HNHacker News
TopNewBestAskShowJobs

sudioStudio64

375 karma · joined November 22, 2014

submissionscomments
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Well, today was the day. I finally got my fill of this site.

Thanks for the memories HN, but this just isn't worth it. I could have been coding. From now on I will be.

Adieu.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
You can actually customize a large part of it and turn all of it off.

You can't firewall it off, but you can learn how it actually works and just turn it off.

sudioStudio64··on Windows 10, Privacy, and the Hole in the Sky
So, a second ago it was that you can't use a local account...but you can, so now it's..."The defaults are bad and people are dumb."

Literally all of the people who install it or buy a PC with it installed have the choice of making that decision or purchase.

And you're right, they won't change the defaults and that's not a travesty of some kind. It actually really doesn't matter to most people. Not because they don't understand it. They do, and they want to use it for one reason or another. People in our technical circles overestimate the importance of this stuff by some fairly crazy amounts.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
I might just be tired of hearing the same arguments over and over, but it I did see the assertion that BitLocker shouldn't be used to keep your "secrets". As if the choice of which drive encryption software you use on your laptop should be your primary concern when securing yourself against an adversary. (The primary concern is to thoroughly evaluate your adversary and look at your available options for opsec and InfoSec. Maybe you need drive encryption. Maybe you need burners. Maybe you should only use public terminals. Etc. It also means seriously asking yourself if you actually have an adversary or just like to think that you might some day.)

Just sort of saying..."How can you trust MS NOT to have backdoored bitlocker just use Linux. Suck it NSA." Won't actually make you secure.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Some of it's pay as you go, oddly enough. But you are largely correct that more money equals more access to these kinds of things.

There is a company in China that paid them to install Office 365 in their data center. There is an amount of money that will make them install it in your data center, too.

I just think that there has never been more choice for end users and a lot of this stuff about privacy is disingenuous. There are a group of people that wouldn't be happy even if MS released their own version of TAILS and hosted part of the Tor network. (It would be "embrace, extend, extinguish!"..."Tor is part sponsored by the Navy...I be MS gives your Tor traffic directly to the NSA."...It's really not hard to imagine the BS.)

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
One other thing. A "pile of power over you"...that's not helping, man. They have some commercial legal arrangement that you don't particularly care for. They can't come and kick you in the shin and torture you. They can't beat you to death and plant a weapon on you or anything. We are talking about an issue that is squarely within middle and upper class privilege in an industry that literally could not exist without government defense funding.

Take, for instance, Richard Stallman is an Alumn of Harvard and MIT. There literally can't be a place that is more establishment. So all of that "freedom" is about being able to use an expensive commercial product that was developed with RnD money from the DOD...but somehow it's morally wrong to not ship source code to a compiler? Can you see where I'm coming from here? The moralizing is pretty arbitrary.

Furthermore, if they did give your content to the Government because of a national security letter how is that abuse of power? Should they not comply with the law? I disagree with a lot of the laws that have been passed in support the war efforts of the last decade, but that's kind of the way that democracy works. I lost, but I still have to live by the rules.

I just think that the privacy absolutism that everyone keeps bringing up isn't reasonable. Even Bruce Schneier says that the way that you actually change these things is through the political process.

Power is a boot on your neck. This is more of an inconvenience.

sudioStudio64··on Windows 10, Privacy, and the Hole in the Sky
I just don't think that's an accurate picture. They aren't recording your voice and storing it somewhere. Browsing and search history are collected by other platforms for predictive browse ahead and autocomplete, and it's a useful feature. App usage is collected for diagnostic purposes.

You don't have to use a MS account. You can use a local account. 10 is different from windows 8 in that regard. You can take Cortana off the taskbar. Use a different browser in incognito mode all the time. Store your encryption keys in a TPM, smartcard, or Active Directory. There are actually lots of options. You have to actually look into it though.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
There's an OS project run by Joanna Rutkowska and some other folks called Qubes that does exactly that. It's really interesting work by sharp people.

https://www.qubes-os.org/

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
And what secrets are those? If you think that you are secure because you don't use bitlocker or windows AND THAT'S ALL that you do...you aren't secure, you just have bad UI.
sudioStudio64··on Windows 10, Privacy, and the Hole in the Sky
That's not really accurate. Maybe we can reach out to someone at MS and they can explain exactly what is being sent. It certainly isn't virtually everything that you do...it's something, it's not accurate to say its everything.

MS people frequent this site. Maybe one of them could get some detail on the subject?

sudioStudio64··on Bokken – Open Source Reverse Code Engineering
That looks like some amazing work. I'm going to give it a try.
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
It actually does run locally with access to API's that you authorize. Just saying...
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Businesses actually have very different privacy arrangements than individual consumers. Its a function of how much they spend.
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
That's the thing, though. I find the constant kvetching about privacy the most cynical thing. None of these posts are news, new information, or even a new take on existing information.
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
I didn't mean to make it sound that way. I actually agree with you completely. I was trying to write for my audience there...my point was just that obviously they will want to gain something from the relationship as well.

You and I are in complete agreement on the subject...I just fell into hyperbole...

:)

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
businesses actually can get a very different deal when it comes to data "sovereignty" issues.

it's really consumers who have the least leverage. If you want an arrangement where your data is encrypted with keys that you store in a tamer proof hardware module you can. It's priced differently, but you certainly can have that. (It's not all that expensive in the scheme of things.)

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
I'm going off on a tangent?

YOU installed their software. You didn't have to. No one forced you to. Don't like the TOS? Call them and schedule a meeting to talk about coming up with a different arrangement...they will want money for that, but you can certainly have it.

The truth is that there is jack all that I or anyone else can say to you that would change your mind about any of this.

Also, I'm not willing to grant that you are reading the TOS correctly...so there's that point. No offense, but its pretty dense and things that are probably pretty reasonable come across as a privacy invasion to people that are really sensitive on the subject.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
That's actually how it works. You give it permission to use your O365 account. You give it permission to use your location either at setup or in the config settings at a later date.

A whole host of the Cortana functionality is local that interacts with online services via API's that you authorize.

I don't think that really anything that I say is going to change your mind, but you could check out some of the video's on Channel9 where they go into it in detail. Some of it's pretty good and if you use headphones you can't hear your co-workers talk about stuff that makes you want to slap someone.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Those aren't even remotely the only two choices here. There have never been more options for an end user of technology.

You don't have to use agree to it. It's a trade off.

If you have different requirements they are more than willing to come up with a different arrangement with you. (Yes, for a fee.)

They aren't the government. They are an overblown bubble gum factory. It's up to you if you chew or not. And there have never been so many flavors!

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
You are completely free to not use it. I'm not trying to be a smart-a here. There have never been more options for end users.

You aren't signing away your rights to privacy without due process...that's your part to evaluate. "Is this useful enough to me that it's worth agreeing to this?"

Also, this is version dependent. The TOS for an individual consumer is different than a developer with an MSDN license, and a business with a volume agreement. Do you have different privacy requirements? Are you willing to pay for them? If they can't make money with the product that they built in the manner that they came up with then it isn't illegal, or really even remotely morally odious, for them to ask for a different payment arrangement.

Now. Do I like everything about life in a capitalist national security state? No way. But do I whine when some vendor doesn't do exactly what I want when I'm really not event scratching the surface of enough money to get their attention? Seriously, man.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
It's insecure by a standard that you are setting. If they can demonstrate an audit log of every admin who has escalated their permission to logon to the container of your data and access it, including the files they accessed, would that be good? (Because they do that.)

Again privacy-violating by your, arguably, very narrow standard. I'm sorry friend, but you are stating these things as if there's no question as to what you say.

More accurately, you might say that there are higher privacy and audit-ability standards that you would require for your given situation or application. I wouldn't be able to argue with that at all.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
I believe that you are mistaken. Could they turn over your BitLocker recovery key to the authorities that would then use it to decrypt your HDD that they have already taken from you? Yes.

Are they going to reach out over the internet and take your data? No. They are not going to do that. I follow this stuff really closely. I promise I haven't seen or heard of a capability where they can remotely take data from your machine and turn it over to the government.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Every company that has access to your encryption keys can be prompted to give them up with a warrant.

You can keep them from having the key. That's one way around it. Using hardware of some kind (and there are multiple.)

You are also free to use another solution that might meet your strict requirements to personally review the encryption, filesystem, device driver, and memory management code of your operating system to verify it's operating to your specifications. There have literally never been so many options for the privacy minded person with the time to pour through a metric ton of C code.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
OK. What I'm trying to say is that backing up to OneDrive is optional. You get the choice. You can protect the key with a TPM or a smart card...It's not an all or nothing thing. You have options there, if you are interested.

The other thing is that it sounds like a lot of privacy minded people can't trust BitLocker despite any number of assurances from MS or code reviews by third parties. AND THAT'S OK. Use something else.

EDIT: I forgot to mention that if you are an admin or just operate your own AD installation you can store the key in Active Directory. The behavior is version specific, I think.

EDIT EDIT: I believe that the TOS you are talking about is specifically referring to online services. I don't have time to stop and read it right now, but I think that you are misconstruing the intent.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
There are dialogs and UI hints that come up when the service is first accessed. Is it enough to placate someone who is seriously concerned with online privacy...probably not. It meets the minimum requirements to not be too sneaky.
sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
But the entire point of the service was to use data mining techniques so that you could use natural language directives to say "add a reminder to my team's calendar to update some presentation in O365, etc"...

Maybe you don't find it that useful, but I think that a lot of people would. It will, in a future release, be genuinely useful. It's getting there.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
I know. I think it's actually pretty cool. (Though it doesn't seem to work well with some builtin mic's.)

I really like the direction they are headed.

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
That's a new one on me.

Bitlocker keys can be backed up to onedrive if you want, but you can also store them in a TPM or a smartcard (physical or virtual).

sudioStudio64··on I noticed some disturbing privacy defaults in Windows 10
Of course you did. Large companies have no vested interest in building systems that do the "right thing" for you as defined by tech types like us who are arguably more sensitive on this subject than most people.

They are building services that take your information and try to do something interesting enough with it to make it worthwhile...and why is it on by default? Because they want to make money off of the new features and deep integration with your information.

This isn't news. But it certainly may be another excuse to have the exact same conversation that nothing will come from.

Never mind that data generated and collected from cell phone usage will always make the privacy impinging features of your laptop look tame in comparison.

Never mind that the only way to stop companies from doing this is through the political processes that everyone seems to have written off.

EDIT: Downvoting because someone disagrees with the principal argument of the post is lame. Cheers.

sudioStudio64··on Sleeping Through a Revolution
I'll take that point. Cheers.
Page 1 of 10Next →