Our continuing commitment to your privacy with Windows 10
blogs.windows.com
blogs.windows.com
MS and I have radically different expectations about what privacy means in the context of a personal computer.
In particular, I run applications I've written myself. You could easily figure out what I'm doing from knowing which application was in the foreground at any given time.
Contents of files etc. is at the extreme end of privacy violation. I strongly object to the thinnest end of the wedge.
Could you imagine if Facebook pushed a notification to all your friends when you visit a new page?
If Microsoft sent an email to your entire contact book every single time you opened a program?
And yet, that's precisely what Steam does. Insane.
Isn't the whole point of friending people on Steam so that they can play games with you? In that case, this behavior seems pretty intuitive to me. Though from that angle, broadcasting this announcement for single-player/non-networked games doesn't really achieve anything and should maybe not be the default.
I'm okay with Steam saying "Soandso has logged on" but not "Soandso has moved their mouse 400 pixels, double left clicked, and is starting new software... stay tuned!"
"Isn't the whole point of friending people on Steam so that they can play games with you?"
The whole point of steam is a distribution platform. It has a defacto monopoly on computer gaming with some 3/4 of the entire market through the platform.
Sure, I play the occasional multiplayer game, but the other 80% of my behavior doesn't need to be publically broadcast against my will at all times.
It's ridiculous: I have to click "appear offline" then log into the Steam Chat website just to play a game and not have my steam account announce that to everyone I know. Sometimes you just don't want to push notify everyone you know about your every behavior.
Also -- why be friends on steam? "Dude you didn't friend me yet" "Dude i sent u my info a week ago" "Dude i thought you said you wanted to friend me" "Dude" "dude"
You have to friend people or they get offended. Social networks and psychology man. I just don't want a f'n social network in my video game launcher. Crazy. Not every single computer endpoint has to be a social network.
I guess I take partial solace in the fact that my number of hours played is almost always wildly inaccurate because I have a habit of (sometimes accidentally, sometimes intentionally) letting my PC sit idle for long stretches of time with a game still running. Steam doesn't track for activity within the game, just that it's open.
They've been collecting "telemetry" through an opaque encrypted collection system [1], and after a year of this collection, comes a "deep commitment to privacy"? This is very difficult to believe. Am I needlessly cynical here?
[1] As far as I know, nobody has decrypted the "telemetry" streams, so we don't actually know what MSFT is collecting, so nobody can be sure that it doesn't collect your sensitive documents, private keys, keyboard logs, etc.
No way -- there's no such thing as "ALL your private data" (emphasis mine). You're always making more data, it never stops. There's no way there's diminishing returns on collecting it, nowadays those systems must be super cheap to maintain, especially for a company that runs one of the largest cloud computing systems in the world.
> Am I needlessly cynical here?
In reality, yes. In Hacker News Distortion Field, not even close.
Well, in one year of monitoring your PC, I've seen your tax returns, documents/photos, countless correspondence samples, countless voice samples, internet browsing history and online spending habits. I've identified everyone you regularly communicate with, a list of locations you regularly visit, and what your career path is. What is year two going to reveal? "Bought a new lawn mower"? "Finally joined a gym"?
How did you see my online spending habits? Surely those were done over an encrypted connection online, and probably not to any of the services my OS manufacturer has partnered with. If anything, that data-in-motion is the most secure data there is.
I'm so confused how this notion is so prevalent on HN.
I'm so confused why anyone would want to normalize the idea of backdoored computers that let Microsoft collect whatever data they want from your on a routine basis. Normally we consider this kind of thing spyware or malware and try to get rid of it stat, why does Microsoft get a pass?
Sequence of events:
1. Microsoft ships an OS with signal collection roughly analagous to OSX. 2. Microsoft is raked over the coals for this. 3. Microsoft scales it back a bit. 4. People demand more. 5. Microsoft actually makes a UI and offers even more cutbacks, with less collection by default and a more thorough set up experience. 6. People claim this is a PR stunt.
