Windows OS, Services and Apps: Network Connection Target Hosts (2021)
helgeklein.com
helgeklein.com
I personally prefer Linux, but what’s holding me are the streaming services (netflix, amazon, etc), I can only watch SD content if I’m on Linux, so my second opinion is macOS, I can watch at least in a decent resolution and also their notebooks are the best ones out there (the air is amazing between price, performance and battery life) for my use case, that’s also work.
Yes but then these turn off, drop the content you were watching with little/no warning and are unreliable. Buy physical media while you can at least then you have a licence to watch it when you please until the media degrades. (Or better in the territories which allow for backing up across media formats)
It used to be bearable back in the day, but now software has gotten so bloated that compiling it all constantly is just ridiculous... especially on older, slower systems.
Also, I don't know about you but I don't want to waste my time writing init scripts for every application I run that needs them. I'd much rather just use a distro that has already written them for me.
I hadn't noticed. Wife's 43" TV is connected to a linux box with firefox that is used for Amazon Prime, Netflix AND Disney+.
I haven't noticed poor picture and assumed it ran at 1096x1080. I will certainly have to check this out.
Could it be that you are using Plex, Kodi or similar that might allows you to stream at a good quality?
Correct, see my reply to myself upthread.
I can't really say that it has made a difference to my enjoyment of the shows I watched[1]. It is something to keep in mind for if we ever replace that TV with a 60" one.
[1]I just now compared a FHD download of "My Name Is Earl" to the SD Disney+ version and did not see a stark enough difference to switch away from Linux.
It was cool to go to someone's house who had a big TV, but now everybody has a big, high-res TV. Most people aren't even utilizing the resolution their TVs are capable of.
Just like most people are fine with a Sonos speaker or soundbar (IMO, they sound like any other crappy integrated speaker), most people would probably not care above 1080p.
I've used Linux desktop in the past and it looks like things haven't changed much. I don't like the idea of having to compile kernel modules just to get my machine to work (and then having to do it on each distro upgrade) - I have better things to do with my time.
Also, if you use a modern distro instead of, say, gentoo, you don't have to compile anything yourself, there's packages and dkms available if you really have to go with broadcom. Do you not install drivers on Windows?
To give a concrete recommendation for a wifi adapter, look at Intel-based hardware. Intel stuff generally works out of the box because they contribute drivers to the Linux kernel directly. The ASUS PCe-AXE58BT is based on Intel's AX200 so should work out of the box on any modern Linux distro.
You basically never have to compile kernel modules anymore. Even if compilation is necessary, DKMS-based packages mean that the recompilation is done when you install your package updates, so you don't need to think about it.
It's the chipset that you would need to ensure compatibility with, unfortunately I can't find anything concrete on the actual chipset used, Intel only has 3 wifi 6E chipsets and as far as I can tell (from here https://venzux.com/intel-ax411-vs-ax211-vs-ax210-wi-fi-6e-mo...) they should all be compatible with Linux.
In the end is the compromises you are willing to make. For development Linux is way better IMO, even gaming now really good with DXVK (Steam Proton)
One extremely important aspect of Linux support is that once it happens, it stays there virtually forever: there's no such thing as declaring a product obsolete so that users are forced to migrate to the newer version. This applies to software too; WINE allows Linux users to run perfectly good Windows software that stopped working on native Windows ages ago forcing Windows users to shell out a lot of money.
Bitwig (which has an Ableton-like interface, and was made by Ableton developers) is also available for Linux.
Can be a bit of a pain migrating from windows though if you have loads of previous projects, all expecting to find a specific vst in a specific place. Thats why I'm dual booting windows for now.
There is a weird “wildvine” plugin thing that chrome and Firefox use for video drm for some services. I think that enables video.
Linux seems to be the only OS that is respectful of the user.
But desktop Linux has come really far. It my daily driver on my home machine and I’m switching to it at work (or cluster is Linux anyway). I’m hardly a sys admin type and it’s been working great for me the past few years. Even steam works on Linux now.
Regardless, I use firefox and Amazon, Disney+, Netflix, HBO Max all work reliably for me. I believe there was a period were a couple of them didn't work for a month or two on linux when they came out but I wasn't subscribed to them then and they've always worked for me.
I can also have gorgeous font rendering. I would mess around with some live distros to see what you prefer.
This is how my comment looks to me (on linux): https://i.imgur.com/wvruFyX.png
If you look at those screenshots on a 4K display they're incredibly blurry because all you're looking at is your browser doing image scaling optimized for photographs.
I guess font rendering is very subjective.
And if you're looking at those other screenshots on a 4K display then you need to also zoom to 50% and get your eyes close the the display, otherwise you're just seeing the results of an image scaling algorithm, which will indeed look terrible.
