He made this error countless times, rendering the entire experiment a failure.
Oops.
He made this error countless times, rendering the entire experiment a failure.
Oops.
But to show how easy of a mistake this is to make, here is what Microsoft's documentation from https://docs.microsoft.com/en-us/windows/configuration/manag... says:
Enable the Group Policy: Computer Configuration > Administrative Templates > Network > TCPIP Settings > IPv6 Transition Technologies > Set Teredo State and set it to Disabled State.
Reading that, it seems as though you should disable the policy but in fact you should first Enable the policy, then go into the policy settings and Disable the setting there. And even with that mistake, I had it manually disabled in both HKCU and HKLM so if disabled means it uses the local host settings then it should use that.
Nevertheless, there are some serious concerns here:
1. Why is it even connecting to facebook, msn ad services, google analytics, etc when nothing is running?
2 Why is it doing this by default on an Enterprise operating system?
4. Why is this the default setting that requires dozens of group policy settings (and knowledge of group policy) to disable?
5. And why is there no option to opt out completely?
Yeah, it's his fault that he didn't properly navigate the Kafkaesque nightmare that Microsoft has created in order to thwart people from disabling all this spyware.
It should read "unconfigured" -- not "disabled"
Some of the GPO settings make me feel like I'm reading a contract written by a lawyer out to get me.
I don't have any concrete examples, but I swear I've stumbled across settings like this <not a real setting, just an example, probably exaggerated>:
Setting - Disable Windows Error Reports.
Description: Disable the submission of error reports
Options: Unconfigured - Use client settings.
Disable - Send only minimal information in error reports.
No - Do not send any error reports.
Yes - automatically send full error reports.
So when you Enable the "disable windows security reports" option, it Enables sending of the security reports, and when you "Disable" the option, it still sends reports.
Many of them are extremely confusingly worded like this. It takes several reads to figure out which option actually disables it.
edit: fix formatting
What an unnecessary insult. If you can read the incredibly confusing Microsoft documentation better than him (or any of us), then please post the definitive step-by-step instructions for turning off all telemetry and privacy-invasive connections in Windows 10.
Then we'll see if your insult was warranted.
https://social.technet.microsoft.com/wiki/contents/articles/...
It shows how there's an Explain box that describes what the various settings do.
[ * ] How do you know that it even works? Plenty of times I've followed instructions from Microsoft's TechNet that didn't solve the problem it purported to solve.
And by the way, that's a helluva lot of steps to disable IPv6. Multiply that by a hundred other things you need to do, and probably a hundred you don't know about, and changes that get undone by updates, and you have a nightmare trying to create a privacy-respecting Windows 10.
https://docs.microsoft.com/en-us/windows/configuration/confi...
No matter your opinion about the subject at least we are talking about it now and from what I can tell he's going to make a more reproducible test with a script so we can all tear it to pieces.
If not, I hope someone else do it. Even better if it's somebody with the proper credentials some of you all are requiring (from a freaking tweet).
Sensible defaults matter.
I haven't published results anywhere and many people, including in the comments here, have corroborated what I saw.
The results are the results. I am re-verifying before I publish anything on this and to provide a script so that others can reproduce the results. That certainly does not make it wildly implausible.
I don't know if this will be of any help but https://news.ycombinator.com/item?id=13727712
But the major result shown was your incompetence in setting GPOs.
You should be retracting your 'findings' until you learn how to use Windows properly, not doubling down on your claims. What an embarrassment.