Microsoft is phoning home the content of PowerPoint slides
rogermexico.bearblog.dev
rogermexico.bearblog.dev
Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, and allow inspection of the actual traffic.
What Adobe CC, Google Chrome, MS Office, and macOS/Windows itself do with this background network connectivity is completely out of control and abusive to the user. They get away with it because the vast majority of users are non-technical and don't realize it's happening.
I've profiled and decrypted the background traffic on a stock Android install and the volume was also appalling. Getting macOS to 0 background traffic involved blackholing large Apple IP blocks at the router, whereas some of their processes use random IPs from these ranges and don't use DNS.
Just as the general public doesn't have the awareness or ability to fight for their privacy rights I doubt any of this will ever be remedied.
https://github.com/evilsocket/opensnitch
I still recall the old days of Windows when I tried Kerio Personal Firewall and realized how much software already phoned home two decades ago. That was the last wake up call that pushed me into getting rid of closed source software, possibly also hardware, especially when they connect to the internet.
https://linux.die.net/man/8/iptables
--pid-owner processid
Matches if the packet was created by a process with the given process id.
But was disappointed by the note:> NOTE: pid, sid and command matching are broken on SMP
But does it have any sense? Usually you block inbound connections, allowing only certain services. If a rogue process starts listening on a local port, you could display a warning alert, and as inbound connections are already blocked you'd be safe (as long as you trust netfilter...) and you wouldn't need to ask the user to perform an action.
To get around the slowdowns, I made an alternative program called picosnitch which only monitors connections since I just stop using anything I don't trust or move it to a sandbox. It also uses BPF, has fairly low CPU usage, and some other features for improved reliability and detection of programs.
> Keep in mind, simplewall is not a control UI over Windows Firewall, and does not interact in any level with Windows Firewall.
> It works over Windows Filtering Platform (WFP) which is a set of API and system services that provide a platform for creating network filtering applications. Windows Filtering Platform is a development technology and not a firewall itself, but simplewall is the tool that uses this technology.
No:
"simplewall is not a control UI over Windows Firewall, and does not interact in any level with Windows Firewall"
It's a long time since I looked, but I think some apps (mainly ones not using native APIs) only showed the hostname, rather than full URL/API endpoint path.
This also didn't show you the content, or method type (POST vs GET), but to do that you'd really need to start doing proper SSL inspection as you suggested.
Yes, I know that's not completely true. I _could_ use Linux (I even used Solaris on a notebook for 2 years in the past and I survived) but the cost in terms of effort, lost productivity would be higher than I'm ready to pay. It's a rational choice.
Also someone told me here that LS should be considered harmful.
The implications of this are unclear. I like blowing these claims out of proportion, but in reality we genuinely have no idea what this means. It could simply signal that Apple is complicit with benign cloud-storage security procedures enforced by the USA. It could also mean that the US has carte-blanche access to iCloud data and decryption keys. You're free to draw your own conclusions, but the surrounding context seems to imply that Apple has an under-the-table relationship with our government (as does most of the tech industry, surprise surprise).
Oh, and I don't really know/care if LS is harmful. You should be aware that it's not going to outsmart Apple if they want to collect your info, though. They have kernel-level networking access, which companies like Microsoft have abused in the past to collect telemetry on crafty users. It's probably not harmful, per-se, but your perception of it as an impassible wall might be.
Then any program that is not run inside the namespace with configured virtual network interfaces can see only unconfigured interfaces, so it will not be able to open and connect sockets.
The Internet browser and any other program that needs network access, e.g. a NTP server, DHCP client, e-mail client etc., can be run inside the namespace with an IP-configured network interface.
The same could be done in FreeBSD by using a jail for the programs that need network access.
Obviously, this would not be enough to prevent network access for a program that would be aware of this configuration and would try to circumvent it, because such a program could list the network namespaces and try to execute itself, or another helping program, inside the network namespace. For complete isolation, all the programs for which network access is not desired would have to be executed inside a distinct namespace. That requires a more complex configuration.
If you want to you can do that with Linux.
