Live data from Hacker News

Microsoft is phoning home the content of PowerPoint slides

rogermexico.bearblog.dev

61–70 of 391 posts

Re: Microsoft is phoning home the content of PowerPoint slides

#63

I've raised this point repeatedly in different orgs. It's met with some combination of indifference and lack of understanding and not-my-responsibility-ism, but I'm sure that this will eventually blow up hard in some company's face - like 9-digit settlement for breach of contract, or worse things like breach of export control laws. Enterprise data security on the "MS Office level" at this point is like driving 60 mph…

> is like driving 60 mph on a road with no lane dividers

That’s somewhat funny, because a Landesstraße in Germany has no lane dividers and the speed limit is 100 km/h (about 60 mp/h).

Unless I’m misunderstanding and lane dividers mean the printed lines.

Re: Microsoft is phoning home the content of PowerPoint slides

#64
What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that).

Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, and allow inspection of the actual traffic.

What Adobe CC, Google Chrome, MS Office, and macOS/Windows itself do with this background network connectivity is completely out of control and abusive to the user. They get away with it because the vast majority of users are non-technical and don't realize it's happening.

I've profiled and decrypted the background traffic on a stock Android install and the volume was also appalling. Getting macOS to 0 background traffic involved blackholing large Apple IP blocks at the router, whereas some of their processes use random IPs from these ranges and don't use DNS.

Just as the general public doesn't have the awareness or ability to fight for their privacy rights I doubt any of this will ever be remedied.

Re: Microsoft is phoning home the content of PowerPoint slides

#65
post #45

Earlier quoted context omitted.

It doesn't count anywhere that is protected by GDPR.

> protected by GDPR This is like the firewall in windows 95: nice but useless.

I wish I could disagree with you.

GDPR technically does have real teeth, to the extent that one really shouldn't want to raise the ire of an EU Data Protection Authority. Unfortunately, enforcement to date, and the resulting fines, have been lackluster at best. When will people learn that disincentives like fines and such have to actually hurt to be effective in changing the behavior of corporations?

Re: Microsoft is phoning home the content of PowerPoint slides

#66
post #12

The next era will be of Offline Apps because of stuff like this

quite the opposite. the next era will be online-only SaaS apps accessed via rented thin clients tied to your real identity.

and your dangerous general purpose legacy hardware will not save you from that, as it will be impossible to access the internet with a device that doesn't disclose your identity. to combat disinformation and hate speech, of course.

you vill ovn nothing, und you vill be happy.

Re: Microsoft is phoning home the content of PowerPoint slides

#67

I've raised this point repeatedly in different orgs. It's met with some combination of indifference and lack of understanding and not-my-responsibility-ism, but I'm sure that this will eventually blow up hard in some company's face - like 9-digit settlement for breach of contract, or worse things like breach of export control laws. Enterprise data security on the "MS Office level" at this point is like driving 60 mph…

Yeah, I'm surprised every healthcare related business doesn't either ban PowerPoint or block this "feature" somehow. HIPAA is a hell of a drug.

HIPAA is tame compared to export control and classified information handling. Single occurrences can get you 7 or 8 digit fines and prison sentences.

Re: Microsoft is phoning home the content of PowerPoint slides

#69
post #12

The next era will be of Offline Apps because of stuff like this

quite the opposite. the next era will be online-only SaaS apps accessed via rented thin clients tied to your real identity. and your dangerous general purpose legacy hardware will not save you from that, as it will be impossible to access the internet with a device that doesn't disclose your identity. to combat disinformation and hate speech, of course. you vill ovn nothing, und you vill be happy.

> as it will be impossible to access the internet with a device that doesn't disclose your identity.

and prove the software that's supposed to be running is running.

Re: Microsoft is phoning home the content of PowerPoint slides

#70

I've raised this point repeatedly in different orgs. It's met with some combination of indifference and lack of understanding and not-my-responsibility-ism, but I'm sure that this will eventually blow up hard in some company's face - like 9-digit settlement for breach of contract, or worse things like breach of export control laws. Enterprise data security on the "MS Office level" at this point is like driving 60 mph…

After the issues with Github Copilot and copyrighted code, my mind is drawn towards similar inadvertent leaking of proprietary information via a model trained on that information.
Post reply on HN