Outlook is Microsoft's new data collection service
proton.me
proton.me
Companies just blindly trust MS with their data and even force their employees to hand their personal data over in the process. I've pushed for my company to stop leaking so much company/employee/customer data to MS, but as long as the corporation doesn't personally experience how that data is being used/abused and they aren't being fined or hauled into court over it I doubt much will change.
Their use of 3rd party and external tools for adjusting registry during licensing problems is wild.
“Can we have access to X, but don’t worry, we don’t let anyone look at X unless Y happens” is a bit suspicious when “grant X permission when Y happens” isn’t an option.
Even worse when the access to X is only disclosed to users living in a jurisdiction requiring it.
Microsoft’s many brand and marketing folks have a big uphill battle if they want to convince me otherwise. Or they can just stop collecting data.
Which is one of the many reasons why I will not allow Microsoft products on my machines.
My objection to Microsoft's methods in this regard isn't the data that customers voluntarily and knowingly store on Microsoft servers, it's the collection of data about customers, their machines, and the use of their machines that happens behind the scenes.
Wish you all the best though, a Microsoft people trust would do good for the world.
I’m sure you understand, we need to collect your credit card number because that’s how we make money at this bakery. No I will not explicitly explain how. Don’t you feel like I’ve improved your experience?
You also mentioned that collecting user data is how Microsoft is paid in the GP comment. That’s pretty clear to me. I thought when I paid Microsoft, that was the main revenue stream.
The document provided in theory communicates what you said so succinctly before, but with more legal and confusing language.
If it says the opposite, then just asking me to assume that this document that’s extremely difficult to read explains why outlook should ingest information I wasn’t told about, since I live in a jurisdiction where Microsoft doesn’t need to, and why that’s actually a neutral or possibly “good” thing for me, is a bit silly.
—
Edit: if I’m misunderstanding what you said earlier by:
> We have to collect customer data that's what we get paid for.
Then I’m sorry. I don’t mean to frame you as saying something you don’t mean to.
We store data everywhere to meet european GDPR standards regardless of where you live. We have logs but they can only contain sanitized information.
Any document which attempts to describe how a large origination handles data is going to large and complex. As sometimes different standards conflict. For example we have to keep records of anyone who changes the system for some period of but we also have to delete data that has end user identifiers. When stuff like that happens we have to go to lawyers and have language that describes how we handle thoes conflicts. That doesn't lead to a small doc.
This is a major problem, actually, and exactly why people can't and won't trust you.
SOC compliance and external audits can help keep things reasonably secure and prevent the totally careless/incompetent handling of data, but I'm skeptical that they would typically be robust enough to detect Microsoft's own equivalent of Room 641A let alone the actual hardware installed by the feds which MS itself isn't allowed to touch.
I'll just chime in to say that, while I appreciate the sentiment the user is conveying, I certainly don't trust a Microsoft pinky promise.
Right but no one is saying your department is violating our privacy. I'm not sure why you feel a need to defend it.
I think we can safely say that MS's methods of violating our privacy are all automated and that you + coworkers aren't eyeballing our personal data. So we can move on from that.
If you'd like to speak to the privacy violations that are referenced in the article, we're all ears. Education guesses about methods or who some of the 3rd parties are would be terrific.
That is what a support team is for.
And those access elevations will be tracked and audited, just like at any other organization that handles sensitive data.
This isn't some super duper secret, when shit breaks there needs to be a, well secured, escape hatch for the people who fix things to crawl in and make repairs.
Prior to cloud hosting, Microsoft could get permissions to remote in to your servers, or prior to those days, send someone physically out with a laptop and a debugger.
But surely you can see that saying this is still the same as just saying "trust us". It's very, very hard to trust Microsoft.
And the number of markets Microsoft completes in now is tiny. This isn't the 90s where Microsoft competed in slews of consumer and business markets. The potential upside from the Cloud team slurping up secrets from competitors in literally ANY other business segment, is dwarfed by the losses that would hit MS.
Now of course that doesn't mean some corrupt fool in sales won't risk destroying the company so he can make his yearly bonus (that very thing has brought down companies before!), but Microsoft internally has a lot of motivations to ensure that doesn't happen.
So, don't trust Microsoft saying "trust us". Trust Microsoft being greedy and wanting to keep growing the cash cow that is Azure Cloud.
Rergardless, my point is that Microsoft saying that they have audits and controls in place is exactly the same as them saying "trust us". They're just saying "trust that we have effective controls in place".
What an organization can (and should) do is to behave in a way that earns people's trust over time. Microsoft actually had a window of opportunity to do this. They even made a very public campaign proclaiming how they weren't like the Microsoft of old and were more trustworthy than they used to be. And for a while, I even thought that perhaps a real culture change really did happen. But their behavior (especially around Windows and Office) is uncannily similar to that of other companies of questionable trustworthiness.
https://servicetrust.microsoft.com/DocumentPage/6ee23fc7-20d...
In any case, it doesn't much matter. The threads I'm in here are pretty much just me saying I don't trust Microsoft and others saying that I should, so I'll just bow out and leave it at that: we have different opinions.
The utterly massive enterprise market that values security and privacy and also pays Microsoft oodles of money says otherwise.
Also, people aren't enterprises. Microsoft doesn't treat people like they treat enterprises.
And frankly given the monopolistic nature of the business, there are a lot of enterprises that pay for microsoft's services because they don't have the power to make the decision not to
It's one of those commonly overlooked things.
The pros: Outlook doesn't get to speak to MS The cons: When an email has linked images, they don't load, which for the past 20+ years hasn't been a problem.
Cannot say for the entire Microsoft, but in Azure the only way to access customer data is through support flow for cases where customer explicitly gave permissions. Otherwise support portal will not allow access. And there is no other way of accessing customer data. Access is revoked after a case is closed.
