Live data from Hacker News

Microsoft no longer allows admins to block Windows Store access in Win10 Pro

zdnet.com

231–240 of 251 posts

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#231

If Microsoft wants SMBs to use Enterprise then make the Enterprise edition more easily available to SMBs, don't try to force them to move to it by making petty little changes to make their life more difficult. I can go on the Google Apps website right now and buy myself seats with a few clicks and a few minutes. If I want to buy Windows Enterprise licenses it will take weeks, cost an unclear amount (at the onset), an…

> People want to give Microsoft money, but Microsoft is intent on making the entire thing as painful as possible and their licensing as obtuse as possible. This. I don't know if this is still the case, but a few years ago I bought an MSDN subscription, and it took weeks . I could never figure out why they made it so difficult, nor why they forced me to go through partners. Just add a subscribe button on your own webs…

Similar story... But not with a human sales person. Went to order github enterprise for our company. Went to Microsoft Asure as one of GHE's recommended hosting partners. The interface was extremely complicated and cloudy. Costs about $200/month for what seems to be a $40-80 VPS anywhere else. Performance is not that great, too. Found out a month later that bitbucket would fit our use case hosted for $10/month. Gitlab would fit our use case hosted for free. Management had insisted on GHE "for consistency".

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#232

Earlier quoted context omitted.

They used to, and they decided to download and execute random malware, and never take security updates.

Isn't that their choice?

Sure it is. So what? Are you going to pretend that they are the only ones affected? It hurts the rest of the internet when their machine is then used by hackers to attack others. It hurts the banking system and indirectly, small vendors when these people's credit card information is stolen and used to make fraudulent purchases.

Taking away the right of individuals to make bad decisions that harm others is the entire point of society.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#233

Earlier quoted context omitted.

I'm not advocating. I am pointing out that user control is fundamentally anti-security. Bad security may very well be worth the tradeoff if you value other things like freedom, fashion, backwards compatibility, fewer restarts, price, etc.

I don't see how your argument works. You seem to be saying that user control automatically leads to less security which is obviously false. Maybe you are conflating groups with individuals. If an individual has control then by definition he can chose to be more secure or less secure by his actions e.g that individual may chose to perform updates asap and stay away from suspicious downloads. He can also chose to do th…

>You seem to be saying that user control automatically leads to less security which is obviously false.

No.

> If an individual has control then by definition he can chose to be more secure or less secure by his actions

He can in theory, but he does not in reality.

>He can also chose to do the opposite of these things and be less secure but there is obviously no direct implication either way.

Again, reality shows us that the vast majority of users choose to be insecure.

>But underlying this is a one-dimensional view of security, consider more complex scenarios where users are forced to use a single software to perform a task. If that software is insecure then 100% of users are vulnerable whereas if there are a diverse range of programs the users are more resilient to attacks.

Correct, a diverse set of platforms would also be good for security. But that is a separate argument.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#234

Earlier quoted context omitted.

I am not. I am under the impression that some people believe "I control my own machine" is a point in favor of security. And that those people are wrong. Perhaps not for themselves specifically, but in turning that philosophy into a general rule to apply to consumer products.

Care to offer any arguments to support your claim?

The entire history of Windows.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#235
post #88

Earlier quoted context omitted.

> taking away control from users If you don't control something, you de facto don't own it. You're advocating for a future without personal property. If you doubt this, see John Deere. > improve the overall security of the internet When someone else has remote control over your system, your system is - by definition - insecure. The recent drama involving the FBI and an iphone is a perfect example: the phone is insecu…

"Freedom" necessarily includes the freedom to make bad decisions. You want to take away that choice. Very well said. There's this relevant Gandhi quote: "Freedom is not worth having if it does not include the freedom to make mistakes." The whole approach to computer security seems to be based on an argument along the lines of "let's just throw everyone in jail and treat them guilty by default because they might possi…

Choosing to have less security because you value freedom more is totally fine. What I object to is choosing to have less security because you value freedom so much you pretend that less security is actually more. And especially when people are making that choice because those of us who are more informed than they are lied to them in order to manipulate them into doing so.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#236

Earlier quoted context omitted.

I don't see how your argument works. You seem to be saying that user control automatically leads to less security which is obviously false. Maybe you are conflating groups with individuals. If an individual has control then by definition he can chose to be more secure or less secure by his actions e.g that individual may chose to perform updates asap and stay away from suspicious downloads. He can also chose to do th…

>You seem to be saying that user control automatically leads to less security which is obviously false. No. > If an individual has control then by definition he can chose to be more secure or less secure by his actions He can in theory, but he does not in reality. >He can also chose to do the opposite of these things and be less secure but there is obviously no direct implication either way. Again, reality shows us t…

> the vast majority of users choose to be insecure.