What the hell do you actually want other than a black hole to swallow the Redmond you learned to hate in high school? That ship has sailed. They're already gone.
Is that so unreasonable?
Blocking IPs could work, but then I'd need to stay on top of the current addresses, which they could (and probably do) change inside their CDN.
What I want is for the switch that currently says "Basic, Enhanced, or Full Telemetry" to say "Security, Basic, Enhanced, or Full Telemetry". (Security setting essentially turns it off.)
https://technet.microsoft.com/en-us/itpro/windows/manage/con...
I do block searchui.exe at the network level, and that works. Unless you block it, Win10 talks to MS with every local filesystem search, even with Cortana and web search integration disabled.
Only telemetry and windows update is whitelisted in the kernel?
The only people who cannot do so are people on the insider ring builds. When you sign up for those builds, you accept the telemetry as part of the agreement (which is not unprecedented at all).
I don't really get why OS metadata is so disturbing but the fact that every other app and website you visit (including this one) is a blinking light of information with effectively no overarching privacy policy is overlooked. This website is run by people who fund companies that use data collection as a primary business model and early revenue driver. Why are you here if you don't support that?
What we want is "security" level, which is only allowed on Win10 Enterprise and Education.
That's a charitable assessment. Microsoft does not get privacy points for reducing a privacy invading program, any more than an abusive person gets credit for abusing less often.
A more realistic assessment is that this "telemetry" aims to normalize windows users to the idea that you don't have an expectation of privacy on your windows computer, that your windows computer regularly reports data back to Microsoft, and that you do not get to inspect what data is reported back.
> What the hell do you actually want
Opt-in "telemetry".
[1] https://technet.microsoft.com/en-us/itpro/windows/manage/con... CTRL-F "windows 10 enterprise"
I'm kinda sad to see that's where we've hit on service dependence though.
I expect Spotify to know I just listened to "Bring Me to Life" by Evanescence. I don't expect MICROSOFT to know that too, unless I use a Microsoft music service.
That said, I'm not sure if Microsoft still stores Wi-Fi passwords at all; if they do, they removed the primary benefit: Wi-Fi passwords can no longer be shared. The Wi-Fi Sense privacy page only talks about open networks now. If they still store Wi-Fi passwords on their servers, it must be only used for profile sync. I can't find any information one way or another.
https://privacy.microsoft.com/en-us/windows-10-about-wifi-se...
Is that even true anymore with SecureBoot?
From their PR only the LTSB edition (most expensive one), allows one to disable all phone-home "features" (even there opt-out, and if you miss one, your bad)
There is a reason Win7 goes still strong, and many are very carefully with recent patches of Win7 (which backport some phone-home features and degrade performance, like they did with WinXP3 in its last days).
I am waiting until MSFT board member and lead managers get fired over this case. In the early 2000s, US went after adware and spyware distributers. Nowadays MSFT is the biggest adware and spyware distributer, please go after them. They should split MSFT up in two companies.
Your bing search history shouldn't be linked to your identity in the first place. Same for cortana and edge. So Microsoft isn't getting any kudos for allowing users to see what kind of data is being collected on them (which they have to do by EU law anyhow).
I applaud any serious projects that advance privacy but this ain't it.
They conclude:
> When it comes to your privacy, we strive to make choices easy to understand while also providing clear visibility and control over your data.
This is entirely the wrong approach. Just don't harvest the data in the first place. Have opt-in measures if you must. That's it. That's what a serious commitment to privacy looks like. Anything else is a serious commitment to get away with harvesting as much data as possible while minimizing PR backlash.
That's right-- there is no supported way to opt-out of telemetry on Windows 10 Home or Pro SKUs. You need to use a third-party program to do it, and these settings are lost with every major upgrade, which come twice per year.
> Just don't harvest the data in the first place.
for better or worse, I just don't think this is feasible anymore. Telemetry is, by now, a fundamental part of the engineering process. Products that don't incorporate it are going to be clobbered by products that do. Microsoft didn't start this paradigm, but I think they had to incorporate it in order to stay competitive.
