German federal office publishes Windows 10 telemetry analysis
51–60 of 239 posts
Re: German federal office publishes Windows 10 telemetry analysis
#52Earlier quoted context omitted.
https://www.ip-tracker.org/locator/ip-lookup.php?ip=Microsft... It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.
> Using misspellings of names is something malware often does your spidey sense is telling you what you need to know, you just won’t say it
Re: German federal office publishes Windows 10 telemetry analysis
#53Re: German federal office publishes Windows 10 telemetry analysis
#54Earlier quoted context omitted.
Why would they use the short names in URLs? I thought they make sense only for file names.
I'm mostly joking. However, I've been observing Microsoft since the Windows 2.0 era, and I can't completely discard the possibility that Microsoft actually would use 8.3 domain names. Using 8.3 names "for legacy compatibility" in unusual places is something they've done before.
Re: German federal office publishes Windows 10 telemetry analysis
#55Earlier quoted context omitted.
https://www.ip-tracker.org/locator/ip-lookup.php?ip=Microsft... It does seem MS owns that domain, but to be actively using it --- especially for telemetry --- raises red flags for me too. Using misspellings of names is something malware often does.
> Using misspellings of names is something malware often does your spidey sense is telling you what you need to know, you just won’t say it
Re: German federal office publishes Windows 10 telemetry analysis
#56Did they find something that contradicts stuff listed at https://docs.microsoft.com/en-us/windows/privacy/ ?
EDIT: On second thoughts, given that the M$ Windoze avoiders haven't shot this post up to 800 points, its probably nothing scandalous.
Re: German federal office publishes Windows 10 telemetry analysis
#57Page 31 of the report was of primary interest--hosts hard-coded in diagtrack.dll:
geo.settings-win.data.microsoft.com.akadns.net db5-eap.settings-win.data.microsoft.com.akadns.net settings-win.data.microsoft.com db5.settings-win.data.microsoft.com.akadns.net asimov-win.settings.data.microsoft.com.akadns.net db5.vortex.data.microsoft.com.akadns.net v10-win.vortex.data.microsft.com.akadns.net geo.vortex.data.microsoft.com.akadns.net v10.vortex-win.data.microsft.com us.vortex-win.data.microsft.com eu.vortex-win.data.microsft.com vortex-win-sandbox.data.microsoft.com alpha.telemetry.microsft.com oca.telemetry.microsft.com
At this point, I would recommend choosing to treat the {akadns.net, microsoft.com, microsft.com} TLDs with general distrust. Also in the report:
40.77.226.249 40.77.226.250 13.92.194.212 52.178.38.151 52.229.39.152 52.183.114.173 13.78.232.226
For convenience, I've enumerated the corresponding CIDRs:
13.104.0.0/14 13.64.0.0/11 13.96.0.0/13 40.112.0.0/13 40.120.0.0/14 40.124.0.0/16 40.125.0.0/17 40.74.0.0/15 40.76.0.0/14 40.80.0.0/12 40.96.0.0/12 52.145.0.0/16 52.146.0.0/15 52.148.0.0/14 52.152.0.0/13 52.160.0.0/11 52.224.0.0/11
I'm not sure how to react to the observation of the usage of "microsft.com". I'll admit my instinct is to perceive this as, at worst, a rather clandestine attempt at circumventing basic DNS black-holing techniques--in which case, well played MSFT.
Now if you'll excuse me, I have some firewall policies to update.
Re: German federal office publishes Windows 10 telemetry analysis
#58I am surprised that they using server names like "alpha.telemetry.microsft.com". when I see something like "microsft" in an E-mail or link I immediately suspect that somebody is trying to fake being from Microsoft. Or are these spelling errors in the article? Edit: these domain names are in the report too. Very strange. I would get very nervous if I saw "microsft" in a firewall log.
It could be an attempt to bypass DNS blacklists. I have Microsoft domains blacklisted on my pi-hole because I find their telemetry practices so difficult to constrain otherwise. Not sure if I caught any micrsoft domains, but there were definitely some that seemed intentionally semi-obfuscated, with msft or something like that instead of the full company name.
EDIT: Seems like there are a lot *.microsoft.com URLs, too, so disregard this theory.
Re: German federal office publishes Windows 10 telemetry analysis
#59Earlier quoted context omitted.
dnschecker.org says it doesn't
https://www.whois.com/whois/microsft.com It is owned by Microsoft, registered by MarkMonitor (MarkMonitor is a legit company)
Re: German federal office publishes Windows 10 telemetry analysis
#60Earlier quoted context omitted.
Telling users to disable updates it's not a good recommendation.
Sure it is. Microsoft software deployment on client is a dumpster fire. Blindly installing Windows updates these days is very dangerous and should be avoided. Your best approach for avoiding malware is to use browsers like Firefox and Chrome. Critical task workflows should be in LTSB, iOS or ChromeOS. Microsoft’s guidance is to have around four deployment rings each for Windows and Office, and only immediately patch…
Windows 95 was capable of 49.7 days of uptime. That's pretty difficult on client versions of Windows 10 unless you take extraordinary measures.