Live data from Hacker News

German federal office publishes Windows 10 telemetry analysis

ghacks.net

51–60 of 239 posts

Re: German federal office publishes Windows 10 telemetry analysis

#51
Note to power users who don't subscribe to hacker news FUD against Microsoft (while using Gmail) remember how disappointed most of us were when start menu jumplists disappeared. This is how it wont happen again. Please don't turn it off- I don't want Microsoft removing power features

Re: German federal office publishes Windows 10 telemetry analysis

#52

Earlier quoted context omitted.

https://www.ip-tracker.org/locator/ip-lookup.php?ip=Microsft... It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.

> Using misspellings of names is something malware often does your spidey sense is telling you what you need to know, you just won’t say it

I don't get it.

Re: German federal office publishes Windows 10 telemetry analysis

#53

Earlier quoted context omitted.

> Using misspellings of names is something malware often does your spidey sense is telling you what you need to know, you just won’t say it

I don't get it.

Windows 10, spying on its user, is malware.

Re: German federal office publishes Windows 10 telemetry analysis

#54
post #39
post #27

Earlier quoted context omitted.

Why would they use the short names in URLs? I thought they make sense only for file names.

I'm mostly joking. However, I've been observing Microsoft since the Windows 2.0 era, and I can't completely discard the possibility that Microsoft actually would use 8.3 domain names. Using 8.3 names "for legacy compatibility" in unusual places is something they've done before.

It could be that at some point they mapped domain names to folder names or something like that. Still looks pretty hacky (or malicious) nowadays.

Re: German federal office publishes Windows 10 telemetry analysis

#55

Earlier quoted context omitted.

https://www.ip-tracker.org/locator/ip-lookup.php?ip=Microsft... It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.

> Using misspellings of names is something malware often does your spidey sense is telling you what you need to know, you just won’t say it

Dang are you okay with unsubstantiated opinions with oblique references?

Re: German federal office publishes Windows 10 telemetry analysis

#56
post #38

Did they find something that contradicts stuff listed at https://docs.microsoft.com/en-us/windows/privacy/ ?

Are you really expecting anybody to waste time reading either of the reports when that time can be utilized spreading FUD against Microsoft?

EDIT: On second thoughts, given that the M$ Windoze avoiders haven't shot this post up to 800 points, its probably nothing scandalous.

Re: German federal office publishes Windows 10 telemetry analysis

#57
(More) direct link to the publication: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Si...

Page 31 of the report was of primary interest--hosts hard-coded in diagtrack.dll:

geo.settings-win.data.microsoft.com.akadns.net db5-eap.settings-win.data.microsoft.com.akadns.net settings-win.data.microsoft.com db5.settings-win.data.microsoft.com.akadns.net asimov-win.settings.data.microsoft.com.akadns.net db5.vortex.data.microsoft.com.akadns.net v10-win.vortex.data.microsft.com.akadns.net geo.vortex.data.microsoft.com.akadns.net v10.vortex-win.data.microsft.com us.vortex-win.data.microsft.com eu.vortex-win.data.microsft.com vortex-win-sandbox.data.microsoft.com alpha.telemetry.microsft.com oca.telemetry.microsft.com

At this point, I would recommend choosing to treat the {akadns.net, microsoft.com, microsft.com} TLDs with general distrust. Also in the report:

40.77.226.249 40.77.226.250 13.92.194.212 52.178.38.151 52.229.39.152 52.183.114.173 13.78.232.226

For convenience, I've enumerated the corresponding CIDRs:

13.104.0.0/14 13.64.0.0/11 13.96.0.0/13 40.112.0.0/13 40.120.0.0/14 40.124.0.0/16 40.125.0.0/17 40.74.0.0/15 40.76.0.0/14 40.80.0.0/12 40.96.0.0/12 52.145.0.0/16 52.146.0.0/15 52.148.0.0/14 52.152.0.0/13 52.160.0.0/11 52.224.0.0/11

I'm not sure how to react to the observation of the usage of "microsft.com". I'll admit my instinct is to perceive this as, at worst, a rather clandestine attempt at circumventing basic DNS black-holing techniques--in which case, well played MSFT.

Now if you'll excuse me, I have some firewall policies to update.

Re: German federal office publishes Windows 10 telemetry analysis

#58
post #46
post #24

I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.

It could be an attempt to bypass DNS blacklists. I have Microsoft domains blacklisted on my pi-hole because I find their telemetry practices so difficult to constrain otherwise. Not sure if I caught any micrsoft domains, but there were definitely some that seemed intentionally semi-obfuscated, with msft or something like that instead of the full company name.

I'd actually lean towards it being the opposite - put the thing that people and organizations would be inclined to block on a separate domain so that the core business domain isn't blocked.

EDIT: Seems like there are a lot *.microsoft.com URLs, too, so disregard this theory.

Re: German federal office publishes Windows 10 telemetry analysis

#59
post #47

Earlier quoted context omitted.

dnschecker.org says it doesn't

https://www.whois.com/whois/microsft.com It is owned by Microsoft, registered by MarkMonitor (MarkMonitor is a legit company)

Yes, but just like microsoft.telemetry.elegantcode.com it has no ip address associated with it.

Re: German federal office publishes Windows 10 telemetry analysis

#60

Earlier quoted context omitted.

Telling users to disable updates it's not a good recommendation.

Sure it is. Microsoft software deployment on client is a dumpster fire. Blindly installing Windows updates these days is very dangerous and should be avoided. Your best approach for avoiding malware is to use browsers like Firefox and Chrome. Critical task workflows should be in LTSB, iOS or ChromeOS. Microsoft’s guidance is to have around four deployment rings each for Windows and Office, and only immediately patch…

Yep. All of the Windows machines that I actually rely on for work—the ones that I need to be able to start up and immediately use, and need to be able to trust them to keep running without interruption or regression—are completely firewalled off from the public internet, so that they are secure both from malware, and unwanted updates. The rest of my work is done on other, more obedient operating systems.

Windows 95 was capable of 49.7 days of uptime. That's pretty difficult on client versions of Windows 10 unless you take extraordinary measures.

Post reply on HN