The incentive for customers to give this access is simple - with this my team can answer questions right away without very lengthy back and forth (especially if customer is in different time zone). Which results in (way) faster support and problem resolution.
Is there technical protection? Is it encrypted in a way that's only accessible to me?
> Cannot say for the entire Microsoft, but in Azure the only way to access customer data is through support flow for cases where customer explicitly gave permissions.
That article notes that Microsoft says Microsoft accesses our data and make it available to 7xx 3rd parties. It is safe to assume that Microsoft has automated process to violate our privacy and not eyeballs and fingers.
So you don't really need to defend Azure tech support because no one is accusing Azure tech support.
sabarn01> We don't have access to that data internally. We can't access customer data outside performance metrics about the service. At least for the normal dev there is no real way to get access to what the customer does.
On the other hand we have:
Microsoft> We and 7xx Third Parties access Outlook data on user devices.
Taking both you and Microsoft at face value, we seem to have two fairly different assertions.
Customer concerns could be allayed if their shared data was fully auditable at any time by the customer. This would include what buyers of this data can see.
Fortunately, Microsoft has infrastructure so robust they can share a customer's data with 733 3rd parties.
I think we can safely send one more copy to the customer (who's data it is) without overtaxing anything.
We were sold on (in my mid biz) Microsoft being all-the-things compliant: HIPAA, GDPR, etc.. and this is why we put all our data there. As long as they keep touting this, businesses will keep on feeding them data.
If you think it is a big issue you can of course talk to your employer about it and see if they will change, but they're also free to disagree with you.
These contracts are extremely lucrative and extremely detailed. Microsoft applies a business analysis to each one of them. If they determine it’s more financially beneficial to abide by the contract, they will.
There is zero “blind trust” involved, on either side. Where there is trust, it has been earned. And it can be burned.
If Microsoft uses the data they have to come up with competing products, or to time the release of their competing products, or to decide which stocks to buy or short, or to decide which companies to partner with or avoid, or which of your employees they should try to attract, or even to sell or leak privileged information to your competitors you'd never know about any of that without a whistleblower at Microsoft saying something, and that person's income and very comfortable lifestyle depends on them keeping their mouth shut. A whistleblower may also risk legal consequences themself if they ever come forward. Risking themselves, their future, and their family is asking a lot which is why whistleblowers are extremely rare.
That's part of the problem with surveillance capitalism. All the spying being done is to collect massive amounts of extremely valuable data, but very little of that data is used transparently. You simply can never know how the data being collected about you will be used against you, you can just be sure that it will be.
The reason companies are investing huge amounts of resources into collecting, storing, and analyzing every single scrap of data they can get their hands on is because doing so is making them money hand over fist. I doesn't matter if it's your data, or your company's data, they'll be using it in any and every way possible if they even suspect that doing so will give them an advantage or make them more money and their gains will almost always be at your expense.
Just last year Microsoft was fined for illegally collecting children's personal data. Microsoft has also broken the law to sell software in violation of US sanctions. They've illegally bribed government officials. They've committed a number of anti-trust violations. In these cases breaking the law was probably still worth it for them even after the fines they were forced to pay and other slaps on the wrist they received. We have no idea how many other laws they've been breaking without being caught.
For a company willing to break laws in the US and around the globe, violating a contract with Boeing is nothing, especially when the risk that Microsoft would be discovered taking advantage of the data Boeing gave them is basically zero.
You could even argue that Microsoft owes it to their shareholders to exploit every possible advantage they have at their disposal to maximize profits, laws and contracts be damned. That seems to be the position many corporations take at least, and even the companies that have been caught committing the worst kinds of acts like Purdue Pharma, DuPont, or Philip Morris still exist today and seem to have no problems with sustainability. MS could even use the data they collect to help ensure that they maintain their relationship with Boeing for as long as it benefits them to.
Given that I understand all the bad things that a business can do, how do I structure a relationship with a service provider such that I get the benefit of their service, and avoid the bad stuff? What tools can I use to ensure our interests remain aligned?
You’re writing like it’s not possible to do that. Even though we live in a highly specialized society that is chock full of examples.
A large enterprise may have the resources (time and money for corporate counsel) AND leverage (# licenses needed across many products) to negotiate privacy terms that align with their needs, or even pick another product.
A smaller firm is effectively stuck: they don’t have the resources or leverage, and sometimes must use the same products as large enterprises to do business with them.
In the case of Outlook specifically, if you do business with enterprises that use it, your meeting calendaring needs to work flawlessly with theirs. A missed or broken reschedule or repeating event can mean your teams sometimes don’t show up when expected. This really happens.
Has any business really succeeded in keeping business information confidential while outsourcing operation of that information? It seems like at a minimum you'd need a PCI-DSS/HIPAA-style audit regime, which I haven't seen the likes of MS granting access for (why would they?); even then those schemes aren't great at protecting confidentiality. Core business trade secrets get leaked all the time; the idea that a company would manage to protect stuff that's proprietary but peripheral, like how they use their workflow tools, seems like wishful thinking.
They controlled the upgrades, and Microsoft for a long time couldn't even count how many copies of office, etc were being used because the software didn't phone home. That software is probably still running until it's updated to have telemetry added.
Maybe Microsoft used the information found in outlook to tailor their product offering and craft their sales pitch when convincing Boeing to buy into their cloud services and AI tech (https://news.microsoft.com/2022/04/06/boeing-and-microsoft-d...). Perhaps Microsoft found and leveraged detailed information on Boeing's finances and IT budget which allowed them to set a price much higher than they would have for those services. The more you know about a company and their situation the more leverage you'll have in a negotiation.
Just because MS isn't making airlines doesn't mean that they aren't able to abuse the data they collect for their own profit at Boeing's expense.
