Microsoft’s enterprise products covertly gather personal data on users
thenextweb.com
thenextweb.com
I think it would benefit large companies like Microsoft to realise that this sort of behaviour has knock-on effects. Every MS product is tainted by this because it ultimately has effects on trust.
If it's not making them, or can't be linked to, significant amounts of revenue, it would surely be beneficial in terms of customer numbers to stop doing this. Why?
I don't understand, or believe, that they're making significant amounts from this. It feels like bean-counter style decision making that doesn't take in to account the wider picture.
Anyone from MS willing to chime in?
If MS is making money from this, the last thing anyone involved in it will do is tell you how much.
Its dumb, dangerous to users and I hope they will get a massive slap on the wrists. But Win10 is out for long time and nothing is happening.
Roku devices are far and away the noisiest devices on my network.
Android seems pretty awful too, the higher the version number the more noisy it gets.
All of my Windows machines are running with the lowest level of telemetry that Microsoft permits you to set, I don't use any of those reg hacks hosted on github. Interestingly a Windows 7 laptop is much noisier than a Windows 10 laptop. Surprisingly Windows Server 2012r2 makes the shit list too. What's strange though is an always on Windows 10 desktop isn't even on the list.
Interestingly Amazon Echo and Google Nest DNS traffic is rarely blocked despite them being the top clients (behind Roku) by a fair margin.
The DNS logs for my home network are full of proprietary stuff.
All of my actual work systems do queries when I use them and that's it. Extremely rarely there'll be a hit out to NTP.
It's quite amusing, because by percentage, the systems I use 8 hours a day are barely even represented in the logs (contrast with my Android phone attempting to hit Google DNS and being prevented by the firewall, over and over, _forever_.)
Those kinds of effects are hard to measure and quantify even if they are critically important to the long term success of a company, whereas the revenue from whatever they're doing with this data is directly reflected in their quarterly earnings report.
Let's take a hypothetical example of where you assign a given user a random ID, based on something (machine ID). You then track what this user is doing, in general, in the operating system.
You can find data points such as what % of users discover/use X feature, how many pin applications to the taskbar, use X app with Y app, have night mode enabled, etc.
This allows you to expend resources where they are actually needed, to improve the features that the majority of people would find benefit in.
And at the end of the day, none of the above features require knowing anything about WHO that person is. Sure, they can be classified into groups based on how they use the software, such as "business user", "power user", or "gamer" ... but not "John Doe at 123 Main Street, Hollywood, California".
This is likely all for product improvement and not for $$$. Why do they subject end-users and not opt-in testers for this? To get real world data at scale.
How can you be so sure? Between IP addresses and what wireless networks are available you can get a decently precise location for the majority of users. And this is assuming you don't just capture the address and name when they type it in.
Okay, so maybe they aren't using it for evil yet. How many times has a large corporation been able to indefinitely resist the pull of an alternative revenue stream where the majority of the cost has already been paid?
Agreed. They are mining and storing a mineral (our data) that they may enrich and sell (or lose via theft) one day in the future. This is the worrying part. This is a direct violation of GDPR which states that if you don't need the private data for an explicit purpose for the user (not your company) then you are not allowed to keep it.
They are collecting usage-stats, aggregated data, in a way which deliberately has been decoupled from your identity so they won’t have to face the kind of liability issues you just mentioned.
If anything, MS seems like one of the few big actors in IT which “gets” GDPR, and they are using it their advantage in the enterprise market.
Of course unwanted telemetry (no matter how anonymized) is going to taint that image somewhat.
If they'd like to give me some consideration for my data I'd be happy to entertain their offer. (Being granted the right to use the software, in cases where I'm paying for the license, doesn't constitute consideration to me.)
Do you own that data? Where do you draw the line?
Not alleging there is such transparency here, just raising the question. It always seems like even anonymous telemetry is considered harmful, and I don't understand why that is from a conceptual standpoint.
There's probably, like, a particular way I move the mouse from the bottom left to the top right corner of my screen. A 'mouse cursor gait', if you will.
