XP, Phone Home
Randomeyes writes: "The Register reports that Windows XP has functionality built-in to the Search Companion module that allows Microsoft to log users internet searches. Information collected includes user IP address, search term and related information. A cookie is also set. 'TrustUnWorthy Computing' anyone?" Tanveer1979 writes: though, that "the bright side is that it doesn't send anything to internet, it only downloads files, and compares the files on your computer with the files on server. And I guess a little effort is needed for the malicious to program it to send your data to web."
I just saw it on my Microsoft Baseline Security Analyzer ©®(TM):
.NET ©®(TM).
View Security Report
Sort Order: Score (worst first)
Computer name: MYADSDOMAIN \WindozePeeCee
IP address: 225.-1.65535.1
Security Report Name: MYADSDOMAIN - WindozePeeCee (04-12-2002)
Scan date: 12/04/2002 12:00AM
Hotfix database version: v2.0.10^23+[1/(planks constant)]
Security assessment: Sever Risk (As usual)
Windows Scan Results
Vulnerabilities
Windows Hotfixes
1. Local Account Passwords are simple or Weak. Please change them to something overtly convoluted and difficult to remember. It wont matter anyway because the Active Directory Server©®(TM) you authenticate against is probably not patched.
2. IIS©®(TM) Installed. Please update to Apache 1.3.24 or 2.0.35
3. JRE 1.4 is installed. Wow. That's even more bloated than the first revision of
4. Auto-login is enabled. This is inherently dangerous because this OS has no inkling as to what multi-user means, for whatever reason, everyone is a su-doer.
5. Passwords are too short. This is weak because the domain controller isn't patched. If you are running Samba 2.2, please disregard this. We can't tell the difference.
6. File systems. They all appear to be running NTFS. Good (you should have two UPS for this. If its get corrupted, snicker.........)
7. Your Cell Phone, Palm Device, monitor, printer, hub, DSL router, joystick, speakers, KVM, other PCs, scanner and filing cabinet do not have Client Access Licenses.
8. Sent all info to Microsoft.
© 1999 - 2009 (We paid of the US DOJ until then, they only take kick in decade increments), All your rights are belong to us.
xenon baxter meowmix purina
they were so forgiving! It's sounded bad to me... but maybe I'm getting out of touch with what it's really doing.
If it contacts the interent on a local file search, then that's bad. If it contacts microsoft when I search the net, that's bad.
This "we can't identify you" stuff is a lie that should be well known by now. What they mean is "they don't have your name in the file, we would have to look that up".
Maybe someone can explain why half the article is about mentioning this doesn't matter?
-pyrrho
Isn't this just a cache
I mean, netscape keeps track of my bwrowsing history. MS Find keeps track of my last searches.
BASH keeps track of my last typed command.
Usually this comes in handy. Hell, I can probably code something that will post my BASH command history and my netscape browsing archive onto the net.
What's the news here?
If an experiment works, something has gone wrong.
the bright side is that it doesn't send anything to internet
Doesn't sound so bad to me.
Donate background CPU time to fight cancer.
In the USA, Internet access is usually a monthly subscription and that's it. No phone charges, no charge per minute, just a certain amount of bandwidth per dollar spent.
In Europe, some people have now got access to 2 types of "free" Internet (neither is free).
Which brings me to my point. If Internet connections are configured in such a way (as often they are) that the connection happens transparently because the username and password are stored, then people are going to pay call charges to search their local disk. If they don't realise this (especially in the case of ISDN connections) then they may run up quite a bill when they do an extensive search every time they lose a file.
I don't like this Internet-integration with the desktop in the OS. Sure, if I want it to happen, I can download some software helper. No doubt by hacking the registry or something equally scary for any novice user, you may be able to switch this off. But it reeks of abuse of my phone line.
It's interesting, no, that Microsoft do not necessarily take account of the European market when it comes to actual Internet access. Sure, they do multi language support but what about this particular Internet case?
I have clients who have been caught with huge bills due to shit like this before. Like transparent connections happening when they are not surfing when connected to an ISDN router which connects when any packet that is non-local causes a router to connect. I know that this can (and is) fixed on the router with better access lists, but the packets themselves come from crappy Microsoft things like MSN Messenger trying to auto-connect at boot and various SMB packets.
It's time that the Internet was a separate part of the desktop. Plenty of people embrace the Internet, but many others will not, especially in countries where it is still expensive just to stay online an hour costs me $2. That's right, a crappy 33.6K connection costs me $2 due solely to phone connection charges.
Conversion Rate Optimisation French / English consultant
Obviously this isn't surprising. You have information Microsoft could possibly sell, and it is certainly information they can use. Of course they're gonna try to get it, and try to keep it quiet. This is happening more and more often, and it's everyone, not just Microsoft.
:)
I do use XP, mostly as a gaming platform, but I use Mozilla, and when I'm not playing games often I am running Linux on the same box. This doesn't have me worried one bit. Some people are gonna get all in a twist about this, but this is just a small step towards the ultimate goal: human batteries.
This does make me wonder, however, since Microsoft is causing bandwidth to be used on my network for activities I have not expressly envoked, can I charge them for use of my connection?
I say, charge them for use of my bandwidth. They won't get it free out of me. I just wonder where do I send my bill..
Ever heard the idea that if you throw enough "crap" at a wall something is going to stick. With all these companies suddenly forgetting how to treat their customers, it takes a lot of action by informed people to oppose things like this.
I fear that we risk spreading ourselfs thin in the upcoming onslaught of unreasonable software, privacy policies.
Chicago2600.net more than a lifestyle, its a survival trait.
This is stupid. Why are people being so paranoid? Of course a search engine needs to know what you're searching on! You reckon Google doesn't log what you searched on? Or your IP? Of course it does... Stats are valuable - even if you don't sell them to anyone. The Register is known for spamming it's own front page with poorly written "non-event" news stories written by poorly informed editors feasting on hype from other news sites.
I'm disappointed in any slashdot editor who thinks we need these stupid articles pointed out to us.
Nick...
It states very clearly that it only attempts to download certain files when searching on the local machine / LAN / ... and DOES send information to a *.microsoft.com server when searching on the internet through the utility.
----
--
[insert witty one-liner here for your own pleasure]
To which I'd add, it also shows a problem with the culture in the organisation that makes the stuff. It's not so much arrogance, but something more akin to carelessness: an inability to appreciate that other people - including some of your customers - may have different criteria and preferences than yours. I personally doubt whether the people who developed this even thought to ask themselves whether this behaviour would be considered reasonable, nor that it was ever considered in any formal reviews that may have taken place. And it's far from the first time that I've got that impression about MS: their use of that reserved field in the Kerboros protocol feels similar: not so much malicious as just a failure to know and appreciate the etiquette that had grown up in an area that they were entering for the first time.
There's a reason we keep 800lb gorillas in cages...
I don't have an XP box handy, but I'd like to see what happens if you change add sa.windows.com to the host file and make it point to 127.0.0.1. Or to some other server. It would be nice to be able to send other files then the ones MS wants you to get...
No sorry, you're not quite right here; The Register says that a local search only results in the search agent doing a quick version check on some XSL files - it doesn't send your search terms. Hardly an invasion of privacy.
It's only when you do an internet search that it sends your search terms.
It even says "For now it appears that there's nothing here for users to worry about." - and this is The Register talking!
When you do an internet search, it sends your search terms (so it can do the search!). This is hardly an invasion of privacy... If you really want privacy - don't connect your computer to a public network.
Nick...
Ah Microsoft stop the secrecy.
The actual act of aggregating search engine data itself it not particularly bad, its just the way the have to keep all this stuff secret, even if they're doing something innocent, they make it look sinister and because of their history it looks pretty bad, whatever the real reason for doing this.
For marketing reasons, I can see it being useful information to a lot of companies, if they are strictly aggregating data as they say.
Is this for use on MSN etal, as obviously to sell keywords they need to know generally what words are the most popular, and they can't do that without aggregating data about people search preferances.
Is this any different to say googles toolbar, Ok before I get flamed I know google do it right and gather info on an opt-in basis, but all search engines want to know information about our browsing habits, thy've got to make money some how.
Microsoft don't seem to be doing anything really bad here, its just like their software the problem is with the implementation, if they only made it absolutely explict they were doing this it would not be a problem.
Microsoft you build in cookie management to IE and then build in 'freatures' like this without any opt-out, you're just asking for bad publicity here. Guess it must be the pointy haired marketdroids at work.
When I first saw the title I thought
"Ok it will phone home, that means that soon we will get rid of it"
Would you all kindly read the damn article before you start your ranting.
It all boils down to the fact that when you use the file search tool, it connects you to the internet and downloads a privacy policy type of file.
That's it, the end. Period.
When you are on the internet and perform a web search through XP, they log what you searched for... Even google does this for purposes of finding the most popular sites, and creating a table of the most popular searches and all that. This subject is not only trivial, but misleading in the context of the article... They quickly switch from talking about an offline file search which downloads a single text file when you first use it, to a completely different subject of a search tool recording what you searched for.
Of course, the ironic thing being that this web search tracking is no worse than the Netscape 6 tracking discussed a short while ago.
And if you haven't heard it enough so far, local file searches download a single damn file when you first use it. May seem a stupid thing to do, but it's not phoning home, it's not tracking your habbits, etc.