That might be so for big companies. Most smaller shops more likely just accept the (still extremely detailed) T&C's outright. That certainly structures the relationship, but I doubt there's much balancing involved.
I'm thinking of e.g. the medical lab next door, the girlfriend's gynecologist, most smaller businesses really, of which there are a ton which deal with relatively sensitive customer data.
And yet their standard contracts don't say "if you give us all your data, we'll do whatever we want with it, tough shit." In fact they say pretty much the opposite of that. Isn't that interesting?
Big companies like MS will apply the same business analysis to their small customer contracts as they do their big contracts--but at scale. If they decide they'll make more money by honoring all the little contracts, they will honor them.
So even small customers need to understand the incentives that help that analysis come out in their favor. They tend to rely more on external incentives like criminal penalties under statutes governing fraud, personal data, medical data, etc., and the potential for negative press coverage.
If the majority of businesses (and employment, and communications) are small businesses.. where does that land?
https://www.reuters.com/technology/microsoft-overtakes-apple...
Some mess.
Protonmail is using this to drive demand gen for their services. doesn't make them wrong but understand the motivation and how they are pitching the narrative.
Proton mail may be trying to capitalize on this newish development but they are also not wrong.
Which is also how old outlook works but new outlook wants to man in middle all my email.
Edit: https://sparkmailapp.com/help/general/email-storage-and-back...
I don’t use Teams or the Send later feature which does involve their servers.
EDIT: you are correct. Looks like I know what I am doing today. Ugh I just want a local only email client that supports archive/snooze
Summary of Retention Details: Email address, email content, mail server credentials, APNS device token, appToken assigned by us, device info - During the services provision period services + archive time If you delete Spark Account: 3 months after deletion of your Spark Account.
Thanks though I will double check. If it is storing this I will need to move clients again lol.
EDIT: you are correct I misread the privacy policy. Deleting a spark account and moving clients again. I guess it’s back to the standard Apple Mail app for now.
But the Push is initiated from a server. So the server must get a notification of a new email. IMAP-PUSH / Outlook has support for that on a desktop, but not on a mobile device.
So if you get push from a 3rd party email, they listen for new emails in your name. Whether via the technologies mentioned above, or some other APIs, it's done on a server, and the server triggers the Push to your phone.
https://www.claws-mail.org/index.php
It's lightning fast compared to Outlook, and very stable/reliable. Also available on Windows.
Outlook .pst files (both mail and contacts) also can be easily ported to Mbox or other standard formats, then imported into Claws Mail, by using the readpst utility which is part of libpst utilities, available on various Linux distros. On Debian it's part of pst-utils.
Also opening a mail that's 30 MiB in size (pictures) and has to be downloaded just freezes the entire UI.
I'd like to advise people to use other software, but I don't know of any perfect email clients:
* sylpheed/claws-mail has this locked UI problem
* mutt doesn't render images and has a steep learning curve
* thunderbird has software bloat, doesn't work on my low end hardware
And other recommendations?
Webmail is also mostly broken. I liked prayer, but it also doesn't render images IIRC and roundcube dropped the classic theme on new versions, and the new theme has less information density.
I like the classic HTML UI of GMail and OWA, though.
Since you mentioned mutt and it's steep learning curve, I recommend you another TUI MTA/mail app. It's nmail (https://github.com/d99kris/nmail). Simple, Pine/Alpine like interface, has great features (for example, saving mails in sqlite - can be viewed offline). Also the developer is active and friendly, in case you find bugs or have any proposals for enhancements.
Eventually our subscribers will get in touch with us asking why our emails are no longer getting sent to them. This is with very low spam rates, DKIM, and DMARC set up. There's also no good way to contact the iCloud postmaster, which is an option for every other major email service.
I also have had several instances where iCloud Drive would take forever to sync. The most recent time got so bad (100% cpu usage that persists after killing the process when I added 5KB worth of files) that I stopped using it completely. Tried Microsoft OneDrive instead and it synced at good speeds and gave me no problems.
Most services just offer a paid email. Proton offers all of its services for an extremely low monthly price. Not to mention their security protocols are among the best.
Everyone uses email. Most use a VPN (everyone should) and almost everyone utilizes some form of cloud storage.
I started off purchasing to use their VPN and now actively use all 3.
It’s a false sense of security and a waste of resources. The ones making the money are datacenters and middle-men.
The point of cyber security tools like VPNs is to limit tracking, data sharing and reduce the potential for malicious actions to be taken against you.
You can't honestly say not using a VPN is better than using one. What's the alternative? Unencrypted web traffic? Your ISP harvesting your web data and selling it? Exposure on public networks?
I don't know if you're aware, but basically all sites on the internet use something called SSL these days. However, SSL is useless if you use a VPN that also provide DNS servers (which most do) - because the provider could listen in on all of your traffic by hijacking the handshake, DNS and traffic to and from any target server - making it much easier to create a user profile, because you're authenticated to the VPN.
Also, third party cookies are blocked in the mainline browsers by default, making VPNs even more useless.
Most if not all of the ISPs also use dynamic IPs, making it unlikely to be cross-site-tracked based on IP sources.
Additionally, 3rd party cookies may be blocked but cross-site are not.
What is the difference between the ISP knowing this and being a problem, but the VPN sitting with the exact same information, also knowing it?
Your VPN doesn't protect against squat when it comes to the agencies that might be watching. Hell it doesn't even protect much against marketers fingerprinting your movement around the internet. You leave a plenty big breadcrumb trail that isn't just IPV4.
Honestly VPNs have been a great marketing example of the last 5 years. You all buy something without needing it or knowing why t f you have it. Yes using internet without one is better. Why? It's cheaper for starters.Auth. faster! No relay slowing down your connection!
