Windows 10 Privacy Changes Appease Watchdogs, But Still No Data 'Off-Switch' (zdnet.com)
Earlier this month, Microsoft announced several privacy changes in Windows 10, but it didn't give users an option to completely opt-out of data-collection feature. The announcement came at a time to coincide with a statement by the Swiss data protection and privacy regulator, the FDPIC, which last week said it would drop its threats of a lawsuit after the company "agreed to implement" a string of recommendations it made last year. The news closed the books on an investigation that began in 2015, shortly after Windows 10 was released. Though the Swiss appear satisfied, other critics are waiting for more. The French data protection watchdog, the CNIL, was equally unimpressed by Microsoft's actions, and it served the company with a notice in July to demand that it clean up its privacy settings. In an email, the CNIL said that the changes "seem to comply" with its complaint, but it's "now analyzing more in [sic] details Microsoft answers in order to know whether all the failures underlined in the formal notice do now comply with the law." ZDNet adds: Microsoft still hasn't said exactly what gets collected as part of the basic level of collection, except that the data is used to improve its software and services down the line; a reasonable ask -- but one that nonetheless lacks specifics. Microsoft said it wants users to "trust" it. And while the likelihood that the company is doing anything nefarious with users' information is frankly unlikely, the running risk is that the data could somehow be turned over to a government agency or even stolen by hackers is inescapable. That risk alone is enough for many to want to keep what's on their computer in their homes. While changing the privacy controls is a move in the right direction, it's still short of what many have called for. By ignoring the biggest privacy complaint from its consumer users -- the ability to switch off data collection altogether -- Microsoft has favored the "just enough" approach to appease the regulators. Without a way to truly opt-out, Microsoft's repeated pledge (eight times in the blog post, no less) to give its users "control" of their data comes off as a hollow soundbite.
what ever the NSA or their EU equivalent asks for and more just in case they need to ask for more in the future.
stop using windows if you want any semblance of privacy.
Apparently Microsoft uses the word "Trust" in the same way Apple uses the word "Courage". I still haven't figured out what either one means... only that neither correspond to what's in the dictionary.
That's all Microsoft wants out of Win 10, why they were willing to give it away for free. They want what Google has with Android, a funnel for all your data that they can use to tune their algorithms for search, and (probably) pin advertisements to you
Seriously. Why bother with Windows 10 if it's going to spy on your activity?
Why bother with Windows 10?
Why bother with Windows X?
Please do not read this sig. Thank you.
Where have you been for the last two years? MS uses hard-coded IPs to avoid any messing around with DNS.
This CAREER IT TECHNICIAN, will NEVER recommend it. Currently, we Recommend its REMOVAL from all workstations, and a regression to a safer, less intrusive, more compatible OS, that isn't able to uninstall things to make way for its own broken updates... Win 10 has uninstalled the following applications from our Users systems WITHOUT permission or ANY user interaction required... 1. Quickbooks. 2. Sage Accounting 3. Wintac (HVAC CRM) 4. Connectwise (IT CRM) All uninstalled from multiple systems, without permission, causing DAMAGE to several of our Business Class Environments, and taking 4 clients networks DOWN, as they primarily used Quickbooks. When its down they cannot function. It also damaged the Wintac Database, by uninstalling it WHILE IT WAS OPERATING! Win10 is by far and wide the VERY WORST thing ever produced and sold as an OS!
I will simply refer you to my comment in last week's discussion on "Microsoft To Enhance User Privacy Controls In Upcoming Windows 10 Update": here
Bottom line: Microsoft's only objective was "get people to quit trashing us openly". Of course, the current state very well could have been their desired end goal and they went extreme from the outset to give them room to appear to compromise. Either way, whether or not it was planned, they make themselves look (comparatively) like the good guys.
This is clearly a partnership with the US government in expanding its surveillance practices. Free access to all emails on their servers and now it's free access to everyone's computers, key logs, data and documents. Microsoft knew exactly what they were doing, just as well as the US government.
surely someone must have a list of addresses to blacklist in our HOSTS file?
