Microsoft’s new small print – how your personal data is abused
edri.org
edri.org
Stallman is an optimist! This "privacy policy" is much worse than what we expect from malware [1]. Cryptolocker might hold my files hostage for some bitcoins, but they're not going to sell me out to aggressive lawyers or overzealous law enforcement.
[1] http://www.networkworld.com/article/2926215/microsoft-subnet...
Closed both Microsoft accounts and cancelled my MSDN and AP subscription renewals.
I do a big chunk of my work on a CentOS desktop machine already. There's not much of a push to chuck everything in an 8.1 VM and start moving it all over. The MSDN licenses I need persist past the sub so that's enough for me.
I've been on the verge of doing this for a couple of months already anyway for ref.
Edit: Also, I'm really not happy about the pro-Microsoft spin all over the media recently. It appears to be covering up a number of nasty changes behind the scenes and lacking in critical analysis.
Edit 2: Proof: http://imgur.com/a/ZYWZM
Edit 3: does anyone know of a decent 4G modem for a laptop, preferably one that works in Linux. I can then skip my phone as a tether and use a dumbphone.
Annoyingly my ThinkPad has a Gobi 3G card in it but I've got used to 4G speeds now.
I appreciate the sentiment there, but you'll have to close pretty much everything if you really want to protest the abuse.
Don't use any stock/operator/manufacturer version of Android either, by the way. They're full of spyware.
I'm not touching Android. Too many bad experiences there about a year ago for me.
i.e. no smartphone at all.
Short of that, you can just load CyanogenMod or another AOSP-based ROM on most devices. It's entirely possible to use Android without the proprietary Google Apps bundle.
I ran my own mail server (postfix, dovecot) for a few years so I agree with you entirely there!
If they did some static hosting included that'd be nice too but I can't complain.
https://wiki.freedesktop.org/www/Software/ModemManager/SupportedDevices/
It doesn't explicitly call out 4G support so you will have to work backwards.fyi: some laptop firmware, such as thinkpads, have a whitelist of supported WWAN cards. If you can't find a suitable internal card you can use a USB dongle without restriction.
I've got a ThinkPad X201 with a built in Gobi 3G card already. Just used to 4g speeds :)
Your X201 has decent support in the free coreboot BIOS, so if you fancy a weekend project you can ditch the WWAN whitelist altogether:
Thanks for the heads up with CoreBoot
https://www.microsoft.com/en-us/privacystatement/default.asp...
"Finally, we will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good faith belief that doing so is necessary to: 1.comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies; 2.protect our customers, for example to prevent spam or attempts to defraud users of the services, or to help prevent the loss of life or serious injury of anyone; 3.operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks; or 4.protect the rights or property of Microsoft, including enforcing the terms governing the use of the services - however, if we receive information indicating that someone is using our services to traffic in stolen intellectual or physical property of Microsoft, we will not inspect a customer's private content ourselves, but we may refer the matter to law enforcement."
Definitely close your accounts if you want to protect your data, no fault there :) But make sure you know that this article doesn't actually tell an accurate picture.
This is extremely important. Right now we have an extremely inefficient market with respect to privacy. Users don't know what policies companies have, and even if they know where to find that information, it's extremely inaccessible. Making it easy to compare services would allow users to actually distinguish based on this metric, which is the first step towards pressuring companies to actually compete on this metric.
Simplistically, this could be achieved with a set of data policy components (account information, login information, purchase information, location information, various activity information items, etc) and their policy on them in well defined terms, such as Not Applicable, Does not collect, Collects but does not share, Collects and may share, Collects and known to share. That would be the start of something beautiful.
They need much more contributors though.
Maintaining it would be a pain. I'd like to see each company maintain their own table of terms and policies.
Other than maintenance, I'm concerned about how conditional sharing would be expressed succinctly... of course it's just a watered down version but you'd have to do it carefully.
The first step would be getting a formalized set of metrics, which is in itself a bit project. Once you have that, a framework to crowd source the specific answers from users (hopefully with references to a TOS/Privacy policy section) would be the easiest way to keep it up to date. Allowing comments and annotations for further info on a specific company's rating for an item that could be expanded would let people drill down on the details.