VPN best use isn't on consumer end. It's on orchestration end as another tool to guarantee you are who you say you are via another layer of auth.
What does Apple really do with that information? I at least know what Google or Microsoft is doing, by example of this article.
I just laugh as Apple users misplace their trust and think they're somehow secure for it buying an iphone, at least Microsoft users know the insecure mess they're stuck with.
What does this even mean?
> your IMAP and SMTP username and password are transmitted to Microsoft in plain text.
What the heck?
I think that is not true. I think that is a lie on Proton's behalf.
When I set up the email client, it connects via OAUTH2 to the other services. It's connected as an app and not via credentials. If it connected via bare credentials, then it'd be a "legacy app" and you'd need to generate an "app password" for it, but you don't.
> I think that is not true. I think that is a lie on Proton's behalf.
Sadly, it is all too true:
Microsoft lays hands on login data: Beware of the new Outlook https://www.heise.de/news/Microsoft-lays-hands-on-login-data...
Warning: New Outlook sends passwords, mails and other data to Microsoft https://mailbox.org/en/post/warning-new-outlook-sends-passwo...
Their objection is that the credentials are being transmitted to and stored by Microsoft at all, instead of Microsoft generating and storing an automation token / app password. That is a valid concern. But tacking on "in plain text" to it just creates confusion.
Today, when the context is service provider and customers, "plain text" is used to say that service provider has the data unencrypted.
if password "secret123" is sent to you, it doesn't matter if it was sent via carrier pigeon, locked up in a secure briefcase and delivered by someone driving an aston martin, or via a TLS channel. It's still plaintext, because the receiver now has the actual password, and not a hash of the password.
Do you pay for your personal emails? I do (Fastmail) and I'm very happy. Same with search (Kagi) and many other services.
So you could have two different Outlooks on your Windows 11 computer now. Just like there could be 3(!) versions of Teams installed (Teams for Home with Friends and Family, Teams for Work or School, and New Teams for Work and School).
This Outlook risk hangs over my client's head because they opted to pay. Last year they moved from self-hosed Exchange to hosted-Exchange + Office 365 + all the recurring fees (and support costs).
Paying rent to reside in MS's surveillance hydra isn't a terrific bargain.
I and several people I know are happy to pay for email. Every report like the one linked here makes me an even happier paying customer.
Perhaps you have a different definition of "no one".
I pay for protonmail, and I'm very happy with what I get. I can even use it as a client for receiving and sending email from my own domain. So, if ever I were to want to get away from it, my accounts won't be tied to the email provider.
If folks ask "why would you pay for email", I think the right first answer to that question is that it's a better service than the free service providers. Then, you can talk about the why's (when you pay for email, you're the customer, not the product, the privacy aspect of not having their email being farmed to enhance a company's advertising profile about you, or being used for AI/ML research if that's important to you, or any of the other reasons that might be important to folks).
So yeah, paid email is a premium service, and if we're being honest, it's been a premium service for regular folk for decades. I happily pay for email myself, but my parents sure don't, my wife doesn't, and most of my friends don't.
1) On the login screen (if you let it do its OOBE login background thing)
2) On the post login screen every time I update asking me to sign in to cloud (which is actually asking me to pay for cloud)
3) On the OS notifications on login prompting me to sign in to cloud
4) On the badge of my non-cloud user in the start menu with an orange blip that looks like a notification but is really a prompt to sign in and pay for cloud
5) At the top of my start menu begging me to pay for xbox live
6) Looking at email
7) Any app with AI features that'll be horny to beg you to buy new AI credits. Like notepad.exe
Is there a reason I shouldn't continue showing people how to steal their software or /ideally/ invest in alternatives?
1/ Train AI models on corporate customer email
2/ Ask that AI questions about commercially interesting things
3/ Print money
In much the same way that models trained on GPL code write out code which is byte-for-byte identical to but otherwise completely distinct from the code it was trained on, said model will emit interesting emails that have only coincidental correspondence with the commercially sensitive information in the training data set.
Microsoft has absolutely everything they need to do this already in place. Obviously they'd never do something unethical like that so it's safe to continue giving them all your corporate email.
For proton, I assume they have a free tier (I don't know I pay for it). So I guess they let people know to push adoption or get people to make the jump, but the assumption is they have some conversion rate to paying customers. For those that never want to pay for email as their usage scales, they're better off staying.
According to her, "their" product used to be information. Then it became prediction. And now it's behavior modification, which they achieve by constantly mining us (the data we provide them).
At least IMHO, this is a more accurate depiction of the current state of affairs. Although in the end, it may be quite a similar metaphor, either way.
I don't know who Shoshanna Zuboff is (I'll 'kagi' them), but I agree with the points made. It's been an evolving strategy of how to exploit users as a resource for financial gain or at least cover the costs of the free tier service.
https://www.heise.de/news/Microsoft-lays-hands-on-login-data...
This is not true.
My business clients on hosted Exchange are paying for O365 Biz. Their local Outlook app has a Try The New Outlook switch in the upper right corner. That's all it says.
The one employee who clicked it (before I could warn them) found the local paid-for, Outlook app transformed into web-based Outlook running in Edge.
All of the same issues mentioned in the article were first discovered in this New Outlook by German researchers.
This client made a point of purchasing local-run Office apps. Web based Office is a non-starter. In this case, MS is using a deceptive method to hijack my client into running software - they they explicitly paid to not have to use.
Microsoft's behavior in this is clearly unethical.
Part of Microsoft Problem here is they have 4 things they call "Outlook". Outlook the Consumer Desktop Application which is privacy nightmare referenced in this article. Outlook the personal free email hosting service (old Hotmail), Outlook the Business Desktop Application most people know. New New 365 Outlook which is just WebView2 Outlook.
Okay. And?