Please don't summon ... him.
The best is simply the best.
Makes me want to keep writing "F**k you Microsoft" in the Cortana search box over and over. Maybe that way they'll get the message.
Microsoft said it wants users to "trust" it.
I hear that a lot from companies and people -- like some newly elected officials -- and it always makes my ass twitch.
It must have been something you assimilated. . . .
ZDNet adds: ... And while the likelihood that the company is doing anything nefarious with users' information is frankly unlikely ...
This quote is a case of somebody writing something to just fit a grammatical template, rather than thinking about what they're writing. Substantiate that wild speculation, ZDNet, or turn in your beard-stroking license asap.
- First they ignore you, then they laugh at you, then ???, then profit.
Microsoft: We know what our users want!
...
Users: How? You haven't asked us about anything.
Microsoft: Oh, we know--trust us
-------
All Power to the NT Overlords!
The opposite of trust? Anit-Trust. Ya'know, that thing Microsoft already violated?
Is that too much to ask? I'd like to pay some money in exchange for software to abstract my hardware into a platform and allow application to run. That is of course the kernel and drivers as well as the libraries and services necessary for applications.
I don't want advertisements, data mining, or even a bundled web browser. I do want security updates and timezone updates, please don't stop updating timezones with the excuse that an older operating system version is "unsupported".
If this were a free market, we could pay money in exchange for the goods and services we want. Assuming we can agree on a price, but I doubt even a million dollars would could get Microsoft's attention.
“Common sense is not so common.” — Voltaire
So you don't black hole those IPs and hosts at the router/firewall level?
Time to offend someone
Win10 was designed *from the ground up* with telemetry and spayware/malware/whathaveyou in mind.
You will never get them to "turn it off", at best you'll get "minimal" and it will require 3rd parties to fix (if they can, closed source and all that)
Why use it to begin with, if you have the option, use anything else, but not Win10.
So rise up, all ye lost ones, as one, we'll claw the clouds.
> "But that tracking can be easily disabled!" or "But that tracking is off by default!"
These are perfectly reasonable mitigations.
Also, it is not reasonable to pretend that a thing that Ubuntu did is somehow "Linux", even if they were still doing it. You know what spies on you? Red Star Linux. But that's not a very reasonable thing. If you don't like the Ubuntu/Amazon thing, then leave it off or turn it off, or just simply don't use Ubuntu. Arch doesn't have that problem. Or Fedora, or Debian, or or or or or or
It's dangerous to think that somehow Ubuntu is somehow better in this regard.
FTFY. Canonical doesn't represent the whole of Linux or open source software. Also being open source means you can remove or add anything you want. Can you point me to the source code for Windows 10?
Then there's Firefox's telemetry, too.
There's also the Homebrew open source project, which supports data collection, and stores it in Google Analytics
Firefox and Homebrew's spyware is 100% optional. You also have access to the source code, so you can yank it completely out if you want to. In addition, neither of them are operating systems with full access to everything.
If you can't see the difference between always-on spyware in an operating system from a multi-billion dollar corporation that can easily afford to do QA and completely optional spyware in an open source web browser and package manager, then you are an idiot.
You let me know when Firefox forces spyware always on and closes the source and then I'll partially agree with you.
What does that have to do with a HOSTS file? Very good job on regurgitating that knowledge, but maybe make sure it's relevant next time.
Mostly just a tongue in cheek comment.
Time to offend someone
It will make it a lot easier for them if you just trust them. Not better for you, but certainly better for them.
Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
Microsoft still hasn't said exactly what gets collected as part of the basic level of collection, except that the data is used to improve its software and services down the line; a reasonable ask...
Unless the OS is free, its not a reasonable ask. Period.
You also have access to the source code, so you can yank it completely out if you want to.
Another misconception.