If you can't avoid telemetry, I think the next best thing is to be transparent about it (with respect to what's being collected, how it's being used) and allow the user some control over it (by letting them 'clear' data that's been collected, and opting in/out as needed). In that respect, I don't think the steps taken today are sufficient, but they are headed in the correct direction. I also think they are being more open/transparent than many other tech companies (who do similar things without receiving nearly as much negative press as MS).
Earlier I said "Products that don't incorporate [telemetry] are going to be clobbered by products that do". High QA costs are the biggest part of this.
As it should be when you're developing an OS for 90% of the market across a huge variety of hardware. There's really no way around that, and jettisoning QA teams as a cost-saving response is incomprehensible to me.
Trusting telemetry alone to ensure the robustness of your product will result in a "good enough to ship" focus on mainstream work-flows and leave corner-cases unaddressed since they're rare. And corner-cases are where the bad, system-breaking things happen.
Telemetry should help QA people write mundane automated test-cases to cover the 99% and then enable them to go and spend the constructive part of their time focusing on breaking the system. But it's absolutely not a replacement for QA.
From where I sit, both roles are combined. The output is a far smoother engineering process and a higher quality OS. You mentioned 'corner cases [being] unaddressed' but I've witnessed the exact opposite: most of the criticism I hear about Win10 has nothing to do with quality.
I understand the value of telemetry-- it truly does help improve software. And I'm fine with telemetry being active by default too. If it wasn't active by default its value would plummet as very few people would /choose/ to turn it on.
Windows telemetry should be set to "Basic" by default on every Windows install, and the user can choose to turn it off entirely or set it to "Full".
As a more sophisticated user who values his privacy, all I want is a supported method to opt-out. That's it.
I don't want to be forced to use a third-party program to do it. I don't want Windows updates to frequently reset my clear preferences, so I need to keep running that program on a regular basis. I just want a switch to turn it OFF.
Microsoft acknowledges that full documents along with stack traces (that can contain sensitive information) can end up on Microsoft servers when error log reporting is enabled. Sending a call stack consisting of function names and pointer offsets and register values to aid debugging is one thing. Sending entire globs of application memory along with the crash log is much less defensible.
My objection about linking user data to real world people still stands. There is no technical reason why _personalized_ logging is necessary. Telemetrics can be pretty innocent (e.g. track which percentage of Windows users have multiple monitors), but as they become more personal it's again much harder to justify.
The absence of a single switch (during install or first login) to get rid of all logging/monitoring/telemetrics and other privacy-invading nonsense is indefensible.
I'm sorry, but it's not economically realistic to demand that companies trying to minimize cost stop all data collection. They're not selling it: they're using it to make their developers work on real problems and improve real features. That's the same as nearly every mobile app. Watch how much your phone sings to mixpanel, kahuna, or google analytics to get a sense of what I mean.
You can raise the price substantially, or you can find ways to make things cheaper. The market is really clear they want the cheaper and are fine with benign telemetry collection. But what's really absurd is that you then decide that doing what a small minority of users are asking for is a PR stunt because it doesn't go far enough in one step.
Are you aware that Windows 10 is ad supported? If the data isn't being sold today, it will as soon as quarterly profits dip low enough.
Which brings me to your second point, that customers are fine with it. The underlying assumption is that consumers are Homo Economicus: rational agents making intelligent, informed decisions. This is not the case, as evidenced by the overwhelming difference between opt-in, opt-out, and must-choose behavior. Customers don't care about tracking, as you say, but not because they've thought about the issue and concluded the trade-off is in their benefit -- in reality they've never thought about the issue at all. Regular people are indifferent to iPhone privacy until they're asked if they ever have conversions or ever take photos they don't want to become public. And then it all clicks, and then they do care about their privacy. People don't care, until they do.