If you want reliable protection, you eliminate or block those mechanisms which expose information to others. You could create a matrix which identifies different types of exposures and shows which can be avoided when using a given product or service. It would be a major task though, because technical details that are often not well documented can have a big impact on exposures. You couldn't afford to miss something like a user identifier that accompanies phoned home data.
The whole point is making it easy to judge how companies interact with their customers in regard to data and privacy so market pressure can do it's thing.
Additionally I'm not entirely sure how to split out all the different things to track with regard to privacy, which is why I think it's a big project. But I see a need, and I think someone could do well for themselves filling that need.
They could have an expanded version with more details, which satisfies both goals.
Unfortunately, I'm far too burdened with commitments to do this myself, so it's more a call to arms than a statement of intent. :/
This is probably for Cortana. She has to understand and process your voice commands, learn your nickname and preferences to be effective. She already works in Windows Phone (very nicely), and I don't think a little phone processor would be enough to power her up. In fact, she doesn't work without an internet connection, at least in WP. What happens is that she takes the information you input to the cloud, processes it there with more than enough horsepower to do her stuff and brings it back to you. I suppose this is how it'll work as well on PCs.
So for all this to work, yes they need to collect our data. Face it, with any smart assistant that we want it's going to be the same, they're all cloud powered. Doesn't Siri also require a internet connection? Probably Alexa too, and any others work exactly the same.
It is a necessary evil to have a useful virtual assistant. Although if we don't want her we can opt out of the MSA account, as someone posted in the comments. Unsure if that removes all the privacy concerns, that would be useful to know. On Windows Phone it did (you can opt out of sending data to MS and Cortana is disabled).
The fundamental problem with this privacy policy is the scary wording. When Gmail first came out, Google was (probably) the first company to read emails to figure out ads. But they enforced the not-touched-by-human-handsiness claim hard throughout. MS, on the other hand, not only says it will collect data but again and again mentions "disclose when necessary." There are too many uses of "disclose." It almost sounds like they will just hand over data without much conviction.
[0] https://www.microsoft.com/en-us/privacystatement/default.asp...
There's also a Data Retention section further down that specifies how long your data is in their servers.
edit: In the top section (Personal Data we collect) it also says: "You have choices about the data we collect. When you are asked to provide personal data, you may decline. But if you choose not to provide data that is necessary to provide a service, you may not be able to use some features or services."
Few IT departments will allow opting-out -- it'll be part of how your work computer is setup, and part of your job to use it.
https://www.microsoft.com/en-us/privacystatement/default.asp...
"Finally, we will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good faith belief that doing so is necessary to: 1.comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies; 2.protect our customers, for example to prevent spam or attempts to defraud users of the services, or to help prevent the loss of life or serious injury of anyone; 3.operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks; or 4.protect the rights or property of Microsoft, including enforcing the terms governing the use of the services - however, if we receive information indicating that someone is using our services to traffic in stolen intellectual or physical property of Microsoft, we will not inspect a customer's private content ourselves, but we may refer the matter to law enforcement."
> It is a necessary evil to have a useful virtual assistant
Not necessarily. With things like the Jasper Project [0], you can run your own personal assistant that decodes voice on your machine and doesn't use the cloud. Granted, Jasper doesn't fit in your pocket (yet).
Microsoft licensing is hellish, I've worked with it for years and I still don't entirely understand it.
Most of this was down to a SQL Server upgrade where core and CPU terminology was changed.
Our main SQL cluster is two 48 core HP machines with 512Gb of RAM each and a big EMC SAN. We want this as lots of much smaller machines but you can't really scale down SQL Server once everything is coupled into it.
Redis looks nice but I suspect that it may be easy to lean on it too much for functionality. We were looking at it for a couple of tasks but haven't found much motivation to move yet.
http://i.imgur.com/Q8NtKTk.png
Cache hits versus misses. The latter may result in multiple SQL queries whereas the former are returned from the cache. Imagine the cluster we'd need to support that!
