Live data from Hacker News

Edge sends images you view online to Microsoft

neowin.net

401–410 of 517 posts

Re: Edge sends images you view online to Microsoft

#401
post #162

Earlier quoted context omitted.

I got a laptop in from a user the other day, that shocked the hell out of me, that floating search bar thing. MS is downright creepy the way they slip things in.

With remote work it always fascinates me to see how many people leave the weather (& news) bar displayed next to the tray on the taskbar, this is something that came with a Windows 10 update. People really don't change defaults... I was wondering if I could make a fake one, just add an appropriate icon and change its label to say something like 6000°C Nuclear Holocaust

Defaults are incredibly powerful. For us on here, we expect to have control and to be able to manipulate these things. For most people a computer is just an appliance like a washing machine. Accept it as it comes!

Re: Edge sends images you view online to Microsoft

#403

Earlier quoted context omitted.

> Today it’s obvious Microsoft can’t be trusted. You weren't around when they were threatening linux with patents and forcing OEMs to not deliver PCs without a Microsoft operating system preinstalled then?

Also, Microsoft nowadays is very much in the business of mass surveillance. This "feature" prepares the ground for a future with client-side scanning and upload filters running all your "local" data and "private" communications through [PhotoDNA]( https://en.wikipedia.org/wiki/PhotoDNA ) and other spyware.

* GETS UP FROM CHAIR * Alright back to DOS it is...

Re: Edge sends images you view online to Microsoft

#404
post #22
post #5

That's nothing. This is on by default: "Allow Microsoft to save your browsing activity including history, usage, favorites, web content, and other browsing data to personalize Microsoft Edge and Microsoft services like ads, search, shopping and news."

Windows is not the product anymore: it's now 1) an ad delivery vehicle. 2) user surveillance collector, 3) cloud service loss leader

Except they do ask you money for it. At this point, they should at least make it a free download. Being forced to have all that crap on something you paid for is just insulting.

Re: Edge sends images you view online to Microsoft

#405

How does this pass legal review?

It's more than likely anonymized, aggregated data that mostly just counts how many times a given picture was visited globally. If it's over X times, by at least Y unique devices and can be accessed publicly (I.e. Random Microsoft server can access it), then they probably upscale it via AI and redirect future navigations to their version of the picture.

Such simple heuristic also circumvents most (or all) the concerns about medical images.

Re: Edge sends images you view online to Microsoft

#406

Earlier quoted context omitted.

With remote work it always fascinates me to see how many people leave the weather (& news) bar displayed next to the tray on the taskbar, this is something that came with a Windows 10 update. People really don't change defaults... I was wondering if I could make a fake one, just add an appropriate icon and change its label to say something like 6000°C Nuclear Holocaust

Defaults are incredibly powerful. For us on here, we expect to have control and to be able to manipulate these things. For most people a computer is just an appliance like a washing machine. Accept it as it comes!

While I appreciate the ability to configure software, I also believe that software that requires too much configuration is poorly suited for my needs and will replace it with something better suited to my needs. There is an incredible number of options out there. We do not have to put up with the nonsense that overbearing businesses subject us to.

Re: Edge sends images you view online to Microsoft

#407
post #362

Earlier quoted context omitted.

It's sending URL's, and it's not clear if it is also sending cookies or other auth info. I would think / hope that any images covered by HIPAA would not be leakable by URL alone.

Even if the payload is inaccessible, consider the implications of leaking an URL like: medical-intranet.example.com/uploads/secure_link/adc83b19e793491b1c6ea0fd8b46cd9f32e592fc/john_doe_1987-04-23_chlamydia_1.jpg

And what prevents a distributed denial of service attack or fuzzing using Microsoft's infrastructure? If you were to trick many users into visiting a site with 1000 variants of:

  
or

  

Re: Edge sends images you view online to Microsoft

#408
post #336

Earlier quoted context omitted.

Just curious, how are images protected by login:password? The only way I know is htacess, which isn't really an easily scalable/usable feature... Many years ago, maybe 10 when I used Facebook I recall you could share a picture location with anybody regardless of login (i.e. Right click, copy image location, send over whatever), so the URL wouldn't be guessable or possible to predict, and the protection would be that…

Images are like any other web asset and can be protected either by the web server (htpasswd) or the application's logic. I think you've been brainwashed by modern storage services (S3) where the URL is essentially always public and out of your control. It's trivial to password protect an image when it's on your server. I would assume any medical provider would protect their images by checking the session and not serv…

You're right, although I would not assume anything when it comes to privacy, there are so many examples where companies did not follow best practice.

We need to move away from this model where others are in control of our private data to one where it's owned and controlled by us, giving access to service providers as needed.

Re: Edge sends images you view online to Microsoft

#409
post #259

Earlier quoted context omitted.

> See that’s on-brand with the cutthroat ruthless billG company Tangential, but this made me reflect on how "good"/"nice" Ballmer, and Ballmer-era MS, was in a very relative sense. This is slightly startling considering how my mental image of either Ballmer or MS is not great. But now looking back it does feel like relentless anti-competitiveness lessened a bit during that era, and lot of good stuff happened then. Wi…

Ballmer was as bad as Gates (and seemed completely unhinged at times to boot), Nadella only looks good next to Ballmer but has done plenty of stuff that should have never ever happened. All of them were present at MS when they pulled their 'millions of lines of code' bullshit in an attempt to kill Linux and harm FOSS.

As a long-time Linux user, the Nadella era looks far better. Back in the earlier eras, MS was my clear and present enemy: they did a lot of stuff to me, personally, to make my life hard because I didn't want to use their software, and tried to force me to be their customer with various tactics.

These days, that's all gone. I don't feel any pressure to use Windows, and I don't see MS doing various legal shenanigans to try to destroy Linux. I'm able to do what I want and not worry about MS much at all. It's very different from the earlier eras that way.

Instead, the difference these days seems to be that MS is the enemy of its own customers (or should I say "users"?). If you use Windows, MS will make your life hard with all this built-in malware and advertising. But if you're like me and you simply don't use Windows, you never see this stuff, except when people complain about it on forums like this, or if you have the misfortune of having to deal with a relative's PC.

Personally, I like this new era much better. I'm able to easily opt out of MS's shenanigans by simply installing Linux. When other people gripe and complain about that stuff, it falls on deaf ears here. ("but but but... I need to play $game on my PC!!!") I feel the same way as when sports fans complain about how much they're getting raped by the media companies so they can follow their favorite team.

Re: Edge sends images you view online to Microsoft

#410

Earlier quoted context omitted.

Reminds me of the issue where Xerox machines would replace some 9’s on your scanned documents with 0’s due to over enthusiastic compression. https://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres...

Wow, I can't believe they shipped the product knowing this could happen and thought that putting 2 warnings in the software guidebook (who reads that?) would suffice. Maybe they only added that in to avoid getting sued. Also, reading the timeline was great. > March 2015 The German Federal Office for Safety in Information Technology bans JBIG2 from being used for archival purposes. Wonder if any other governments took…

I hope they didn't ban lossless JBIG2.
Post reply on HN