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
Sadly the two posters above me haven't read the article properly.
8 359 for a good comment on that subject.
True, when searching local files and intranet, nothing about that search is sent to Microsoft.
Now, I haven't used XP, so I don't know how the Search Assistant works, but apparently you can tell it NOT to use MSN for searches, but something like Google. I don't mind Google collecting info about my searches, but I do mind when Microsoft collects info about my searches on Google - that's simply none of their business.
As a poster above me mentioned, many people in Europe have to pay for the call-time they use when surfing. Why should they have to pay a minimum of 5 cents to their ISP, just to search their own harddrive? I can't think of a single good reason for that.
Read this post: http://slashdot.org/comments.pl?sid=30967&cid=332
The privacy statement for Search Assistant has the following provisions, which is what I base some of my arguments on:
http://sa.windows.com/privacy/
"No information is ever collected by Search Companion when you search your local system, LAN, or intranet for any reason."
"When you search the Internet using the Search Companion, the following information is collected regarding your use of the service: your IP address, the text of your Internet search query, grammatical information about the query, the list of tasks which the Search Companion Web service recommends, and any tasks you select from the recommendation list."
"Search Companion does not record your choice of Internet search engine, and does not collect or request any personal or demographic information. Information collected by the Search Companion cannot be used to identify you individually, and is never used in conjunction with other data sources that may contain personal data."
Now, like I said, I don't use XP, I don't know how Search Assistant works, and I probably wouldn't even use it, but it's still a bad thing to do for two reasons:
1) Making people pay their ISP/phone company to search their local harddrives.
2) IF I can make Search Assistant use another search engine (like Google), it's none of Microsofts business what I search for. If I can't use another search engine, then obviously Microsoft has to know what I'm searching for.
We do not live in the 21st century. We live in the 20 second century.
For those who don't know, Thomas C. Greene is the Register's equivelant of Jon Katz. His job is basically to find things to be angry about, and he does that very well indeed. He has just enough technical savvy to appear credible (think Steve!!! Gibson!!!!!), but that doesn't actually give him any deep cosmic insights.
If you were blocking sigs, you wouldn't have to read this.
Hey, it only downloads a file, so let's stop thinking now. There are some things bothering me here though, but maybe you can help me with it, so i can soon embrace blissfull ignorance again:
Do the other downloaded files alter the system behaviour in any way? They're providing information connecting file-extensions to file-types at least, and that might have some impact on a windows system. And if they don't do anything at all, why download them? Maybe i'm using a special app with uncommon file-extensions and took some pains upon me to make the system recognize them. Will that work be undone with every search query?
Then "downloading" is not a onesided action. To download a file i have to establish an internet connection, and in that process all kind of information is transmitted, not just the ip. I don't think someone concerned with network security of some larger corporation would be too happy about all their desktop machines sending out packets announcing their ip, the number of hops to them and the type of their operating system beyond the firewall to a specific location without need. Also why should anyone trust Microsoft not to collect all that ip-addresses to compile a nice list of windows-XP installations, maybe to set up a BSA-raid?
And finally: Why do such a "stupid thing" as downloading a privacy statement for an action that can be performed locally? Just to get some load on Microsofts server? Microsoft is paying for that bandwith, so why put extra load on it? Well, maybe someday in the future Microsoft will quietly decide to change their privacy policy and start collecting information about your local/intranet searches. But there's no need for you to know that. Only your Operating System needs to know.
"By the way if anyone here is in advertising or marketing... kill yourself." -- Bill Hicks
IANAL, however this probably illegal under UK (& EU) Law.
In the UK we have the Data Protection Act, which states that a Company may not share personal data with others, without the Data Subjects permission. They may not send Personal Data abroad, unless the data is equally protected 'abroad'.
http://www.hmso.gov.uk/acts/acts1998/19980029.h
The Data Protection Act comes from EU treaty obligations so similar laws exist throughout the EU.
http://europa.eu.int/comm/internal_market/en/me
We need a UK XP licensee to complain the the Data Protection Registra, I not a XP user so I'm not in a position to complain.
http://www.dataprotection.gov.uk/
No one is forcing you to use Windows. You've never had so many choices. Linux, Mac, BeOS, atheOS, etc.
You left out a small part of the Privacy Policy:
Microsoft will occasionally update this Statement of Privacy to reflect company and customer feedback. Microsoft encourages you to periodically review this Statement to be informed of how Microsoft is protecting your information.
Basically, this policy is in effect until MS decides to change it. When (not if) they decide to change it, any information they have already collected will be subject to the _new_ privacy policy.
We've seen it happen already with Yahoo!, among others.