Sure you'd need to use the CLI, and a combination of tools but you can pinpoint every packet to an associated process and if you add your self made cert to trusted certs, then you can decrypt TLS as well in most cases.
For this to work well, all your apps need to run with not being able to do their own TLS, but to various (reasonable) reasons a lot of applications today do their own TLS.
You also don't want to add self-signed certificates, but grab the traffic _before_ it gets encrypted IMHO.
In some cases it's still quite viable, like if they dynamic link to OpenSSL (or similar) you could create a facade which allows grabbing traffic.
But things get problematic when it's statically compiled in and not open source.
Additionally there are quite a bunch of use-cases where the encryption is not TLS, like e.g. with some WebRTC applications it's not uncommon to have an encrypted channel we could access to a broker server but in that channel E2E encrypted messages are send e.g. using libsodium statically compiled in.
that would be ideal but self signed + added to trusted store works
> Additionally there are quite a bunch of use-cases where the encryption is not TLS, like e.g. with some WebRTC applications it's not uncommon to have an encrypted channel we could access to a broker server but in that channel E2E encrypted messages are send e.g. using libsodium statically compiled in.
yeah youre right.
In other cases the only options we have are ld_preload to catch encryption lib. If that doesnt work we can still use ptrace to capture syscalls but encryption will be done in userspace so capturing network activity wont help us with encryption.
Like the other guy said, the info we can gather is still useful.
Reverse engineering + modyfing the binary is a possibility too but it gets complicated fast, especially if they intentionally try to protect it. I feel this isnt really an issue with jvm or interpreted langauges but with the others its hard especially if theyre statically linked. C/C++ have good enough decompilers that its still possible, I don't know about Go/Rust tho.
It is not impossible but it is far from easy. If the application uses statically linked SSL client (as it should if it is commercially distributed) then you have to modify the application (for example in memory) to get a copy of everything that gets written to the SSL stream.
What I want is Little Snitch on steroids built
into the OS where every process,
You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people.The real answer IMHO is to control your networking stack outside of your computer instead. Firewall that and you have way better security
Multiply that by all the multibillion dollar other companies, the tens of thousand open source focused smaller and large companies, the hobbyists, the enthusiasts, the CS professors, the CS undergrad and grad students, the PHD candidates who would be thrilled to discover a flaw on the basis of which they could write their thesis, etc. and I think one can have a fair degree of confidence.
There’s still a decent chance something would be missed. But it’s much smaller than the chance that the proprietary OS owners, whom we know for a fact phone home and have been trying to collect increasing amounts of data, are sending stuff we may not know about.
To prevent standard data leaking or rather stealing like in this case, linux is a quite solid choice.
But if you think you are a high profile target, you should probably learn how to deactivate Intels ME and co.
And if you are really paranoid, you should assume that there are hardware backdoors. But what do you do then? Build your computer from scratch?
... with a compiler you wrote yourself. In assem-- uh, in hexade... no. With toggle switches.
You may instead want to look at the bootstrapping work done using stage0, m2-planet, GNU Mes, etc.
https://bootstrapping.miraheze.org/wiki/Stage0
https://guix.gnu.org/manual/en/html_node/Reduced-Binary-Seed...
It starts with a hex monitor of less than 500 bytes and bootstraps all the way up to gcc, all from source.
Just like PayPal. There's a table you can bring up that lists everyone you ever engaged with on paypal for recurring pricing, and deactivate them.
I've wanted exactly what you describe for years. Little Snitch taught me that there's just too much data that isn't organized properly. Even if you get down to the app level (like PowerPoint), it is still transceiving a lot of data. How do you tell what is necessary and what is dubious telemetry?
I'm not sure of that. Provided you can add a cert to your OS, you should be able to get away with a piece of protocol downgrade network gear that you can then pipe to a different (ideally, offline other than UDP receive) computer for analysis.
You'd need to disable HSTS, but other than that I think it should be the solution you're looking for. Oh, and for good measure, ethernet cable instead of wifi.
Of course for obvious reasons, few commercial apps would actually use this API unless they have some other incentive.