To be frank though, there doesn't need to be a reason. You're treating this as a Stockholm-syndrome esque situation - I don't need to use Windows, I definitely don't need to justify why I don't like certain aspects of it.
Some people do need to use Windows for various reasons. Consider yourself lucky if you don’t.
It's a relatively new addition to the landscape and Windows isn't any better or easier to use than the 2000/XP days - at least in ways which telemetry would influence - the genuine improvements are all obvious wins like display compositing, kernel stability, etc.
It also dismisses the point that by including telemetry you've excluded some users, and your automated collection won't be aware of it at all in many cases.
Some won't ever use Windows 10 as a main desktop OS because it attempts to spy on them. They won't recommend it to others or develop for it either.
Other power users will use it, but will opt out. So your telemetry is now completely biased towards non-power-users.
This isn't sour grapes - I wouldn't be using Windows anyway because I'm a free software advocate - I just wonder if they've realised that the incentives line up to effectively ignore some of their "best" users.
It makes loads of sense, to me. It started with the Customer Experience Improvement Program, WAY back in the Windows 2000 era, if I recall, which you would see an option to enable or disable when you installed a Microsoft SDK. They clearly saw benefit from this information, so they expanded it to include the whole OS.
This collects lots of data for them, which helps them understand the usage of their products better, and a nice side benefit is that they can use the knowledge gained by organizing and inspecting this data in their "big data" offerings on Azure and in other places internally.
The greatest benefit of Microsoft's telemetry to others is that everyone focuses on MICROSOFT's telemetry, argues about MICROSOFT's telemetry, debates MICROSOFT's telemetry, endlessly, while literally 90% of the rest of the software you use (99.9% if you count software you use that isn't on your computer, like servers, routers, web sites, and so on) collects telemetry, also, even when you think you've turned it off. Nearly every game you have installed on your phone collects FAR more about you than Microsoft has ever dared try to collect, and no one knows or gives a damn because "OMFG MICROSOFT I HATE MICROSOFT
I don't care if they collect usage information from me. I truly don't. The entire Internet is trying to make me feel like I should care about usage data that originates from my computer, but I don't. I don't feel like it's my data if it truly is telemetric data about software usage.
I would use more free software if more of it were good enough to use. Of course, a lot of free software is GREAT, and I use a lot of that stuff, rather than paid alternatives.
The reason they might want to just collect all data without asking is that there's a chance that making it opt-in could cause bigger bias problems in the data you collect. For example, what if "power users" are significantly more or less likely to opt-in? You could end up with a very distorted view of what features are most popular, or are giving people the most trouble.
Not saying that this concern is well-founded (I really don't know), or that this choice makes sense from a business perspective (I'm skeptical). Definitely not saying that this is the ethical choice to make (it isn't). Just trying to shed light on a possible thought process.
From - https://www.theregister.co.uk/2018/11/16/microsoft_gdpr/
"...[Microsoft] also recommends simply not using the web-only version of Office 365, or SharePoint Oneline. And it recommends periodically deleting the Active Directory accounts of VIP users and creating new accounts for them so that the diagnostic data associated with those accounts is eventually deleted."
Seriously, we should be deleting and recreating accounts in our own fucking domain to keep the data anonymous? Why is that on us?
They have you AD account info, and diagnostic data directly tied to it. There's no anonymization going on here at all. They're gathering it recklessly.
Also from that link:
"Much of what Microsoft collects is diagnostics, the researchers found, and it has seemingly tried to make the system GDPR compliant by storing Office documents on servers based in the EU. But it also collected other data that contained private information and some of that data still ended up on US servers."
> This allows you to expend resources where they are actually needed, to improve the features that the majority of people would find benefit in.
Let me give you a different idea. Instead of allowing you to expend resources where they are actually needed, it allows you to (often incorrectly) guess what users are trying to do.
Product improvement? You're not improving the product at all if you're not directly engaging the user.
That is clearly about money.
> to improve the features that the majority of people would find benefit in.
