Windows 11 collects an awful lot of telemetry about your PC
extremetech.com
extremetech.com
To be honest, I would have preferred WSL1 which implemented the syscalls directly under Windows for the best possible integration, but they eventually just threw that away and switched to using virtual machines!
Given there's no "Linux specification" the spec is the actual code, nooks and crannies and all, down to nitty gritty details and implicit behaviours that end up indirectly getting relied upon. The only solution is to basically implement these in excruciating details, which may or may not possible depending on the Windows things being wrapped. Then the question of intellectual property, copyright, and licensing come in, as MS would have to ensure that it's a clean room implementation or be subject to GPL terms (cue the Oracle Java vs Android shenanigans).
So at some point it makes sense to just throw a VM at the job, cleanly separating realms, sidestepping any legal landmines, and ensuring perfect compatibility, especially as the whole HyperV infrastructure is quite solid and used throughout the MS ecosystem as a general strategy, e.g the Xbox uses HyperV to isolate games and apps.
Tangent: I wish (the VM part of) WSL2 would be available on Xbox, allowing one to run Linux while keeping the whole regular OS and features!
With Linux, all the syscalls and their bugs are documented, at least in the commit history, if not the man pages.
It doesn't mean they are implementable atop NT/Windows kernel facilities, semantics, and behaviours, in which case it's an alternative implementation to maintain that foregoes integration.
While Wine's effort and compatibility levels achieved are impressive, they actually prove my point: compatibility is a constant fight, there are a ton of tunables (some automated), and it's still not perfect (which is what a VM gives you for essentially free).
There's more than "basic" syscall interface to it though, there's the whole implementation of features (that are GPLv2 licensed) e.g btrfs? iptables? ebpf? ptrace? hold my beer; run kernel-backed wireguard in WSL2? no problem; alsa? you betcha; real time facilities? sure! custom kernel with a missing feature like usb passthrough? be my guest; contribute to the linux kernel code? entirely possible. It's all there, today, and not at the mercy of MS's will or ability to implement this or that.
--
[1] never trust an OS that can't reliably be left alone for 24 hours without rebooting itself while you aren't looking
In any case: How do I get the version+configuration used on US military installations on my machine?
Windows 10 is terrible at privacy. It is known to broadcast to 400 IP addresses. It’s not the OS to use to avoid privacy issues in Windows 11.
I bought a Samsung Galaxy Book 12 bundled w/ a Staedtler Noris Digital Stylus, and it was perfect --- then Fall Creators Update crippled the stylus making it impossible to select text --- rolled back to 1703 twice, but finally broke down and bought a Samsung Galaxy Book 3 Pro 360.
Currently trying out a Wacom One paired w/ a Linux box and wishing someone would make a nicer screen w/ touch which used standard pens (don't want to go to a Cintiq since it would lose on the synergy/compatibility of _all_ my devices using the same pen technology).
Used to be it selected text, now it scrolls (which can be easily be done via touch).
These days to select text w/ a stylus you have to press-hold to get a selection.
Do you use any legacy applications? They don't work anymore, unless one disables Windows Ink or enables the option to use stylus as a mouse.
Microsoft is the second-most valuable company in the world, with revenue comparable to the GDP of a small country.
Seems like it's still working quite well.
Microsoft is as big as if is today because it broke the law in the past and avoided severe punishment from the DoJ.
The law they broke is of the type where you can't be known if what you're doing is allowed or not in advance. Dictatorships love these sorts of laws, but unfortunately in the West companies are made to deal with a bunch of them
one could say the same about exxonmobil, chevron and haliburton
The problem isn't big corporations, the problem is regular, everyday people.
these companies spent a whole century destroying public transport to sell more cars. they spend that century spreading propaganda about cars, bribing politicians (or lobbying as you like to call it), and completely redoing the entire infrastructure of a major world power for... more money. you cannot blame the people being exploited for having to buy into a system they cannot do without, in a country where public transport is just a hollow imitation of itself from the past. again, they spent trillions to get things how they are now! government propaganda since the red scare hasn't been as effective as this.
Stop blaming this on "the corporations". The people are the real problem here. They wanted to move away from the Black people and have redlined suburbs away from them, and this is what they got. Euclidean zoning is entirely a local issue, not something forced on everyone by lobbying.
## Installing a JDK on windows
-Search google/whatever
-Click on first link
-Find .exe
-Agree to terms and conditions
-Click download
-Have to login with oracle account
-(I stopped here)
## Installing JDK on ubuntu
-Open terminal
-sudo apt install openjdk-8-jdk
- y, enter
-done
Downloading openjdk on windows doesn't require an oracle account.
- open terminal
- winget install -e --id ojdkbuild.openjdk.11.jdk
> The winget command line tool enables users to discover, install, upgrade, remove and configure applications on Windows 10 and Windows 11 computers. This tool is the client interface to the Windows Package Manager service.
https://learn.microsoft.com/en-us/windows/package-manager/wi...
Inviting over open source developers under false pretenses, milking them for all the knowledge of their projects and then proceeding to ghost them for months before releasing a complete ripoff of the original open source project.
At least they wont suffer a culture clash from the Activision acquisition.
How is it any different on any other mainstream/moderately popular OS? macOS, Ubuntu and a couple of others basically have the same experience.
With C# the difference is huge since you just need to install visual studio and you have everything you will need, with the best tooling there is.
How does it compare to the mysql one or MS sql server management studio for that matter?
> Also it "feels" easier to click on the wamp installer and just run it from there compared to sudo apt install xyz.
Wamp installer is windows specific but i'd assume you browse to find the download for it, etc or use winget or chocolately instead of sudo install xyz, etc so i fail to see the advantage there?
Similarly I'd just open pacmac and click to install xampp or so no? Maybe an equivalent experience can be had using the windows store if WAMP is found on there but i think the windows store is a bit of a disaster still. (It can't seem to grasp that I do not speak French all that well for example)
>With C# the difference is huge since you just need to install visual studio and you have everything you will need, with the best tooling there is.
There's a reason people jokingly call it microsoft java. The second half might be mischaracterizing it on many fronts but the first half is true to form. I'd argue it as an argument in this matter is similar to bringing up the best platform for developing with Swift.
It dosent compare, but then when working with php and mariadb you dont often use the advanced/esoteric features you have in SQLserver
>Wamp installer is windows specific but i'd assume you browse to find the download for it, etc or use winget or chocolately instead of sudo install xyz, etc so i fail to see the advantage there?
Well there is less configuring with wamp and there are gui tools to manage things, installing the services in linux and setting them up is always a bit more work. I have never tried xampp in linux so it might be equal there.
>There's a reason people jokingly call it microsoft java. The second half might be mischaracterizing it on many fronts but the first half is true to form. I'd argue it as an argument in this matter is similar to bringing up the best platform for developing with Swift.
It being an complete integrated package from the OS to the IDE is the best feature about dotNet. You can look at it the same way as "the lisp machine" but with better third party software support. I guess swift has the same benefits, altho when i tried it the tools where not really up to the same standards as visual studio.
I have yet came across a language platform i cant develop with ease on windows. Also these days with tech such as docker etc there really are no boundaries.
In a general purpose development context I consider it a downside. In the same way that I don't consider it a boon for XCode & the like that I can't run it on my machine and will need to go buy a mac.
When it comes to a more general purpose development context I find that a lot of things have this "if you are on windows" asterisk. From recent memory it can go from the rustup installation page just referring to a completely different page or rediscovering that text files having diverging line endings there or needing to do some workarounds when making commandline tools in such low level languages so that they'll also work on windows, needing to bundle some redistributable dll in your installer to make things work on windows even if you used visual studio on windows to make your binary. They'd work everywhere except windows because vcruntime isn't statically linked by default or something. Given PHP being mentioned think this was also the reason it took so long for various PHP functions to become available on windows in the past (Not sure if they're all available now. I haven't kept up). I remember discussions from back then with complaints about Windows being a second class citizen for php when that wasn't really the case rather it was just more often the odd one out.
I don't doubt that Windows collects and transmits telemetry data (hell, text editors do that nowadays), but if an analysis of that exists, it is not in this article.
Such an analysis does not exist because that traffic is encrypted. Which is also the reason why using Windows 10/11 is not fully compliant with EU privacy laws in places like Germany, as there is no telling what Windows is actually phoning home.
Officially Windows 10/11 can be used but only after jumping through a lot of hoops that involve turning off the telemtry and phoning home, but even then only with an "acceptable residual risk" [0]
The only reason this isn't a bigger topic is because there is no realistic alternative; Everything is tailored to MS, and MS spends absurd amounts of money and effort to prevent anything from changing that.
So the majority just goes with the "easiest" and most convenient solution, even when it might actullay be an "illegal" solution that enables a ton of industrial espionage.
[0] https://www.heise.de/news/Datenschutzkonferenz-Hohe-Huerden-...
... by software that resides on the same system, with keys that are in memory on the same system.
I'm not saying it's trivial to decrypt the traffic, but it's certainly possible, and much, much harder reverse engineering is routinely being performed.
Or MS could simply share the keys with those government institutions there have been literally asking for it, to see wether Windows is actually sending home privacy relevant data.
But the matter of fact is it's a very real issue and still on-going problem.
Just because investing a lot of effort could shed some further light on it does not really change anything about that or the non-compliant behavior MS engages in.
Security only being as good as the effort lobbed at it to break it, is not really a novel or useful insight in this scenario.
What data is sent: https://learn.microsoft.com/en-us/windows/privacy/required-d...
The Diagnostic Data Viewer is a Windows app that lets you review the Windows diagnostic data your device is sending to Microsoft, grouping the info into simple categories based on how it's used by Microsoft. https://learn.microsoft.com/en-us/windows/privacy/diagnostic...
I'm not sure that actually holds — the encryption keys are in memory, but the decryption keys don't necessarily have to be.
The pre-encrypted payloads definitely are in memory at some point; however snatching them probably involves larger-scale reverse-engineering.
Yeah, they might be playing some patty cake protocol /s
(you'd need the Windows kernel debugger and to reboot the thing in developer mode. This is a pretty niche skillset)
What addresses are connected: https://learn.microsoft.com/en-us/windows/privacy/manage-win...
What data is sent: https://learn.microsoft.com/en-us/windows/privacy/required-d...
The Diagnostic Data Viewer is a Windows app that lets you review the Windows diagnostic data your device is sending to Microsoft, grouping the info into simple categories based on how it's used by Microsoft. https://learn.microsoft.com/en-us/windows/privacy/diagnostic...
If you trust Microsoft to not send data you don't want to be sent why worry about telemetry and other potential spyware from them in the first place? You already have trust in them anyway.
But if you do not trust Microsoft to do that, then why trust their claims? They could be collecting a bunch more and if ever found they can claim that it was a bug like a bunch of other companies already did (e.g. HP having keyloggers on their laptops).
(this is also vindicating the "the best way to get correct information on the internet is to post incorrect information"; all the replies could have been top level replies to the OP but weren't)
Is it really? Seems you need to install ~2 packages, flip some switches, edit some files/run some terminal commands, reboot and connect the debugger and you're pretty much setup for it. Seems more like something you need to read an article about, rather than a skillset per se.
Some examples: calls a service that helps companies comply with GDPR "1984" since the analysis is superficial and almost entirely gut reactions to random domains they observed. They have no issue with one CDN they observe but take issue with a Microsoft CDN literally only because they see 'geo' in the sub-domain, when if they'd taken a moment to check it's just used to locate the nearest data center like CDNs do generally.
If the video were instead, 'let's look at what comes pre-installed with Windows 11 [Home, Pro, Education?] that connects online' then it may have been a more informative video. Instead it has a lot of assumptions but little evidence about DNS queries, leaving only casual viewers thinking they've learned something.
>
>I don't doubt that Windows collects and transmits telemetry data (hell, text editors do that nowadays), but if an analysis of that exists, it is not in this article.
Crikey mate; second paragraph, first sentence.
Does Microsoft provide any transparency on what is sent?
Turns out it was a good policy to have, because when I built a new desktop/home workstation system recently I happened to go with a gigabyte mobo, which has that firmware hole enabled by Windows essentially willy nilly downloading and installing whatever unsigned blobs you throw at it.
Had I ever installed windows directly on that machine, I would have had to assume every component with any form of non-volatile storage on it(i.e pretty much every component except maybe the CPU itself) was potentially compromised, making it useless as a workstation, at least in doing any kind of work for customers, which I prefer to do from home. Because once the firmware is compromised, all bets are off.