As I mentioned in my post, the same behaviors discussed by the Proton researchers were also discovered by German researchers in the "New Outlook". Does the purchase channel matter here?
That is indeed what Proton showed.
And for the 3rd time, I am saying that German researchers showed that the same bad behavior happens in the New Outlook client that is part of Microsoft's office business suites.
> Outlook (Desktop/Web App) in 365 is COMPLETELY outside of proton article.
Again, so what?
Very specifically, please explain why it matters that the bad Business Outlook behavior was reported in a different article.
But when I click it I get the PWA version of Outlook shown in the article.
The old Hotmail service is now called Outlook.
The website there is the same as the one on Office 365.
And that website stuffed inside a PWA is the new Outlook meant to replace both the UWP Mail app on Windows 11 and the old paid Outlook desktop MFC C++ application.
Once this has been completed they have ONE version. The same website that drives outlook.com, Office 365 and the PWA.
I couldn't find a way to turn off these ads.
Great way to destroy trust, Microsoft!
Enshitification galore!
(I'm a proud customer of Proton but only for my business, for the whole family I find the cost just a tad to high to justify so I have a small local provider)
Sure, they will disable the data collection and gladly obey the rules we put in the contracts (how do we know?). But they'll make sure that we're paying extra money for it. They're sucking away our now even more valuable tax money[0] and our idiotic leadership of panic throws more money into this black hole.
[0] A "Kleine Anfrage" in the German parliament to the Bundesregierung in December 2023 made it public (but mostly ignored) that the German Bundesregierung will pay 6bn EUR to Microsoft and Oracle in the upcoming years. Source (in German): https://www.zdf.de/nachrichten/politik/deutschland/it-open-s...
Another place where I encounter this behavior is the pop-ups shown by web browsers for sites asking for special, sometimes weird [1], permission like "location" which took me about five seconds to make sure I pick the "Block" button.
I hope this sort of behavior gets regulated by the corresponding authorities.
1. I once hear a youtuber say: Why on earth a wallpaper app needs to access my and manage my phone calls?!
They want to basically make windows machines, telemetry kiosks for every bit of data they can extract.
This ought to be classified as adware itself now by malware detection. Obviously Windoze "Defender" won't have a problem with this I'm sure, no conflict of interests there.
The things we learn thanks to these regulations keep proving why they’re necessary.
The thing-to-learn from the EU rollout:
The public is a stakeholder and needs to be represented by 1) folks correctly knowledgeable to do so and 2) be invested with enough weight to not be overruled by govs & corps.
[1] https://www.reddit.com/r/Windows11/comments/1443318/whats_up...
Which of my employees is leaking info to a competitor? Looking for a new job?
I’m buying a property. What’s the level of interest from other buyers?
A client is applying for life insurance. Does he have any serious health issues?
Far-fetched or not, someone will be selling insights that would surprise you
I've been on Linux for more than a decade, and even with advancements like Flatpak, Linux is very far from the protections Android, iOS, Mac and Windows have.
In any case, "any software may be tracking the Linux user" is an exaggeration. The vast majority of software on the average Linux user's desktop is open-source software from their distro repo.
Might not be for gaming, but it's perfect for the daily drive!
Spectrum OS is trying to do that, but is still has a long way to go
We do not need Android, iOS, Mac "protections" here. We don't need overlords to protect us.
Not that it justifies the behaviour of course but it's not always the case.
So like every login form in the world, which sends the username and password in plain text over SSL. This is pure FUD.
Old outlook didn’t do that. Thunderbird doesn’t do that. This is completely unnecessary for a mail app. My computer can check my email. No reason for Microsoft servers to do it on my behalf.
Not sure what your evidence is for lying. Because they're not.
When creating an IMAP account, c't was able to sniff the traffic between new Outlook and the Microsoft servers. It contained the target server, log-in name and password which were sent to those Servers of Microsoft. Although TLS-protected, the data is sent to Microsoft in plain text within the tunnel. Without informing or inquiring about this, Microsoft grants itself access to the IMAP and SMTP login data of users of the new Outlook.
ref: https://www.heise.de/news/Microsoft-lays-hands-on-login-data...But you just gave Microsoft your credentials! How could you not intend that?
They're pretty clear about this: if you set up a 3rd party IMAP account, then yeah, credentials get used. If you set up an OAUTH2-capable account, then it uses that instead. That's why it's a lie, because of course if c't has some custom bespoke IMAP server, it's going to need credentials, and the user is going to intentionally hand them over so it can retrieve the mail.
That it's happening as plain text (notwithstanding TLS on the transfer) distinguishes this from some kind of credentials-sync system (think: LastPass or Keychain) which wouldn't necessarily need to have the credentials in plaintext to function.
Proton also has a VPN, encrypted storage space, and password manager. They're slowly building a full suite of privacy-focused apps with paid tiers for all of them. Development stagnated for a while but it seems like they've made decent progress recently, although their products still don't match the features of Google's app suite.
Full disclosure, I have been paying for Proton services for several years now and use them as my primary email provider.
It's not just Microsoft's email, it's all of Windows too. I tried Windows 11 for the first time not too long ago and it's an abomination of an ad delivery vehicle that makes ChromeOS look magnificent.
After too many years of Windows, I finally bit the bullet and installed Linux on my desktop. Within a few weeks I was more productive than I was on Windows and my OS is no longer trying to sell me something constantly, and I should have done it sooner.
-
For me; Its harder to fall into the "Oh - Ill just intall a bunch of these old games" distractions... or "what new games can this bitch run (slaps laptop's lid)"
--
Also, since Linux has evolved to effectively run an F-ton % of the internet - thousands and thousands of devs, techs, ops, indies, etc have just made the experience so much better.