When you call telemetry "benign" you're begging the question: the definition of benign implies you can't reasonably be opposed to it. So that's fallacious.
I never said what Microsoft did was a PR stunt. My claim is that Microsoft isn't genuinely committed to the privacy of their customers, because these privacy measures are (a) insufficient (b) an afterthought (c) opt-out only. I see this as an effort to appease disgruntled customers, not as PR stunt. And as somebody else pointed out already, it still isn't possible to opt-out entirely.
Yes I suppose if you draw an unrealistic line between data collection and Facebook suddenly sharing photos you could scare up any sort of response you want.
Sharing content vs app usage metadata are quite different in point of fact though.
> People don't care, until they do.
Yes. I suppose this is true in the sense that it's tautological. I only bring that up because of your meticulous dedication to discarding social context in:
> When you call telemetry "benign" you're begging the question: the definition of benign implies you can't reasonably be opposed to it. So that's fallacious.
(P.S., this is not "begging the question". "Begging the question" is not "Obviously we should ask." If you're going to use a technical term, perhaps look up its technical definition? I do not think this assertion is unusually cyclical.)
> I see this as an effort to appease disgruntled customers, not as PR stunt.
I sure do wish people would hold desktop to the same uncompromising standard they hold Windows to...
> And as somebody else pointed out already, it still isn't possible to opt-out entirely.
Actually, they were referring to the current state of affairs for specific editions of windows. We are not entirely sure how this will change with the new edition.
2. I am using the technical (dictionary) definition of "begging the question" and I'm using it correctly. We're not in agreement whether the data collection is fine. You say it is, I say it isn't. Begging the question is the fallacy where you assume the statement under examination to be true, which do you when you label collection "benign". After all, if I agreed it's benign we wouldn't be having this discussion.
3. Non-sequitur.
4. No evidence has been provided that opting out entirely will be possible, and it's not possible today, so it stands to reason it won't be possible in the future either (except perhaps with registry hacks).
2. No. You didn't. And no, it isn't quite that.
3. Industry security as a holistic vision does indeed seem to be immaterial to this conversation. I talk back against this point in this community because I'd prefer not to see the slashdot-esque "M$" mindset take over the discourse in an industry that sorely needs competition in this space.
4. Since no evidence has been provided either way it doesn't seem safe to assume either way. I'm not sure why the lack of clear policy here is license for you to say "It is not changing."
How about you take a page from your own book and go back to an O/S that strictly runs my programs and doesn't look for analytics in my computing habits? Honestly, taking payment for a product and still using the client as a product through gathering analytics is double-dipping. It's monetized twice over and provides no added value to the user.
The joke is that Microsoft finally solved the perception problem around spyware by making the OS into one big bundle of spyware.
I still have a VM running Win7 that I use to run CNC software. Like any other software I don't trust, it isn't allowed talk to the net and any time it breaks I roll it back to a checkpoint and continue.
And that's all the Windows I need in my life. And now that Apple's laptops no longer appeal, the future, for me at least, is all about Linux and FreeBSD.
Your actual Windows work is run in AppVM's which are based on the template. Any changes in an AppVM is rolled back every time it's restarted (it's always based on the template), with the exception on the user's home directory.
For anyone that hasn't used Qubes OS, this is how you do most work in it, even for the Linux VM's, and I like how it allows you to be in better control of what is actually running on your system.
Using Qubes OS take a bit more effort, but once you get everything up and running the way you want it, you'll be asking yourself why not all operating systems do this.
My most painful hurdle will be passing PCIe through to the Win VM, as I do enjoy some CS:GO in my life.
I really like the idea of Qubes, but it just seems Not There Yet. Or at least, was when I last looked.
Anyway, I wouldn't recommend doing what I'm doing. My home environment is the result of many years of incremental change, benign neglect, not-so-benign neglect, quick duct-tape fixes and grandiose redesigns half-completed. Learn From My Mistakes.
