Live data from Hacker News

Even when told not to, Windows 10 doesn't stop talking to Microsoft

arstechnica.co.uk

241–250 of 267 posts

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#241

Earlier quoted context omitted.

While I hardly think you're asking with any sincerity, sharing every keystroke, local system search, application activity, wifi passwords, and so on is over the top . Making that the default, instead of a value-add that you pitch, was profoundly poorly considered.

Let's refrain from assuming anything about anyone's sincerity. As far as I can tell, most of the Windows 10 scaremongering on HN is nothing but FUD. The key logger argument is a case in point: http://www.zdnet.com/article/does-windows-10-really-include-... Yet, you unquestioningly repeat it. Local system search while sharing some basic diagnostics data with Microsoft does not share the search queries. WiFi passwords…

"Yet, you unquestioningly repeat it."

Why are you quoting an ancient article (one that, humorously, incorrectly claims that the typing data telematics was just some temporary preview release inclusion, when actually it made it to production), when the actual privacy policy of Windows 10, when you install it, tells you that it will monitor and send "typing data" to Microsoft? Microsoft left this very nebulous, but ultimately that simple privacy setting allows them the legal right, and the technical facility, to log every keystroke.

"I couldn't find any evidence that Windows 10 shares any worthwhile application activity data."

Somehow I don't think you actually looked, given how aggressively you have attempted to defend Microsoft in this whole discussion.

No one thinks Microsoft is evil, but rather that they tried to out-Google Google (not very long after their terrible series of anti-Google ads that you even mentioned), taking the basic principal of Google's activities and multiplying it.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#242
post #230

Earlier quoted context omitted.

This protects you from nothing. It actually makes it LESS secure. Because you now have to enable JavaScript. The service provider can still decode the info by MitM'ing. If you are using Google Fiber, for example, your service provider can do whatever they want anyway – they control your browser, they are a CA and they are your ISP. If not: As we’ve seen with CINNIC, MitM'ing is trivial because CAs give out root certi…

This is not to protect you, it's to protect the website. >The service provider can still decode the info by MitM'ing. Yes, but as I explicitly mentioned, only if you visit the website. If NSA goes to the website and demands the data, they can't do anything with it until I visit, whereas if it was decrypted, they could. This is a non-trivial difference. >If you are using Google Fiber, for example, your service provide…

As you’ve probably seen with MEGA, this does not protect the site at all.

Take Megaupload (not MEGA), they had unencrypted data, but complied fully with DMCA and operated fully legally.

Take MEGA, they have to comply with DMCA, too, even though everything is encrypted and they never can decrypt the data, either (MEGA does literally the same as up1.ca)

Additionally, Certificate pinning only works if I visited the site before the MitM started. And some carriers like T-Mobile just strip every Certificate Pinning header anyway, as they use proxies to compress data. (Chrome’s Turbo mode does the same).

Essentially, the site uses JavaScript for showing images without providing any advantage to either the user or the site.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#243

Earlier quoted context omitted.

> Up1 uses client-side crypto, so in this instance it is. What crypto? I didn't provide any key, so both the content AND the key came from the same place. Looks like completely useless crypto.

You did in fact provide a key. See that bit after the # in the URL? This is the beauty of Up1. It makes the crypto as transparent to the user as possible. That part is not sent to the server by your browser. That's a seed, it's run through sha512 then split into parts, including a key, iv and filename to fetch from the server. Now, as I said, in this instance, since I distributed the link on a public website, it's pr…

"Private", well, it’s not private. Seriously.

There is a reason you do actual crypto differently. Encrypt the image with the public key of your friends and send it to them, that is privately.

Giving a foreign entity control over your data and key is not "privately".

And, worse, I have to activate JavaScript, which decreases security by a lot.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#244
post #80

Earlier quoted context omitted.

I'd like to know the difference between free upgrades and Win10 installs with a real product key

There's no difference (obviously).

There _should_ be no difference, but who knows? Who can be sure?

MS probably doesn't even know. I recall reading that there were 6 different versions of the Service Pack update for Office 2000 depending on where you got them from, and they weren't all compatible with each other. Do you think after another decade of Monkey Boy and his winning business strategy of pitting all the departments against each other that they've improved? Nardella actually seems like a grown-up, but he's still a dyed-in-the-wool Microsoft exec.... less stupid certainly, but just as evil.

One of the biggest problems with Microsoft is that they are too big and disorganized. They have no vision, and no guiding principle, other than maintaining the lingering shreds of their monopoly. This is obvious from looking at the designed-by-committee, piecemeal UI for Windows, which is getting worse every release and not better. The best you can hope for for any particular feature from release to release is that it's just arbitrarily different and not broken or hidden or completely removed.

Windows clearly peaked with XP, but their UI peaked with Windows 2000. The only reason 7 is liked is because they backed off most of the bad things they did with Vista, and the only thing, the _only_ thing I think is better in Windows 8 than any previous version is Task Manager, which is not something I use often. But it is nice.

My #1 wish for Windows post-7 is that I could just use the "Classic" theme, but apparently Windows is now too sophisticated to do what it could do 15 years ago. Their UX department has gone totally off the rails or maybe was taken over by wild monkeys. Microsoft used to be _the_ place for good UI design back in the 90s. They were very scientific about it, and their designs were very well-thought out, based on CUA, and an absurd amount of user-testing and most of all, consistent. Not perfect, but they were very good. But as soon as graphics cards could do more than 256 colors and Photoshop was invented, everyone went wild and UI became the lawless, Wild West funhouse it remains today. Except in the past few years, everyone decided that the "flat look" is cool (news flash: it's ugly and hard to make out) and now we have UIs that are as usable and good-looking as Windows 2, but without the consistency.

I'd thought Microsoft had run out of sharks to jump with Windows 8, but they keep finding more. But here's the thing. I still like Windows. I just wish I could make Windows look at work like it did when it looked and worked well (I'm not referring to the underlying technology, which is presumably improving all the time, although I still think Windows 8 is absurdly slow compared to 7 and much worse compared to XP... and I have empirical evidence. I do a lot of work in a Windows 2003 VM running on VirtualBox (long story) and it's much faster than the Windows 7 host and doesn't suffer from the, oh gee, everything's going to go "Not Responding" for 30 seconds to 2 minutes for no apparent reason that I see with the apps (at least MS apps) on the host.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#245

Earlier quoted context omitted.

Facilitating high connectivity is what modern mass market operating systems do That's a bold claim, considering that until recently Windows was exactly what you used if you didn't want that kind of always-online emphasis and instead wanted to retain a degree of control and running your software locally. Like many of the software companies moving in user-hostile directions, Microsoft's biggest competition is still the…

Having owned 3.1, 95, 98, Me, 2000, XP, 7, and 8 boxes and been paid to use 2.0, NT and Vista, my experience has been that each version [except Me which was meh] has been significantly better...and the amount of improvement from version to version has been markedly increasing...that is, 8 a larger improvement on 7 than 7 was on Vista. People can legitimately disagree on the meaning of "user-hostile". If the way in wh…

Perhaps you weren't aware that Microsoft has a monopoly. They've been milking that since the early 90s. Sure, they lost that iron grip on mobile, but they are still a monopoly on the desktop. The number of organizations that aren't part of the Office Hegemony, and therefore Windows, is still a very small number. If you get rid of the Apple marketshare, it's probably in the low single-digits, percentage-wise... if it even breaks 1%.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#246

Earlier quoted context omitted.

You did in fact provide a key. See that bit after the # in the URL? This is the beauty of Up1. It makes the crypto as transparent to the user as possible. That part is not sent to the server by your browser. That's a seed, it's run through sha512 then split into parts, including a key, iv and filename to fetch from the server. Now, as I said, in this instance, since I distributed the link on a public website, it's pr…

"Private", well, it’s not private. Seriously. There is a reason you do actual crypto differently. Encrypt the image with the public key of your friends and send it to them, that is privately. Giving a foreign entity control over your data and key is not "privately". And, worse, I have to activate JavaScript, which decreases security by a lot.

> Giving a foreign entity control over your data and key is not "privately".

Yeah, if you have this concern strongly, well, we're working on browser extensions which will prevent any potential risk here. However, like I said to someone else, unless you reverse engineer every update to your OS, you really shouldn't be commenting. This is just as much "giving a foreign entity control over your data" as using an OS provided in binary form is giving a foreign entity control over your CPU, which would be far, far worse really. Unless you're manually validating the code in all cryptography products you use, there's really no argument to be made here.

> Encrypt the image with the public key of your friends and send it to them, that is privately.

When you do this, say using PGP, PGP generates a static key, encrypts that key to their public key and encrypts the message using the static key.

This is essentially the same thing, the only difference being that the Up1 does only the static key portion and does not provide the public key portion, which you can do out of band using whatever method you prefer, be it PGP, SSL to a private server, OTR, TextSecure, etc.

And it allows the transfer of images and small files in this secure form to be incredibly simple and fast. Pipe into a command line tool or use ShareX, paste that link over a secured protocol and you've securely shared a file.