0.000023425% of the userbase actually has the ability to do something more than point and click to start the application. Since you evidently missed this, please post your repository where you've already done the work, so the majority of the userbase can download it. thanks.
As the title says, how do /.ers turn off W10 telemetry completely? I've seen many solutions, but none seem to be successful in both allowing updates to come through and blocking *all* telemetry.
Just curious, but is anyone running SSL decryption on their networks where they could see this traffic leaving the network? Would they be able to see the traffic in plain text to see what is being reported to Microsoft?
"A plan fiendishly clever in its intricacies"- Homer Simpson
Read my data.
Enjoy your PTSD.
Have gnu, will travel.
I don't think there's anything illegitimate about it. It's just that he's mentally ill, and that the software in question really doesn't work where an OS or software manufacturer hard codes callback IP addresses. I went to his page about six months ago, and was fascinated to see screenshots from what was either XP or Server 2003, which said a lot not only about the software, but about APK's state of mind. He's also made a number of posts over the years that suggest he's a good old fashioned netkook, maybe the last of that ancient breed. So, like all good netkooks, he has a fixation, which in his case is his obsession with the hosts file.
The world's burning. Moped Jesus spotted on I50. Details at 11.
... it always makes my ass twitch.
In a good way?
Unfortunately, generally no.
It must have been something you assimilated. . . .
You're just pissed because the hardcoded callback IPs make your host file software redundant, at least so far as Win10 goes (and, so far as I understand it, Win7 and 8/8.1 as well).
I'll sit back now and wait for you to stalk me for a few hours. Watching you get unhinged and demonstrate your manic phase with grandiose claims and threats.
The world's burning. Moped Jesus spotted on I50. Details at 11.
Whatever helps you sleep better troll. FYI, no fucks were given. You were already properly rebuked... :-D
I am sure Microsoft has smart people who know how to sift through data to make future decisions, but I can see it going wrong (and have seen it go wrong).
Camera pans over boardroom:
Data Guy: "Did you know user data shows that consumers spend less than 0.1% of their computer time in the control panel?"
Executive: "It must not be important and takes up a lot of developer time. Remove it!"
Programmer: "Um... can we, maybe, not do that?"
Executive: "Just KILL it! Also, you're fired!"
"Anything you say can and will be used against you in a targeted advertisement" - Adam Harvey
I love all the personal attacks... The serve ONLY ti highlight the weakness of your debate skills... Oh, and where pray tell did I misinform? I stated that "You may feel however you like to sleep better - Which cannot be misinformation, as it contains no information. I stated that "No fucks were given" - which they certainly weren't, so strike two... I stated also that You were already properly rebuked. - As in you have already been responded to and we are ignoring the attempt at trolling further So, WHERE did I misinform? Please enlighten me... Keeping in mind that APK is not me... Two different persons you inattentive troll :-)
EDIT - *they serve only to
You are correct. I mistook him for Mighty... My Bad.
First, Microsoft has to treat us like users: People who have sensitive data, want to know what their tools (computers) are doing with the rest of the internet, don't have to use your products (although the ubiquity of MS Office and vertical market software make that difficult) and yes, pay for the products you make.
So you don't black hole those IPs and hosts at the router/firewall level?
How will you ever know if you got them all? Malware authors have evolved techniques like rotating their C&C to different IPs based upon to the current UTC time. Microsoft has 20+ million IPs to pick from, and those are just the ones with their name on them. You can't block them all without taking out all of Azure, which hosts lots of legit non-MS services.
"BSD: Free as in speech. Linux: Free as in beer. Windows 10: Free as in herpes." --Man On Pink Corner in #52607549.
Sorry about that. You are correct. Thankfully, I have been reminded of the results of assumption :-) (I'll slow down!) thx!
Says the troll whose life has no value to anyone... LoL
This is the least objectionable use for the data. If it was truly and irreversibly anonymized, I wouldn't have a problem with MS datamining trends to give users what they want.