When I first started with Linux in the mid-90s - I had to hire four promising consultants to help me transition a ETF process by FTP from SUN Microsystems to my company where I was head of IT, to build scripts to create manifests from SUN to us, via FTP - watch the directory, and parse the new-fangled XML that SUN was trying to establish.
Ill never forget the first call with SUN and our execs (we physically manufactured all Software Box Sets of SUN's software, manuals etc - then packaged them and shipped it - so if you bought SUNos/Checkpoint or any Intuit or certain games' companies physical products - we manufactured and shipped it)
So we were using flat files for the transfer or order information for SUN and had some wonky scripts on these four linux FTP servers.
I was not to familiar with Linux at this time - but hired Dave Sifry, Chris DiBona and some others to re-do our FTP flat file ETF process to access SUNs new XML requirement.
We didnt know what XML was at the time - and I infamously said on a call with SUN "OK let me understand. You have your current crappy etl process and you want us to rebuild our pipeline to support your new XML standard.
(The sales people were jumping up and down at me on the call because I called SUNs current practice "crappy" while I was on the phone with a bunch of execs...)
Anyway - I went to our Linux Consultants and I talked to Sifry and I said "If I were you, I'd take your team and start a Linux Support Company."
A few weeks later Sifry and I have a sit-down, and he told me that him and team had created a new company - called "LinuxCare" to offer some of the first enterprise support....
We talked about me joining, but we never came to an agreement, and I believe Dave was one of the first 100-millionaires in the linux space on paper after LinuxCare took off a bit....
(they used to be in the Macromedia building's basement level in SF after that...).
So back then, productivity came from the server side for workflows...
Now - you can achieve exceptional productivity because you're not at the Childs Table when it comes to the UI-first (windows) vs UX-first (linux) utility platform that became a desktop.
But that took decades and millions of people contributing to how Linux can be empowering.
---
But if you just look at the productivity in technological evolution Linux has contributed to computing, I personally feel its a Tier-1 level contribution, and now you can just rely on FN awesome tools, for free, written by millions of smarter people than an induvidual, to make speed to deployment of anything (even if its to gaming) faster, easier and you arent spinning mental cycles on "what the fuck is /usr/sbin?" "Where the heck do I grab these dependencies from? What the FUCK is a make file?
--- Neither of the people replying to me read my whole post.
Not to ruin your productivity but it's actually insanely easy to install a bunch of old games on Linux these days. And plenty of new games run just fine thanks to the advances Valve has been making with Proton.
top 100 games on some torrent sites tell the story of where games are landing
https://i.imgur.com/1rT2wCL.png
EDIT: YOU REPLIERS ARE KILLING MY PREMISE! MAKING HARD TO NOT INSTALL GAMES ON MY LINUX DISTRO! So by making it "insanely easy" you are promoting why I dont want to install them!!! xo :-)
Thanks for keeping the DNA of my comment alive!!!
double click to install, wait a few minutes for the download, press play and it launches
as someone who grew up compiling different forks of wine with various patches to try to play half-life in the 2000s the improvement is quite incredible
But then someone created systemd, the end.
In Linux. If I had something setup on desktop 3, win+3 takes me to it every time. No matter if that’s one window or multiple. It’s always one hot key away. And then one to get back. I never get lost in a sea of applications that look identical in the alt+tab thumbnail.
I haven’t found a way to replicate this in windows. The closest is “never group things on taskbar” so I can at least click specific firefox windows directly. But that no longer exists in windows 11, so I guess I won’t use 11.
(I don't use virtual desktops anymore so I don't remember that well)
It's like they're drug dealers adding fentanyl as if it's a sales perk after everyone's learned about it killing the users.
The big question is how are they going to do it without giving the vultures root access
Edit: I am "posting too fast" it seems (a few messages per hour, I guess?), so here's a response to a comment below here about the mixed-OS household:
I wouldn't mind using macOS or Linux, and I actually would pay if I could install macOS on my PC tower. I might be the idiot here, jumping out of the MS frying pan into the Apple fire, but I find macOS to be just fine for my use, and not too locked down overall when it comes to running the software I need on it and it's very well integrated with some of my other tech stuff. Sure, I can't tweak every aspect of the OS, but I don't mind how it works out of the box so I am cool with that. It would also be nice if I could use some of the macOS features on other platforms, like iCloud, Messages (whatever the blue-bubble messages are called), and iPhone integrations.
Kernel level cheat engines (not VAC) will catch you on a different OS 100% of the time. EAC is vastly more popular for detecting in game cheating, versus VAC which scans the users computer for possible cheats and typically doesn't work well when it comes to preventing cheating if at all.
Many companies invest heavily in kernel level anti-cheat and having to support multiple OS's when the other two big OS's account for less 0.5% of the profit, I just don't see business folk lining up to ensure non-windows users can play video games given the fact it's probably Microsoft making or publishing the game in some capacity.
Anyways, from what I am seeing from tech trends, the future is multi-platform, and it's only becoming easier to code for everything all at once. Smart people are taking time and energy to research things like WASM and APE (which supports Cosmopolitan Libc), not to mention long-running initiatives such as containerization, the various JS engines and other languages which run anywhere, etc. Even with ARM vs x86 happening, software runs cross-platform more and more.
Could change if Linux numbers on Steam hit double digits, though.
I don't see how that can be true. Valve has made huge strides in pushing Linux gaming forward, and thousands of Windows-only games are playable on Linux, sometimes even with better than native performance.
The small percentage of games that have anti-cheat mechanisms or intrusive DRM (Steam notwithstanding) that are problematic on Linux are likely games that don't deserve my money or attention anyway.
Disclaimer: I do still game primarily on Windows, but mostly because I find dealing with Linux issues (whether that's related to games or otherwise) much more annoying than dealing with Windows' spyware. I can reasonably handle the latter, but nothing is more frustrating than having non-working software when I just want to unwind for a while. I think these are not unsurmountable issues and am pretty hopeful the state of Linux gaming can only improve.
