Live data from Hacker News

Edge sends images you view online to Microsoft

neowin.net

301–310 of 517 posts

Re: Edge sends images you view online to Microsoft

#301
post #220

Earlier quoted context omitted.

Yeah, I switched to the web version of outlook when I noticed (via little snitch) that the desktop app was sending 100's of MB upstream. No idea why it'd need to send much of anything in that direction.

> switched to the web version of outlook I don't understand what you believe this gained you.

It would decrease their bandwidth use, especially uploads. Much more efficient.

Re: Edge sends images you view online to Microsoft

#302
post #285

Earlier quoted context omitted.

It's sending URL's, and it's not clear if it is also sending cookies or other auth info. I would think / hope that any images covered by HIPAA would not be leakable by URL alone.

If you put an image in a Google doc it will be accessible by the URL regardless of if you are logged in or not. Perhaps not in every case, but in the basic case I have tested this has been true. Sharing the URL is equivalent to sharing the image in these cases.

Discord is the same

Re: Edge sends images you view online to Microsoft

#303
post #220

Earlier quoted context omitted.

Yeah, I switched to the web version of outlook when I noticed (via little snitch) that the desktop app was sending 100's of MB upstream. No idea why it'd need to send much of anything in that direction.

> switched to the web version of outlook I don't understand what you believe this gained you.

I think I was mainly upset that it was using a bunch of upstream bandwidth (if I remember right, it kept going while idle), possibly also didn't like the disk space that it was using for caching. Nothing important. Arguably a web application is more secure, since it can't read my disk, but that wasn't my concern.

At this point, I prefer the UI of the web app (I tried switching back), and since it is a PWA, it behaves like a normal application.

Re: Edge sends images you view online to Microsoft

#304
post #171

Earlier quoted context omitted.

> The security model alone is an unfixable disaster (and many have tried over the years) Surely you are talking about Windows... :-)

Linux isn't any better. Take any Debian based os download a .deb and double click it. It's executable by default, opens up in something like Eddie and just asks for a password. Nothing about Linux is really more secure than windows other than the fact it is a small target.

You are aware that users are not privileged by default in Linux? While historically in Windows...at least until UAC and Windows 2008...

Not sure what the example proves. The simple fact you can compile your kernel, have a strong model with Linux SE, it's just another ballpark.

Besides the fundamental aspect that Microsoft are telemetry kleptomaniacs, one OS assumes the user machine does not belong to the user, and Microsoft knows better. Linux assumes it's your machine and nobody else.

You can have your own hardened and lighter Linux kernel, with less surface exposure, while with Windows you start with whatever version version of Cortana Microsoft would like to push that week on it's users...Plus all the other unnecessary components that create an almost infinite opportunity of attack vectors.

Naturally for Linux, the open source code, makes for a more transparent process, even if I don't subscribe to the idea that more eyes on the code, correlates directly to higher safety.

Re: Edge sends images you view online to Microsoft

#305
post #257
post #236

Earlier quoted context omitted.

There is a little more to the series at this point than the 30 years old Link to the Past.

That game is still great. Show some respect! More seriously, Tunic also draws upon newer Zelda titles as well as games outside the series. In addition, many 2D Zelda games have come out since the time of the SNES, not even counting re-releases like the recent remake of Link's Awakening. Tunic doesn't just evoke Zelda aesthetically as a substitute for developing its own aesthetic! It's a loving homage to a series that…

The cynic in me wants to argue that all post-SNES 2D Zelda games are in fact remakes of LttP :) I mean that as a good thing.

I haven't had a chance to really play Tunic yet, but I just get the feeling that calling it a Zelda clone is unfairly reductive to both. If Tunic and Okami are both Zelda clones, but not clones of each other, something needs reevaulation.

Re: Edge sends images you view online to Microsoft

#306

Earlier quoted context omitted.

Windows is free. MSFT is literally siphoning data from your personal devices. You’re speaking on an agenda without accounting for reality

More than 80 percent of Google's revenue comes directly from selling your privacy to advertisers --- aka "personalized" ads. More then 80 percent of MSFT's revenue comes directly from selling software and services. Google earns about as much money from privacy invasion as MSFT does from software and data services. You can try to deny or ignore the reality of it --- but you have nothing to refute it other than persona…

Question is who is more predatory not who makes more money

Re: Edge sends images you view online to Microsoft

#307

Microsoft Edge is insane. The amount of privacy invasion it has by default, the constant nagging to re-enable and undo all your changes to the defaults, and maze of settings you have to disable is just crazy. Is there anything it doesn't phone home? Every image, everything you type, history, absolutely everything. I was interested in it initially but I 100% avoid this browser now. I feel like it takes 20-30 minutes t…

I mean is it worse than chrome?

Re: Edge sends images you view online to Microsoft

#308

This is just bananas to me that a browser would perform "super resolution" at all, much less by default . Couldn't this wreak havoc on doing things like viewing medical images, inserting false detail that isn't there? As well as on text in images, e.g. inventing a cleanly readable but hallucinated license plate number on a car, or financial figure, where the original is blurry? Not only does this seem like a terribly…

Reminds me of the issue where Xerox machines would replace some 9’s on your scanned documents with 0’s due to over enthusiastic compression. https://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres...

It's absolutely astounding that they weren't sued into the ground for that. Contracts, medications, engineering drawings, chemical formulae...

Re: Edge sends images you view online to Microsoft

#309
post #89

Earlier quoted context omitted.

Only a matter of time until Ryan Gosling shows up in someone's X Ray[0] [0] https://petapixel.com/2020/08/17/gigapixel-ai-accidentally-a...

Or before the images accompanying a comparison article between a Samsung Scene Optimizer moonshot and $4,800 Sony astrophotography rig become completely incomprehensible: https://www.inverse.com/input/reviews/is-samsung-galaxy-s21-... https://www.samsungmobilepress.com/feature-stories/how-samsu... Don't want to bring too many Reddit memes over, but if the browser enhances the images on both sides of the comparison, a…

Just to be clear, Samsung was caught using basic pattern matching to detect the camera being pointed at the moon, triggering wholescale substitution with the image from the $4.5k camera. A redditor blurred an image of the moon, took a photo of the blurry image on their screen, and got the high-res image.

https://www.theverge.com/2023/3/13/23637401/samsung-fake-moo...

Re: Edge sends images you view online to Microsoft

#310
post #211

Earlier quoted context omitted.

It's sending URL's, and it's not clear if it is also sending cookies or other auth info. I would think / hope that any images covered by HIPAA would not be leakable by URL alone.

I don't know HIPAA specifics off-hand, but I would not be the least bit surprised if ephemeral pre-signed urls get generated for sharing HIPAA protected assets based on cookies/auth. If the URL is live for a time window and doesn't insta-expire on refresh, then it's conceivable that data gets leaked here.

HIPAA requires "reasonable" measures. Hilariously, you can't chuck a drive full of plain text PII into a dumpster in the back of your building...

...unless there's a fence around it.

A lot of the nonsense around shredding hard drives is just the drive industry convincing people that they need to destroy perfectly good devices.

Unless you're facing state-level actors a simple zero-out or pipe from /dev/random will suffice. Or with a lot of modern drives where the data on the platter is encrypted by default, just send the "secure erase" command, causing the drive to roll over the controller's private key.

Post reply on HN