I run two virtualization hosts - FreeBSD and Ubuntu[1]. FreeBSD runs my always-on VMs (DNS, DB, some apps, monitoring, etc.). The Ubuntu box is where I run the Windows VM I mentioned, and sometimes others, depending on what I'm working on.
Ubuntu/KVM is fine as a virtualization host. I'm less thrilled with Ubuntu overall; generally, I don't like some of the decisions they've made. Next rebuild I'll probably be back to vanilla Debian.
I wouldn't recommend FreeBSD/Bhyve to anyone who is not already conversant with FreeBSD. From the perspective of a user coming from Linux, the transition isn't bad, but if you're running VMs, you're at least a part-time sysadmin as well, and managing FreeBSD looks a fair bit different than Linux. Additionally, Bhyve is currently missing some features KVM/libvirt has. In particular, if you want VGA or USB passthrough, stick to Linux[2] for now.
This is all predicated on this being a workstation - if you're doing server virtualization, I really like Ovirt, which requires an RHEL-lineage host OS.
[1] The FreeBSD box used to be "just" a storage server, but has grown up a lot and last time I did a lot of work on it, I renamed it 'spof', as in 'single point of failure', in honor of the role it serves. The Ubuntu box is my desktop machine.
[2] Actually, unless you like the adventure, maybe wait a bit - there are patches soon to be merged that will make VGA-passthrough quite a bit easier than it is now. I had a terrible time getting it working and to a kinda-stable point.
(Note that Microsoft patched Win10-style telemetry into Win7 and 8 in 2016, so this is no longer the case. But it was when those OS's were current.)
Mobile operating systems are a completely different animal.
Like I said elsewhere in the thread, I expect Spotify to know I listened to "Bring Me to Life" by Evanescence when I streamed it via their program. That's perfectly fine. I don't expect MICROSOFT to know that.
Why do you think they do as it stands? Unless of course you use the media player from their store. iTunes has a nearly identical setup.
In general they're only collecting the outer edge of application usage. I hope people realize Apple effectively has the exact same data via their bundled store solution? The idea that MS is unique or even first here is wrong.
Note that Enhanced is the default today, but Full will be the default telemetry level in the update this thread is actually about.
Anyway, that was just an example illustrating the difference between an application talking back to its server to deliver core functionality and OS telemetry.
If the app developers elect to use testflight to manage crash reports (which they're suggested to do, and it's a good service for devs), then yeah, Apple owns that pipeline. So yeah, they do end up handling that data.
https://support.apple.com/en-us/HT202031
Again, I have no problem with telemetry being on by default, so long as the user is permitted to opt-out.
All of them should be held accountable.
This doesn't make any sense. There's nothing in Windows 10 that is a prerequisite for being a "gamer".
DX12 certainly isn't it.
https://en.wikipedia.org/wiki/List_of_games_with_DirectX_12_...
It's not a coincidence that most of the DX12 exclusives are published by MS. Also note, that none of those are particularly good games, albeit they probably do work okay in showcasing some of DX12's features.
Not only that, but I noticed you purchased a laptop, which makes even less sense, since the most graphically demanding games that require DX12 are unlikely to run at decent framerates on a laptop anyway, without spending $3000+ on it.
I would be very surprised if MS allowed users to disable the newly added Win7/8 telemetry, as they do not allow it on Win10.
Can I choose to keep all of my data private? Why is there no opt-out?
They like to talk about the benefits of the sharing the data with them and I think that's great. They should make it so compelling that I want to share my data. So far, they haven't. I feel like I'm giving up far too much for what I'm getting in return.
Translation: in our opinion, individuals don't need that much privacy. So we won't give them any.
https://www.gnu.org/philosophy/free-software-even-more-impor...
Excerpt: "With free software, the users control the program, both individually and collectively. So they control what their computers do (assuming those computers are loyal and do what the users' programs tell them to do).
With proprietary software, the program controls the users, and some other entity (the developer or “owner”) controls the program. So the proprietary program gives its developer power over its users. That is unjust in itself, and tempts the developer to mistreat the users in other ways."