Of course, if you don't trust the public Up1 instance, feel free to run your own, it's all open source, server included.

> And, worse, I have to activate JavaScript, which decreases security by a lot.

It's a trade-off, privacy for a slightly increased risk of security, these days you're more likely to get exploited by a fucking web font than by a script though.

Worst case, like I said, don't trust the public instance if you don't want to (well, if you're the type who doesn't trust their OS provider at least). You can always run it yourself or wait for the browser extensions.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#247
post #230

Earlier quoted context omitted.

This is not to protect you, it's to protect the website. >The service provider can still decode the info by MitM'ing. Yes, but as I explicitly mentioned, only if you visit the website. If NSA goes to the website and demands the data, they can't do anything with it until I visit, whereas if it was decrypted, they could. This is a non-trivial difference. >If you are using Google Fiber, for example, your service provide…

As you’ve probably seen with MEGA, this does not protect the site at all. Take Megaupload (not MEGA), they had unencrypted data, but complied fully with DMCA and operated fully legally. Take MEGA, they have to comply with DMCA, too, even though everything is encrypted and they never can decrypt the data, either (MEGA does literally the same as up1.ca) Additionally, Certificate pinning only works if I visited the site…

It actually works quite well for MEGA.

MEGA is only able to comply with the DMCA when the link is provided with the full hash.

MEGA is technically unable to remove similar or matching files based on content.

> And some carriers like T-Mobile just strip every Certificate Pinning header anyway, as they use proxies to compress data.

I question the t-mobile thing, unless they're installing certificates on end-user's phones that should not be possible. This is SSL traffic, remember, all those headers are also sent over SSL so unless T-Mobile is performing MITM, this shouldn't be a problem.

As for the Chrome Turbo mode thing, it is disabled for SSL traffic, as are most of these other things.

https://developer.chrome.com/multidevice/data-compression

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#248

Earlier quoted context omitted.

"Private", well, it’s not private. Seriously. There is a reason you do actual crypto differently. Encrypt the image with the public key of your friends and send it to them, that is privately. Giving a foreign entity control over your data and key is not "privately". And, worse, I have to activate JavaScript, which decreases security by a lot.

> Giving a foreign entity control over your data and key is not "privately". Yeah, if you have this concern strongly, well, we're working on browser extensions which will prevent any potential risk here. However, like I said to someone else, unless you reverse engineer every update to your OS, you really shouldn't be commenting. This is just as much "giving a foreign entity control over your data" as using an OS prov…

I’m the type that only runs arch because I can’t be bothered to run Gentoo ;)

Anyway, for posting on a public forum it’s pretty useless, as it provides no benefit and requires the users to have JS enabled, which is, especially on Hacker News, not really a given.

Even the mods complained when an up1.ca link was used as submission link recently.

Using a standard protocol would be an advantage here most definitely.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#249
post #230

Earlier quoted context omitted.

This is not to protect you, it's to protect the website. >The service provider can still decode the info by MitM'ing. Yes, but as I explicitly mentioned, only if you visit the website. If NSA goes to the website and demands the data, they can't do anything with it until I visit, whereas if it was decrypted, they could. This is a non-trivial difference. >If you are using Google Fiber, for example, your service provide…

As you’ve probably seen with MEGA, this does not protect the site at all. Take Megaupload (not MEGA), they had unencrypted data, but complied fully with DMCA and operated fully legally. Take MEGA, they have to comply with DMCA, too, even though everything is encrypted and they never can decrypt the data, either (MEGA does literally the same as up1.ca) Additionally, Certificate pinning only works if I visited the site…

> Essentially, the site uses JavaScript for showing images without providing any advantage to either the user or the site.

That is a very baseless and false conclusion.

Re: Even when told not to, Windows 10 doesn't stop talking to Microsoft

#250
post #249

Earlier quoted context omitted.

As you’ve probably seen with MEGA, this does not protect the site at all. Take Megaupload (not MEGA), they had unencrypted data, but complied fully with DMCA and operated fully legally. Take MEGA, they have to comply with DMCA, too, even though everything is encrypted and they never can decrypt the data, either (MEGA does literally the same as up1.ca) Additionally, Certificate pinning only works if I visited the site…

> Essentially, the site uses JavaScript for showing images without providing any advantage to either the user or the site. That is a very baseless and false conclusion.

Well, admittedly, in the context of a link on Hacker News, it's pretty true. The link containing the seed is trivial to obtain and could easily be reported to the providers who would have to take it down if deemed legally necessary.
Post reply on HN