> This is likely all for product improvement and not for $$$.
Read those sentences again. They are doing it so they can make $$$, whether that means nefariously using your data for advertising/tracking OR improving the product, it 100% translates into making money for them. Improving the product means they continue to sell the product you continually pay for.
I think you're missing the overall point - any for-profit entity that tells you it won't infringe your rights, will eventually infringe on your rights. Especially one that takes $110B/yr in revenue. I'd be happy to share countless stories of for-profit entities, especially in tech, that do this.
> 1: Using customer data to improve your product, to make them happier paying for it, which makes $$$
> 2: Using customer data to sell to someone else or to sell the user's attention, which makes $$$
The extra level of indirection through a product that you deliver to the user that provides value to them makes a huge difference between these two ethically.
That said, I will admit that a company can move from 1 to 2 completely seamlessly, without the knowledge of the user. A bean counter, unscrupulous wallstreet exec, or changing priorities may take something that was intended to only ever be 1 and turn it into 2. This risk may be too high for you and that's your call to judge, but I find it hard to fault a company just for trying to improve their product.
I do wish more companies took Apple's "differential privacy" approach which allows the data collection technology itself to draw a hard line between 1 and 2 that can't be crossed invisibly.
Nor do I. So the argument thusly is -> why make the opt-in/out so difficult to manage (e.g. dark patterns)?
It's the same excuse always. Nowadays everyone suddenly needs tracking for everything, from softwares to TVs and cars.
I was made aware of this from blackviper.com, a great place for windows service configuration information and reccomendations.
The assessment is about Office ProPlus (actually called Office 365 ProPlus - I don't know why it's called "Office ProPlus Enterprise" in the article/assessment which doesn't exist as a product). The assessment also complains about Office collecting data so I wouldn't say it is fair to say that "Microsoft’s enterprise products covertly gather personal data on users" (which really includes a lot more products than just Office). The blog posts title is actually "Impact assessment shows privacy risks Microsoft Office ProPlus Enterprise" which is more specific than "enterprise products".
>I wouldn't say it is fair to say that "Microsoft’s enterprise products
It also includes sharepoint and onedrive which are used in enterprises in the article.
OpenOffice is cancer to MS Office users.
> Periodically delete the Active Directory account of some VIP users, and create new accounts for them, to ensure that Microsoft deletes the historical diagnostic data
The fact that this is necessary is beyond retarded. Imagine you're a big corporate, paying money for a software product, and you have to jump through silly hoops to protect your privacy. I'd have a good laugh watching MS account execs explain this to me...
I have worked for companies and with goverment contracts in the past and you had to use special hardware provided by the goverment to work on those projects. So it doesn‘t surprise me at all they they themselfes can‘t use SaaS offerings.
Microsoft repeatedly switches a flag which urges Windows users to "upgrade" to Windows 10 when users had said no. http://www.computerworld.com/article/3012278/microsoft-windo...
Microsoft forces some Windows systems to switch to Windows 10 by silently downloading Windows 10 https://www.theguardian.com/technology/2015/sep/11/microsoft...
This forced "upgrade" had adverse effects on some users with poor connectivity. https://www.theregister.co.uk/2016/06/03/windows_10_upgrade_...
Once the switch to Windows 10 was accepted there was no way out https://www.theregister.co.uk/2016/06/01/windows_10_nagware_...
Windows 10 is quite nasty for many reasons all of which boil down to being nonfree, proprietary software. For example, it by default sent core dumps to Microsoft or whatever organization Microsoft chooses. http://betanews.com/2016/11/24/microsoft-shares-windows-10-t...
Windows 10 ignores users' so-called "security" settings putting a fine point on how insecure they are. https://www.eff.org/deeplinks/2016/08/windows-10-microsoft-b... and https://archive.fo/2ey80
https://www.gnu.org/proprietary/malware-microsoft.html is filled with more references to still more stories of how Windows runs against user's security interests and control over their own computer.