So I would agree with Microsoft that the two have different needs: individuals require more control over what and how their personal and private data is harvested by Microsoft.
LOL here I stopped reading this FUD. Do they still re-enable telemetry when updates to them are installed?
It seems that the new Microsoft are now using the word "experience" for the same effect.
"Basic" telemetry is absolutely not required for Windows to function. How do I know that? Because I turned it off using a 3rd party program (link below) and Windows still functions.
Windows Enterprise and Education can set telemetry to "Security" which is ACTUALLY a minimum reasonable setting for Windows to function. They explicitly block Windows Home and Pro users from setting telemetry to "Security".
It's outrageous that MS gets away with this. If only videogames released on MacOS, I would have switched years ago.
O&O Shutup10: https://www.oo-software.com/en/shutup10
"Security" telemetry description: https://technet.microsoft.com/en-us/itpro/windows/manage/con...
MacOS collects this same telemetry data. Do you trust Apple over Microsoft? It's non-identifying data that is used to make their products better and track crashes. Now they are going above and beyond other products and letting you turn even that non-intrusive feature off.
Apple allows MacOS users to opt-out of their telemetry. Microsoft doesn't.
That includes this change, too, by the way. Users still are not permitted to opt-out of telemetry on Windows 10 Home or Pro.
Microsoft admits that at one point (unclear if this is still happening) collecting your browser history and keystrokes. I can't find any articles online claiming that Apple collects this information. Do you have sources for this claim?
- The telemetry,
- Spying on kids by default (https://boingboing.net/2015/08/10/windows-10.html - I helped my kid disable this on his new Christmas laptop), and
- The "share your Wi-Fi passwords with your friends" feature
I just don't have any confidence that Microsoft isn't analyzing everything I do and sharing all my metadata with anyone who wants it. Say what you will about macOS and Linux, but at least with those I'm the customer and not the product.
MWAHAHAHAHA... Jesus. Just read it word by word.
That's some Grade A newspeak. Such a strong wiff of Orwell.
I acknowledge that this alone doesn't guarantee my privacy, but I refuse to make it easy for corporations to rifle through my personal documents and watch me like a hawk.
Aside from that, I object to having a "free" upgrade option shoved down my throat so often and aggressively that I've got to hack the registry to shut it up. It's clear that Microsoft still doesn't give a damn about what I want as a user.
And I'll continue using Linux. Redmond can double-down on their Orwellian fantasy while calling it the opposite, but in the long run it will cost them dearly.
It's very easy to see how they do product updates without them. Simply have the user do "software update ..." at his convenience.
What you meant to say is it's kind of hard to see how they FORCE product updates without them.
This results in users getting compromised... a lot... that's why pretty much every heavily used piece of consumer software now does automatic updates, from Apple, to Google to Microsoft.
Decrying automatic updates as "zero privacy" seems a bit daft in that context.
I expected Microsoft to realize how much trust they've burned, and that the data from 5% of users who bother to change their settings aren't worth the bad PR. As a result, I expected that after however long it takes for a big company to react to feedback, they'll do an about-face and try to salvage what they can. Seems like I was wrong (or they need another year or two to come to that conclusion).
If only Linux ran Overwatch as well as Windows does, I'd never boot this spyware again.
It's so surreal that there are no words for it anymore.
https://www.oo-software.com/en/shutup10
There's also a few scripts on GitHub like win10-unfuck:
I just threw up a little in my mouth.
I understand.
This is by design.
I stopped reading. Marketing bull does that.
What's with all these negative comments here? Does any other os give you so much information about what is going on behind the scene?
Ubuntu's Amazon integration was a failed experiment in an ecosystem with literally hundreds of other players to choose from while Microsoft's Windows telemetry is an inescapable dogma forced upon all Windows users.
At least on 16.04 gvfs-http would sometimes create hundreds of connections to the mothership even with all privacy settings maxed out.