I just have doubts about the truly or irreversible part, even if they claimed anonymity.
Your ad here. Ask me how!
This troll is the WORST at their trade I have ever seen... What are you a fucking 5 year old? Tantrum much there big boy? LOLOLOLOL!
So I use Ublock Origin, NoScript, a good restrictive firewall, and also a comprehensive /etc/hosts file.
In what way does this make me "scared shitless" of a hosts file? Really, I am confused on this matter. I consider the minor resource usage to be a worthwhile trade-off for this beefy system. So you understand my confusion, then? Perhaps you could elaborate? Hopefully my multi-layered approach won't lead to accusations of not being enough of a pure "true believer" for your tastes. That would be a definite detriment to your (potentially reasonable) position, considering that I regard a good hosts file as a useful and valuable supplement to my multi-layered approach. In my use case, "not letting shit get through" is a higher priority than "make the most effecient use of hardware possible" especially when the difference between "current effeciency" and "maximum effeciency" are imperceptible to me.
So I am asking about the nature of your advocacy. Do you believe you have the Holy Grail of Truth? Or do you recognize that your position is technically true, yet the final decision of how to secure a host is a complex problem best solved with overlapping concurrent solutions? This will be a litmus test of whether or not you are the fanatic some have called you. I await your response.
The best is simply the best.
MS has none. They have engaged in criminal acts to screw over customers and competitors. Lying to their customers is something they routinely do. They have shown time and again that they feel zero obligations to their customers.
Anybody trusting MS is stupid. They do not deserve trust. They must make legally binding accurate and complete statements about the data they collect, what it is being used for, and how it is secured against unauthorized access. And if they violate any of these assurances, it must be easy to get them convicted of misdoing and face penalties and pay compensation. Only under these circumstances does MS and win10 deserve a modicum of "trust".
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
"Mr. Kowalski, it really is about time you registered a username" And This is coming from "Anonymous Coward" LOL!
Or Fedora, or Debian, or or or or or or
Many a Linux distros feature opaque proprietary binaries. Kali [Debian] is one of them. So, yeah.
You're not likely to run Kali Linux on your office workstation...
The best is simply the best.
Lots of software developers are somewhere on the autism spectrum, and are classified as high-functioning ASD. Personally, I also have dysthymic disorder (essentially chronic low-grade depression that's gone through two name changes since my diagnosis), and people seem to trust what I write.
"When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
That only works if you carry your router with you everywhere you take your computer. That would be a totally feasible thing if someone produced a micro router/firewall that was the size of a bluetooth dongle, but I haven't been able to find anything like that yet.
Why are you running Windows 10 anyway? If you really need to run it for some specific applications then just dual boot, yes it's slightly inconvenient but that is the price of privacy.
Well given we're talking about blacklisting IPs that Windows sends information to and that you are looking for (haven't been able to find) a micro router/firewall I'd say it's pretty reasonable assumption that you do or that you would like to run Windows 10. If not then why bother? Just use the hosts file on Linux.
Anyway ok, you're not running Windows 10, no big deal. The suggestion still stands for anybody who does need to run it for whatever reason.
You probably wouldn't notice me as being ASD or depressive. Lots of us are quite adept at looking normal. I'm being open with it because it's unlikely to hurt me (not any worse than it has already; I've already been denied insurance).
People depend on stuff I've written for safety purposes. They haven't regretted it.
"When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
I've got the diagnoses. Therefore, I'm mentally ill, although it usually doesn't show. I also have some physical illnesses you won't notice by looking at me. I'm reasonably healthy for my age, and I know a lot of contemporaries who are worse off, but I'm not in perfect health.
I'm emphasizing this because I really hate "mentally ill" being used as an insult, and it often is. APK does not necessarily have a mental illness; APK might just be an asshole, which is not a category in DSM-V. There are mentally healthy people I wouldn't trust with a burned-out match.
"When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes