HP installs system-slowing spyware on its PCs
engadget.com
engadget.com
It is now well established that if you choose to run Windows you're going to be playing this game of cat and mouse until the end of time. You simply are not in full control of the OS.
I also don't understand why anyone who cares about these issues would buy HP - they're establishing a great track record as a company that really wants to spy on their customers[2]. Almost worse than that is how incompetent they've been about it - a couple years ago it was FinFisher, and I believe they somewhat recently shipped a key logger in a driver by apparent accident.
For my part, my machines save one run OSes that expose full control of the machine[3]. OSes that don't, like other untrusted software, run in VMs so that I can still control them. Windows instances don't get network access anymore. I only use it for a couple apps that do what they need to do, so the bottled demon doesn't need updates until underlying needs change. It makes life much easier when a whole class of problems can't happen.
[1] Which is as it is 'supposed to be', as the rules are currently written.
[2] Not to mention board members...
[3] Yes, cellphones; not a novel observation. That's a different discussion that I've had several times here.
After about a year, I made it clear to my boss that I was much more valuable to the company running in a Linux system. They 'found' some extra budget and made it happen, and I'm very pleased with that, but I don't disagree with their first decision to just get a simple HP.
I boot the HP probably once a year to blindly click through the flash based corporate training that one of us draws the short straw to write down the answers for.
I was able to get Arch on it without accepting the Win 10 license.
With a Windows PC you're having to trust Microsoft, the OEM, the ODM, the BIOS manufacturer, the driver author for each and ever piece of hardware in your system.
It's much easier to vet a single source.
Did you mean uninstalled or updated? ROM Apps can be updated but not uninstalled and sometimes not disabled.
1) Use SystemInternal's process explorer and track all network connections: (As admin: Add column to track the network tx, rx counts)
https://docs.microsoft.com/en-us/sysinternals/downloads/proc...
2) When I see some app, system that connect to network which I think it should not. I just block their network connections with Windows Firewall or uninstall those app.
There is a "netsh advfirewall firewall" command that can do this from command line.
3) BTW this works very well with Windows' own service too. I block svchost.exe, Edge, SerchIndex, etc from accessing internet. svchost.exe is allowed to access local subnet for file, print sharing. When I feel like upgrade to to latest version windows 10. I turn off the firewall rules for a few hours to allow the update to go thru.
4) Only Firefox and Chrome in my windows system are allowed to connect to internet full time. The CPU usage is normally < 15% and most of the time < 10% even when playing youtube @ 1080 resolution.
The latest Firefox Quantum has less CPU usage and faster also. I love it.
5) The WSL (Windows Subsystem for Linux) is getting better - X, xfce4-termnial now working good enough for me. I like accessing the Ubuntu shell in windows environment without the overhead of Virtualbox.I have a beloved 2015 MBP that I'm trying to keep alive, but it's becoming a little underpowered and it's not upgradeable. New MBPs are a non-starter with the port and keyboard situation and my coworkers all hate them. Then I have a maxed out XPS 13 which is a very nice and capable machine that suits me completely, except that it has a malicious OS that I have to constantly fight. And Linux doesn't support a lot of the tools I need.
So..... what's the solution here?
So..... what's the solution here?"
The solution is sitting in your hands. That XPS 13 can run Ubuntu (and probably Debian, Arch/Antergos, or any other major distro) flawlessly since Dell ships a version with Ubuntu preinstalled. Set it up to dual boot with Windows, and use VirtualBox's raw hard disk access feature to set up a Windows guest under Linux using the Windows partition as the VM's boot drive.
That way, you can slowly wean yourself off of Windows; use the VM for your Windows-only tasks with the option of booting natively into Windows for anything strictly hardware dependent, until you have replaced your Windows workflow with Linux. Even if you find you can't 100% escape Windows, at least you're not living in it so you're not being spied on all day.
> with the option of booting natively into Windows for anything strictly hardware dependent
IIRC, years ago, when Windows 7 was the latest Windows, this couldn't be done. Windows used to take offense if the hardware it was running on changed significantly from boot to boot. Has that changed with Windows 10?
I've recently moved to Mint with Win7 in a vm and its lack of GPU and DirectX support is not really workable. Basic apps are fine.
Well, yes, if you want to do any significant amount of gaming on a computer, you'd want a dedicated GPU. If integrated GPUs meet your demands for gaming, you're better of with native Linux games and Wine for Windows casual games.
> "I've recently moved to Mint with Win7 in a vm and its lack of GPU and DirectX support is not really workable."
It sounds like you're better served by dual-booting then. Running a VM isn't a solution for everyone, just another option for some.