In TLS, the client authenticates server, then they both agree to use a key for the session; the OS can get a hold of this key (this is usually a bad move because then any captured traffic frames could be later decrypted).
At some point phoning home was a sin for software. Sadly that changed, also because of the naivete of some developers.
Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall https://news.ycombinator.com/item?id=33481518
Disclaimer: I'm the CTO.
Why not set the Windows computer's gateway to a computer that the user can properly control, i.e., do not give the Windows computer direct access to the internet.
Windows is an OS that was created before the public had access to the internet.
It worked just fine "offline", i.e., connected to a LAN but not an internet.
Same for the Mac.
To be honest, I cannot think of many PowerPoints that needed internet access, at least not in the fields I have worked in.
Obviously, "tech" companies want personal computers to be online for every waking moment of their owner's day. Neverthless it is in fact possible to "block", i.e., not assent to, much of this outgoing transfer of personal data/metadata to "tech" companies at the user's expense. I have been doing it for over 20 years. With few exceptions, I inspect all HTTPS traffic that I allow over the networks I control. The "tech" companies gathering this data do not pay for the user's internet or cellular service. The user covers the cost of the data transfer.
Change begins with the people who know how to make it. For example, it is not difficult to stop PowerPoint from phoning home. Why go along with it. But when those with the requisite knowledge year after year make statements on HN how it is futile to thwart any personal data mining because it is not 100% "perfect" solution,^1 I have been seeing these comments on HN for many years, then it is arguable this becomes a self-fulfilling prophecy.
The "majority of people", "general public", etc., do not know they have a choice. They will use whatever is presented to them. What happens when those who do know there is a choice go along with what "tech" companies present to them. They are in no position to blame "the majority".
Certainly, those working at or investing in "tech" companies would welcome a lax attitude toward avoiding data collection. "Nothing is going to change because no one cares." Tell that to Zuckerberg after Apple prsented its customers with the means to "block" some of Facebook's data collection.
https://www.cnbc.com/2022/02/02/facebook-says-apple-ios-priv...
1. All-or-nothing, black-and-white, binary style reasoning.
I tend to just mitm said talkative devices and drop packets -- it is alarming the amount they want to phone home.
(Lessons have already been learned of course)
I don't think adding technical layers to block these data leaks is going to work long term.
What if you didn’t use PowerPoint?
Seems much simpler.
Also, maybe the data makes PowerPoint good? Or better?
Alternatives to PowerPoint: won’t all of the viable ones be hosted on the web?
What do you want? You can install PowerPoint 97. No one is stopping you.
Microsoft's OS.
It would be asking Microsoft's OS to tell it about traffic Microsoft's software wants to keep secret.
I'm sure there's a world where that isn't a laugh line, but I certainly don't live there.
For example there have been numerous claims made previously that link ANY network traffic to a supposed invasion of privacy, but once you delve into the underlying traffic it isn't nearly as nefarious as it initially seemed.
This article is telling you to "open up the network monitor of your choice" but network traffic and CONTENT are apples Vs. oranges, and yet we're meant to draw conclusions from that? We're meant to know Microsoft are taking your slide's content whole-hog? Isn't that yet to be determined?
The Microsoft website says it "analyses your data": https://learn.microsoft.com/en-us/deployoffice/privacy/conne...
That being said, I don't doubt that they do :)
Would it just be encoded and Wireshark could decode it out of the box?
Enterprise data security on the "MS Office level" at this point is like driving 60 mph on a road with no lane dividers. You just pray that you never meet a drunk driver or someone texting in oncoming traffic who suddenly swerves into your lane. You pray that none of your employees click the wrong button and bankrupt the company.
The entire Department of Defense runs on PowerPoint, along with all of their contractors. It is not at all uncommon to produce slide decks that are either classified or covered by ITAR; this is a disaster waiting to happen.
I work in healthcare, and the legal department bars me from using Google Analytics for HIPAA reasons.
Meanwhile, IT made Chrome the only browser the employees are allowed to use on every Windows machine in the org.
Windows 10 has only made the problem worse. The last desktop PC I got from my company's IT department had windows 10 on it and it was configured to send every last keypress to MS. Why they had the Windows 10 keylogger enabled I'll never understand, but at least it was easy enough to disable.