Here is Fedora/KDE/Flatpak/Firefox with default settings at 4K resolution and 100% browser zoom for comparison:
https://i.imgur.com/s3ynhuj.png
Also with my preferred browser zoom: https://i.imgur.com/9PXDbxY.png
For the above images you'll need to zoom 50% on a 4K display, because PNG image files do not carry pixel density metadata. If you have 1080p display then you have to keep 100% zoom and sit far away instead.
edit: your second screenshot looks very sharp and nice on my display.
See: https://johankj.github.io/devicePixelRatio/
If you see more than 1 at 100% zoom you have resolution scaling. Try browser zooming to 50% or 200%.
I look at the original commenters screenshot at 50% browser scaling but it's still blurry. I guess there is an element of image compression there.
On the other hand; from my own experience (I own linux, macos and windows pcs) on the same display Macos text rendering is much more sharper and pleasant to look at.
I mean with fractional scaling where 1 < devicePixelRation < 2 you're doing it wrong and everything will look bad anyway, so I just assumed integer scaling. And 4K @100% is unusable anyway.
But more to the point you can't easily display those screenshots with different fractional scaling without pixel grid misalignment.
> On the other hand; from my own experience (I own linux, macos and windows pcs) on the same display Macos text rendering is much more sharper and pleasant to look at.
On hires displays (devicePixelRatio >= 2) you're probably just comparing default fonts. And on lowres display (devicePixelRatio = 1) OSX is much much worse than Windows's Cleartype, it's not even a contest.
Linux was always able to be as good as Windows on lowres displays, just was held back by patents, so the Freetype defaults used to suck, and you had to configure it yourself for the full effect.
Idk if it's any better nowadays, 4K display are so cheap and ubiquitous that I really don't get why anyone would buy anything else, except I guess gamers. But with all those AI scaling technologies (FSR 2.0 etc.) hopefully 1440p is on the way out.
That depends on the physical display size and viewing distance.
If you need more working space there's always 5K. That's 1440p@2x. You can even DIY one for pretty cheap. I know there's at least one 3:2 4K display on the market as well, though I wish there was a 24" version.
That's a distinction that doesn't have to exist. If you don't insist on maximizing all windows, a single large monitor gives you more flexibility that multiple monitors with the same total screen area. E.g. for many applications 1080p is too wide to be effectively be used by a single window but too narrow to have two windows side by side. Dividing a 4K or screen by 3 is much better and also allows you to freely choose the window sizes. Some basic tiling support in your WM (either automatic or via shortcuts) is recommended ofc.
I use a 38" 3840x1600 monitor (= about 110 DPI) at 100% scaling and it works just fine for me at normal sitting distance. That's the same horizontal resolution as 4K and I don't think the missing 560 pixel rows would make much difference to how I would use it.
Apple's "retina 4K" LG Ultrafine 4K Display is actually 4096x2304 at this size, which is much higher density at 218.58 PPI.
This is as good as macOS' rendering as I've ever seen on any other machine, and I'm really fastidious about my fonts. It's really easy to achieve:
1. Install Fedora
2. In GNOME Tweaks, disable font hinting. Looks good only on HiDPI screens, this is why it's not default. If you're not on Fedora, change all fonts to Noto because they're much higher quality.
3. Optional: copy the Windows and macOS fonts to avoid the crappy "lookalike" replacements. The screenshot above uses Verdana straight from a Windows 10 installation, which is exactly what's requested by HN's stylesheet.
What's your distro?
Fontconfig is working fine but Verdana is a Microsoft font and Geneva is a Apple font.
My font fallback for sans-serif is DejaVu Serif.
You're right about trying different distros. Manjaro+Gnome does much better IMO: https://i.imgur.com/kiLDWzJ.png
Perhaps there's a component of how the LCD is presenting it involved? to me my font is extremely uniform and sharp with no bleeding or blurring.
What tweaks do you have? I used to run X11 and ran the gamut of x11 based font rendering tweaks (example of how my old machine looked: https://i.imgur.com/J9biJsW.png )
But with sway/wayland I have much less ability to change things.
Additionally, for ages Linux had shipped with Full hinting, which means distorting the font so straight lines are always on integer pixel boundaries, which looks atrocious. These days distros like Fedora use Light hinting, which is a little better, and in my opinion No hinting looks best, which is what macOS does, but on a low DPI screen means having blurry font. So on low DPI screens you have the choice between distorted but clean fonts, or undistorted blurry fonts.
I don't know about sway, in my case I'm using Fedora with 2x scaling, so I have the option of disabling hinting and avoiding distortion.
What's interesting is the MBP handles external displays horribly with the current version of OS X. Lid closure is a crap shoot on what the device decides to do.