I started off in a dual boot situation, and i can't even remember the last time i went into my windows partition. It has to be less than 5 times in the past 3 years.
There may be Linux equivalents of the tools you use, but it would be difficult to say without you naming these tools specifically.
The new 2017 models don't have much more horsepower. They just have a worse keyboard and a touch strip.
Also Linux multi-screen/multi-DPI support is still bad.
I just want this to work, but it doesn't. This was a Dell laptop that came preinstalled with Ubuntu, too.
It is very fun to play with a full screen MacOS on a touch screen enable Laptop.
https://github.com/caesarshift/msfw
I would run "msfw log --tail" to watch for blocked connections. If I wanted to allow the connection, I then added it as a rule.
It was alot of work to setup initially, and I even found some scenarios where adding a rule was not sufficient to allow the connection. I never understood why.
Why do people continue to purchase products from companies that blatantly want to spy on them? Vote with your wallet and never go through a bizarre multi-step anti-spyware setup again.
Still you count as a happy Windows user and will reinforce the Microsoft position. This way they will be able to abuse 99% of their users, those that don't have the same competencies and time to spend on these countermeasures.
As for the WSL I stopped using it. This is an honey trap to let people use Windows as their primary OS by just giving them the developer goodies they like. I may consider it again if you can use it to develop a full-fledged Windows application that can access the windowing system and can be redistributed. You may have noticed that with WSL you cannot and the applications you may do remains nicely restricted to the linux subsystem.
A honey pot? I don't think that means what you think it means. If you are interested in developing full-fledged Windows applications, why in the world would you want to use WSL? You are not the kind of developer that WSL is designed for.
If you want to develop to a Windows target, then configure your WSL environment to do cross-compiling. That's up to you. If you can cross-compile in Ubuntu, then you can cross-compile in WSL. Just don't expect WSL to be anything but Linux.
And regarding (5)... well, the same thing I used to tell people about WINE applies, just in reverse. Unless you're butting up against a corporate policy or something, why pick the inferior, broken imitation when the real thing is right there?
Any closed-source, non-free software - drivers, productivity tools, games - all pose the same danger.
And it's not just software - binary firmware blobs (including ones found in most ARM-based SBC, such as Raspberry Pi) should be seen as potentially dangerous. Not to mention Intel's Management Engine and such.
But specifically Windows has the track record that it will do this, and when you attempt to stop it, it will attempt to go around you and keep doing it. Random drivers and Raspberry Pi firmware do not have this track record, and so saying they "all pose the same danger" is technically accurate, it's disingenuous to the point of being borderline untrue.
While the argument often seen from the FSF - that all non-free software is dangerous - is technically true, it's about the same level of true as "all software is dangerous if you can't read the source code," in which case, all software is dangerous to everyone who isn't a software engineer.
Even though all non-free software has this issue, we should still be vigilant about fighting and curtailing it where we can. Proprietary software isn't going away, and the harm is real, so we need to encourage its lessening.
And even everyone who is, unless that engineer understands every language and hardware component in play, and is able to spot subtle vulnerabilities at a glance.
You have to have some level of trust. That trust should have a pretty high barrier, though.
FOR ME, one of the biggest things I look at is motivation. This often means looking at business models. We've seen where the race to the bottom for laptop prices gets us. I'd rather buy a laptop from a company that makes money off of selling the hardware, itself.
In my opinion a better tool would be a legal framework to limit companies what they can and can't do. For example EU GDPR is much stronger factor in limiting what companies can do with personal data, and it forces companies to provide opt-out option (and proper opt-out, not like "we use cookies, if you don't like - please leave"). The reason why EU GDPR is not a joke are fees - 4% of global revenue (or 20 million EUR, what is bigger), so companies are forced to comply. I would love to see a proper legal framework for opting-out from tracking, but looks like it will take another 10-20 years to develop it :(
A much better example is the new telemetry in OS Chromium, OS .NET core, and OS VSCode.
Finaly a computer I fully control. :) Next, I'd like a tablet I fully control, without all the complexity of Android or traditional Linux desktop environments. Nice small userspace with small tablet GUI apps + HW access server, written in C. All snapping fast without a crazy-bloated SDK. Something that can start in 3-4 seconds including linux boot.
And what closed source has to do with it is this: if you try to do this stuff in free software, people can simply remove it and distribute the clean version.
Open source is not really a remedy here for the same reasons. We have seen how developers incorporate telemetry into projects, especially projects with mass appeal. Sometimes there is some pushback (e.g. Ubuntu). Other times it is mostly seen as a fact of life (e.g. Firefox).
The only time that you have a reasonable degree of protection is when you're far enough into the fringes that you're a part of a collective that is working proactively to protect a common interest.
2. Even in the case of Firefox, there was pushback. It may or may not have been sufficient, but there was. Ultimately, the disabling of that telemetry, whether by toggling a setting or by forking the browser, is still doable. The same cannot be said of some closed source software, particularly of the OS-level spyware that Microsoft has been peddling.
I just finished reading a book [0] about the Conficker worm, which infected people's computers by causing a buffer overflow in an unprotected port.
Windows published the security patch to prevent the buffer overflow as soon as they found it, but they couldn't force users to update. As a result, the Conficker worm continued to spread, despite the company fixing the problem, because people couldn't or wouldn't install the new patch.
While the botnet created by the worm never did anything too malicious, it had the potential to be catastrophic [1]. Experts even talked about it potentially creating enough traffic to shutdown the root servers of the internet.
All that to say, automatic updates aren't always a bad thing. I, too, hate having updates forced down my throat.
Security updates, however, are in a bit of a gray area when it comes to that, IMO.
[0]: Worm: The First Digital World War - Mark Bowden, 2011
Still, there isn't really sufficient protection to avoid telemetry and data collection on most of the platforms I use.
Mac App Store apps are somewhat sandboxed, but many common apps aren't. And running "little snitch" is great, but it's not for typical users.
Windows and OEM software/drivers are on the local machine.
In a restaurant, I expect other people to see what I eat. In my own house, I don't.
In any case, IMHO the stronger argument is that just because webapps spy on you doesn't give Windows any right to do the same. Unfortunately, a lot of web companies have shown that people will throw money at you if you attract enough users, and sell their eyeballs or habits.
The problem with Windows is that Microsoft control it totally. There is no way out.
Although Google control android, they only do so with the permission of the userbase. I run LineageOS on my phone (no gapps) and although Google are the gatekeepers of what goes into AOSP if they become problematic then the opportunity is there for somebody to take what we already have and carry on in a different direction.
Either you control everything, including hardware, or need to compromise at some level.
https://qz.com/1131515/google-collects-android-users-locatio...
Just a quick example, as I am on the go currently.
Apple's constant update nags make older iOS devices borderline unusable, but acquiescing to the update makes the device completely unusable due to massive lag.
While Google has deprecated and removed features in major updates, I don't remember a single instance of something that generated a measurable extra workload on my phone was pushed automatically by Google.
Do you remember any such event?
https://android.stackexchange.com/questions/122918/google-pl...
Name one big, successful project which doesn’t do this.
edit: VLC.
The article doesn't implicate Microsoft in this at all.
A great thing for 99% of the users.
Most banks in Germany allow HBCI, so you get an external chip reader, any HBCI-compliant software – be it StarMoney, or GnuCash/KMyMoney with the HBCI plugin – configure your account, and authorize API accesses via the card and PIN on an external keypad (which shows what you’re authorizing on its own display).
This is the average way a consumer does online banking, and it’s much more secure than on iOS.
And the chip reader is required for the new Personalausweis anyway.
To me it looks like nobody actually uses the Personalausweis online. Just recently, companies have switched off their support (e.g. HUK or DKB). And the majority of the readers around are just RFID readers without any dedicated keys or display (which obviously is not a secure way) which can't be used for HBCI.
lol. At least on iOS they can trust what they see.
On desktop they can't, https://securityintelligence.com/tatanga-attack-exposes-chip...
All of your security theater falls apart when the device is infected with malware that can make the bank site say anything.
On iOS your banks app/site will never ever lie to you, if it does it'll almost certainly be the banks fault and not the users.
While German banks support that almost universally, hardly anybody uses it.
[0]: https://shop.reiner-sct.com/chipkartenleser-fuer-die-sicherh...
The vast majority of users simply do not benefit from being exposed to such complexity, it certainly shouldn’t be the default.
Think safety locks on pill bottles or cabinets.
Sure, but my point is mostly that generally restricting user freedom results in much less of such getting installed.
The ability to control your machine is always good for users in the long run, though you're right it's important to make stupid changes very difficult for less sophisticated users.
Perhaps your bank should control your money so that you don't spend it unwisely? Users are stupid, after all.
One of my father's laptops runs Xubuntu. It's totally fine too. He doesn't even know what root permissions are and he never needs them. But still, sometimes he has to install something and I have to help. The point is, I never get asked to help with W10 neither from friends or family, which is actually amazing.
It's common with phones too. My new Sony phone came with several Sony apps as well as Facebook installed as non-removable system apps. None of these are necessary for proper function, as it can run a third-party build of Android that doesn't include any of them.
Facebook in particular is an odd one. I can understand preloading it since it's very popular, but why the hell is it a system app?
I'm sure it will get better over time but I don't want to have to change the way I pick up my phone to avoid Samsung's garbageware.
Like why buy it? Did you not see the button when you looked at the product? Did you not read any reviews?
So many other phones to select from and users are buying a phone with a button they don't want.
Companies continue to get away with these poor design decisions and forcing this system-wide apps because we continue to buy their products.
If it's the best phone otherwise, why not buy it? It's not a deal-breaker; it's just annoying.
Is it? I'm not up to date on the latest models, but in the past when I've compared Samsung's flagships to others, there wasn't a really obvious winner. I always found it a little weird that Samsung got such a large share of the market.
For me there's a ~four-way set of compromises: Stock (or near-stock) Android, Headphone Jack, Excellent Battery Capacity, Quality components.
Unfortunately there's nothing that meets all four of those requirements.
The Google Pixel 2 is probably as close as it gets, but has no headphone jack - which is a deal breaker for me.
After that, it's down to either the Samsung Galaxy range (S8, S8+, Note8) which all have the Bixby button, or LG V30/V30+.
Both of these are unfortunately running heavily modded versions of Android that are well out of date, and the LG V30/V30+ have had issues with screen quality and general availability.
So, I have a Galaxy S8+ - not my first choice, and I'm not really happy with it (too much Samsung crapware on it), but it's better than the alternatives.
I really wish Apple would ship a phone with a stylus, but we know it's against their religion. His Steveness spake thus: thou shalt not use a stylus with a phone! And it was so in all Appledom.
Not quite, but I think it's the only flagship with an integrated stylus.
It's also the only one with it's monstrously large screen, and it's aspect ratio, which is a nice combo because it gives you a lot of visible screen content while using the on-screen keyboard.
Not the best for everyone's preferences, but there's no obvious substitute for someone who wants Note 8’s distinct features other than Bixby.
There are other features, like a button on the stylus that the phone can detect a press of, and a small cursor that appears on the screen when the stylus is near but not touching it, but these are less important. Still, I think it's fair to say that the stylus is more useful when integrated into the design.
Because there's a phone identical to the Note 8 but for the button? Just because the Android ecosystem is more diverse than iOS doesn't mean that there is unlimited variation available in the market. I don't want Bixby, really dislike the button placement (too easy to accidentally activate even if I wanted Bixby), but that's not enough to prefer another phone to the Note 8.
You can turn it off, see https://www.androidauthority.com/disable-bixby-button-samsun...
It makes the button do nothing, which is kind of annoying in its own way, since you can't remap it to something useful but at least you don't have to suffer Clippy 2.0.
Honestly it's been extremely useful and I'd recommend it to all S8/Note8 users.
They could potentially be getting some useful saleable data from you, possibly even if you don't use facebook.
My phone is rooted, and I've uninstalled it properly using Titanium Backup. There were also hidden Facebook "app installer" and "app manager" apps, which I removed.
[0] This is also why the disable button dialog discusses uninstalling the updates to an application. Because updates are obviously not written into the ROM; they're in normal application storage.
/system shouldn't normally be writable at runtime on non-rooted devices, so updates get installed to /data/app like user apps. A proper uninstall with root, e.g. using Titanium Backup does remove the app from /system/app.
Here’s a screenshot: https://i.imgur.com/QbJF1AG.png
I'm assuming that's why Evernote came as a system app on my Samsung too. And a load of other crap.
Much easier to do it that way than to either add a first-boot process to install it as a non-system app (thereby taking twice the space) or have the factory flash include it in the user partition, which means that a factory reset doesn't actually return the device to the state in which it left the factory.
That does make a bit of sense, though I suspect it wouldn't be too hard to tell Google Play to install a list of apps after the first boot.
At least in the case of things like "Google Sheets" and "Google Docs" the preinstalled apps are only like 1kb, and are basically just placeholders telling google to go to the play store and download the current version of the app once the phone is started (unless you disable and uninstall updates, at which point it's back to the 1kb placeholder)
1) Give me all the stuff I need pre-loaded.
2) Don't make me do system management. Do it all for me.If anyone knows how to slow down systems with their software, it's definitely HP. Haven't used one in awhile, but you could get a boost similar to going from a mechanical hard drive to an SSD by reloading the OS without all their bloatware. I wonder, has any security researchers ever thought about going back to circa-2005 printer software to see what it was up to?
Either way, that fine is just a minor expense compared to their $300B revenue. It won't even show up on a summary report. Punishments are supposed to hurt if you want behavior to change.
Sadly more and more bloatware is included by manufacturers, along with all bloatware that is already in Windows.
And during an update [1] it seems smart enough to get most of the model specific drivers installed. The things that remain for one off download and install from the manufacturer web site are firmware updates.
The next time I do a clean install, I won't install HP's Support Assistant. It's OK UI/Ux, a bit laggy to discover what updates to apply, but more importantly it regularly fails to inform of and install firmware updates, even though they appear on that model's support page.
[1] Windows Update times are incredibly shitty. On a system fully updated as of 2017-09-25, and then not used at all (Fedora is my main OS) until last weekend, it took 7 hours and 6 reboots to get it updated. That includes one update with "Getting Windows Ready Don't turn off your computer" for 4+ hours. I have never had macOS or any Linux distro take more than 10 minutes for a minor update, or more than an hour (slow embedded spinning rust system) for a major version update. It's obscene and any wonder why people prefer to opt out and end up with riskier systems as a result.
Lenovo has only just settled a massive $3.5 million fine for preinstalling adware on laptops without users' consent, and now it seems HP is getting in on the stealth installation action, too.
How is that a massive fine? Instead of deterring anyone, it looks more like a bargain.
Are we saying that only people technically competent enough to install an OS (plus a few close friends and relatives) can have fast, safe computers? Do we think that what we don't accept should be good enough for the rest of them? Or have we already given up any hope of solving it more than individually?
I don't have an answer here, but I'd like to see the discussion go beyond 'no probs, reinstall the OS' now and then.
So far that seems to be pretty sustainable advice for non-technical friends and family expecting to use Windows.
Another point of view is I don't like this assumption users can't or won't learn. I don't complain that a TIG welder is only for experts because I can't operate it with no training, because its a tool that requires training, and so is a computer. This is why I think one of the main problems is that schools should not be teaching proprietary systems. (Once again a thing RMS was right about)
I've been using Linux and Windows for years. When Windows 7 came out, I moved any Linux installs to VMs simply because it still cannot get the things you mentioned working, even on Thinkpads and Dell Precisions, which are far better than most laptops. It was good enough for most development.
Work provided me a MBP about 2 years ago, and while it's not perfect, it's good enough. I will not be buying another Windows computer anytime in the future.
They remind me of the ultra cheap office pens that I bought once. I was new and my boss sent me out to get a box. When I got back he used one and said “these are too cheap, we use these every day”. He was right.
If you are buying a laptop get a Thinkpad or a Mac. If you are want a desktop and don’t play games get a Dell.
On point: HP and Apple are the worst companies to buy a laptop, expensive as hell but they usually have local support staff in your city. Also Thinkpad suck, they feel super cheap for the price they ask and install even worst spyware preloaded.
I know, Lenovo has completely wrecked the Thinkpad brand. I wish IBM would start making laptops again.
But also the customization is very valuable. Being able to move budget around to get a top-end GPU at the cost of SSD storage doesn't tend to be possible when you buy pre-built. You might want a GeForce GTX 1080 Ti, but every prebuilt gaming machine that includes one might also include a 1 TB SSD, i7 GPU, and and 32 gig of RAM, inflating the price. By building yourself, you can budget for the god-tier GPU by sacrificing the large SSD for a smaller one, going for the i5 CPU which will still be enough power for gaming, and 16 gig of RAM because you don't plan on multitasking while gaming.
</snark>
I think we oughta make a common repo + windows service to remove crapware.
[user-complaints] -> [scripts] -> IO happinessBut as someone above already noted, it really is a cat & mouse game with MS. Things that worked yesterday will not work today, after MS silently installs new updates.
It wouldn't surprise me to learn that MS has full-time staff dedicated to fixing any issues the most popular of these tools modify.
ps: hmm quite a lot of batch, sad
Also, your spam filter is trolling you.
How can an app be so poorly implemented? This had to have been noticed in QA and yet some exec prioritized gathering user analytics of user experience. How pathetic!
The HP that sells laptops in department stores is consumer-hostile and sees the purchasers of their computers as cash cows to be farmed out to third parties and upsold remote support plans when the computer has a problem. And problems will inevitably occur since the machines are built with such poor quality control.
It's sad to see a brand new computer be slower than one that is 10 years old but can't be used because it has the wrong operating system.
Seems to be fixable via hosts file blocking.
I personally don't know of anyone that uses a HP system for personal use. When I think of HP or Dell, I think of bloatware.