What this means is that healthcare providers have annual audits performed by third parties who check compliance with these "best practices" which may or may not have any relation to what the lawmakers intended. Its ultimately about checking boxes. yada yada security is hard. You can't write a law that describes a security posture and expect to be relevant for more than a year at most.
That’s somewhat funny, because a Landesstraße in Germany has no lane dividers and the speed limit is 100 km/h (about 60 mp/h).
Unless I’m misunderstanding and lane dividers mean the printed lines.
Also, only about 70% have no speed limit. https://en.wikipedia.org/wiki/Autobahn (ctrl+f "No speed limit" for a nice table)
In compare, on the Autobahn, which always has dividers but often has no speed limit at all and is not below 100 km/h under normal circumstances there were "only" 318 deaths.
Source (German language, Federal Statistical Office): https://www-genesis.destatis.de/genesis/online?operation=abr...
In many cases the roads are also used by cyclists or agricultural vehicles which many drivers feel compelled to overtake, which can be dangerous because of limited vision and the need to switch onto a lane that may contain oncoming traffic.
Compared to the Autobahn, Landstraßen are chaotic and often dangerous, not just for the people driving on it.
Also 744 < 606 + 318 so it doesn't even seem to be "more than half" even with some road types missing.
I do wonder how many of those accidents are related to cars overtaking others.
Well, we also have plenty of really narrow roads on the countryside, with no lane divider, no printed lines and - no speed limit, where you could do 100 km/h, as well.
(And well, some people do, but if you crash, it would be also legally your fault, for not having the adequate speed, even if there is no formal speed limit. Which is a nice counterexample to the usual, everything is forbidden unless it is explicitely allowed mentality)
My point is that your only "defense" against oncoming drivers on such roads is to pray that they stay in their own lane. This mostly works because people are mostly sober and undistracted and not malicious. It is kind of terrifying when you start to think about it.
Edit: As was pointed out elsewhere, the phoning home stuff can be turned off at org level. So MS will not be affected by any fallout of potential export control violations.
I bet that is less than .01% of all power points created in the world
This is not a useless feature. I can imagine it might help someone make a better presentation. We have to weigh the potential privacy implications against that.
And asking the user to consent for every little thing isn't the solution either. It's so annoying to be pin-pricked by dialogs. At work, this sorta thing should be decided at the organization level, by setting appropriate fine-grained org policies for Office.
> there's a difference between the data being nigh-impossible for internal employees to access (perhaps only used as input for other automated systems), and data with few controls.
A Chinese software vendor could do as much as sending your keystrokes for autocomplete you bet it will be front page news on Reddit and here with every comment reminding me about Xinjiang and 1989.
But Microsoft could upload the entirety of your hard drive and we would find apologists like OP rationalizing away the behavior.
I’m not convinced either governments are not in kahoots with private companies.
By which you mean that we have plenty of evidence that both are?
Yes? It’s not like it’s a double standard or remotely hypocritical to hold a US corporation or the US government to different standards than a Chinese counterpart.
This seems like less of a "precision" issue and more of a "transparency and accountability" issue. Do you know how long this information is stored by Microsoft? Where it is stored? Who has access? What the process is for requesting that data is deleted or even for opting-out of it's collection? An opt-in prompt is a great place for organizations to provide access to resources that answer these questions.
When we don't have the answers to the questions, (or don't trust the organization providing the answers to be truthful), we should assume the worst case, not the best as you seem to be implying.
> And asking the user to consent for every little thing isn't the solution either.
Prompts/permission can have varying and nested levels of granularity. This is absolutely not an excuse for not providing opt-in for data collection. (Edit: E.G. You can simply ask "Allow Us to Collect Data: Always, Never, Sometimes" and then you only need to show additional prompts if they select "Sometimes". If you are seeing to many people saying "Never" then you can do a better job of explaining the benefits/features, but you can't just ethically ignore the wishes of the user.)
I see no problem with organizations pre-deciding this for their employees, (thus no need for a prompt), but this doesn't remove the need for individuals and members of less organized organizations to have the ability to not have their data collected.
