Live data from Hacker News

Windows OS, Services and Apps: Network Connection Target Hosts (2021)

helgeklein.com

271–280 of 296 posts

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#271
post #172

I’m surprised by the number of requests to port 80, especially for requests to PKI certificate related domains. I assume there’s an element of chicken-and-egg somewhere that means they can’t use TLS in certain cases. Can anyone offer insight into why this is OK and not subject to MITM attacks on the certificate validation/supply chain?

X509 cert retrievals is predominantly done over HTTP, because otherwise you’d need X509 to implement X509.

It may sound “insecure”, but if you can’t trust X509 without HTTPS, you effectively can’t trust either X509 or HTTPS.

This is why we have layers in software. We trust X509 because of fundamental math. Therefore we trust HTTPS built on X509. Therefore we trust systems built on HTTPS.

Everything is perfectly fine.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#272

Earlier quoted context omitted.

> I personally prefer Linux, but what’s holding me are the streaming services (netflix, amazon, etc), I can only watch SD content if I’m on Linux, I hadn't noticed. Wife's 43" TV is connected to a linux box with firefox that is used for Amazon Prime, Netflix AND Disney+. I haven't noticed poor picture and assumed it ran at 1096x1080. I will certainly have to check this out.

Turns out, for me, watching on a 43" screen in SD is no different to watching on a 43" screen in FHD because I don't use my glasses when watching TV. I can't really say that it has made a difference to my enjoyment of the shows I watched[1]. It is something to keep in mind for if we ever replace that TV with a 60" one. [1]I just now compared a FHD download of "My Name Is Earl" to the SD Disney+ version and did not se…

Yeah a big screen is only exciting for the first few times you watch a show. Then it just becomes the screen. We used to watch TV on a 19 inch CRT from clear across the room, and we enjoyed the shit out of it. The TV is not what made the show good or bad.

It was cool to go to someone's house who had a big TV, but now everybody has a big, high-res TV. Most people aren't even utilizing the resolution their TVs are capable of.

Just like most people are fine with a Sonos speaker or soundbar (IMO, they sound like any other crappy integrated speaker), most people would probably not care above 1080p.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#273

Earlier quoted context omitted.

take it with two tablespoons of salt if someone who avoids the onboard ping tool claims there are no ill effect of blocking all network connections of OS components except DHCP and NTP. This recommendation will cripple windows features and your enjoyment may vary. (breaking updates, breaking crls, breaking active directory integration, breaking office integration, breaking push notifications, breaking companion app i…

[dead]

you misunderstood the reference: "this" was meant to mean the recommendation in the parent post. I edited my post to be clearer.

concerning the intentional breaking of the windows updater and then using a third party update tool: such workarounds don't make the recommendation less bad. The question is: why break the onboard updater in the first place? And all those other features? Sure you have an alternative to office365 and to onedrive and live without the companion app is possible and happy, and maybe you even have a third party crl updater as well and a workaround for the side effects of blocking oscp.

But honestly if you want to replace everything because microsoft is bad and can't be trusted, then start by replacing the kernel.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#274
post #260
post #255

Earlier quoted context omitted.

It's not even the right font, unless you're using custom CSS. The Hacker News stylesheet calls for "Verdana, Geneva, sans-serif", and your PC renders a serif font instead. Something's wrong with your fontconfig setup. What's your distro?

I'm using Archlinux and/or Gentoo. Fontconfig is working fine but Verdana is a Microsoft font and Geneva is a Apple font. My font fallback for sans-serif is DejaVu Serif.

The font fallback for sans-serif should be DejaVu Sans, not Serif. I didn't have any issue last time I used Arch.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#275
post #259
post #254

Earlier quoted context omitted.

That screenshot is not very good at all, and I'm on Linux myself. You're just a few tweaks away from better rendering.

Willing to be wrong of course, I suspect that what I'm seeing and what others are seeing are quite different. Perhaps there's a component of how the LCD is presenting it involved? to me my font is extremely uniform and sharp with no bleeding or blurring. What tweaks do you have? I used to run X11 and ran the gamut of x11 based font rendering tweaks (example of how my old machine looked: https://i.imgur.com/J9biJsW.pn…

This screenshot looks better than the other of yours, but honestly I think it's more due how how antialiasing is rendered there vs in your Firefox screenshot.

Additionally, for ages Linux had shipped with Full hinting, which means distorting the font so straight lines are always on integer pixel boundaries, which looks atrocious. These days distros like Fedora use Light hinting, which is a little better, and in my opinion No hinting looks best, which is what macOS does, but on a low DPI screen means having blurry font. So on low DPI screens you have the choice between distorted but clean fonts, or undistorted blurry fonts.

I don't know about sway, in my case I'm using Fedora with 2x scaling, so I have the option of disabling hinting and avoiding distortion.

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#276

Earlier quoted context omitted.

I already use a pi-hole for our local network, everything msn, windows, microsoft related is already blocked for all our devices, so it's really not a big task. It's also not a big task to maintain the list of domain to block, every few months I find a new one to add. I also don't mind some level of telemetry. And I personally like Windows as an operating system, NT is a very cool and well documented technology, and…

Windows 10/11 would be cool (I really liked 7), if you could buy a professional version. (not the one they call so). I dont want ads and telemetrics.

Windows 10 Enterprise LTSC?

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#277

Earlier quoted context omitted.

Windows 10/11 would be cool (I really liked 7), if you could buy a professional version. (not the one they call so). I dont want ads and telemetrics.

Windows 10 Enterprise LTSC?

Yes. I like that. Minor nitpick: wsl support was a bit behind

Mayor nitpick: can you buy it, if you are not a big coorp?

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#278
We need a crowd-sourced solution for documenting and keeping up with Microsoft's bullshit. After every "cumulative update" I fire up WireShark and find new connections popping up from unexpected places. It's too much of a hassle and I'm just about ready to give up.

That said, Linux is not an alternative for me; I use Office daily, OneDrive, and Xbox Game Pass for gaming.

With a dedicated community we could distribute the work of reverse-engineering the purpose of each of these connections and classify URL endpoints by that (Ads / impressions / telemetry can just get blocked immediately; the rest can be documented based on what functionality is disabled / broken by blocking).

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#279

Earlier quoted context omitted.

Windows 10 Enterprise LTSC?

Yes. I like that. Minor nitpick: wsl support was a bit behind Mayor nitpick: can you buy it, if you are not a big coorp?

> can you buy it, if you are not a big coorp?

I wouldn't know because I 'found it online' (if you know what I mean).

Re: Windows OS, Services and Apps: Network Connection Target Hosts (2021)

#280

Earlier quoted context omitted.

Hah, I thought Silverlight was dead years ago, but I don't keep up with Windows tech at all.

Silverlight is long dead, the poster was mistaken: https://help.netflix.com/en/node/2090

Funny thing is, on an older Mac, If you try to run Netflix with the most current supported version of Safari, they redirect you to a page about Microsoft Silverlight[1]. If you don't read that page carefully, you might conclude you need Silverlight to use Netflix, which, of course, 404's when you go try to find it. Totally broken experience. I encountered this recently and had to download Microsoft Edge for Mac.

I'm not sure if I should be more irritated with Netflix, who can't be bothered to maintain backwards compatibility with not-that-old browsers, or Apple, who can't be bothered to get newer versions of Safari to work on older Mac hardware. Both companies are displaying a total disregard for paying customers who just don't happen to have the latest expensive hardware.

1: https://help.netflix.com/en/node/2090

Post reply on HN