Live data from Hacker News

Microsoft is phoning home the content of PowerPoint slides

rogermexico.bearblog.dev

191–200 of 391 posts

Re: Microsoft is phoning home the content of PowerPoint slides

#191
post #123

Earlier quoted context omitted.

Since 2014 I don't trust my macs. There is no Apple computer without LS installed on in my company. Actually, if LS is not available, I will not use Apple computers at all. Period.

Why don't you trust your macs since 2014. Also why do you still use them if you don't trust them any longer?

Not OP, but for me the answer to your question is: is a tool I need. I _could_ use Windows, and absolutely not Linux/BSD (for the programs/tools I need for work), and, frankly, I don't think Windows is better.

Yes, I know that's not completely true. I _could_ use Linux (I even used Solaris on a notebook for 2 years in the past and I survived) but the cost in terms of effort, lost productivity would be higher than I'm ready to pay. It's a rational choice.

Re: Microsoft is phoning home the content of PowerPoint slides

#192
post #78

The future of personal computing is really dark these days. I just attended an apple event for education and government. The amount of data tracking and the standardization/normalization of this behavior is dystopian. What happened to computers being just fun and a source of exploration and freedom? Microsoft, Gooogle, Apple all constantly push their cloud based accounts … where everything is tracked.

That was never a thing. It was always an illusion for the advancement of artificial intelligence.

Why do you think they are going so hard on the Semantic Web shit? It's not for the disabled - it's for the blind, deaf and dumb AI that needs the entire content of the web to train on.

Re: Microsoft is phoning home the content of PowerPoint slides

#193
post #123

Earlier quoted context omitted.

Since 2014 I don't trust my macs. There is no Apple computer without LS installed on in my company. Actually, if LS is not available, I will not use Apple computers at all. Period.

Why don't you trust your macs since 2014. Also why do you still use them if you don't trust them any longer?

Work only allows Mac or Win to log in to their VPN.

Re: Microsoft is phoning home the content of PowerPoint slides

#194
post #107

Is there any way to tell if your company has opted in? Mine makes a huge show of classifying Office documents and barking about the policies of what can be shown to outside people. It would be hilarious to find out that they've done this, and are letting Microsoft slurp up all the stuff that would get us fired if we sent it to an outside email address.

When I click "Design Ideas" (rightmost icon in Home ribbon), I get a prompt that says "This experience is unavailable. Your organization's admin has turned off the service required to use this experience." This is despite both the Privacy -> "Turn on Optional connected experiences" and "Automatically show me design ideas" options being modifiable by me (and give the same results whether enabled or not), so I guess th…

In options (under General), I see there's a tick box for the feature, and it is checked. I have a button that says "Designer," and it seems to work. Nice! Next time someone in IT tells me something as moronic as "all web application authentication code must be written in C," or that "SAML authentication happens by adding a key to the HTTP header," -- both of which have actually happened -- I'll have a nice redirection to share.

Re: Microsoft is phoning home the content of PowerPoint slides

#195
post #112

What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, an…

The Little Snitch would be asking the OS to please tell it about network traffic. Microsoft's OS. It would be asking Microsoft's OS to tell it about traffic Microsoft's software wants to keep secret. I'm sure there's a world where that isn't a laugh line, but I certainly don't live there.

OS network filtering APIs don’t work that way and another unrelated and unimportant Microsoft team can’t override it

Re: Microsoft is phoning home the content of PowerPoint slides

#197

What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, an…

What I want is Little Snitch on steroids built into the OS where every process, You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people.

With the compiler that you verified and built yourself :)

Re: Microsoft is phoning home the content of PowerPoint slides

#198

I can't say whether the blog is correct or not, as I haven't seen the actual network traffic, but there are privacy controls that the author probably hasn't configured [1]. If it was configured correctly, Designer wouldn't even be available. So it's not as though every user of PowerPoint will have their data collected by Microsoft. [1] https://learn.microsoft.com/en-us/deployoffice/privacy/manag...

Still, Designer should display a notice that this is happening on first use (and until the user checks “Don’t show this anymore”, and maybe auto-turn that on again once a year), because a normal user doesn’t necessarily realize that this is happening. You shouldn’t have to be an IT/Office expert to have your privacy being respected.

Re: Microsoft is phoning home the content of PowerPoint slides

#199

Earlier quoted context omitted.

Do they run on the same infrastructure as the rest of us?

No. DOD/Gov projects can be hosted in completely secure locations, and Azure for Government follows all the required standards. Office365/Sharepoint supports FedRAMP High. Most agencies are in the process of finishing migrations so that both their desktop and online apps use the same data in secure cloud installations.

Sometimes classified leaks onto unclassified networks via human mistake, coincidence, or ignorance. I've literally seen classified PowerPoint slides marked unclassified due to ignorance. This situation requires security to confiscate all machines the data may have leaked to.

Re: Microsoft is phoning home the content of PowerPoint slides

#200
post #173

Earlier quoted context omitted.

What I want is Little Snitch on steroids built into the OS where every process, You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people.

That assumes people actually have the capacity to examine the source to do so and make the requisite adjustments. The real answer IMHO is to control your networking stack outside of your computer instead. Firewall that and you have way better security

How do you do packet inspection when they're all encrypted?
Post reply on HN