That's over 28 days for reference.
That isn't the same as we couldn't get some benefit, because we could especially as the userbase scales. But so far we haven't had to scale to the point where it's worth the added complexity to persuit. One can only look forward to the day it is.
Right. Funny how 'best practice' became to use stored procs rather than generated queries. Partly because it constrains and defines the API exposed by the DB and greatly helps avoid SQL injection issues. Those things can also be achieved with a well written code layer, and as for the 'API', well, we have so many stored procs that that argument has become somewhat tenuous.
There's the performance aspect as well - having the DBA know what queries will be 'thrown' at the server. But again, it's not black and white, it's more that the stored proc does tend to limit really bad SQL queries moreso that open ended srting queries, but 'it depends'.
Our main issue (IMO) is that if you get a SQL Server person in to solve SQL Server performance issues then you're likely going to go down the route of one massive all powerful SQL Server box which just compounds the problem. A broader solution of moving away from pure SQLServer and towards distributed work, caching layers, etc. is probably a saner long term path to take. But in business short term thinking generally takes precedence over long term.
The immediate cost savings is all the business sees.
The French revolution, US revolution etc. talked about and put equality into their constitutions, and that has kinda been the prevailing world view ever since. Although, I guess the real cause for this were technologies like the printing press, gun powder and the assembly line - technologies that made people more equal.
But now, even if most people hear about this, I'm guessing that most will continue using Windows. For the last 200 years or so, we've had various leaders standing up for the little guy, but I wonder if anybody will bother in the future, when they see that most "little guys" will not even bother to switch operating systems or use a different search engine in order to preserve their freedoms and rights.
Only when we cease to consider Corporations more important than the rest of the economic actors can we move the balance of powers back where the it has been intended by the previous revolutionary movement.
But this is kind of off-topic with this news.
I hope MSFT get a bash for this kind of niceties and implement an opt-out solution for all their in-built spyware.
Can you unpack that for me? I own a corporation and enjoy nothing of what you mention. I fear I'm missing out on something.
Regarding their power, I think that corresponds to corporations' ability to amass wealth and influence (often) faster than an individual. Of course there is a spectrum -- national defense contractors with billions of dollars in the bank can have a surprising amount of say in the way things are run, but an incorporated small business might have a hard time getting a local zoning issue addressed.
But what the other comment mention is on the right track as members of a corporation can easily rip the benefice produced by it, but can as easily distance themselves from it, should it find itself in financial or legal troubles. Of course one can argue that owners and decision makers from that particular entity can be sued individually. And that's fine as well.
And before anyone mention, that investor should have some kind of protection, may I kindly remind you that there should be a balance: the Greek bailout (and the other big bailout from the last few years) is anything but a way from private entities to off load onto the public some mistakes they have made. I don't know of a single instance of a family that has had their debt wipe out during the same period.
I guess there is a critical size to acquire for any social actor to be able to leverage the government and the law makers into protecting them from catastrophic outcome.
And this differs from Google's and Facebook's usage policies how?
Throwing out a red flag at this point for a corporation stating that people^H^H^H^H^H^H^H users are their product is the quintessential example of "closing the barn door after the horse is out."
This article has nothing to do with Google and Facebook. It doesn't even mention them.
I think the article's purpose is to dispute the claim that the terms aren't as "straightforward" as Microsoft would have us think, as evidenced by the sarcastic closing line, "So much for clearly understandable and straightforward terms of service."
In part, it is quite convincing. Phrases like "or as necessary" and "we collect voice input, as well as your name and nickname" is a little unsettling to me.
Agreed. My point was not that the article critiques either of those organizations, simply that this move by Microsoft is quite comparable. To the point of being indistinguishable, IMHO.
> I think the article's purpose is to dispute the claim that the terms aren't as "straightforward" as Microsoft would have us think, as evidenced by the sarcastic closing line, "So much for clearly understandable and straightforward terms of service."
I recommend detailed reading of the ToC's the various Google and/or Facebook offerings which you are interested in as well then. Perhaps they are less shrouded in "legalese", but I submit their implications are no less disturbing.
The problem is not Microsoft. They're actually only doing it now because smartphones gave them permission.
I respect the point you are making, yet must point out that all it does is establish a timeline. There is no significant difference between the three companies' treatment of their customer base in this regard.
And don't forget, including Google _also_ includes Andriod.
> Given MS makes their money mostly with enterprise/businesses I doubt that this will succeed.
I believe it would not be a surprise to find that the enterprise/ultimate/wtf-ever-they-call-it are excluded from this. Of course, I'm sure a user could receive the same exemption should they choose to pay the fee...
Correct. What's different is the customer's expectation (so far) about this treatment. IMO this is significant.
> I believe it would not be a surprise to find that the enterprise/ultimate/wtf-ever-they-call-it are excluded from this. Of course, I'm sure a user could receive the same exemption should they choose to pay the fee...
I would certainly hope this to be the case, but so far this is AFAIK just speculation. Did MS think as far as building in these use cases? After what they did to the desktop UI (even on Windows Server) on Windows 8 I have stopped to just assume Microsoft knows what they're doing.
I was going to discuss customer expectations and how they vary when smart phones are involved. But your statement quoted above is simply too good.
I submit it as a candidate for the Windows equivalent of Godwin's law[1] but without all negative implications :-).
Well said.
Let's remember that you aren't running your desktop on facebook, you can use custom android rom or self-built chromium that doesn't interface with google.
I believe the problem (and I am outraged about that) comes from the fact people are paying for Windows and practices such as the collecting of e-mail and contact shouldn't be necessary for 1. the OS to run smoothly and 2. for MS to cover for a low selling price.
The OS and its default bundled application's set price should be enough to guarantee MS doesn't need a user's private data and metadata to provide the product (aka: we gave MS some money, they shouldn't need our private data to make money in order to keep the price `low').
There are many things like "data about network you connect to" that need to be collected and stored on the device unless the user wants to introduce the same password over and over again. This has to be stated somehow and phrased.
Now if MS stores it on-line through the windows account for convenience it's almost the same thing if it's encrypted and hashed so MS just stores something that can't be exploited if leaked.
I have been looking at Surface recently and now I wonder if I can run Debian on it.
[0] but considering the upgrade path implies a paid product (win 7/8) it's a huge change for the user and my point still stand.
The consideration I hope to make evident now is: how do your points differ when applied to an Andriod device for which Google has been paid their licensing fees by the device manufacturer?
Facebook's offerings are different, true, yet their Machiavellain use of whatever is presented to them warrants inclusion in this type of discussion IMHO.
As far as I know, Google charges no licensing fees for Android (not even for the proprietary apps / "Google Mobile Services").
http://9to5google.com/2014/01/23/google-we-do-not-charge-lic...
While Android is open source, the Google
applications, like the Play Store, Gmail,
Google Maps, Google Play Services, and others
must be licensed. This licensing agreement is
called the "Mobile Application Distribution
Agreement" (MADA) and comes with tons of
restrictions.[1]
This is only one example and the monetary considerations are unknown.1 - http://arstechnica.com/gadgets/2014/02/new-android-oem-licen...
By very little. Why are you still using google and facebook?
Was waiting for someone to bring that up. Microsoft has never done anything different than Google does yet, until now, no one bothered to check up on Microsoft. However, Microsoft has its tentacles more tightly wound around Windows users.
If you charge me $25/year to use facebook, I know what that means. If you charge me $25/year to use google, I know what that means.
Now, however, the currency of the Internet is privacy, and not very many of us know what that means. It's still too abstract- and abstract thinking is hard for many of us.
In that day, targeted ads weren't a major source of revenue (revenue models were still being worked out). Many web sites built primarily for Microsoft then-that is, taking advantage of their standards-breaking browser. The public didn't really cared about any other browser (by that I mean the same "public" that doesn't really care about privacy now).
Microsoft did many bad things in that day. But if you wanted people to be able to use your site it had to work in IE (version 5 or 6 or so-I don't really remember). If it didn't work in Netscape it was no big deal. The web page would say "best viewed in IE5.5 or later" (or whatever version).
So, no, websites couldn't afford to block Microsoft. They would lose their customers.
>So, no, websites couldn't afford to block Microsoft. They would lose their customers.
I see. So they can't afford to block Microsoft, but they can afford to have their main revenue stream cut off by Microsoft.
Not then. Ads weren't the (major) revenue stream then.
I see.
No, you obviously don't. In fact, it seems like you're not even trying. Whatevs.
Unlike Microsoft, Google didn't criticize their competitors for their privacy polices. They really are hypocrites.
Not linking a Microsoft account with the local account seems to be a good starting point. I also plan to do my best to get rid of OneDrive and Cortana, neither of which I have any use for. But I have no idea how to go about discovering and tackling all the other possible channels for data leakage, which we're bound to hear about in the days and weeks to come.
Free upgrade means you're no longer a customer. It's a cliche, but it fits perfectly this time. Some of the things I'd like to disable will probably require upgrading to the Pro edition, which of course is only available to paying customers.
"Today we were unlucky, but remember we only have to be lucky once – you will have to be lucky always."
At least if I get Windows 10 Pro, I'll be able to turn off non-security-related updates.
No longer true. Canonical took a lot of (deserved) flak for making that feature opt-out, and last year they finally fixed it [1].
http://www.omgubuntu.co.uk/2014/03/ubuntu-make-amazon-produc...
.... but some searching indicates that they won't get around to disabling online searches by default until Unity 8 is default in Ubuntu. It seems that Unity 8 won't be default until 16.04 [1] or later [2]. So I rescind my previous statement. Canonical deserves as much scorn as you can dish out for disregarding their users' privacy for 3 years and counting.
[1] http://mhall119.com/2014/10/unity-8-desktop/ [2] http://news.softpedia.com/news/Ubuntu-16-04-LTS-Won-t-Have-U...
The wired world leaks data. Much of it by design, e.g. to a first approximation all browsers work with cookies, store history, cache content, use some sort of thumbprint for SSL, etc. No browser vendor promises operational privacy because implementing it would make the browser unusable. Just using NoScript (as I do) is a bit of a pain in the ass. Microsoft has a browser plus a whole lot more stuff including third party vendors, and big stacks of cash to make itself a lawsuit magnet...some lawyer somewhere will allege transmitting an IP address is breech under a strong privacy policy.
The reality is that nothing you do on a computer connected to the internet should be considered private. The Microsoft privacy policy reflects this reality even if it upsets the world some of us wish existed [so long as we don't have to give up our mobile GPS, Uber, and iTunes]. But it hasn't existed since the days of credit card processing over copper. I admire Stallman, information wants to be free. Alas "An atom blaster point is a good weapon, but it can point both ways."
Amen. This is what I have been telling people for the past few years. If you put something online, consider it public and irrevocable.
That doesn't excuse Microsoft and others for becoming more and more invasive. And voting with your wallet works.
I read Microsoft's policy as more legal cover for the reality that data gets stored all over the place. The internet is full of caches and nobody can guarantee that they can identify all of them, much less control them. The nature of people's complaints show how vulnerable Microsoft is to some jury believing "they should have known."
If you want privacy, don't turn on your internet connected devices. TANSTAAFL.
Why is it free? First of all because they are scared to death that iOS and Android will eat their lunch in the consumer space. Secondly, because they want to sell services and SaaS (Office 365, etc.).
For the latter part, you can certainly vote with your wallet.
I'd say RedHat/Fedora/CentOS ecosystem is probably a more likely business model. Microsoft was already in that space (e.g. Mono).
1. preinstalled / bundled Windows is not free, the "Windows tax" being very real
2. this upgrade is not free for XP / Vista users
3. Windows 10 is not free and will probably cost about the same price as Windows 8.1, which is $120 for the Standard version or $200 for the Pro version - it might turn out to be cheaper this time, but that's only because they are changing the license to be tied to a particular device
4. Windows being a platform, is a complementary to Microsoft's Office 365, OneDrive, the Windows Store, Exchange, etc... the Windows Store in particular charges a revenue fee and is the only source possible for "modern apps"
5. personally I can't use the standard version, as it is missing features I need, like BitLocker or the ability to make a bootable USB drive - things that with the other operating systems I get for free
So in case I haven't been hibernating to wake up in some weird future in which a beer costs $200 and comes with strings attached, yes, voting with your wallet is significant.
Any of the popular Linux distributions are much less invasive than Microsoft's Windows 10, plus if you have the resources, you can audit it for backdoors (e.g. my government can certainly audit a Linux distribution, but they'll never be able to audit Windows). A Linux distribution is currently the only reasonable choice for privacy and security. Also take disk encryption. The way Microsoft is doing it lately is for the encryption keys to be sent to their servers, tied to your Microsoft account. On Linux you've got dm-crypt, ecryptfs, battle hardened firewalls and SELinux/AppArmore, all open-source and open for inspection, free as in beer as well.
Of course, you've set myself up for failure by demanding "comparable services". You know what, I could live without things like Cortana, Google Now, or Siri for a long time and while I get the potential, for now there is no benefit. Google Now somewhat helps with my traveling or daily commute, but that's a task for my phone, not for my laptop. Microsoft is continuing to break the utility of the desktop. That's too bad because all of this post-PC craze is misunderstood and I hope others will jump on the created opportunity.
So let's accept that as a baseline? Why is that even 'normal' ?
It's my PC, not theirs. I licensed the OS, but I didn't tell them to do any other thing. My PC is connected through routers which at least for the first hops I control myself, how is it then 'normal' I still am not able (!) to stop an outside company from peeking into what I do on my pc?
More importantly, that information about you leaked because of your deliberate decision to connect to the internet. The only way Microsoft could have protected you is to prohibit your connecting, and even then you'd probably work around it because that's more or less how Windows 3.1 machines connected to the internet (with 3rd party software, I'm not suggesting Microsoft prohibited connecting, they just didn't support it).
Load on user land apps and more information leaks, and Microsoft can't prevent it. Run OS features that require a web backend and there's more information leaks. Nobody can provide a fulfillable written guarantee of privacy for web connected apps. Microsoft's privacy policy reflects this reality.
Can Microsoft treat your with a different level of respect for your privacy than Google? Perhaps, since its business model is different. So it's really a matter of tradeoffs and trust and alignment of interests. If Microsoft's policy is a problem, and it's no worse than Google's provision to use your data for new products and services, then don't use Windows. But at least Microsoft is being honest for the industry standard definition of "honest". That that standard is less than "We'll use your data however we please" is unfortunate.
I must be missing something here since I know Microsoft wants Windows to be used for businesses and the privacy of this information is vital to that.
They have already banned use of Microsoft's new mobile Outlook apps (iOS,Android,Win Phone) when they found out that these are actually thin clients to a cloud service that performs MITM on the hospital Outlook server to download, store and processes all email (the cloud servers aren't even fully Microsoft--they became Microsoft's via acquisition). And of course it stores usernames and passwords in order to accomplish this (confirmed by common sense, obtuse fine print and deceptive non-denials by Microsoft support). The penalties in HIPAA and HITECH aren't jokes (and now include jail time).
I just forwarded some comments re MS's privacy statement to a law-related listserv. But everyone responded they couldn't see the text I cited from MS. It turns out that the document looks very different with noscript than it does without. With all script allowed (ie for those using IE/edge) all the scary stuff hides behind "learn more" buttons.
Check it out for yourself: https://www.microsoft.com/en-us/privacystatement/default.asp...
I'll be adding this underhanded approach to my loooong list of reasons to love linux.
And don't forget windows comes with Defender installed, which collects user metrics out-of-the-box. IE/Sparta also collects your usage data. Even windows "search" does.
What I was talking about is an online feature, called Windows Account, which works online by default(!). Therefore we must ask ourselves what is Microsoft doing with that information.
Please do demonstrate/prove that then.
https://news.ycombinator.com/item?id=9224880
I had a feeling about this ever since the first announcements that Win10 would be (monetarily) free. That old saying is still relevant as ever: "If you're not paying for it, you're the product being sold."
How do you trust a company like that with any data?
Created new and unique Microsoft account
I figure it was something he hadn't used before.If you create "james053164@hotmail.com" it will get spam eventually.
(Well a bit faster now that it is indexed)
If you want to be treated like you live in a box, then you're going to have to live by it.
Everyone complaining and "fed up", closing their MSDN accounts, boycotting MSFT products - you're in an echo chamber which won't be felt as our devices become more service oriented rather than boxed solutions. MSFT is trying to stay relevant, not undermine their massive user base. Whether it is right or wrong, I don't have an opinion on, but if you think MSFT is a pioneer in this space, you're being unjustly biased.
you want a service that requires your data? you have to give your data. you don't want to? don't complain for the missing service!
Perhaps these are growing pains for the direction services are heading, or we'll just learn to accept invasion of privacy as a default.
I don't like the bloat, but I don't see it as more privacy invading than any other system logs.
As this comes out-of-the-box by default, and is in fact a pain to switch off, I compare it to this new windows behavior.
Should we compare syslogd to the new Windows behaviour?
Zeitgeist itself runs with the users privilege (it's not a system daemon, it's started by the user's session), so that hypothetical application could simply log the data itself. There's no leak of information to underprivileged processes.
On similar note, I rememember someone arguing that the baloo/nepomuk db was a security threat, I guess since it makes slightly easier to search among the files on the system for a string like "password".
Both claims are technically true, and in neither case I believe they are practically relevant, neither for security nor for privacy. I was nitpicking, I guess.
Syslogd can be compared to windows event logs.
Ubuntu, on the other hand, does not have such a commitment to free software, and has included Amazon ads in the Unity dash in the past.
[0]: https://www.debian.org/social_contract
I simply don't have time for that on a day to day basis where I need my machines to just work. I need it to work to the extend that I now have a base machine running Windows and with VMWare Workstation installed. All production work is done inside a VM with daily snapshots so I can always go back to before it was broken, and then tackle the issue when I have time for it. If my machine suddenly goes up in smoke, I can restore my production machines on another machine. I never have more downtime than buying a new machine, installing VMWare WS, and restoring my VMs results in.
My biggest problem was multiple monitors. The setup was, and still is, an absolute pain to get working properly with difference screen size and dynamic docking/undocking of a laptop.
Transparency is a dependency of trust. While many components of OS X are open-source, even more are entirely proprietary and opaque, and therefore untrustworthy. Not to mention that Apple is the king of absurdly-long-and-unreadable EULAs.
First is technical. Encrypt everything on originating devices and store the encrypted copy to which Microsoft would have no key (not even escrowed one). Not like this works for all cases, but a lot of data - like browsing history or WiFi AP passwords - does not require server-side processing.
Another is legal approach. Have sane privacy policies - not "we'll use your data as necessary" - and make sure users opt-in. Not like this also works - certainly not against all adversaries, but at least you can sue.
This is a hyperbolic statement. Here's a fixed version: "Microsoft has created an opt-out privacy-hostile software ecosystem"
The world is not Microsoft. You're free to use alternatives.
I may well be free to go live in a (digital) cave but presenting it as a viable choice merely exacerbates the existing problem.
Point 2 is probably not unusual but were starting to see (imho) more pernicious attitudes. Examples include the current Windows discussion, where your employer may be perfectly happy to sign (on the employees behalf) that your data be sent off to Microsoft (and used for whatever Microsoft deems 'necessary'). There was also the announcement of Facebook at Work, which I'm sure would be more than happy to cross-correlate the 'work' you with the 'personal' you, in order to 'provide a better service'.
In both these scenarios, I'm sure the company will act to protect itself from exposure, but it's unclear what choices the employees really have.
Anyway is it not as if apps aren't collection information on people without asking already.
I know this isn't binary some data may be dual purposed (training and ads for example) but I'd like to see an audit of what it's used for.
I'll never get that, but it would be interesting.