So when the Privacy Company "recommends admins of the enterprise version of Office ProPlus in the Netherlands (although many of them should also be applicable to other countries) [...] Apply the new zero-exhaust settings" there is no reason to believe that one gains privacy from Microsoft in so doing. Ultimately one's control over proprietary software only goes so far as the proprietor will allow. This remains true notwithstanding user's requirements or willingness to investigate and implement whatever the computer owner wants changed.
Microsoft is merely illustrating the inherent and unjust control over one's computer proprietary software has. It is this power that is at the heart of what's so wrong with these recommendations, nothing to do with a relatively minor quibble over whether one set of users has different requirements for privacy or security than other users.
People are going to look at their bottom line and decide this money-grabbing maximal-ism just makes them greedy, unconscionable bastards.
Of course, that's never stopped their juggernaut, before.
For my part, watching this behavior, I'm all the more convinced that de facto UEFI control and the like need to be ripped away from them. They will exploit anything. The problem is, who can and will serve as a neutral steward -- of implementations and not just theory and maybe design?
You'd have to do something insane like IP whitelisting only for services you care about, hope that none of them use MS services like Azure, disable Windows Update entirely, etc.
It might be possible in the abstract sense of "right now nothing is getting out" but they have root on your box, it's closed source proprietary software, and you've basically broken the OS with this firewalling anyway.
You need to be able to trust them.
The fact that you're running Windows means you are potentially already compromised.
Therefore, Glasswire/Little Snitch-type firewalls are being used, where you get an alert during connect() time, and you can create the rule on the spot. Windows Firewall cannot do that, and neither can UIs built on top of it, like TinyWall.
1/ it's not novice friendly (your best suggestion thus far required users to input dozens off lines of code into cmd.exe)
2/ it's defaults still allow Windows telemetry to get through (which was the exact thing the GP was trying to protect against)
3/ it's a pain in the arse to keep updated compared to any of the other suggestions made in this thread.
If the only option was Windows firewall or nothing, then I'd suggest people go with a PiHole since it takes an equal amount of technical know how to get the initial set up done. But at least once PiHole is set up, it's self managing (unlike Windows firewall) and will have much saner defaults too.
Thankfully though, there are other software firewalls for Windows that address the limitations I've described above. I've named one, another poster has listed a few others. If the option is software firewall or nothing, then I'd strongly recommend that user go with a third party one instead of relying solely on Windows firewall.
Just create a rule that denies internet access for the telemetry service. It can be configured by GUI and script.
Anyways the OP was asking if there are any tools available to the basic user to deny internet access for these telemtry services and there is the inbuilt Windows Firewall. I even found a script [0] that does what the OP is looking for. I‘m not sure if it‘s up to date though. All the information needed to update the script is published in the public documentation provided by Microsoft though. Thanks to GDPR you have extensive documentation on all things telemtry related to Windows 10 and Microsoft Office. For most users setting their telemetry settings to basic should suffice.
[0] https://winaero.com/blog/stop-windows-10-spying-on-you-using...
You're assuming that Zone Alarm et al wouldn't also contain sane defaults ;)
> Anyways the OP was asking if there are any tools available to the basic user to deny internet access for these [telemetry] services
To which I offered one possible solution
> and there is the inbuilt Windows Firewall.
Windows firewall is not novice friendly though. This is why -and at risk of repeating myself- I suggested a 3rd party solution that was designed specifically for home users who might not be technical rather than suggesting Windows firewall.
Contrary to what you seem to assume, I was aware of the existence of Windows firewall before your post however I wanted to suggest something that I felt might be more accessible for non-techies.
> I even found a script [0] that does what the OP is looking for. I‘m not sure if it‘s up to date though. All the information needed to update the script is published in the public documentation provided by Microsoft though. Thanks to GDPR you have extensive documentation on all things [telemetry] related to Windows 10 and Microsoft Office. For most users setting their telemetry settings to basic should suffice.
At least now you're finally starting to contribute something to the question rather than dismantling anyone else who was trying to help :) However your "novice friendly" suggestion requires manual steps to be kept updated - which have to be manually researched - and is installed via dozens of lines of code into cmd.exe. I think you and I have very different ideas about just how capable the average novice is. While I do actually prefer your solution from a technology ideology, it's definitely more of a power-user solution than something I'd expect novices to do. However at least the GP now has two solutions he can choose from.
> You're assuming that Zone Alarm et al wouldn't also contain sane defaults ;)
I worked with third party firewalls and that is the case. They also are most of the time really similar to the Windows default.
My point is the Windows Firewall is a really good product. It's easy to understand for a normal user since it basically asks if you trust the network when you join it. This means no technical knowledge is needed for a sane configuration. Most normal users I know are overwhelmed by the Pop-Up they get when the Windows Firewall asks them if they want to allow Internet access for a unknown application.
The problem is there is no good solution to avoid the collection of telemetry data for the basic Windows user. But this is not a problem with Windows, this is a problem with most software in the year 2018. Since telemetry is everywhere and it's used more and more. If a basic Windows User is really privacy conscious they should jsut configure the settings at the first login (I think they are easy enough to understand and you can disable most of the data collection there) or get a professional help them setup their system.
Edit: The following link provides information about the data collected by Windows: https://docs.microsoft.com/en-us/windows/privacy/
The issue is Microsoft still send telemetry data even with those default configurations. After all, if it didn't, we wouldn't be needing this discussion in the first place because telemetry wouldn't then be a thing on Windows. Thus you're suggestion here doesn't address the question the GP has asked for.
> Most normal users I know are overwhelmed by the Pop-Up they get when the Windows Firewall asks them if they want to allow Internet access for a unknown application.
That is probably quite true. There's is no perfect solution. But asking a normal user to input stuff in the command line and then manually keep those lists up to date is definitely NOT easier than clicking a pop up. So your point about the difficulty of pop ups here is moot considering you've failed to provide a better alternative that does protect the user against Windows telemetry.
> The problem is there is no good solution to avoid the collection of telemetry data for the basic Windows user. But this is not a problem with Windows, this is a problem with most software in the year 2018.
I'd say it's totally a problem with Windows considering Microsoft haven't just ignored the problem but instead actively contributed to it. Thus now we don't just need to monitor 3rd party application to ensure they behave; we need to monitor what the OS itself is doing (and thus we cannot trust Microsoft's own default firewall rules any longer). So yes, you have a partial point that no good solution exists for novices but I think Windows does deserve a large part of the blame now given it's complicit in the problem.
How can Windows be used in such an environment if the data collection can’t be stopped?
At my work we are considering moving to the cloud with exchange and other services. I will make sure these articles will certainly be topic at next meeting
I think that would be a very helpful bit to surface before a solid judgement call can be made. Anyone with more info?
I feel like this sentence is phrased maliciously. The adjective "personal" is applied to the more generic term data, rather than the more specific term behavior.
By placing the adjective on data, it encourages the reader to imagine the worst possible scenario. By simply moving the adjective you can more accurately describe what Microsoft is doing and avoid allowing the reader's imagination to run wild.
> Microsoft collects and stores data about the personal behavior of individual users
You could also remove the adjective entirely because the term individual has the same implication. This makes it sound even more innocuous.
> Microsoft collects and stores data about the behavior of individual users
Personal behavior is a more specific classification like "user scratches his butt every morning" or "user picks nose".
In the context of Office Applications it's going to be even more specific things like "user always tries to click on URLs in emails before CTRL+clicking them."
I think that's a large part of the reason they don't stand up to the EU.
That really isn't that huge anymore, and it's definitely not growing that fast.
I don't think you want to make a consumer argument because consumers buy expensive stuff everywhere.
There are also larger and more growing consumer markets.
The better argument would IMHO probably be "They need to sell business products and to businesses there, and the EU businesses are spending more than elsewhere".
IE it's a concentration of business wealth.
That is also likely to change over time.
