Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.
Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.
It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.
your spidey sense is telling you what you need to know, you just won’t say it
Any user-facing names obviously get reviewed by the whole departments that are dedicated to ensuring it fits with the brand, translates well into all languages, not offensive to anyone, etc.
For identifiers that are not expected to be user facing, they're likely to get code review, simple profanity filters, and certificate policy checks, plus whatever bikeshedding those particular dev+ops+networking teams want to have about it. For a service endpoint that's really only resolved in the guts of client code, I could easily imagine an individual dev just using an arbitrary name for the prototype, and then eventually finding that the service became useful and that it's just not worth updating all the existing clients for a cosmetic change mostly no one sees.
Also, you hear conversations like "so-and-so registered that name years ago for idea X, but that didn't really go anywhere, so we can just repurpose that since we know that it's both already working and unused".
So I wouldn't read any particular motivation into 'microsft.com'.
It also randomly creates a new service matching the name of an old service + a random changing hexadecimal suffix, and I apparently have Skype running on my gaming rig. As is, I don't consider Windows a defensible platform.
I have the feeling that everyone just keeps slapping features, services and more telemetry onto Win 10 left and right with little coordination. Would be funny if some government agency just told Microsoft "now give us a complete list of all telemetry" - I would be surprised if MS could do it (with any reasonable confidence that the list is actually complete).
[1] https://support.microsoft.com/en-us/help/4023057/update-to-w... [2] https://answers.microsoft.com/en-us/windows/forum/windows_10...
...and they didn't even bother to check that there's an existing project of that name (which will only serve to scare those who come across it by searching --- the description begins "Platform for moderated remote access"...): https://github.com/rempl/rempl
It also randomly creates a new service matching the name of an old service + a random changing hexadecimal suffix
That is extremely disturbing. It's like MS is following in the lead of malware persistence techniques.
There's also this:
https://www.askvg.com/what-are-sedsvc-exe-sedlauncher-exe-fi...
"Hardens the servicing stack against admin tampering." Yes, they're fighting against you, the owner. As the exclamation goes, "fucking bastards!"
All this aggression is going to do is drive even more users who are forced into using Windows 10 to turn off updates completely. They were already wary, now they'll have lost their trust completely.
I did that 6 months ago best thing I ever did to win 10 so far.
I don't understand this type of argument.
EDIT: Seems like there are a lot *.microsoft.com URLs, too, so disregard this theory.
However, I've been observing Microsoft since the Windows 2.0 era, and I can't completely discard the possibility that Microsoft actually would use 8.3 domain names. Using 8.3 names "for legacy compatibility" in unusual places is something they've done before.
p.s. Further proof that history's written by the victors, from that 8.3 wiki page:
"An 8.3 filename...is a filename convention used by old versions of DOS and versions of Microsoft Windows...Similar 8.3 file naming schemes have also existed on earlier CP/M, TRS-80, Atari, and some Data General and [DEC] minicomputer operating systems."
"Similar naming schemes also existed"! A strange way of saying "DOS copied CP/M's drive letter + colon + 8.3 filename exactly". ..and everything else.
(Disclosure: I grew up on CP/M)
Just like MacOS has UNIX API under it and so does Linux as they were based on Unix standards.
hehe come on, DOS was a quick copy/imitation of CP/M. That seems a funny way of describing it, dignifying what was a knock-off job. As if accused forgers or plagiarists were to say "Huh? I'm building on the standards of the earlier work."
I mean, fair enough (initially), Gates did try first to give the IBM gig to Kildall.
It was created in 1996, so likely not. Although that expiration date is interesting...
Domain Name: MICROSFT.COM Registrar: MARKMONITOR INC. Sponsoring Registrar IANA ID: 292 Whois Server: whois.markmonitor.com Referral URL: http://www.markmonitor.com Name Server: NS1.MSFT.NET Name Server: NS2.MSFT.NET Name Server: NS3.MSFT.NET Name Server: NS4.MSFT.NET Status: clientDeleteProhibited https://www.icann.org/epp#clientDeleteProhibited Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited Status: clientUpdateProhibited https://www.icann.org/epp#clientUpdateProhibited Updated Date: 31-jul-2015 Creation Date: 02-sep-1996 Expiration Date: 01-sep-2016
Updated Date: 2018-07-31T09:30:41Z
Creation Date: 1996-09-02T04:00:00Z
Registry Expiry Date: 2019-09-01T04:00:00Z
its right there with spynet2.microsoft.com and spynetalt.microsoft.com ;). Plus you have to remember W10 spy^^telemetry switches to hardcoded IPs if DNS fails.
Do we have a definitive list somewhere? I'd like to block them and add them to my script [0]
[0] https://gitlab.com/moviuro/moviuro.bin/blob/master/blackhole
It is owned by Microsoft, registered by MarkMonitor (MarkMonitor is a legit company)
Although alpha.telemetry.microsoft.com doesn't currently exist either, others do, e.g. us.vortex-win.data.microsoft.com resolves to a Microsoft-owned IP address.
It's a mistake in the report.