Live data from Hacker News

I noticed some disturbing privacy defaults in Windows 10

jonathan.porta.codes

51–60 of 596 posts

Re: I noticed some disturbing privacy defaults in Windows 10

#51
I dont' know why so many people are surprised by the Cortana data vacuum. Doesn't Siri send everything you say to it to Apple or a "trusted partner"? Why would Cortana be any different?

The keylogger and Start menu ads are just creepy though. I shouldn't have to opt-out of targeted ads INSIDE MY OS.

Re: I noticed some disturbing privacy defaults in Windows 10

#52
"Send typing and inking data to Microsoft to improve the recognition and suggestion platform"

"Typing data" sounds like keylogging. If it's what it sounds like, that's really emphatically not okay; that would include all passwords and the contents of all emails sent.

Would someone with actual knowledge care to chime in and say what data is actually sent? If it turns out that Windows 10 really is sending keystrokes to Microsoft by default, it seems likely to cause a significant backlash from Microsoft's business and government customers.

Re: I noticed some disturbing privacy defaults in Windows 10

#53

I dont' know why so many people are surprised by the Cortana data vacuum. Doesn't Siri send everything you say to it to Apple or a "trusted partner"? Why would Cortana be any different? The keylogger and Start menu ads are just creepy though. I shouldn't have to opt-out of targeted ads INSIDE MY OS.

MS seems in the mindset "Can't beat 'em, join 'em" as we're only In-App Purchases away from a freemium OS.

Re: I noticed some disturbing privacy defaults in Windows 10

#54
post #44

Earlier quoted context omitted.

See http://thenextweb.com/microsoft/2015/07/29/wind-nos/ ; "Windows 10 automatically encrypts the drive its installed on and generates a BitLocker recovery key. That’s backed up to your OneDrive account." Together with the ToS: "We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good…

> We will access, disclose and preserve personal data, including [...] files in private folders I don't see any language that restricts that to their cloud offerings. It's in the privacy statement that covers windows too. So unless i'm missing something they're granting themselves the right to disclose your harddrive to government agencies or their own legal department on a good-faith basis.

Every company that has access to your encryption keys can be prompted to give them up with a warrant.

You can keep them from having the key. That's one way around it. Using hardware of some kind (and there are multiple.)

You are also free to use another solution that might meet your strict requirements to personally review the encryption, filesystem, device driver, and memory management code of your operating system to verify it's operating to your specifications. There have literally never been so many options for the privacy minded person with the time to pour through a metric ton of C code.

Re: I noticed some disturbing privacy defaults in Windows 10

#55

People want to be connected, join social networks, download apps, be able to control their appliances from across the ocean, carry devices loaded with sensors everywhere they go--and on top of all it, they want privacy. These are fun and interesting times.

PGP solves all of those. Encrypt on device and prevent the cloud operator of seeing anything.

Re: I noticed some disturbing privacy defaults in Windows 10

#57
post #12

Upon seeing these options in the installation, I thought I downloaded beta version that needs these for feedbacks Realizing I have installed retail version, I regretted my decision now I will read the all EULA for the firet time in my lifetime to see what it gets without asking. And probably I will just keep windows for games only.

Are the games really worth it? There's a lot of games out there. You can live with missing a few Windows-exclusive titles.

Re: I noticed some disturbing privacy defaults in Windows 10

#58

This goes along with the news that Windows 10 backs up your drive encryption key by default, and that Microsoft can use it to decrypt your data. In "good faith", of course.

For most users, this protects them to a useful level. Most users don't think losing a password is a big deal and would be very upset to learn their data is lost because they forgot. That's an anti-feature.

The number of people that'll be protected from leaving their laptop in a taxi, or home burglary, or selling/trading-in a device, or just snoopy relatives or acquaintances, etc. is large and MS absolutely made the right call here. Otherwise, you'd have "experts" giving advice to disable this feature or suffer data loss.

Also, if they use OneDrive to back stuff up (like they should!), the security damage is already done as most juicy files will be unencrypted in MS's hosting and still subject to warrants.

Re: I noticed some disturbing privacy defaults in Windows 10

#59
post #44

Earlier quoted context omitted.

> We will access, disclose and preserve personal data, including [...] files in private folders I don't see any language that restricts that to their cloud offerings. It's in the privacy statement that covers windows too. So unless i'm missing something they're granting themselves the right to disclose your harddrive to government agencies or their own legal department on a good-faith basis.

Every company that has access to your encryption keys can be prompted to give them up with a warrant. You can keep them from having the key. That's one way around it. Using hardware of some kind (and there are multiple.) You are also free to use another solution that might meet your strict requirements to personally review the encryption, filesystem, device driver, and memory management code of your operating system…

I'm not talking about encryption keys.

I'm talking about the data itself. Sitting on my harddrive, as it is.

As I understand it microsoft is saying that they could siphon data from my computer if they deemed it necessary.

Maybe that's an adversarial reading of their privacy statement[1]. But it clearly speaks of accessing files in private folders.

[1]: https://www.microsoft.com/en-us/privacystatement/default.asp...

Re: I noticed some disturbing privacy defaults in Windows 10

#60

Earlier quoted context omitted.

See http://thenextweb.com/microsoft/2015/07/29/wind-nos/ ; "Windows 10 automatically encrypts the drive its installed on and generates a BitLocker recovery key. That’s backed up to your OneDrive account." Together with the ToS: "We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good…

OK. What I'm trying to say is that backing up to OneDrive is optional. You get the choice. You can protect the key with a TPM or a smart card...It's not an all or nothing thing. You have options there, if you are interested. The other thing is that it sounds like a lot of privacy minded people can't trust BitLocker despite any number of assurances from MS or code reviews by third parties. AND THAT'S OK. Use something…

> OK. What I'm trying to say is that backing up to OneDrive is optional. You get the choice. You can protect the key with a TPM or a smart card...It's not an all or nothing thing. You have options there, if you are interested.

Except that the default is both insecure and privacy-violating.

Post reply on HN