Source: I have this blocked and I'm not missing anything.
If a feature needs to phone home, I don't need the feature.
Yes, it helps Microsoft, and it helps The Powers That Be advance their goal of total information awareness to maximize their security and power and be unaccountable. As a bonus, the harm it does to users is hard to see and hard to reason about, so the genuine proponents and their useful-idiot accomplices throughout the tech (and political) world have been very weakly opposed in advancing the pervasive surveillance agenda.
https://support.microsoft.com/en-us/office/create-profession...
Who knows though? They provide so little information and I have no particular reason to trust them without some kind of evidence. I'm flagging this article since all we can do is speculate.
>Fire up PowerPoint. Turn off all the cloud options.
What happened to computers being just fun and a source of exploration and freedom?
Microsoft, Gooogle, Apple all constantly push their cloud based accounts … where everything is tracked.
Having this experience isn't any harder than it was in the old days, it's just that there are so many more people participating in computing in some form that it's harder to find the people who truly own their computing experience.
The companies that made "personal computing" easy enough for the masses want to profit off of that, and they've settled on strip mining data and robbing user control as the best way to make money. This leaves their mass-marketed version of "personal computing" a hollow shell of the original, but it doesn't remove the original.
You can still install a privacy-friendly Linux or BSD with only FOSS software. You can still self-host your data and retain full control and privacy. What you can't do is benefit from the ease of use that mass-market computing provides while still retaining full individual control.
https://www.nytimes.com/2021/05/17/technology/apple-china-ce...
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
Apple shares with the CCP for all users by default.
This is antithetical to Apple's privacy branding.
Atlassian should have better bet on their Server solutions, but they really really wanted to be a cloud operator. “For strategic reasons.” Maybe for governmental reasons, who knows.
Write the source code in some Assembler language (or even binary code ;-) ). Or use some obscure programming language that the vendor cannot scan, thus having a reason not to upload it.
Given the barn storming financial performance of other cloud operators and Atlassian's impressive record in (un)reliability, I think investors are quite aware that converting people to the cloud is going swimmingly most places that aren't Atlassian.
Why do you think they are going so hard on the Semantic Web shit? It's not for the disabled - it's for the blind, deaf and dumb AI that needs the entire content of the web to train on.
Yet, this plays into people’s own confirmation biases so it’s already being taken verbatim by people here.
Just because one could say a company has done controversial things before doesn't mean there's no benefit in verifying claims.
https://news.ycombinator.com/item?id=33509159
There’s an expression, paraphrased as “when someone tells you who they are, believe them.”
But it's not because there aren't sufficient consequences. Memory leaks don't properly crash the company as they should.
Typically, companies just worry about about liability leaks. Which they take seriously enough to dedicate a lot of lawyer time to plugging redundantly with innocuously vague disclosure wording, terms of service wording, difficult to find and inconvenient to use opt-out tools, etc.
I suspect you mean data leaks, in the context of your comment. But memory leaks should be a thing of the past also - they hint at the quality of the underlying code.
Chrome:
Settings > Sync and Google Services > Make searches and browsing better
Edge:
Settings > Privacy, Search and services > Personalize your web experience
It may be glitchy in some areas, but I've been using it since graduating high school, and I can do whatever I want with it.
I cannot believe this, in particular for the comparison Excel vs. LibreOfice Calc: the latter is used insanely actively in the finance and insurance industries, thus any proper user sampling should bias towards these industries. On the other hand: users in these industries know Excel really well and use very advanced features of it.
I suspect anything more advanced than this would be better worth implementing as a script, rather than using Excel.
The main arguments for Excel, that I suspect, would be better collaboration features (like comments and sharing and such), and better integration with other MS tools (Outlook etc.).
But even then, perhaps a script or Jupyter Notebook would be easier to work with (for diffs and version control that are not vendor-locked).
1: the export to docx had problems, and most publications require your submissions to be in docx format;
2: it gets laggy with large documents. This lag becomes distracting when writing novels. Seems to start around page 20-50 and gets worse and worse as you go.