Fonts on my main Linux "workstation" may not be as perfect as on the M1 Mac I use from the couch but it's because my 38" monitor ain't retina and it's a far cry from making "browsing uncomfortable".
Yes, many of the CSS stacks (even for the big sites which really should know better) are totally broken when it comes to Linux (they don't list enough fonts that various distro will have by default, they list fonts that many distro will not have by default and unsurprisingly end up defaulting to shitty fonts) and as soon as one site started using that one CSS stack, they all started the copy/pasta. But I wouldn't go as far as saying that browsing on Linux is "uncomfortable": many people do that on a daily basis and are perfectly happy.
Also not all websites have broken CSS font stacks for Linux. Some saw the light.
Yes.
> my 38" monitor ain't retina … perfectly happy
Put another way, either you are not visually discerning or your bar is lower.
// Since “FHD” laptops, and monitors <4K, are still a thing, you are not alone.
You're all shifting the goalpost.
Nobody is saying that fonts on a retina display on OS X do not look better than fonts on a non-retina display on Linux.
What we're disputing is that fonts rendering on Linux is so bad that it's "uncomfortable".
Now we may have a discussion as to whether everybody should be using retina display or not but that'd be another topic.
I do not expect a non-retina display to display fonts as beautifully as a retina display, just to make things clear.
What I'm saying is that fonts under Linux aren't bad to the point of being uncomfortable.
And just to make it clear: I've got Windows and Linux, on non-retina displays, showing the same sites. Linux ain't worse.
There's a big difference between saying: "Retina displays are better than non retina ones" and saying: "Linux font sucks".
Yup: not everyone is on 4K / retina display. We know that. It doesn't make font rendering on Linux broken.
But I suspect you bringing it up, and me responding to it, doesn’t make either position more authoritative. And given “I’ve written more books than I can count” it could be your discernment of numbers or bar for objectively counting things is lower. ;-)
About retina vs. non retina, I’d argue font rendering algos matter more the less resolution they’re working with, so are even more important on non-retina displays. I’d further argue MacOS regressed on this by killing off sub-pixel rendering in Mojave, effectively dropping support for non-retina.
On low quality displays, Windows and Linux could/should look better than MacOS. When they don’t, they’re “doing it wrong”.
(In particular, I get color banding and inconsistent weights in Windows, especially with thin fonts.)
The thing with the linux community, is that once linux covers 90% of the perceived use-cases for a desktop/laptop/workstation computer, it really feels like it should be enough to see a big switch. We can relax, right? But that 10% of use cases where windows is the /only/ option is the other 90%.
Sounds like you have a good reason to get content from third-party sources that don't saddle you with annoying BS.
And honestly, I won't boot my PC from Linux (at home or work) because I'm afraid it will break. I'll explain: I have some VMs with Ubuntu and, from time to time, I hit some problem that made the system unrecoverable. For instance, filesystem breaking or not mounting, I also remember Nvidia drivers updates that generated a black login screen (1), or strange error messages showing up before seeing the Ubuntu login screen (that I wonder myself what should I do with them?).
Not to mention the times my SSH connections to development servers don't work, and I have to physically go there and reset the PCs.
I don't want to be twiddling with my main PC, which puts food on my family table. The fear of coming to work (or from work at home) and turning on my PC just to find out that some partition isn't mounting, my printer is not working anymore or some other problem that would take me an hour to fix... is too much of a risk for me and my mental health.
On the functional side... there are some things that I can't understand... It's been years already and I cannot control the scroll speed of the mouse wheel in Ubuntu without hacking with the xinput system. What does that tell me?
And why asking my password every 5 minutes? I always said: if you want to remember a phrase, use it as your Ubuntu password. You'll be asked for it for every little thing and in a couple of hours you will remember the phrase forever.
https://askubuntu.com/questions/1129516/black-screen-at-boot...
PS: I love-hate Ubuntu, and I am not saying that these things don't happen on Windows, but from personal experience, Windows is much more stable since like the past 10 years.
And I am a menacingly wild-user. I put my systems through a lot! I do a lot of full-stack development, arduino(and other iot stuff) coding, blender work (3d), inkscape, gimp, a lot of audacity for audio, a lot of kdenLive for video-editing..
and my laptops (although always being mediocore in spec) never broke a sweat. And I have never ever had to 'format' my PC cuz I'm locked out of it.
So, maybe, it's you who doesn't understand how to use the system. Maybe!
It is possible that you are 100% right. But I also believe your answer (or that kind of answer) is part of the general problem.
I have to say that I'm totally capable of fixing those issues since I do it all the time for Android (which I debug and customize). The problem is: I don't want to. Not on my main PC.
On the other side, what am I possibly doing wrong to generate those problems? I install Qt, Firefox, Thunderbird, Git, build-essentials. I never hibernate, I always do a clean shutdown and... that's it...
