Live data from Hacker News

German federal office publishes Windows 10 telemetry analysis

ghacks.net

41–50 of 239 posts

Re: German federal office publishes Windows 10 telemetry analysis

#41
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

That seems to be a typo, it should be microsoft.com for all these hosts.

That would be a serious problem in the PDF they published.

Re: German federal office publishes Windows 10 telemetry analysis

#43

Earlier quoted context omitted.

Could just block all communication with Microsoft by the OS. Or, move to non-Windows OSes like the retail giants already have. Kroger and Walmart run Suse Enterprise Linux (relevant Uptime Funk reference) https://www.youtube.com/watch?v=SYRlTISvjww

Not in a government or business environment using Office 365. 365 requires all sorts of open connectivity to function.

If your using Office 365, telemetry in Windows is the least of your concern.

Re: German federal office publishes Windows 10 telemetry analysis

#44
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

That seems to be a typo, it should be microsoft.com for all these hosts.

alpha.telemetry.microsft.com resolves and has Microsoft name servers as SOA. I see no reason to conclude this is a typo. What evidence do you have?

Re: German federal office publishes Windows 10 telemetry analysis

#45
There is an API monitor included in the appendix of the report. From the looks of it, it seems to be designed to hook into the API for the ETW sources and log the data that they record. But I can't tell what script language it is written in, so I cannot be entirely sure. Can someone have a closer look and tell me what this does exactly and how to run it? Seems interesting for those who want to get the complete picture of what Windows is recording.

Re: German federal office publishes Windows 10 telemetry analysis

#46
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

It could be an attempt to bypass DNS blacklists. I have Microsoft domains blacklisted on my pi-hole because I find their telemetry practices so difficult to constrain otherwise. Not sure if I caught any micrsoft domains, but there were definitely some that seemed intentionally semi-obfuscated, with msft or something like that instead of the full company name.

Re: German federal office publishes Windows 10 telemetry analysis

#47
post #44

Earlier quoted context omitted.

That seems to be a typo, it should be microsoft.com for all these hosts.

alpha.telemetry.microsft.com resolves and has Microsoft name servers as SOA. I see no reason to conclude this is a typo. What evidence do you have?

dnschecker.org says it doesn't

Re: German federal office publishes Windows 10 telemetry analysis

#48
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

https://www.ip-tracker.org/locator/ip-lookup.php?ip=Microsft... It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.

> Using misspellings of names is something malware often does

your spidey sense is telling you what you need to know, you just won’t say it

Re: German federal office publishes Windows 10 telemetry analysis

#49
post #47
post #44

Earlier quoted context omitted.

alpha.telemetry.microsft.com resolves and has Microsoft name servers as SOA. I see no reason to conclude this is a typo. What evidence do you have?

dnschecker.org says it doesn't

https://www.whois.com/whois/microsft.com

It is owned by Microsoft, registered by MarkMonitor (MarkMonitor is a legit company)

Re: German federal office publishes Windows 10 telemetry analysis

#50
post #46
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

It could be an attempt to bypass DNS blacklists. I have Microsoft domains blacklisted on my pi-hole because I find their telemetry practices so difficult to constrain otherwise. Not sure if I caught any micrsoft domains, but there were definitely some that seemed intentionally semi-obfuscated, with msft or something like that instead of the full company name.

Is there a specific update url you whitelist?
Post reply on HN