Live data from Hacker News

Windows OS, Services and Apps: Network Connection Target Hosts (2021)

helgeklein.com

261–270 of 296 posts

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#261

Earlier quoted context omitted.

DRM and Content contracts. They can't just throw 4k into an unsecured environment because they need to make a best effort to enforce that their 4k content isn't pirated.

I'm sure that is the reason, but I find it hard to believe that ripping content could possibly be that much harder just because you're on Windows. And Netflix exclusives regularly make it to pirate sites in 4K afaik?

Windows/Apple have special APIs which allow video decrypting to be done on the GPU. And the GPU will not allow you to access the decrypted video surface.

This is why you can't screenshot Netflix on Windows/Apple - the region where the video is will be black.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#262
post #18

Earlier quoted context omitted.

Aside from fsflovers link; there's a fantastic (paid) firewall software called littlesnitch. You can use it to watch every process send network traffic, you can even collect samples of the traffic and plot it on a map: https://www.obdev.at/products/littlesnitch/index.html (not affiliated, just a happy customer; it's one of the few things I like the mac ecosystem for.. there's attempts to port it to linux with https:/…

Friend, your link ends with a semi-colon. https://github.com/evilsocket/opensnitch

That's awful, I'm sorry.

Thank you for fixing it, I can't edit the post now.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#263

Earlier quoted context omitted.

Is blocking on a DNS level even sufficient? I'd imagine there are hard coded fall back IPs involved at least sometimes.

A lot of IOT devices (including smart TV's), completly ignore DNS

Easy! Just set router level firewall rules to redirect DNS.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#264
post #3

Is there any way to block connection to these sites with DNS or something?

I doubt you'll have a working operating system if you were to block all of those Hosts

You would be fine, Microsoft allows and supports fully air gapped deployments and no internet connectivity deployments.

Yank your internet cord out and start windows.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#265

Earlier quoted context omitted.

Yes and no. That post is about the plugin, but silverlight the standalone application framework is now just part of UWP (and this is about the netflix standalone app after all)

Ok, but the the standalone application is still not required for 4K. You can watch Netflix in 4K using Edge on Windows or Safari on Mac.

You’re right, edge is supported again (during the migration from old edge to new edge it was unsupported for a while). I totally missed that, although it doesn’t change anything regarding linux support.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#266

I read a lot of comments here wanting to block the connections, but wouldn’t be easier/better to switch to an OS that doesn’t spy you? The answers possibly is no, because they might use X or Y that requires them to use Windows, so a better question is, what holds you back to switch to Linux? (macOS also talks to a lot of servers and collect telemetry as Windows, maybe in a different scale, so isn’t an alternative if…

I "solved" this issue by connecting a macbook to my TV so that I can use all streaming platforms without any problem, and I use a separate machine for work. And I prefer to keep it this way.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#267
post #16

Earlier quoted context omitted.

You don't want to block all of that. CLR checking (else your apps may become slow to start) and windows updates (else you may become vulnerable) should be enabled. Someone else has some suggestions?

If I was still using windows I would totally block everything and run a wsus server in a VM that has a vlan and firewall config. The issue is you can only control your firewall at home. Whenever you are out you are pretty sure that MS and Apple bypass any rule you'd put on the local firewall. I prefer running sane operating systems.

Pretty sure your sane OS makes calls to CRL/OCSP lists to validate cert revocation. Many of the calls in that list do just that.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#268

Earlier quoted context omitted.

"It's just too much work for me to figure out how to use Linux" This is the crux, really. I'm adept at server administration, and have used Linux there for decades, but on the desktop it is, from my POV, pretty much a dumpster fire of bad usability. Had Apple not gone to OS X 20 years ago, I suspect desktop Linux would be materially further along, but with a well-designed and well-supported commercial *nix OS in the…

(Joke) Unless you're North Korean: https://en.wikipedia.org/wiki/Red_Star_OS Jokes aside: > Had Apple not gone to OS X 20 years ago, I suspect desktop Linux would be materially further along, but with a well-designed and well-supported commercial *nix OS in the market that ships married to bespoke hardware, there's materially less motivation to make desktop Linux better for people who won't want to have to tinker to…

Android is, but nobody's running Android on the desktop.

ChromeOS is, I guess, but how much of a true desktop OS is it vs. a front-end for Google? (Not trolling; I honestly don't know because I don't use any Google products, so it's never been on my radar.)

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#269

Earlier quoted context omitted.

Install free Comodo Internet Security. Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the service's startup type from 2 (auto) to 4 (disabled)). In CIS, create a new group for all files under c:/windows. Create a rule denying all in/out requests to that group. Create a rule allowing only DHCP and NTP requests (255.255.255.255:67 and :123) for svchost.…

take it with two tablespoons of salt if someone who avoids the onboard ping tool claims there are no ill effect of blocking all network connections of OS components except DHCP and NTP. This recommendation will cripple windows features and your enjoyment may vary. (breaking updates, breaking crls, breaking active directory integration, breaking office integration, breaking push notifications, breaking companion app i…

[dead]

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#270
post #166

Earlier quoted context omitted.

Eh, Linux is more stable than Windows 10 in my experience, even with a bunch of extra bs and custom configuration that I needed. Windows 7 was rock stable. Indeed, it was W10 that caused me this kind of headache a few times - just updated itself overnight and blue screened. No way to recover even with their recovery tools. Still have no clue what was wrong with it. Oh and it still to this day starts hibernating rando…

"it still to this day starts hibernating randomly on my ZBooks, with the event log saying it is caused by a CPU overheat event." Hybernating or thermal throttling? Thermal throttling is done on the hardware level and can happen while using any operating system, including Linux.

It's hibernating. Apparently, Windows has the ability to perform some actions based on ACPI, which presumably is disabled by default. For whatever reason, some update enables this feature (once every 6+ months, but not right after restoring from backup, strange as hell), but I guess the thermal zones are improperly calibrated? No idea.

https://docs.microsoft.com/en-us/windows-hardware/drivers/br...

It just hibernates. Passive or active cooling setting, disabled thermal controls in group policy or not, registry tweaks or not. Tried everything.

It just hibernates, middle of work or not. At least it doesn't shut down ¯\_(ツ)_/¯.

I'd say upon reaching ~60-70 degrees on the CPU, but it does it at idle (People with some Dell and Lenovo laptops also have this problem, and it seems so rare that the most common answer is "lol, it's overheating dumdum, thank Microsoft or it would break".

Only surefire solution is to restore from backup.

If it did that under Linux, at least I could easily tell it to ignore everything and let the hardware handle it.

Post reply on HN