Even if some rare few developers can properly anonymize data and for instance, scrub core dumps of any user data, them doing so normalizes the practice of opt-out telemetry and most other developers won't be so careful.
Edit: wondering if the correct approach is actually a GDPR one ...
Doubly so if user isn't informed about that.
The goal of telemtry is to gain information about the software and how it is being used.
They have 2 very different purposes and goals.
It really doesn't matter what motivates opt-out or mandatory telemetry; it's spying. It's wrong because it violates user privacy, regardless of the motive.
More than that, you could compress city-resolution detailed weather data into couple dozen kilobytes. The easiest way to see it is to observe that, if your app downloads some kind of weather map image generated on the server, then that image already encodes some of this data directly, through colors of the pixels. If you ignore human readability, you can pack much more information per pixel, at the resolution of... the image. And that is not even the most efficient encoding for it.
Hell, even dumb weather APIs that respond with weather predictions could pack several times as much data in the response if they ditched the horribly space-inefficient JSON response format. There's no technical excuse at all to not ship you the whole continent's worth of weather data with each update, removing the need for the server to know your location.
At this point it is basically a malware, and should be kept in sandboxed environment!
My latest 'favourite' is the snipping tool and how it became much more difficult to use. Also it is made for the default app for png at some point as well not having navigation (next/prev pic in a folder) showing itself in a thumbnail size by default, unsuitable for picture viewing and have to switch back manually to photos. From app settings it jumps back again to a thumbnail sized state, someone have a real fetish about this minimal size view out there in handling screenshots....
The downside is that it’s a pretty advanced tool that can seriously screw up your system if you don’t know what you are doing. For example, several settings require Office to be already installed, otherwise it will never successfully install with those settings enabled. Plus, you need to make note of them to back them out in case you ever want to upgrade to the next version.
But otherwise, it’s an awesome product that can effectively lock down both Windows 10 and 11.
Yes. I've been using it for years now - first on 10, now on 11 (couple of years). Just make sure to check for new versions from time to time, as they keep adding new features and things to block.
That's easy: a USB stick with a partition tool and a Linux installer. Wipe out your W11 partition and install something that isn't blatant spyware.
If you don't like the telemetry that your OS vendor provides, and you don't trust your OS vendor, then why are you using their OS?
But every time someone asks a question about how to improve windows, like a fly to shit some yokel pops their head up from the GMO corn trough long enough to yell out "USE LINUX!" like they're some Alabamian talking about their favorite college football team as if that actually helps someone with their problem and it irks me.
https://learn.microsoft.com/en-us/windows/privacy/manage-con...
Unfortunately this is impractical for many.
At first, the user was the customer. These days we have ads and user data that microsoft earns even more money with.
Has microsoft already started screwing over developers? I'm not paying attention.
Anyway, this slow-mo trainwreck is painful to watch.
https://www.bleepingcomputer.com/news/microsoft/windows-10-h...
Comparing from either base point in time is valid. There are probably win10/win11 comparisons out there if searched for (if not, maybe someone reading this wants to write one and get the attention from publishing it :) )
This article is full of speculation and is trying to just appeal to paranoid people by trying to make Windows out to be doing something bad.
All the user knows is their button doesn't work, and they're angry.
If people can't provide informed consent the dev must make the choice for them. Either do it or don't. Giving them the choice is almost more malicious.
Anyway. All this telemetry topic just feels poorly considered as a whole. Quite "hur dur telemetry bad". I've been on the other side is all.
https://slate.com/technology/2015/02/lenovo-superfish-scanda...
> When Lenovo preinstalled Superfish adware on its laptops, it betrayed its customers and sold out their security. It did it for no good reason, and it may not even have known what it was doing. I’m not sure which is scarier. The various news reports of this catastrophe don’t quite convey the sheer horror and disbelief with which any technically minded person is now reacting to Lenovo’s screw-up. Security researcher Marc Rogers wrote that it’s “quite possibly the single worst thing I have seen a manufacturer do to its customer base. … I cannot overstate how evil this is.” He’s right. The Lenovo Superfish security hole is really, really bad.
'it did it for no good reason, and it may not have known what it was doing'