This is incorrect. The vast majority of users choose to use the things they purchase for the intended features. They usually make no choice whatsoever about security. Your posts in this thread have been trying to blame users for poor product design; if something is badly insecure when used for the intended features, then it is defective.

This is where you probably want to assert that remote management is the solution, which takes control away from the user and allows defects to be fixed at a later time. You have asserted many times that allowing users to control their own devices is "less secure". This conclusion may be true in some cases, but it is simply incorrect most of the time.

When you take control away from the user and give it to the manufacturer (or other remote location), you are creating a backdoor that the user cannot override. Adding a remote backdoor is weakening security for the user. If you want to argue this, you're going to have to explain why both the FBI and Apple were wrong in their recent conflict about pushing a broken OS to a certain iphone.

Yes, users have very little knowledge about computer security. The solution to that is to educate them and make better products that don't need as much technical knowledge to use safely. Only then will security be improved. Your solution of handing over control to someone else is trying to keep users ignorant while lowering user security.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#237
post #23

Earlier quoted context omitted.

> Where is the Windows version of Office 365? Why can't I just pay a per user fee and get one Windows Enterprise key, the CAL, and Azure-based AD? It used to be an optional tier of Windows Intune (now known as Microsoft Intune), which they have since killed (stupid decision, IMO). However, you can just directly join a Windows 10 (Pro?) system to Azure AD, Enterprise is only necessary for things like DirectRoute, you…

It is too bad about Intune. I think the Azure AD with joining is only hybrid, unless I've missed something, which means you still need a local AD resource. Reminds me of Azure-compatible Storage Spaces Dorect -- an amazing idea until they told me I would need four identically configured servers and I realised it would be a waste of time when I only need one server and less redundancy to start. Wish they could figure…

As of Windows 10 you can join directly to Azure AD without any on prem AD implementation.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#238
post #236

Earlier quoted context omitted.

>You seem to be saying that user control automatically leads to less security which is obviously false. No. > If an individual has control then by definition he can chose to be more secure or less secure by his actions He can in theory, but he does not in reality. >He can also chose to do the opposite of these things and be less secure but there is obviously no direct implication either way. Again, reality shows us t…

> the vast majority of users choose to be insecure. This is incorrect. The vast majority of users choose to use the things they purchase for the intended features. They usually make no choice whatsoever about security. Your posts in this thread have been trying to blame users for poor product design; if something is badly insecure when used for the intended features, then it is defective . This is where you probably…

You seem more interested in putting words in my mouth than having a real discussion, so I will simply say that if you want to go with that metaphor, having a backdoor is preferable to having no walls.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#239
post #158

Microsoft isn't the only guy doing this. I understand enterprise/professional customers have gotten exceptions for years, but for everyone else this is common practice on almost all other platforms. I still think it's a bad practice. Microsoft is just following the other companies that are winning and somehow doing so without pissing their userbases off. Their main asset, as I see it, are people that cannot or will n…

>iOS ... don't allow you to install outside of their appstore without running different builds At least companies apparently can create their own appstore for their custom apps: https://developer.apple.com/programs/enterprise/

This is true, but it still costs you 300 dollars a year, uses the same mechanisms the market uses (no loose .ipas) and you have to give lots of trackable info to Apple (company info, devices, apps, update/use metrics). It's all centralized too, so if they change their policy (like go back to the >500 employee rule) or don't like an app you're sharing, you might be in trouble. If Windows can eventually swing even this with their marketplace, I think they'd be ecstatic.

Re: Microsoft no longer allows admins to block Windows Store access in Win10 Pro

#240

We are tied to Microsoft due to a multi-million dollar ERP. I have frozen at Win 8.1 (software assurance contract). I love server and maybe once Server 2016 is out this Fall/Winter, I can circle back around but the 2 Win10 machines we have (one is mine) tripped every security protocol we have (we do some stuff for foreign and local defense contractors). Thi sis the enterprise edition. In the end, I block a few thousa…

You should put something out saying what you've blocked, I'm sure many other people want to do the same thing. I don't know when I'll be able to get off of windows, but I do know that my next computer won't run it on the bare metal. I plan on getting a CPU with good virtualization (non 'k') and only ever running windows inside a VM. Things had already gone too far about 5 revelations ago.

The Intel CPU's with unlocked multi's have had VT-D for a couple iterations now. They're still useless if you have zero plans to overclock. (Even more so now they don't even come with stock coolers anymore.)
Post reply on HN