linux has been significantly eroded.
I like using Cortana and Windows Store apps. I like being able to provide bug reports when something hangs.
I don't like the idea of any data going to the mothership that doesn't have an obvious effect on my day to day computing. I'm especially leery of anything that requires (arbitrarily defined) personal information.
I also don't have time to research every one of these registry keys or policies...soooo...thanks for doing some of the work!
And I am not sure that "everyone else does it" is a good reason. Everyone else does nagging. Apple nags again and again for its icloud, apple pay, apple music, etc. I get some nagging for using instagram all over my facebook feed. Microsofts nags me for using edge, onedrive, etc.
But "the others do it too" doesn't make a good product.
[1] https://github.com/Nummer/Destroy-Windows-10-Spying/
[2] https://github.com/WindowsLies/BlockWindows
Even for very technical people, unless we're willing to analyze the source code, a good clear description (and reviews) is how we're going to decide which product to try.
I do not intend to sell you the project. (Sell in the sense of talking you into using it. Either it's what you are looking for or you need something different. And I will not waste your valuable time if you need something different.)
Honest question: how do you know? I read the OP article and it talks about 100+ 'rules'. How can one ever make sure all this stuff is disabled (or even needs disabling)? And possible new stuff after updates gets disabled as well?
I'd really want to switch to W10 because it certainly has appealing features but didn't do set yet exactly because of this privacy stuff. But reading things like this makes me almost give up and go like 'well, yeah, f this, nothing I can do about it so let's just use W10 it and to hell with my privcay, nothing to see here anyway'
As far as I know, OS X asks for permission for diagnostic data collection on first boot and can be turned off anytime. Unlike Windows, on OS X the data collected is not stored encrypted and can be inspected. They are not equivalent.
Whether that's actually everything, I don't personally know. It seemed like a unnecessary and out of place dig though.
(And yes, I also dug through the settings and disabled things in a rather counter-intuitive Spotlight menu.)
The other thing that holds me back is the UI. Hundreds of Themes available but I always see them as "cartoonish" themes that are not well though of.
[0] Heck, Windows breaks on reboots! Sometimes when I reboot, it either forgets my bluetooth or my wireless. And by forgets, I mean it doesn't think the hardware even exists. Multiple machines, multiple vendors, so it's not just one odd computer.
Rough count, I've worked with 30+ different windows machines over the last few decades. I have never seen the problem you are describing. I'm not saying you're not having it, I'm just saying it's not necessarily a common event. Maybe you live/work somewhere with a lot of EM interference?
I think people just get used to Windows' issues and don't recall how many times they have to deal with them.
[0] At least once per week out of several hundred machines.
I can recall a lot of issues that I've had with windows. I can tell you with certainty that I've never had a device go missing from the device manager.
I've had printers have trouble being discovered after they are unplugged. I've had driver updates cause hardware to stop working. I've even had windows updates completely mess up my windows installation.
But I've never had the issue you are describing.
> [0] At least once per week out of several hundred machines.
You're saying you have a greater than 1% occurrence rate per year? Google doesn't show the issue in the first three pages for me with the query "Windows forgets network hardware." Have you opened a Microsoft support ticket? I mean, if you're losing device drivers every week, that's man hours your burning! I would want to get that fixed ASAP!
I have the same install since 14.04, I have updated to each version up to 16.04 and it still works fine.
OTOH, I reverted the Win10 free update and went back to Win8.1 because Win10 did not work with my bluetooth devices, the tablet functionality was inferior to Win8.1 and it was actually unpolished compared with the Win8.1 experience.
Your second point is simply opinion, and while I can't argue against it, my own experience using Ubunty with multiple monitors and virtual desktops makes Windows feel limited in comparison and therefore much less professional.
So yes, it is simply easier to just use Windows and turn off as much as you can. It's a pain, but the relative pain to using Linux is lower.
I support Blizzard because they make good games which are fun to play. Who is this other person I should be supporting instead?
What graphics tablet maker that provides first party Linux drivers should I support?
As good as Gimp and Blender are, they still can't compete with the Photoshops, Illustrators, Mayas, and Fusions of the world.
The "right people" don't exist; not yet. And I can't afford to support someone on the off chance they sill someday produce an equivalent product.
/sarcasm off
Get a grip and please go trumpet your own "freedom" somewhere else. HackerNews is a place for objectivity, not bandwagon hating.
You also probably don't realize that many of us stream video and music 24/7 and your main PC is de facto a programming + gaming + home entertainment server.
You can hibernate one OS and still start the other one. This way all your apps will reopen the next time you boot the OS.
> You also probably don't realize that many of us stream video and music 24/7 and your main PC is de facto a programming + gaming + home entertainment server.
You're right, most people will have to use Windows at some point :(
Furthermore, native Linux games are only becoming more popular, and one way to make them more popular is to use Linux.
I'd say that's plenty efficient enough.
Additionally, video-card drivers are still buggy and fragile. And it's not just video cards, but wifi and sound as well.
Requires a recent or non-K intel CPU with IOMMU though and the chipset has to play nice.
I'm using it on my machine in conjunction with Synergy to passthrough keyboard and mouse between host and VM seamlessly.
Performance hit: somewhere between 5% and -2% (some games actually run faster in the VM than on baremetal, most notably KSP and CSGO)
Setup is not trivial, as it will probably require an ACS-patched kernel if your CPU is older and also needs VFIO kernel parameters to be maintained.
If you do this, I recommend Arch, as the performance on the newer kernels is sometimes better (due to KVM/Xen and QEMU improvements)
Also lots of RAM and Swap. You're gonna need lots of it.
They run Windows in a virtual machine, and pass a dedicated GPU into the VM, the results are very impressive, but the installation is very complicated, and you won't get rid of Windows.
As VFIO matures, and the API stabilizes a bit more, I think we will see distros offering an easy "install and play" experience.
There is a complete guide here: https://davidyat.es/2016/09/08/gpu-passthrough/ And as you can see, it involves all kinds of steps.
One day, hopefully Windows will be just a shell to play games on :-)
So I would say your advice isn't helpful. Microsoft has a financial relationship with their users (especially their business users) and despite what many people think, they do listen to their customers. So I would say the best way to fix Windows 10 is to continue to let Microsoft know that you aren't happy with specific changes they've made.
Have you actually tried it in recent years? Wine runs a lot of stuff just fine.
grep --files-with-matches wine ~/opt/win32/*/launch.sh | wc -l
71
The most obvious incompatibility right now is probably DX11-only software. Aside from that kind of known compatibility problem, wine has worked well for several years now.> far from user-friendly.
While I agree that wine can get nasty if you need to debug anything or if you have unusual requirements, but the standard "just run this win32 binary" case has also been trivial for years. I believe some distros even enable the kernel feature that launches wine automagically when running a .exe file.
> it is not perfect
Of course it isn't. It is, however, worth trying.
I think his advice is perfectly reasonable, it just doesn't apply to everyone. I bet that it applies to a lot of people in a technical audience, though.
Elaboration: when I have 3 Chrome windows, 2 work VMs fired, a separate Chrome window for the work services, several consoles outside of the VMs, and a live Twitch stream running on the TV hoooked to my PC then no, I am not willing to reboot only to play a game.
Define "gaming". There is a sense in which the best selling PC game is almost certainly solitaire.
Sure, that's still not much compared to 2.5 billion, but that's also 5 times what you said.
[1]: https://en.wikipedia.org/wiki/List_of_best-selling_PC_games
The Toyota Corolla is the best selling car of all time and has only sold 37.5 million units.
By your measure, driving is clearly a niche activity as well.
So... adds up ;)
Frankly? Not much. What gaming I do do is either on the PS4 or is indie gaming, which largely works on Linux or Wine.
Convenience > all, including for some of us the programmers. =)
I had actually planned to setup GPU bypass on the box and run Windows in a VM, but I have more games now to last a long time, and I haven't actually bothered.
Yes, maybe on my phone once in a blue moon? Otherwise, that went out the door(at least for me) sometime in my 20's.
I'm only one customer but I'm letting Microsoft know that I'm not happy with the way they go with Windows by not using Windows 10.
These days, hardware and software is very inexpensive compared to time. I love the idea behind free software, but sometimes it's just too expensive to choose.
In the university context I've found that there is a lot of free software that works good enough or sometimes even better than commercial products. If you factor in that you still can use that particular program after you leave, it becomes a big plus.
That's very true. For example, if I need to use an image editor, Photoshop is the only thing I would consider. It's inexpensive ($35 for a month subscription), but more importantly it's easy to hire people that know it well. It's also well supported and documented.
I usually just went with Ubuntu because at the time it seemed like it was user friendly. I tried openSUSE at one point. If you can name a distro better aimed at supporting these types of devices I'm game.
Linux is fast to install (when no problem occurs). Software installation (and deinstallation) is a breeze. Everything is available out of the box. I maintain a diary with a list of non default packages to install: apt-get install nfs-common wine gnome-media openssh-server squid curl filezilla curlftpfs ethtool docker.io xtightvncviewer x11vnc tmux whois git wakeonlan youtube-dl npm sshfs
Concerning support for old hardware, it was the main reason that made me switch to linux: vista64 had no support for my printer and my scanner.
The only hardware-related issues I've ever had have been trying to run a brand new graphics card or on the latest macbook.
Back in the 90s, sure, there were a hell of a lot if blocking issues. But now?
Frankly anyone posting on a tech site that can't get it up and running adequately should be embarassed.
And this is a big reason why so many people still don't want to use linux. The "Why aren't you as smart as I am" attitude isn't as strong as it used to be, but it's still there. It turns off users. Nobody wants to use software when the other users are going to treat them like idiots. There are still many complicated problems to get linux up and running, and being a jerk ignores those problems, rather than helps solve them.
If you can't install linux on some reasonably generic pc hardware in this day and age, and you consider yourself a hacker or coder, you probably ought to be a little embarrassed. Certainly not proud as some seem to be.
If I was interviewing someone for a role and asked them for their thougts on using linux and got "well I usually give up after a few hours trying to install it" I'd look elsewhere.
Look, it's fine if you breathe Linux in your free time and you don't watch movies or play games, or nail your girlfriend, or even watch the ceiling in half-meditative state with all lights out. That's not sarcasm. Everyone has the right to do what they want with their free time.
But many of us are hackers / coders AND have a happy personal life and don't want to bring their work to their free time. And want to make the best use of their work time, too.
Linux gets the job done and I very much like my XFCE 4.x on my virtual Debian, but it's still far away from a full-blown user OS on the desktop. Numerous articles agree with this fact.
It's a simple comment - if you're working in tech in any capacity and you can't install linux satisfactorily, that really is nothing to be proud of in the modern day and age.
Not directly, but you are being condescending to someone who has legitimate issues. Just because someone is on HN doesn't mean they are great with linux, or that they are even a technical person. Maybe he's got a different skillset, and doesn't like dicking around with shitty config files, obscure error messages, and jerks that tell them they should be "embarrassed" for not being omniscient.
Can you tell me the best way to pull HE levels from a GE MRI's MM? If not, are you going to spend a lot of time looking it up just because? Why aren't you embarrassed that you don't know that?
> If I was interviewing someone for a role and asked them for their thougts on using linux and got "well I usually give up after a few hours trying to install it" I'd look elsewhere.
Depends on the role. If it was a linux-admin job, absolutely. If it was for a job in HR, then I wouldn't care at all.
"Giving back" to the open source world in my case is done by committing code and documentation, not free support. So when you hear "go read the manual" or RTFM - we aren't insulting you or being jerks. We genuinely want you to better yourself and acquire education, and are pointing you in the right direction to do so.
Linux is an industry standard, I think this sort of brag about how much trouble you have with just getting it running reflects much worse on the complainant than the system.
20 years ago? Sure. Now not so much.
If anyone is bragging here, it's you, so no need to be a hero. If you're hearing this a lot, maybe it's not us and instead it's people like you. The whole point of a good UI is to make it easier for people that don't regularly use your system. So if you're hearing this a lot then maybe it really isn't good.
> Linux is an industry standard
On servers it is, on desktops Windows still rules and that's for a reason. Common users don't need to hit up a Reddit beginner forum or spend hours pouring over documentation to learn the command line and all the various utilities for their chosen distro.
On the server, yes it's rock solid and I've had a pretty good experience with it. On the desktop, no. Also, my experiences are not from 20 years back, try 2.
Installing it is not complicated, with a live CD it's arguably easier than windows these days. It reflects badly on you as a person working in tech if you can't do it.
Look, if we're trying to avoid OSes that call home with telemetry about what you've been doing...
Oh, absolutely, but if we're going to advise would-be Linux converts who are concerned with data leakage, may as well advertise actually-telemetry-free distros.
>Afaik Ubuntu removed that module like 2-3 years ago
Hey great! Link? Trust but verify...
[1] http://www.pcworld.com/article/2840401/ubuntus-unity-8-deskt... [2] http://www.omgubuntu.co.uk/2016/01/ubuntu-online-search-feat...
A user can live on the same LTS version of a distro for years but eventually they'll need to upgrade. I have yet to see anyone successfully upgrade major releases of any distro without serious issues. The process is basically format and start over. That's unacceptable.
Sure Windows and macOS have their own set of problems but for the average user they just work. You don't have to dive into the bowels of the registry or modify ktext files to get most things to work and the majority of users don't even know about the CLI.
I've been using Linux in various forms for over 15 years in all forms including daily driver desktop, daily driver laptop, HTPC, foisting it upon my children via netbooks, custom router firmware, Raspberry Pi development, custom ROMs on cellphones, home server hosting, cloud hosting, NAS appliances, development VMs, and production VMs. I tried use the desktop environments really hard for about a decade and constantly founding myself wondering why certain tasks had to be so hard. I always chalked it up to inexperience or unfamiliarity and pushed forward but then my job required me to use OSX. I quickly realized that it was the Linux desktop envs and not me. It was also around this time my kids started using computers more heavily for school and the Linux netbooks I provided them just couldn't cut it. Surprisingly they were able to use Nexus 7 tablets for their school work with relative ease.
I still use Linux daily but never on the desktop. CLI or nothing.
Linux desktop is just not there in terms of "set it up in 15 minutes and forget it unless you want to heavily modify it". Of all OS-es Linux has the biggest potential to be the ultimate desktop system but alas, not just yet.
Thank you.
I've been using Debian since v1.3 and have upgraded I-don't-know-how-many machines across major versions. I've got production servers running Debian 8 right this moment that were running Debian 6 when they were installed.
With regard to RHEL, I always reinstall from scratch instead of attempting upgrades. I think they're a lot better about upgrades nowadays but I still remember, very clearly, the day when attempting an upgrade was just asking for trouble.
they sure are: difference in e.g. desktop usability with like 15 years ago is huge. You can finally install something from cd and have it up and running including audio/network/automatically mounting pendrives/... without having to touch a config file. Usually. But the problem seems to be in the getting better: I'd rather just have it good enough already right now. Too often it does, for me, as a desktop, still not feel quite right yet and still too buggy. 15 years ago a lot of things Windows just worked and now they still do and a bunch of nice stuff was added (ok crap was added as well) and for what I do with it I have close to 0 problems. I just wish I could say that everytime I try any of the distros you mention.
When the subject "Windows 10 Privacy" comes up, linux folks come running offering linux as a magic pill, it's not.
As mature as linux distro's can be there's always the hardware variable in the equation, specially on laptops using nvidia optimus, the experience still sucks. It's the truth.
I have nothing against linux, i actually tried it very recently (you can see it here:https://calbertoferreira.blogspot.pt/2016/10/moving-from-win...) and got a nice initial impression of it, but i will be moving to Windows again very soon.
Want to know why ?
- Creating a virtual machine on virtualbox freezes my machine (excessive IO ? i have an ssd);
- Battery life sucks even with powertop and such;
- My wired internet connection had the same speed as my wireless connection (i disabled wireless to make sure);
- Hdmi audio simply doesn't work and when i asked for help on askubuntu i was even downvoted (http://askubuntu.com/questions/845996/how-do-i-make-hdmi-sou...)!
I tried, i really did but it's a no go for me.
And i feel sorry for it, because i recognise that there are advantages in linux , but until nvidia fixes the damn optimus issues, linux will be held back.
Most Linux proponents are people with older hardware and trivial setups: 1-2 monitors, 1 sound card and a pair of normal speakers (without subwoofer), 1 ethernet or wireless card, only 1 ISP, etc.
We get it, for very regular setups Linux works fine. But there are many people who have more requirements outside the warm little box that Linux serves and I cannot understand why do these people come here convincing us this is not the case; and why are they downvoting the people who are outside this bubble.
Linux is not a magic pill on the desktop. For all its strengths (and I do use it in my work every day) it's still a lousy desktop OS and this hasn't changed for 10+ years now.
Try to keep in mind that the vast majority of internet provided services are served on linux. A large portion are developed on linux, by people that don't seem to be hindered by the parents problems.
edit: typo
Don't be bitter. The fact that most of the internet infrastructure is served by Linux doesn't make it a user-grade OS. Unrelated areas.
In any piece of code, a switch is a point of added complexity. For ANY such toggle:
- The switch might not be saved correctly.
- There can be a regression where the switch stops working in the future.
- The switch, despite being “saved” correctly and displayed by a reassuring checkbox in a GUI panel, might not actually be CONSULTED in all the places it needs to be consulted (resulting in default-on, default-off or “whatever the developer of that component felt like” in various components across the system).
- There can be a regression in any one of the components consulting the switch in the future, leading to an inconsistent combination of things that may or may not check for this setting over time.
When they give over 100 options, I assume 50 of them don’t work and that they have no real incentive to make sure the other 50 keep working.
About the only thing you can trust is a single on/off switch for the whole thing, while simultaneously checking a bunch of low-level things (regularly blocking unwanted hosts, logging network activity, etc.).
And: OneDrive Cloud users or users of others of the above mentioned features should refrain from using this tool at this time, because the functionality of these services will be limited or disabled after running it.
The wording on these options is deliberately misleading and there are way too many of them in different places. Microsoft know full well that everyone would just click "NO" when asked whether to activate all these telemetry tools in simple language.
That's not true. I am more than happy to share anonymous usage and telemetry data with software providers, assuming that it's clear what I am sending, that it's anonymous, and that I can easily change my decision later.
Simple language makes me far more likely to give you as much anonymous data as you want. If I can't tell what I'll be sharing, I won't be sharing anything.
In any case Microsoft has been addressing some of them. My father in law was reinstalling Windows 10 and I was guiding him through it because I remembered a couple of these trick questions(e.g. Cortana). I noticed a couple places where they fixed it.
Oh, and if you start digging you'll get even more angry. Things you trust without thinking twice (not really but you get the idea) is also compromised or doesn't have a practical alternative: hardware, TPM, certificates, your smartphone hardware and software, ∞
(I'm no expert, I just like to complain about it)
Since then, Microsoft has moved to monthly updates which combine security fixes + functional changes. If you want only security fixes, you need to disable automatic updates and download a separate security-only monthly rollup.
It's a shame, but we're approaching the point where we will need to whitelist all outbound traffic using a firewall that is external to the operating system. Anything that isn't whitelisted should be blocked, logged and audited. Someone should start a VPN service that blocks Microsoft, Google and Apple telemetry. If we had regulators, telemetry could be forced to use stable domain names to enable network filtering, and telemetry traffic would be unbundled from application traffic.
I thought maybe I wouldn't have to worry about the telemetry (read: "spying") too much if I stuck with Windows 7 Enterprise (although it wouldn't be on a domain), but apparently that's not entirely true.
I have media that has SP1 slipstreamed and saw that there was a "comprehensive"(?) update that Microsoft put out, reducing the need to downloads hundreds of updates. I'd have to double-check the date on it but I think it was recent enough to include some of the updates you mentioned.
I suppose I had gotten my hopes up that I could just install a volume licensed copy of Windows 7 Enterprise and "be okay". I should have known better. :/
This program will mess up most Windows 10 installations. In ways that may take you months or even years to ultimately notice.
Let's look at some of these rules:
- "[Disable] Let websites provide locally relevant content by accessing my language list." Meaning websites cannot provide a translated version that you'll want (e.g. if you visit a Chinese website, they may not provide an English translation since you aren't sending the language list).
- "[Disable] Let apps access/control my camera/location/contacts/microphone/etc." Breaks all apps that use the custom permissions (e.g. Skype). With it enabled they would still prompt you for per-app permission (camera, location, contacts, etc), with it disabled they're treated like you don't have a camera/microphone/etc at all... But only for modern apps, Win32 can still access the camera/contacts/etc. Effectively you're just breaking all modern apps on Win10.
- Turn back on outdated insecure Bitlocker encryption, turn on incompatible Bitlocker modes, and turn on Bitlocker modes that only exist in higher versions (e.g. enterprise edition). Uhh, k? Why are they dicking around with Bitlocker policies?
- Encrypt the page file (Even on Bitlocker enabled systems?).
- Disable auto-complete, password manager, and other useful browser functionality in Edge & IE. Also clear browser history upon exit (i.e. break browser history).
- Actually disable OneDrive via GPO (i.e. don't just limit it, kill it).
- Break automatic web proxy configuration (may kick certain people offline depending on network setup).
- Disables SshBroker (SSH Sever) because, reasons..?
Just go look in the source code. This is amature hour. Someone's just gone through GPO, set a bunch of stuff without understanding what it did, noted down the corresponding registry changes and built this wrapper around it. But they never understood the GPO policies to begin with! Disabling the IPv6 helper may also kick people offline (even if it is very niche, what does that have to do with "privacy," what do 80% of these changes have to do with "privacy?").
I wish this nonsense didn't get upvoted on HN.