Live data from Hacker News

My application ran away and called home from Redmond

medium.com

131–140 of 143 posts

Re: My application ran away and called home from Redmond

#131
post #44
post #34

Earlier quoted context omitted.

Assume for a second this is correct. What's to stop virus writers from embedding a ToS preventing Microsoft from running the code? I'm not saying you're wrong, I'm saying it's really hard to work out how this is meant to work.

I don't think a virus is relevant here. I'm not a lawyer, but the idea of a "terms of service" for an unwanted and maliciously installed executable seems nonsensical. Virus authors can include whatever TOS they want, but the "user" hasn't agreed to the TOS practically by definition.

[deleted]

Re: My application ran away and called home from Redmond

#133

I was interested in this Beacon software, but then I found you had to contact them for pricing and I gave up on the idea. Lesson: clear pricing keeps people like me in the game

If the price is not on the website, it is either:

(1) 'Enterprise' oriented software, in which case it is too expensive for you anyway (those long and personal sales trajectories, negotiations and commissions have to be recouped somehow)

(2) Not actually a product, but a Trojan horse to sell you lots of consulting and bespoke development services.

Re: My application ran away and called home from Redmond

#134

Earlier quoted context omitted.

OK, that makes sense. So how would one block this exploit? You can't test the malware properly without letting it reach its servers. So then you're also letting it upload its exfiltrated data. Which would likely be encrypted.

I think you'd more or less have to block *.microsoft.com at the gateway, then add explicit allows for WGA and Windows Update. Or a group policy update to tell Defender not to upload stuff to MS.

Sorry. I meant how would Microsoft (and other anti-malware) firms block it. When they're testing binaries obtained from users' machines.

For users, sure, try to lock down Windows. Or (my preference) just don't use it. Or don't give it network access, if it contains any information that you care about.

Re: My application ran away and called home from Redmond

#135

From a copyright law perspective, this seems wild. Microsoft is downloading and running binaries from entities that may have never given Microsoft license to do so, including Microsoft's competitors. All based on a permission setting configured by an unrelated third party (the user).

I'm pretty sure that for most home users who are also administrators of their computers, a setting pops up asking if you consent for telemetry to be collected.

I'm not sure if an appropriate warning or option is given for third-party users of a computer, or if it is required for administrators to warn third-party users as such.

Re: My application ran away and called home from Redmond

#136
post #115

Earlier quoted context omitted.

I suppose it could claim that, but I suspect it would be a tough sell with the regulators if Microsoft is uploading large amounts of data the user probably didn't even know about and some of that data turned out to include sensitive personal data.

Are many folks compiling sensitive personal data into binaries?

Presumably most people don't compile that sort of data into executables, but the situation seems to be unclear about whether other types of file might also be uploaded through similar mechanisms, and there also seems to be something going on involving MS executing the files and allowing remote connectivity, so the issue still seems relevant.

Re: My application ran away and called home from Redmond

#137

Reminds me of the story about the NSA contractor who had pirated Office on their laptop, and when Kaspersky AV predictably collected a sample of the virus-infected keygen to its servers, the US tried to spin it as "Russian data exfiltration".

Oh, yeah, I remember that one !

Re: My application ran away and called home from Redmond

#139

One of the main reasons we don't want anything to do with most recent Microsoft software at my office is concern that unspecified data we're working with -- which might include information obtained under NDAs, clients' trade secrets, sometimes personal data, etc. -- might get sent up to the mothership when one of the telemetry systems phones home. People look at me as if we're crazy for worrying about this possibilit…

If it was just Microsoft... it also goes for Intel and Ryzen era AMD processors. Maybe IBM's new PowerPCs are safe ?

Re: My application ran away and called home from Redmond

#140

Earlier quoted context omitted.

Yet another reason I'm reluctant to upgrade to Windows 10. Too many buttons and toggles to turn off to arrive at a PC that functions the way I expect it to, and an update mechanism that's likely turning new ones on faster than I can spot them.

This is a Windows Defender thing, not a Windows 10 thing. Windows Defender on Windows 7 also submits previously unobserved binaries to Microsoft for the same reason. Go ahead, blame Win10, though. A non-zero number of people will take your comment to heart and believe that you knew what you were talking about with their entire soul, without seeing my comment. I am so tired of seeing communal ignorance on this topic.…

You're splitting hairs on semantics. However you slice it, the software is present after a fresh OS installation, with a default setting that broadcasts my files to Microsoft.

Since you brought up Windows 7, I'll point out in those days Microsoft had the decency to inherit the setting from a choice made during OS installation (but even then you had to dig a little to discern the connection): https://i.imgur.com/SpqXmod.png. You further had to visit a SpyNet enrollment screen before it collected more "advanced" metadata like filenames, location, etc: https://i.imgur.com/z3qtuxp.png

On Windows 10, even if you turn off ALL three pages of privacy-hostile options during installation: https://i.imgur.com/RjXSM6S.png

...you still wind up with a Defender that broadcasts your files: https://i.imgur.com/1M7z3nH.png

Incidentally, the Privacy Policy links in that screenshot all just forward to the generic Microsoft one (https://privacy.microsoft.com/en-US/privacystatement), so who even knows what additional metadata each feature sucks up.

This is what I'm talking about when I complain about all the buttons and toggles to turn off just to get my OS to function the way I expect (in this case, stop indiscriminately bleeding my bits and bytes to the cloud).

Post reply on HN