As an EU citizen, my response to "we're sorry not sorry but due to recent EU laws, we can't continue to offer you this service" is: get bent, go home. I hope we, as the software development community can finally understand and appreciate that the insane proliferation of personal data modern tech has become dependent upon is a Bad Thing.
There are many ways to achieve that goal. I am not buying the argument that automatic data collection about everything you do is there to "improve our software".
The kind of cash that Silicon Valley corps can throw around could be a serious shot in the arm for Eurosceptic political parties hoping to weaken or separate from the union.
But, for example, the number of consumers they represent is only about half a billion.
That isn't that many.
For example, Latin America has 20% more consumers.
Most could totally could afford to ignore the EU if they wanted to and still have a perfectly good business.
(This assumes their goal is not all out growth but instead are happy with sustained profit at some point)
The telemetry can't be completely anonymous. It's attached to an IP address and the EU considers that PII: https://www.enterprisetimes.co.uk/2016/10/20/ecj-rules-ip-ad....
Disclaimer: I used to work for Microsoft, and this is what we did.
For a longer explanation, see my post about the &aip=1 feature in Google Analytics that does the same thing to the end of the IP.
https://code.visualstudio.com/docs/supporting/faq#_how-to-di...
And the relevant HN thread:
I've updated my settings
These people make a VSCode build without M$ telemetry/tracking enabled.
"I don't trust my daughter to spend my money wisely. Here, daughter, have some money."
Addendum: Check our Google Analytics, Hotjar, and Facebook ad targeting if you _really_ want to see “violation of privacy”. In reality, companies want to know how users use their products to make them better.
How about, "Because it's none of their fucking business."
Microsoft has clearly gone all-in on the SV surveillance-capitalism model of doing business, and this is exactly what motivated their acquisition of GitHub imho.
When I run into a problem, I will opt in as necessary (usually through the process of providing a stack trace / core dump / diagnostics data as requested). Outside of that, my usage habits are my business and my business alone.
Nobody needs to know how, when, or why I'm using anything without my explicit permission.
Vim/Emacs don't collect telemetry on what I'm doing, both are still great (both included to avoid the holy war).
EDIT: Or rather, why should I have to justify my desire for privacy? Why do I have to setup a series of DMZs, proxies, firewalls, or total disconnection, in order to retain that?
Right down to a thinly veiled character for Microsoft & Bill Gates.
Migel de Icaza even has a cameo.
See "Antitrust" https://www.imdb.com/title/tt0218817/
Do you care if I stand behind you taking notes about how you use the tool in your work? I promise I won't write down your name in my notes. I just want to know how you use my tool in your work. For research purposes. It's not a "violation of privacy"; I wouldn't take notes on what you're working on - I just want to know exactly how you use my tool in your work. I'll even be careful to not get in your way ("most" of the time). I just want to know how you use my tool so I can make it better.
If I did this to you without explicit prior-authorization from you (such as a contract describing what I'm authorized to do), would you allow it? Would you order me to get off your property? Would you call the police to have me arrested for trespassing and possibly corporate espionage?
Making tools out of software instead of steel doesn't grant permission to using someone's property without their explicit permission. Also, unauthorized use of private property is still unauthorized even if your goals are useful. Other companies doing the same bad behavior doesn't justify that behavior; trespassing is still trespassing even when a lot of people are doing it.
What if they send the data contained in the text files that I open with that text editor? There's partially passwords and such in the files that I edit.
If I knew exactly that all they send is the average size of the files I edit or similar data, I would actually have no problem at all. But Microsoft has proven a lot of times already that what they consider perfectly acceptable telemetry is not in the slightest the same as what I consider acceptable. So, even with something as innocuous as text editor telemetry, I can't trust them to not fuck up and for some reason collect data that I consider sensitive anyways.
No. Not at all. There’s no technical reason which drives such a demand. A big, fat no.
But it can help making the company hosting the site money. By selling your data to others. And that’s another question entirely.
I would like to see laws requiring transparency in telemetry, though. Require all telemetry to be in plain text, and auditable by 3rd-party software (say, by antivirus/privacy software).