If we are talking about games whose compatibility will increase Linux adoption though, most of those have anti-cheat and DRM.
I am more optimist than this, mainly because of Valve. They contributed a lot to Linux gaming and are now in a position where they can pounce and steal Microsoft's cake.
Microsoft simply cannot allow themselves to slip up on this anymore and I feel like we are at a point where one more major blunder or a scandal from Microsoft could irreversibly sway the tide towards Valve and Linux gaming in general.
The hoyoverse titles used to detect VMs, but it seems to have calmed down. (I was able to try Honkai Star Rail with no obfuscation effort on my part.) NVIDIA stopped caring about VMs in their GPU drivers a few years ago. FatShark almost made the anti-VM mistake with the new Warhammer 40K Darktide anti-cheat; I refunded the title during early-access and told them why. They reversed course before launch and that also works in a VM. - I've played many Blizzard properties (but not WoW) in a VM as well, though they tend to hate networked storage, for reasons I don't yet understand. (Had to setup iSCSI because my CIFS share over 10Gbit/s paravirtualized NIC was "not good enough", I guess.)
Windows runs in a Hyper-V VM by default now, anyways, so "running in a VM" as a heuristic is of questionable utility to me. (It's how the "Core Isolation" feature is provided.) The real irony is I can't even use the VM to cheat, anyways. The guest's memory is encrypted by default. Modifying it, or even reading it, from the host-side would be prohibitively painful. I guess a VM would perhaps obfuscate emulated/scripted inputs, but I use real devices, and a real USB hub on the guest anyways, because the latency and functionality of the emulated HIDs is awful.
Thankfully Steam is very pro-consumer: if a title I purchase does not run in the VM, or on Linux via Proton, it gets instantly refunded. The nice thing is it is actually in Valve's interest financially to push back on these devs: both to prop up the value of the SteamDeck, and to stop people like me from getting refunds.
isn't that something
Their products behave too similar to those of bad actors. Recently I had a relative over and was helping them with some computer stuff. They had an odd PDF viewer on their laptop and, when I asked them about it, they called it Adobe. It was not Adobe Reader.
I assumed it was the result of clicking through a paid search result and installing something from the internet, but they insisted they got it from Microsoft. I was confused for a while because it wasn't an app from the Microsoft Store.
Then they explained to me how they got it. They clicked on start, searched for "PDF", and "installed Adobe Reader from Microsoft". The icon for the app they had was obviously made to look similar to Adobe Reader and they had no idea the start menu search is a free for all of Bing results.
They're not stupid and I can't really blame them for misunderstanding. When they showed me, I could see how it would be reasonable to mistake the search result (or ad?) for an app recommendation. The result had an icon and everything. The weird thing is that I can't reproduce it on my PC. I don't get the same results that look too much like recommendations, so either I'm on a different release cadence for Windows or I've disabled some of those unwanted features.
The user should be able to trust everything in the OS. A built-in search feature that exposes users to bad actors is extremely frustrating to see.
One time the shop took a subcontract for a bigger local shop. They were all Windows. Whenever we had to work with their devs, it seemed we fought Windows as a platform on which to run development tools as much as we did actual application problems. I know there's massive shops that live like that, but I know neither why nor how.
(n.b. this was around 2014, I don't know how Windows has changed since then)
The windows shop was non stop hardware, software issues. Laptops (whichever brand) are absolute junk with very short lifespans. Blue screens...
Most games can run on Linux fine ( https://www.protondb.com/ ), some even run better.
After some problems with pop-ups I nuked my parent's Windows install and put Linux on the machine. They had no problems using it.
Between those two use cases, why use Windows at all?
A strong warning, the direction Microsoft is going with Windows, Apple is heading in now. I'll put down money that by 2026 iOS and MacOS will no longer be usable. It's good that desktop Linux is now ready for prime time. We can win on mobile too.
I wish I had the same optimism. I have a Fedora partition that gets wiped and reinstalled every release and there's always some showstopper or things are slightly worse that make me unable to commit. I'm not settling for 'slightly worse'. The display server situation on Linux is depressing.
I don't like were Microsoft is heading, but it's way too early to claim Windows is dead.
I agree with your point though - Windows is not dead; for me its a lot of the photo editing applications that I want to use don't run well on Linux.
I think that's exactly the problem. It's too alive, so they can bastardize the experience in any way.
Because it's a partition I use to test Linux and rather than upgrade I'd rather start over from scratch.
As for the distro choice, Fedora is ahead of Ubuntu but not as bleeding edge as Arch.
I'm sure there's plenty arguments for using x distro over y. Fedora is just what I landed on.
Yes, with WSL to keep it afloat just long enough to steal your private data before it sinks.
It use to be the case that your private data would be sold to advertisers but that model is changing with the privacy laws, user starting to not tolerate it (e.g. see poor Google search results), and moats that are starting to fall apart (e.g. Apples app store).
Just in time for the next frontier. This time, the goal is to to feed GPT models with your private data. Windows and Outlook seem like excellent funnels to do just that. The best GPT model will require the most intimate data and at the lowest price possible. MSFT is positioned to do just that.
When the games run however, I agree they typically run better.
Everything shows a company too complacent and focused on their own business needs. C# and .NET are the exception because they fought hard to antagonize Java in the corporate world, and while they missed the "billion devices" train for being too forceful with pushing Windows Server instead of going multiplatform, they still won over a decent market share.
Use Linux at home since 2020, and have recently switched to a Mac for work. Windows is gone from my life, relegated to doing maintenance-work from a VM for the poor saps still stuck on it.
