I'll go meta here: How can we trust food companies? They have incentives to decieve us, to adulterate their products, produce as cheaply as possible and sell as expensively as possible. There are magazines, websites, that do nothing but test food. It blows my mind when I think about that. How antagonistic is our society, when the people who make our food are working against us. The solution we developed for that are checks and balances in form of journalism and consumer protection laws. Sometimes it works, sometimes not. Whether its adulterants in food or backdoors in software, it's a similar problem.
But, at least, not in the software. That's a large part of the attack surface that just isn't there.
more here: https://www.gnu.org/proprietary/malware-microsoft.en.html
This is FUD plain and simple without facts to back it up.
Microsoft releasing details of vulnerabilities in advance to premier customers is not something new. All software companies have that practice and we have seen it happen with recent OpenSSL vulnerabilities when CloudFlare has been given advance notice.
If storing my disk encryption keys on Microsoft servers isn't harmful to my privacy and security, I don't know what is.
https://theintercept.com/2015/12/28/recently-bought-a-window...
I'm going to address your specific link.
Microsoft has different classes of customers and the functionality that you don't want, many customers request and may even require. You aren't obligated to use their disk encryption or functionality. You can install your own WDE product, but you appear to want the features of a Ferrari for the price of a Ford Focus, which is not reasonable.
Microsoft is not trying to mess with your system via that method. If anything, that is a blanket improvement prior by default there was no encryption. Could the design be made better? Maybe, with any implementation of a security feature there are always trade-offs. Microsoft could force users to store the key locally or print it, but then millions of people would simply turn encryption off or lose their key. This does not grant MS remote access to your system.
There are plenty of things that are wrong with MS, but saying Windows is malware is FUD plain and simple.
And your cost comparison is equally absurd. It costs more money to store and manage our keys than it would to just leave them alone.
> Microsoft is not trying to mess with your system via that method
They use other methods to interact with your pc without your permission
1. http://www.informationweek.com/microsoft-updates-windows-wit...
2. http://slated.org/windows_by_stealth_the_updates_you_dont_wa...
Your core dumps are being captured. And then sent to a third party: https://betanews.com/2016/11/24/microsoft-shares-windows-10-...
Default settings let Microsoft capture everything you type and your browsing history: https://web.archive.org/web/20151001035410/https://jonathan....
And don't forget about the NSA key buried in windows: http://www.marketoracle.co.uk/Article40836.html
I am a windows user. I'm just not sure how anyone could claim that an OS that updates without your permission, sends and stores your encryption keys, captures browser history and all keystrokes, etc is not considered malware.
I'm making that claim and I don't think you have a clue on how security works.
1. Transmitting encryption keys is something many people want as it removes the overhead of them having to manage them on their own. Businesses use this too (via the cloud) in many cases. As for doing it in the background - how else should it do it? Have a big flashy screen that will confuse the average user? This feature allows Microsoft to gradually raise the bar on its OS security and prevent data recovery from physically stolen devices; while still allowing the user to recover their data if they lock themselves out.
2. The cost comparison is valid. Disk is cheap, and key management should be (this I don't know) automated. Microsoft stores tons of data already (all major software vendors do).
3. Windows Updates should trend towards automation frankly for the consumer versions of the product. Those versions don't have sufficient security features to not get updated.
4. No PII is sent with the core dumps; it's debugging information and helps make the product more secure - that's kind of something you want right?
5. The NSA key is a known falsehood. I'm not even going to bother to address it.
I'm honestly not sure if you're a troll or a rabid conspiracy theorist at this point.
This proves you know absolutely nothing about security. lol. The reason they call them "private" is because you are supposed to keep it a secret. Key management services exist to promote ease of use. And those often include extra layers of protection (eg hsm)
> I'm honestly not sure if you're a troll or a rabid conspiracy theorist
Your logical fallicay is "ad hominem". How is this helping your argument?
I use windows. If I was rabid i'd be on SElinux all day. I'm just not ignorant to volumes of data our computers are leaking.
You do? Where? Does this company warranty anything?
What the user needs is not for Microsoft to improve Windows. At 15 new vulnerabilities a day (source: Microsoft) how can anyone argue with a straight-face that this is not a futile exercise?
What the user needs is choice. More choices of computers that do not have Windows pre-installed.
This monopoly is hurting consumers. It relies on a product that is grossly unfit for one specific area of usage: interfacing with an untrusted network, i.e., the internet. And Microsoft today requires a user to connect their Windows computer to the internet (for "updates" and "upgrades") lest the user be blamed for the product's own flaws when used in this way.
Windows should not be connected to the internet, ever. It is for the LAN only.
No one group has a monopoly on knee-jerk reactions, you see.