The idea that the OS vendor can push telemetry that scans my computer, not even analyzing activity, but rummaging through my old files, is crazy.
They've taken what was originally a sort of okay idea, automated updates for security, and turned it into something absolutely nuts. I have a windows PC for the occasional game, and these days I feel like I have to treat it as defacto malware.
> This update is intended to help Microsoft identify the number of users running out-of-support (or soon to be out-of-support) versions of Office, including Office 2013, Office 2010, and Office 2007. This update will run one time silently without installing anything on the user's device.
Sorry, how can this be interpreted in any way other than Microsoft pushing an update who's only purpose is to scan my computer to collect data for them?
And Microsoft has 0 goodwill in this department after pushing updates that made ads start appearing in start menus. These aren't "fears as facts," it's pattern recognition.
Given how little control you have over it, is it your computer?
This is all in service of 365, which is an inferior product. So I understand the bad taste this leaves but it’s not really anything to worry about.
I don't think this is normal. It may be common, but I don't think it is normal. I find this deeply creepy for an OS vendor to think it's okay to push an update that collects data passively from machines. This isn't even collecting telemetry on active users. This is collecting telemetry on installed software.
I get that the Overton window in this shifted a long time ago, and in the tech community I'm in the minority, and especially on hacker news where so many people work for tech companies that track their users every way they can, but I am saying I find it deeply concerning that this sort of thing is a "run of the mill" telemetry update.
I'd go so far as to say this has antitrust implications. MS is using their dominance in one market (operating systems) to collect market data about another market (office software). Their competitors (Google, Zoho, etc) do not have the luxury to scan most of the world's computers on a whim to see what software is installed.
chrome://settings/cleanup>"This update will run one time silently without installing anything on the user's device,"
by definition not an update
This level of telemetry and inspection is beyond abhorrent: it underscores MS believes you are the product, you don't own or control your hardware, you will be forced towards buying more products, and you will be forced to deliver your most private thoughts and your attention on a plate for upload and mining.
Therefore anyone caring about privacy, including what files are on their machine, will not run Windows, period.
I agree, but I do run Windows. I do it for only one purpose: to ensure my software works there.
If my software works on Windows, and people adopt it, it's yet another piece of software that they could bring to Linux or another better platform. Think of it like using "Embrace, Extend, Extinguish" against Microsoft.
It's not. How Outlook 2010 was cut out from downloading outlook.com mail is concerning. I want to know what their next shot will be. Excel is where I draw the line: if Windows 11 stop letting me use Excel 2010, I will resume my Linux migration attempt.
Microsoft excuses about "security" don't pass my sniff tests and create risks for outlook.com: downloading mail with IMAP or POP over SSL isn't a security risk - or you're doing something seriously wrong.
Why is that concerning? Outlook 2010 does not support the modern authentication and encryption that Exchange Online, and Outlook.com require. It only supports Basic Auth, which was turned off after a long and extended delay.
Really? Then explain me why is it important? Why does it require this specific solution, and why other solutions like say using say POP over SSL are absolutely impossible? And if it's so absolutely required, and other solutions are absolutely impossible, why couldn't it be added?
I mean, Google of all people managed to write a plugin that acts as a middleware between Outlook and gmail.com and solves all this, and unlike Microsoft they didn't have the benefit of having access to Outlook sourcecode or APIs, so clearly, something is off.
To me, this means 1) the lack of "modern" auth and encryption is at best an excuse since 2) there's a proof of concept (from a competitor!) that 3) reliably works as a plugin which is using architectural choices ALREADY BAKED IN outlook.
Maybe Microsoft didn't have the money (nah) human resources (possible) or lost the source code (but didn't it get posted during a hack?) of Office 2010 to tweak it and add the feature.
However, since it came right after the end of the official support period, I seriously doubt it.
I see that more like the same money grab that 1Password did: stop selling regular licenses (here office 2010), move to a subscription model (here office 365), introducing incompatible features as needed to "encourage" the migration (here "modern" auth) , and if customers still don't get the memo, just plainly break the product with some technobabble for plausible deniability (here "encryption" - works as well on the average techie as "think about the children!" works on the average voter)
MFA namely, it requires an interactive process. Other auth standards do not support a challenge-response exchange.
Not to mention increasing encryption standards like TLS1.2 that are not included in that client.
>>Google of all people managed to write a plugin that acts as a middleware between Outlook and gmail.com
Ok and... MS is perfectly cable of doing the same but why? Outside of the problems with traffic and auth, old software has a HUGE security risk, personally I think it should be built into office that once EOL date is reached it simply bricks...
People running old software are a risk to EVERYONE online, as these systems are normally the ones turned into botnets, and other control centers for ransomware.
And why is a challenge required? Shouldn't the decision on which level of protection to use be left to the client? The business should be able to say "thanks but no thanks I like my email server just the way it is".
> MFA namely, it requires an interactive process
Assuming that an interactive process is required (even if that's moving the goalpost), again, that's something that can totally be done in the plugin (show a prompt, and pass that to the server along with the rest of the information stored). It could even be automatized by saving the seed (often shown as a QR code) in the plugin.
> MS is perfectly cable of doing the same but why?
They don't even have to. All I ask is to not take steps to actively destroy software. With a profit motive (replacing Office 2010 by 365 with a yearly fee) "Negligence" is no longer an excuse. I see "Malice" as way more probable.
> old software has a HUGE security risk
A client should never cause a security risk to the server. So if you mean outlook.com, no: if Outlook 2010 can cause a security risk to outlook.com when it connects to outlook.com, then you've done the server part seriously wrong (like how SQL injections means a lack of input sanitation).
If you mean on my own computer, I'm sorry but I run what the hell I want however I want - first sale doctrine and all that.
So if I want to run Windows 7, I will.
> personally I think it should be built into office that once EOL date is reached it simply bricks
OMG what did I just read?
If that's what you seriously believe 1) I'm so glad you're not in charge of the products I use, because 2) you have a great future in sales or as a manager to increase the revenue streams, users be damned.
> People running old software are a risk to EVERYONE online
I'm sorry my freedom is a negative externality to you? Actually, no: "Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither"
So that's where I draw the line: if the OS stops letting me run Excel 2010, it's not Excel I'll change, but the OS that'll get the boot.
I've already got a good experience running Excel 2007 on Wine. Sure I'd prefer keeping Windows 11 because I prefer the UI, but Excel is just more important than anything else.
I don't like VMs. I prefer technical solutions like Wine.
And if I go this way, I might as well give the boot to Windows to run Wine on Linux: all I really need is AHK, Office, Edge, and a good Terminal. From my last Linux experiences, I already know Office works great on Wine. Edge is wonderful too, first class citizen on Ubuntu (oh firefox snap, please die already lol)
I'd have to check how well AHK, then mintty or Windows Terminal runs on Wine (Linux terminals offer an abysmal user experience), but I'm ready to do that if that's what it takes to keep Office 2010 running baremetal.
I've been using Office 2007 then 2010 since uni (and back then they were already getting long in the teeth and Office 365 was already being pushed) and ... I don't ever plan to stop as I like many small details, like how Word starts faster than the new notepad.
I'd rather have Microsoft reconsider their move with the data in hand than waste my time on what may (or may not) happen.