There's no separation of concerns at Microsoft: the allure of recurring revenue from ad-tech and online-services is polluting Windows and Office in a really bad way. I need my operating system and productivity software to (a) work, (b) function reliably offline (Office doesn't), and (c) work in perpetuity for as long as the hardware lives. (Windows hasn't since 10, arguably 8.)
Apple seems to understand that the core stuff needs to be free, and the free stuff can't compromise on their privacy & security core-values to be free. They also come with apps that are reasonably worth using, and they use iCloud to sync and integrate that stuff seamlessly across their device-family.
What Apple charges money for is actual value-added service. You want Music? They've got that, streaming or purchased. You want TV? Same deal. You like books? Yep, got that too. Want some curated news? They'll sell you that. - Signed up for all this stuff and have run out of storage? Predictably they'll sell you more of that, too.
What's more is Apple understands _the meaning of no._ - I can turn that stuff off easily, and permanently, right when & where the nag occurred. No resorting to things like registry edits, group policy hacks, hacking the installer, etc. No gamification of the fucking Settings screen. No ads in my fucking Start menu. I can hide or remove their apps just like any other app. (As a concrete example: for ages I have had to hack Explorer to get rid of personal-OneDrive, which I don't/can't use since I am not even logged into a MSFT account. The equivalent to disable iCloud is a very clearly visible setting in Finder's settings.)
I won't lie, it hasn't been perfect, but the amount of UI polish, the ease of cross-device integrations, and the feeling of Apple actually valuing the customer-relationship, are miles ahead of whatever the fuck Microsoft is doing. Modern Microsoft feels like a Facebook or a Google, and that's really not meant as a compliment.
If Microsoft wants recurring revenue, they need to start providing real services. Windows isn't a service. Office isn't a service. I highly suggest they start emulating Apple, or they're going to get left behind.
Redmond, start your photocopiers.
These are basically all tech support providers. I'm not saying Google is a privacy-centric company, but this effort to enumerate subprocessors is admirable.
The internet becomes a worse place when folks criticize the superficial number rather than the intent.
TBH, it's not that it would be impossible for either Google or a subprocessor to conduct themselves nefariously, but I don't think it's practical or reasonable for anyone to expect that they would. Google pays Accenture, for example, >$1b/yr for services. They absolutely would not want to put that cash cow at risk.
Will gladly pay to not have my data shared with 772 3rd parties.
The webmail is slick (and refreshingly simple) and I'm really liking their iOS Mail app which is a huge improvement from the old version from a year or two ago.
Hope they continue to invest in Calendar and Drive (encrypted storage) - both need a bit more work, but are usable enough for now.
Do you have an exit strategy if Proton goes the way of Microsoft or Google? Those two only had apathy and inertia keeping people in their ecosystem, but Proton kind of has you locked in, because you can only use their proprietary apps to access encrypted emails. Yes, I know you can use IMAP, but my understanding is that any email sent via IMAP isn't encrypted, and any encrypted mail can't be downloaded via IMAP. Either way, just because they have IMAP turned on today, doesn't mean they won't turn it off tomorrow in the name of security.
I already run Pi-hole and use Brave, now I have to avoid Outlook.
Thanks microsoft. We don't have enough attack vectors already, so it's nice for you to compile all of our information to make it much easier for bad actors to gain our information. I'm sure the pittance fine levied against them, not if, but FUCKING WHEN, they get breached will teach them a lesson.
/End -Rant
I couldn't care less who the money goes to. What I care about is actually being able to read a webpage.
The UX is typically better, and that was especially true back when Gmail was taking over the market and introduced everyone to the concept of never needing to delete old mail. Good looking apps are available for every device, with minimal setup. Deliverability is so good most people have no concept of ending up in their contact's spam folder. It's what your friends and family are using, and its free.
Concerns like privacy or being able to change provider without losing your address are abstract and out of sight.
I get that this was entirely predictable (see XKCD exhibit 1), and that once we allowed it in websites and webapps there were no real barriers left to downloaded installed native local apps, and my outrage is too little too late.
And I get that saying "I'm now installing Linux on my laptop" is... nice but irrelevant. 0.01% of userbase doing that will make laughably no dent.
But it's really really getting too much. Grumble Grubmle everybody get off my lawn! :-/
Relevant XKCD: https://xkcd.com/743/
That's how Adobe got to where they are. People pirated their stuff (and bought legitimately), got their stuff trapped in their formats. Then they turned the screws and locked people out of their own content. Autodesk did the same exact thing too, with Inventor and Eagle.
Your personal data is too important to be used as some ransomware (read: proprietary programs). Cause then, it's not just the finding an alternate program, but figuring out how to export.... if they even let you.
See:
"... PSD is not a good format. PSD is not even a bad format. Calling it such would be an insult to other bad formats...
If there are two different ways of doing something, PSD will do both, in different places. It will then make up three more ways no sane human would think of, and do those. PSD makes inconsistency an art form...
Earlier, I tried to get a hold of the latest specs for the PSD file format. To do this, I had to apply to them for permission to apply to them to have them consider sending me this sacred tome. This would have involved faxing them a copy of some document or other, probably signed in blood. I can only imagine that they make this process so difficult because they are intensely ashamed of having created this abomination..."
https://news.ycombinator.com/item?id=575122
There is no shame in that game.
How did Adobe do this?
Like CS2, which ran on PowerPC Macs. Intel and ARM macs need not apply.
* Locked-in (for various reasons) userbase moved in to subscription model en masse, begrudgingly and complainingly
* Now, as soon as you stop subscription, your software stops working, and your catalogue will not work with pre-subscription files
We can debate semantics of "turned on the screws" and "screwed over", but take it on my word that most of us are feeling thus :). Yes we were hoisted by own petard and choices.
I can’t say I “love” any corporation.