I wish I had better alternatives to suggest.
I wish that publishers would stop demanding we submit our files in docx format.
There will be a learning curve but I find my attention stays on the content, as I'm not continually distracted by the format issues that are better delayed until the text is complete.
You'll want a reasonable text editor with spell checker, preferably one that knows to ignore formatting commands. Note you will end up with PDF output - if you really have to submit docx, my condolences!
LO Writer can export to PDF when you need to preserve formatting. But if it needs to also be editable, I guess ODT is the only way. Maybe in light of the recent events you can convince your publishers.
About performance, you might want to give AbiWord a try also.
I'm on linux desktop now and this lets me read and write MS office files and works quite well.
I've seen people vehemently argue that merely checking if a new version is available amounts to horrible invasive unethical tracking. You might want to turn that off for the truly paranoid situations, and that's fair, but it's of course completely different than "sends all your data".
I don't have a Windows machine and I certainly don't have PowerPoint, so I can't actually check anything myself. But I see a lot of confirmation biasing going on in this thread, and I bet most people didn't check anything either. All I can give this article is a shrug.
Hahaha, I've been there. And in an open-source code base, no less! We were using a closed-source library to actually send the version data up to the telemetry service we were using, but the payload and how we were handing it to that library were clearly defined in our own source. We even had to request a correction to a major IT news outlet because they had some vague language about "and no one could possibly know what kind of telemetry $BigCorp is sending, and it can't even be disabled". Both were demonstrably false: the payload was visible in OSS, and we had a well-documented env variable that you could use to disable the version telemetry before you first start of the application (which was linked from the graphical installers as well).
In this case, I think the entire content payload is probably being sent up--if you've ever used this PowerPoint feature, it's clear that they're suggesting icons and themes based on the words in your slide--but there's a clear as day prompt explaining what's going on when you first enable the feature.
I'd _prefer_, of course, that Microsoft figure out how to bring the model onto the device so you _don't_ have to go off-box. Google managed to pull this off with the Now Playing feature on their newer Pixel devices[1]. But it is really hard, and I do somewhat understand the business aspect of "that's our secret sauce, we don't want to give it away".
[1] https://www.androidpolice.com/if-your-pixel-cant-tell-what-s...
Producing more evidence is left as an exercise at this point.
Edit: no more posts allowed for me. Reply below:
That’s exactly what telemetry is, today. Grammarly built a whole business on this. Copilot, etc.
Refusing to believe that times have changed because you’ve not been paying attention, is not a compelling argument.
And to reply to your reply:
> That’s exactly what telemetry is
The common understanding of telemetry is sending metadata about how people are using software. That is, things like "this button was clicked", "this feature was used", etc. That is my understanding of the word anyway.
Either way, this is a bit of a boring semantic discussion; my point is just that there is nuance to these things, and that this article doesn't really tell us anything concrete beyond "the network is used". Well, okay ... but for what, exactly? Because that does matter.
[1] https://learn.microsoft.com/en-us/deployoffice/privacy/manag...
[0]: https://support.microsoft.com/en-us/office/linkedin-in-micro...
> Did we consent to this?
Yes, unless Microsoft doesn't ask for consent in whatever country the author is from. There's a consent popup that you need to click through that informs you that the content of your slides are shared with Microsoft. This is part of "intelligent services" in case you're looking for the details.
The author should be able to turn this feature off easily, but yes, they did consent to this. They just might have done so months ago and forgotten about it.
Find out more about the "intelligent services" that also send the contents of your document to the cloud if you click on their respective buttons here: https://learn.microsoft.com/en-us/deployoffice/privacy/conne...
For example, here is the description of the first type of such experiences:
> Connected experiences that analyze your content
> Connected experiences that analyze your content are experiences that use your Office content to provide you with design recommendations, editing suggestions, data insights, and similar features. For example, PowerPoint Designer or Translator.
> The following table provides a list of connected experiences that analyze your content and also provides links to more information about them.
They are going to quite long lengths to avoid mentioning where the data is analyzed.
I think it's safe to say that nobody reads consent popups and just clicks okay to make the magical prompts disappear but there's only so much you can do when you offer online stuff in your offline program. I don't think it's reasonable to expect three or four popups that say "are you really really really sure?" before enabling such a feature, especially since everything is probably being synced to Onedrive anyway.
Furthermore, the target audience of the page I've linked isn't general end users, it's for administrators managing company wide Office installs. I don't have Office installed so I don't have the exact link the prompts try to direct you to, but there's probably a better privacy page that you can find from within an Office install.
Another prompt ends in "Office will use your searches and document content to support and improve the Intelligent Services to you."
The individual popups seem to follow a simple "what is it, what are some examples of it, what are you consenting to" structure. Any less details and you have no idea what you're agreeing to, any more details and you'll quickly lose people in the "EULA too long" problem.
I disagree that agreeing is the only way people will get their work done. There are many ways to translate text and the "let me design a PowerPoint for you" feature is nothing more than a nice to have. There are plenty of offline themes to choose from and individual themes to download without ever enabling this setting.
This is despite both the Privacy -> "Turn on Optional connected experiences" and "Automatically show me design ideas" options being modifiable by me (and give the same results whether enabled or not), so I guess the Group Policy options are more fine grained.
Looks like these instrucitons should help you check:
https://learn.microsoft.com/en-us/deployoffice/privacy/optio...
Please use wireshark or something else to explain what those packages are. It might be downloading design features or some other data it requires.
100 word article really doesn't do it for me.
I hope this submission is flagged and removed. Just because you don't like Microsoft doesn't mean such misrepresentation is okay.
I don't think we know the motivation of the submitter and we should not assume any motivation beyond introducing the link to the community to consider and discuss the content.
The article is very brief and seems to highlight that the designer suggestion needs to submit your slide content to make the suggestion. The question as to whether we consented suggests that we have (through the usual click through), but, to me, it is really asking something like 'do we understand the implications of our decision to consent?'.
I don't see anything being misrepresented nor do I infer there is some sort of anti-Microsoft (nor anti-anyone/anything) in the article. It does seem to suggest there is something for people to consider in that we often 'consent' without really thinking through the outcomes of what is supposed to be our willing, informed consent.
Too often we split into binary extremes when we should really take time to be thoughtful and considerate of questions being posed and where that consideration takes us and helps us to find insights and opportunities to improve ourselves. I encourage people to not automatically jump to our 'team position' (whatever that is).
https://support.microsoft.com/en-us/topic/53c77d7b-dc40-45c2...
Considering it has to be explicitly enabled and includes a privacy policy, I’m going to say it’s “blatantly obvious” to the user.
Now, is it a glaring red pop-up? No. But IT department's can also choose to disable the feature if they don't want their company to use it.
I suppose it could/should be more obvious/explicit on the Designer pane itself, something like "This is an online feature that uses Microsoft's servers to generate recommendations", or a more user-friendly language.
Note however that the article is light on details; does it send a full content of slides? Some hash of text and images? A non-identifiable abstraction of layers involved? This could be done well or poorly.
(I don't think the submission should be flagged FWIW, but I agree that it's not of good enough quality to deserve great ranking; but that's of course subjective:)
I also believe it can be managed by policy.
MS FTE here, I have no direct awareness of how the feature works and am not affiiliated with Office - but I'm sad that something meant to _help_ people (if this raises hackles, I don't want to see what the OP says about the accessibility checks) is used to bludgeon my colleagues publicly.
We don't really know yet if your data/powerpoint content is sent to Microsoft, or if Powerpoint just goes out and looks for layouts, fonts, etc. without communicating any of your text.
This is a pretty huge exaggeration here. Closed rooms exists and are used when appropriate.
And just because something is enabled in the consumer version by default does not imply it's enabled and available in enterprise settings. Last time I dug through the office GPO templates - basically every phone home feature was easily disabled on an org level if desired.
Further - what do you think something like Google Slides is doing with your data? It's ALL stored on Google's servers by default.
If this claim was posted as a HN comment without citation or further explanation it would likely get flagged, why are submissions held to a LOWER standard?
I don't have a link to that exchange handy, but this for the first time drove home to me the realization that we have a whole generation of people brought up on Internet streaming services, who may not even realize that it's not only possible for the media to be stored locally on their machines, but it's in fact the natural state for data.
That being said, I still think theres more work to do, and arguably the hardest work is ahead.
and your dangerous general purpose legacy hardware will not save you from that, as it will be impossible to access the internet with a device that doesn't disclose your identity. to combat disinformation and hate speech, of course.
you vill ovn nothing, und you vill be happy.
and prove the software that's supposed to be running is running.
> The first time you try out Designer, it may ask your permission to get design ideas for you. If you want to use Designer, select Turn on.
https://support.microsoft.com/en-us/topic/53c77d7b-dc40-45c2...
I wonder when that is? Because I haven’t used PP yet, and it didn’t ask me. Of course, we use Office 365, and maybe my boss turned it on globally?
Does anyone know where the setting is?
That seems the salient issue today with regards to children and social media. Most of the giant social media companies profit from participants who cannot legally enrol.
Even if you think Microsoft doesn't have kill switches, it still isn't obligated to do business with them.
This could be as "simple" as Microsoft phoning home with the layout of the data (bullets vs title vs paragraph of text) combined with perhaps hash codes of any topical features (things that indicate technology vs food).
I've never been "surprised" by the feature the way I am with Github Copilot where it sometimes feels like it's reading my mind. The Designer is just a simple way to click a button and get back 5+ recommendations on how you can layout the data.
Without some kind of evidence, my explanation is just as valid as the blog. That which can be asserted without evidence can be dismissed without evidence.
Paint: having Admin rights when you can find it since Windows 95
It appears that MS is using our data to continuously train their large DL networks to provide these recommendations...so what is to prevent a bad actor from cunningly constructing an asset that may trick the recommender into leaking insights from another company (or possibly poisoning the network itself)? These adversarial attacks have been well documented in academia.
Oh, look. We don't need enter Jenkins account. Everything auto populates. And we did not even map it yet...
I did. I guess the author didn't read the T&Cs.
Trying to call people out for not doing so or not understanding the technological reason why data is sent doesn't seem productive.
When I tell Windows-centric tech people that these days, they can't wrap their brains around it. There is no institutional memory of Microsoft's dumpster fire days.
Which it's not going to happen anytime soon, so PowerPoint can literally be a bomb inside their organizations they'll still insist in using it.
If these phone-home allegations are true it's one more case where you spend $50K in an hightech driveway gate but have no fence around the property.
Yes, explicitly, and not in 60 pages of legalese, in a dialog box.
Microsoft is basically the editor of a set of tools designed to make employees more productive. As long as you use Microsoft products with this in mind, there's no ambiguity: you give Microsoft the data you work on, and it gives you productivity in return.
Unless you are the actual CEO of a company involved in trade secrets (or a defense organization), you shouldn't care about Microsoft snitching the content of your slides, and everything else you write or see, to its own servers on the justification that it will make your experience better.
It's not worth entering the debate, and if you accuse Microsoft you will probably need to accuse its competitors.
Just remember to keep out of anything Microsoft when you process anything strictly personal, and you will be more than fine.
P.s.: I almost forgot to answer your question. Yes, you approved this. And again, if it's not your company, your boss very likely approved it and wouldn't even consider the effort of looking into this, so it's not your business. Literally.
It's a pattern of general disrespect for user privacy and exploitation of unaware users for corporate and 3rd party entity benefit. Look no further than Microsoft's Copilot, which is in the spotlight, and arguably has no respect for users copyright.
That PowerPoint (and other Office products) are phoning home users data, should be of no surprise whatsoever.
Check out the developer panel to see for yourself.
Windows store downloads are accompanied by mouse trackers, keyloggers, and more.
Does it beam home? Yes Do I like it? No
We have LibreOffice for decades. Be the change.
What would Microsoft be doing with the text of every PowerPoint presentation once they have analysed the style/font/content information?
Must be thousands of slides per hour 24/7 for years. How long is this information kept?
https://www.avantixlearning.ca/microsoft-powerpoint/how-to-s...