The "Ubuntu has experienced an internal error..." dialog box still appears from time to time
It's not unknown for Windows updates to break systems either, and when you do have serious problems on Windows there's a limited amount of things you can do because the system is so opaque.
At least on *nix you (or expert users helping you) can dive in to the source to figure out what's happening. With Windows you can be left at the mercy of waiting for Microsoft or whatever closed-source software you're depending on for a fix.
Windows 7 was rock stable. Indeed, it was W10 that caused me this kind of headache a few times - just updated itself overnight and blue screened. No way to recover even with their recovery tools. Still have no clue what was wrong with it.
Oh and it still to this day starts hibernating randomly on my ZBooks, with the event log saying it is caused by a CPU overheat event.
First of all, it was not overheating.
Second, Windows or any other OS should never handle these events, it was always and should always be handled at a hardware/firmware level.
Also, hibernating when overheating? Lol, yeah, that's very helpful. Good luck doing that when the processor is actually overheating.
On that note, Microsoft Answers is the most useless website/service in existence and I don't know why they even bother keeping it up.
Hybernating or thermal throttling?
Thermal throttling is done on the hardware level and can happen while using any operating system, including Linux.
https://docs.microsoft.com/en-us/windows-hardware/drivers/br...
It just hibernates. Passive or active cooling setting, disabled thermal controls in group policy or not, registry tweaks or not. Tried everything.
It just hibernates, middle of work or not. At least it doesn't shut down ¯\_(ツ)_/¯.
I'd say upon reaching ~60-70 degrees on the CPU, but it does it at idle (<50degC) too, so it seems more random than anything. Once, it stopped when I had a Kali Linux VM with a USB Wifi adapter passed through to it (only difference at the time) running. Worked for a few days, then it started doing it regardless.
People with some Dell and Lenovo laptops also have this problem, and it seems so rare that the most common answer is "lol, it's overheating dumdum, thank Microsoft or it would break".
Only surefire solution is to restore from backup.
If it did that under Linux, at least I could easily tell it to ignore everything and let the hardware handle it.
Also rm -rf being instant is a big win (I know it probably isn't under the hood but I don't care, as a user I can get on with my day).
Also another nice suprise - I can get photos off my iPhone without it screwing up. Not possible on Windows. I can get the original DCIM images in the weird iPhone format (which is perfectly viewable in Linux too) and I can access all the hidden files to the extend iPhone makes them avilable.
I am really liking the experience. I am not into 'hacking' and just want it to get out the way and make it easy for me to install stuff and use it, so I go with Ubuntu.
Oh it actually is. It's just that Windows is dog slow at handling files (as opposed to their contents), for a multitude of reasons (I understand that there actually has been a little bit of work in recent years on some of these issues to improve performance for WSL and git).
a lot of commercial software just doesn't have support for linux.
for regular use and a lot of my personal programming, I use linux, but it just isn't feasible to be 100% depending what you need
What's holding them up besides laziness?
And Netflix exclusives regularly make it to pirate sites in 4K afaik?
Yes, generally the day of release.
No 4K versions of most shows from the last month.
This is why you can't screenshot Netflix on Windows/Apple - the region where the video is will be black.
Not disagreeing with you, just pointing out their faulty reasoning.
I'm not sure if I should be more irritated with Netflix, who can't be bothered to maintain backwards compatibility with not-that-old browsers, or Apple, who can't be bothered to get newer versions of Safari to work on older Mac hardware. Both companies are displaying a total disregard for paying customers who just don't happen to have the latest expensive hardware.
The small cost of dealing with $ms_bullshit_du_jour is a periodical { 1. sigh, 2. find & run some PowerShell snippet to uninstall or disable the bullshit, 3. be done with it till next time } sequence, but the large benefit is the guarantee to be running games on the de-facto standard platform where they are end-to-end tested by the game devs/QA !
Games are complexity beasts by nature, and I have high fidelity & stability expectations; I don't want an extra source of trouble. (Yes, even if I would absolutely prefer to run games on Linux! All my other machines run Linux)! Until Steam{OS, Deck} gets enough usage to be routinely tested by 90% of the games shipping on Steam, both AAA & indies, for me Linux gaming is a case of "I would absolutely love to, but for now, thanks / no thanks" .
On the occasion where I _have_ to use it I don't set it to fullscreen, just have it as a floating app at whatever resolution I care for. Then I just deal with the lower real-estate for however much time I need to be using it.
Nearly all of my remote work is SSH or SSHfs-based now, which (if you're used to terminal stuff) is so much nicer than any equivalent I've found on Windows.
I was just on a developer group call the other day where another developer from another organization was having weird scaling issues RDPing into the vendor's sandbox. The solution was to adjust some buried registry setting on the remote machine, not fiddle with the local machine. Unfortunately I paid little attention to the details as I rarely RDP and when I do I can tolerate display issues.
I realize this is super vague, but it was so fresh in my brain I had to respond. Maybe someone who actually knows something can provide actual details.
And I personally like Windows as an operating system, NT is a very cool and well documented technology, and since WSL has been available it is also my favorite Linux desktop experience. For a while my main complaints where about the frustrating dev experience (mostly for web stuff, tooling often only consider a Unix environment), and the lack of package manager, but WSl + Windows Terminal + winget is just fantastic. And that's without talking about more niche things, such as the awesome Sysinternal Suite (so many hidden gem here!), the event system, powershell (looks ridiculous when you first read about it but it's such a ridiculously powerful shell once you discover that you can interact with .Net classes), Win32 APIs, etc.
(Edit: I say this as a relatively recent convert to Windows, I started with Mac OS classic, then OS X, then ArchLinux for years, so the majority of my experience has been with Unix environments)
Orwell got things slightly wrong in 1984; he never realized that we would be paying for the privilege of being spied on.
But I don't like that you have so much advertising in the default Windows and Edge experience and understand the general frustration regarding telemetry, not everybody can control their network the way I do just to have a reasonable experience...
Mayor nitpick: can you buy it, if you are not a big coorp?
I wouldn't know because I 'found it online' (if you know what I mean).
I vastly prefer Linux, but I need LINE (a messenger app popular in some Asia countries). Their Linux app (actually a Chrome extension) stopped getting new features 5 years ago. That's kinda THE deal-breaker for me.
Another minor reason is Dropbox Smart Sync. I can use Selective Sync, but having smart sync is of course better.
(I would rather Windows than macOS)
I occasionally need to do some development work in a Debian VM. I can't even remember the name of the window manager it came with; but I just can't figure it out. The equivalent of the dock / taskbar just isn't useful. I had to jump through hoops and hoops just to get Visual Studio Code to work, in part because it took awhile to figure out how to have root access to my own VM.
Now, I obviously could use a different window manager; but that leads to the real problem: It's just too much work for me to figure out how to use Linux, and find a setup that I like. And, after I do that, it's quite a bit of work to "keep up" with the Linux community and the changes. And, then it's quite a bit of work to ensure that I can find good, compatible hardware.
Finally: I'm very happy with Mac, and Windows 11 is "good enough" for me. I'd consider purchasing a laptop with a Linux-based distro pre-installed; but even then, that's a huge financial risk if I end up not liking it, or I hit compatibility issues. At least the Microsoft Surface has a 60-day return policy.
Which leads to my final point: I use a computer as a tool. Linux on the desktop isn't a tool, it's a hobby. I could see myself using Linux if I wanted to develop an alternate shell / UI as a hobby, or using Linux on the desktop if it was common in my profession.
No idea why VSCode doesn't work "out of the box" for you. Again, I can only assume you've picked some odd window manager, possibly a tiling one or something like that? Gnome and KDE "just work".
> Linux on the desktop isn't a tool, it's a hobby.
That's fine. My opinion, is the opposite to yours. My vanilla KDE install has been fine and I use my linux desktop as my day-to-day tool for writing production, revenue earning, code. I've been running KDE full time for over 4 years now with no problems (or rather fewer problems than I had with Windows and Apple, but YMMV).
This is the crux, really. I'm adept at server administration, and have used Linux there for decades, but on the desktop it is, from my POV, pretty much a dumpster fire of bad usability.
Had Apple not gone to OS X 20 years ago, I suspect desktop Linux would be materially further along, but with a well-designed and well-supported commercial *nix OS in the market that ships married to bespoke hardware, there's materially less motivation to make desktop Linux better for people who won't want to have to tinker to make things work.
Jokes aside:
> Had Apple not gone to OS X 20 years ago, I suspect desktop Linux would be materially further along, but with a well-designed and well-supported commercial *nix OS in the market that ships married to bespoke hardware, there's materially less motivation to make desktop Linux better for people who won't want to have to tinker to make things work.
Aren't Android and ChromeOS linux-based?
ChromeOS is, I guess, but how much of a true desktop OS is it vs. a front-end for Google? (Not trolling; I honestly don't know because I don't use any Google products, so it's never been on my radar.)
I would not choose operating system based on this. Instead, if you can afford, you could buy for example Apple TV as separate box which is not too expensive, has great quality for video and audio. But I guess there might be a chance that you want to watch on higher quality on other places than your home as well. For that, I have personally just used Windows sandbox.
I mean, in a perfect world, sure. But it's not always an option.
Sorry to go off topic, but can anyone expand on this? I don't use MacOS but have been thinking about it, I always thought they were a significant improvement over windows (even if not quite as good as linux)
Currently Linux has reached a state where I could tolerate most of the things I hate about it and would be willing to do so to be rid of Microsoft's bullshit, except for the following: VR in Linux is a garbage fire, DCS is hit and miss, and my 1080ti will likely be an endless source of problems.
The one thing I keep Windows for is gaming. More specifically for game streaming. Steam Link works okay (and is cross platform), but I haven't seen anything as performant and meets my needs as much as Nvidia Gamestream (Windows-only for server-side streaming). I use Moonlight to connect to it. I haven't found any alternatives that work as well that are also available for Linux.
I wish there were a game streaming application (open source preferably) as performant as Gamestream that worked as well on Linux.
$ curl -fsSL 'https://helgeklein.com/blog/windows-os-services-apps-network-connection-target-hosts/' | pup 'td:nth-child(5)' text{} | sed 's/:.*$//' | sort -u | wc -l
291
$ curl -fsSL 'https://helgeklein.com/blog/windows-os-services-apps-network-connection-target-hosts/' | pup 'td:nth-child(4)' text{} | awk '{ s += $1 } END { print s }'
2764
There’s also a fair amount of infrastructural stuff such as DigiCert’s OCSP service, and every shard(?) in the Windows Update, OneDrive, etc. CDNs is counted as a separate hostname.Not that I’m happy about of any of these connections, but the report looks much less interesting than the totals alone suggest.
A weakness of the OCSP protocol is that it gets sent the certificate hash as an input. This means that to a significant degree, an OCSP provider can track what software you are using, what sites you visit, etc... For the code signing certificates, they could also determine which year (or two) it came from.
DigiCert could sell that to marketing companies, and spy agencies / state-sponsored hacking groups could use it to determine if you are running vulnerable versions of software they have hacks for.
There would be ways to fix the protocol to be less vulnerable to this, but I'm sure you'll find that any such suggestion would be rejected by the major players like DigiCert in a strangely forceful manner.
On the bright side, with the ca/browser forum limiting the max length of a certificate to about a year it would be pretty easy to just use a single revocation list. A CRL 2.0 so to say. Just like the browser downloads the Google safe browsing list.
EDIT: Just to be clear; With CRL 2.0 I don't mean blockchain...
OCSP stapling helps maintain privacy, so eg. ESNI isn’t completely pointless when stapling is used.
It's not obvious to me. Why can't it be done over HTTPS? From what I can tell nothing stops you from doing that.
To me it seems simple to just skip an OSCP check compared to having to use HTTP.
If it is I'm going to use this way more in all the compliance meetings I attend. Oh, you're worried about the secrecy of all this proprietary private information we're holding? Don't worry, I'll just wrap it in a torrent, broadcast it to the DHT, and _now_ it's no longer private, so the secrecy doesn't matter.
Now if this exists, why aren't people switching to this? Google. Chrome doesn't even actively validate revocation information anymore, and Android didn't even bothered to do many of the required validation since practically its inception (so much that Let's Encrypt exploited that fact to allow their CA to still issue valid certificates to older Android devices: https://letsencrypt.org/2020/12/21/extending-android-compati...). Since Google insists that revocation is broken (as demonstrated though it can be fixed now if we want to) no-one (at least at a corporate level) is seriously pushing OCSP must-staple.
P.S. you should at least read GRC's post about CRLSets (the only mechanism available in Chrome) that was posted in 2014 a few days after the Heartbleed discovery (https://www.grc.com/revocation/crlsets.htm). It's still (unfortunately) relevant today, amd says a lot about Google's security practices.
I could believe that, actually. There are reasons you might want to always host different services on non-overlapping IPs -- DDoS mitigation, traffic prioritization, service isolation, limiting impact of unscrupulous ISP / government content blocks...
Do you have a reason to doubt either the sincerity or technical ability of the Author? Did you find a fault in their methods?
I totally believe it, both from a load balancing perspective and from a stack perspective.
There was a version of Mac OS were different applications used different resolvers so, for instance, changing /etc/hosts would redirect SOME services/browsers to the IP in /etc/hosts and other services/browsers would still use DNS. I've had similar issues manually setting the DNS server address where some services ignored the setting if they could resolve against Apple's favoured DNS. This might still be true but I'm now longer doing security work and I'm not using these tricks anymore.
1) Why would relatively specific services need to contact so many different endpoints? The skype service is using about 40 different endpoints by the look of it. 2) Why can't the providers of these services use much more consistent naming? I am less concerned about pipe.skype.com and avatar.skype.com being called from skype because it makes sense. On the other hand, calling b-ring.msedge.net is weird. What is that site? Could be MS, could be anything. 3) It is not clear whether these services were expected to be enabled or not. For example, I don't like the idea that Windows is wasting internet bandwidth on Cortana or XBox live since I use neither of them.
I guess this is the price you pay for system where everything is possible.
You can make a case for all those things, of course. Just why does it have to launch into them all immediately upon startup? On a beefier machine it's probably not noticeable but it's sad to see on older PCs when Windows 10 at launch was quite reasonable when it came to lower specs.
I think what the main problem was they hadn't used it in a while and accumulated a backlog of mandatory Windows Updates. While these chugged away they got frustrated with an almost unresponsive computer, turned it off, install interrupted for the same thing to happen all over again. I can see how doing this stuff in the background makes sense as you don't necessarily want to bother the user with it, but when it impacts performance so badly maybe it's better to throw up the message and the progress bar. At least they know what's up!
You can use it to watch every process send network traffic, you can even collect samples of the traffic and plot it on a map: https://www.obdev.at/products/littlesnitch/index.html
(not affiliated, just a happy customer; it's one of the few things I like the mac ecosystem for.. there's attempts to port it to linux with https://github.com/evilsocket/opensnitch; but it's not as polished of course)
Concerning.
Thank you for fixing it, I can't edit the post now.
That happens whether or not you are logged into icloud/facetime/messages at the same time, or not.
Anyone aware of a way to figure out what nsurlesssiond is downloading/uploading in the background?
Note: this anecdote may no longer be current. I’m not sure what changes Apple might have made since I tested this.
The desktop appeared, and the system was connected to a dedicated wi-fi network for the purpose, DeviceUnderTest. 60 seconds or so of “no activity” simply staring at the desktop elapsed, and the system was rebooted, automatically reconnecting to the test network.
Wi-Fi was then disabled.
...
In this few minutes, the system generated 38 megabytes of network traffic.My main work-laptop, my server and work workstation are running Ubuntu (because of support, yadda yadda), but I've recently tried Arch linux on my personal laptop.
I'm not yet an Arch fanatic, and find the installation procedure particularly baroque (having to manually hunt down which firmware packages to install to get basic hardware like Wifi working, had to explicitly install a network-manager, or else no networking at all)...
But what I did find immensely refreshing, was working on a minimal system which only had the components I had asked for and nothing else. I knew why everything was there, and how it was supposed to work.
I'm really coming to appreciate that more and more, especially after a botched server-upgrade and having to wait for apt to reinstall 1000+ packages I have no idea if I need or not.
So yeah. Windows, Mac, Linux, or whatever. Keep it minimal, please :)
Some things get better over time like better graphics cards and 64 bit but MS wouldn't keep making money if they said, "yeah just keep Windows 98, it basically does everything you need". Instead they add fluff, search that no-one wants, messaging that not everyone uses etc.
Maybe they should do Windows Lite which would only include the desktop and windows update and nothing else. Sell it for $10 inc updates for the first year. You then pay a subscription if you care about more updates and nothing if you don't.
Espacially if this becomes state mendated for national security reasons. Indeed, have you seen anyone been sued for the PRISM program?
In fact, it's already happening: have you seen a lot of things modified in iOS lately? It's super hard, so few people even attempt now.
There's an unpatchable bootrom exploit in all devices up to and including the iPhone X. But yes, I agree with your sentiment.
Though one thing to keep in mind: phones and tablets are content-consumption devices and they have historically been locked down for about as long as they existed. Computers are productivity devices. You may want to multi-boot 10 different operating systems for very practical reasons and no one should prevent you from doing that. Manufacturers understand this. Even the Apple M1 is capable of booting arbitrary, unsigned OSes, despite being a direct descendant of the same line of locked-down SoCs used in iPhones and iPads.
https://en.wikipedia.org/wiki/Intel_Management_Engine#Assert...
It's in the EULA and privacy policies.
Change Windows Firewall settings to block outbound connections by default [0]
Install Unbound [1] so you can actually see the DNS requests (and block them if you want it) your system performs.
server:
verbosity: 1
extended-statistics: yes
logfile: "C:\Shares\Public\Progs\Unbound\unbound.log"
server:
log-queries: yes
log-replies: yes
log-servfail: yes
val-log-level: 2
[0] https://imgur.com/a/ayq5yiFPlus if you have a massive (>3MB) hosts file it causes other issues during bootup, which requiers disabling another service (dont remember which one off the top of my head, as I am using Pi-Hole these days)
This is not the way...
I am also not sure at what size the issue with the service appears.
I'm currently using Binisoft (now Malware Bytes) Windows Firewall Control to block unwanted traffic. I'm quite happy with it.
The amount of traffic that it regularly blocks is insane. Windows and installed apps constantly want to chat with their cloud friends.
Not at all.
It can be easily configured to block any host or path.
Someone else has some suggestions?
The issue is you can only control your firewall at home. Whenever you are out you are pretty sure that MS and Apple bypass any rule you'd put on the local firewall.
I prefer running sane operating systems.
For example an internal app starts up fine and works, but then can't connect to github. Instead of showing cert errors, I've had ones show errors that make it appear that you may have a DNS problem or that the connection to github itself was broken.
Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the service's startup type from 2 (auto) to 4 (disabled)).
In CIS, create a new group for all files under c:/windows.
Create a rule denying all in/out requests to that group.
Create a rule allowing only DHCP and NTP requests (255.255.255.255:67 and <whatever-timeserver-you-trust>:123) for svchost.exe (place that rule above the one for c:/windows to ensure precedence).
Use third-party utilities instead of the likes of ping.exe, e.g. hrping.
Refer to CIS documentation in case of any troubles.
Enjoy your privacy-hardened windows.
Of course you won't have access to some services in that case, like Windows Update, etc. One particular weird thing I have noticed is that the process that checks CRL on behalf on others is LSASS. So basically you have some extra tuning to do to get a system to your liking if using just the Windows Firewall, after you block everything but "Core Networking" (and programs you want to authorise), but it looks reasonable. I would suggest saving the initial state before you go that route, though.
If you trace connections you will find funny things, like cl.exe phoning home.
Yank your internet cord out and start windows.
That said, Linux is not an alternative for me; I use Office daily, OneDrive, and Xbox Game Pass for gaming.
With a dedicated community we could distribute the work of reverse-engineering the purpose of each of these connections and classify URL endpoints by that (Ads / impressions / telemetry can just get blocked immediately; the rest can be documented based on what functionality is disabled / broken by blocking).
It's not terrifying but it does reveal the scale, this isn't a licence check against something like genuine.microsoft.com this is a completely different scale all together
While MS does not help itself with some of the more invasive tactics, some of the telemetry is super valuable in detecting issues with drivers, updates and many other things.
Even the episode of MS08-067 https://darknetdiaries.com/episode/57/ has some interest bits on early telemetry.
Having a small number of hosts and smaller number of queries would likely result in a worse situation: queries would be impossible to filter because filtering 1 host would likely break too many things.
Also, in terms of telemetry, I consider Microsoft to be the disabled child in the classroom. I am sincerely convinced they have absolutely not the skills nor the vision to turn the data they collect into a process that could be personally harmful to me. Google and Apple, on the other side, specialize in employing engineers and product managers that have absolutely no concern to privacy. Their only constraint is to make sure whatever they do is lawful, which is, in my opinion, the worst way a company should behave. Until today, I haven't seen Microsoft do anything worrying except showing traces of telemetry collection in my router logs.
Never underestimate your enemy.
It may sound “insecure”, but if you can’t trust X509 without HTTPS, you effectively can’t trust either X509 or HTTPS.
This is why we have layers in software. We trust X509 because of fundamental math. Therefore we trust HTTPS built on X509. Therefore we trust systems built on HTTPS.
Everything is perfectly fine.
Be careful, though, it's easy to accidentally break Windows Update.
I have been using Linux systems from the past 10-15 years and they have been my daily driver for almost everything - and I live on my computer. Never have I faced any issue that can't easily be solved. (If at all there were issues)
Yesterday and it was terrible.
> Never have I faced any issue that can't easily be solved. (If at all there were issues)
Good luck viewing hdr content.
I'm not saying that people don't have good experiences with Linux desktops. I'm saying that those experiences are still nowhere near universal, especially when you start to involve people who aren't really power users. The most common desktop environments are still wildly inconsistent at best and frequently an accessibility nightmare at worst. Trying to work out whether a given piece of hardware will be well supported (or supported at all!) is difficult. Resolving package manager conflicts, handling non-free firmwares, building and managing kernel modules, these things are _not trivial_. That's before we've even addressed the software that people are often forced to give up. I use a Linux desktop frequently and there are papercuts _everywhere_.
I'm really not sure where this prevailing mentality that you can just install Linux and ride off into the sunset comes from.
IME there are always people who "get stuck" with their computer or end up in "nuke from orbit" situations.
Which doesn't mean others didn't have issues, huh? Also some people might have not specific knowledge to solve the issues.
You have revealed your point of view. However, for the great majority of Linux users, Linux on the desktop has been a reality for well over a decade.
2. Work in general (Office 365), and for software development "microsoft shops" although that is now more cultural with .NET5 running on Linux etc.
3. Games? (I am not a gamer)
It takes a bit of effort to switch to Linux, for most people's lives they are probably not aware of Linux, or even if they are don't see the point because Windows just works and does what they need.