Live data from Hacker News

I noticed some disturbing privacy defaults in Windows 10

jonathan.porta.codes

151–160 of 596 posts

Re: I noticed some disturbing privacy defaults in Windows 10

#151
post #88

Earlier quoted context omitted.

This is a great suggestion. I'm getting sick of having to open incongito mode on Chrome unless I want Google Now to happily repeat whatever I was looking at later. Uh, I don't need reminders for sales on hemorrhoid medicine or news alerts about the side effects of MDMA. I don't need that popping up where others can see it. Some kind of "off the record" mode would be invaluable for voice interfaces. Hell, it would be…

I agree completely. The split between public and private life is so natural that we sometimes forget how important it is. Sometimes people need to be able to experiment and access information privately so they can think it over without being judged. It leads more genuine expressions in public life, even in simple ways. Maybe I want to experiment with listening to all the worst pop music to see if there's something in…

Absolutely. Or take for example my friend, who's a literary translator - she sometimes has to research online the most outlandish and obscure subjects, which have no bearing on her own interests...

Re: I noticed some disturbing privacy defaults in Windows 10

#153
post #84

Earlier quoted context omitted.

Josh, maybe you don't get how difficult Speech Recognition is now that it comes as standard in your smartphone, but they use Google/Apple (delete as appropriate) servers for a reason. There's a reason people were amazed at the response time of Cortana - local speech recognition that doesn't hog the processor is a big deal. And connecting to O365 calendars offline? Is that not a stupid concept?

I'm well aware of how phones handle speech recognition; there are reasons they do so via services that have little to do with the computational difficulty of speech recognition. It's not by any means necessary to upload raw voice data to a server and process it there, especially if we're talking about full computers rather than just phones. > And connecting to O365 calendars offline? Is that not a stupid concept? I s…

> we're talking about full computers

Worth mentioning: Windows 10 is not just for "full computers."

Re: I noticed some disturbing privacy defaults in Windows 10

#154
post #103

Earlier quoted context omitted.

There's also a difference in perception between Apple's "trusted partners" and MS and Google's "trusted partners". Since MS and Google make a large amount of money from selling you to others, I just instantly assume that they're sharing my data with advertisers . Since I pay for all my Apple stuff and they repeatedly say that they don't sell my data, I assume that "trusted partners" means companies they've outsourced…

Isn't MS closer to Apple than Google in terms of how it makes money? You pay directly for all or most of its stuff. Also, I thought Google sold your eyeballs to advertisers but not your data nor how it figured that it were your eyeballs that were most fit for the ad. (I guess for some ads, the very fact that it thought your eyeballs were fit for them already discloses more about you than you'd like... and I'd guess t…

> Google sold your eyeballs to advertisers but not your data nor how it figured that it were your eyeballs that were most fit for the ad.

This is exactly correct, and it's why I prefer trusting Google with my data over anyone else. I'd rather have my eyeballs bought and sold by a company who's only competitive advantage is the fact that only they have my data.

Re: I noticed some disturbing privacy defaults in Windows 10

#155

Earlier quoted context omitted.

> OK. What I'm trying to say is that backing up to OneDrive is optional. You get the choice. You can protect the key with a TPM or a smart card...It's not an all or nothing thing. You have options there, if you are interested. Except that the default is both insecure and privacy-violating.

It's insecure by a standard that you are setting. If they can demonstrate an audit log of every admin who has escalated their permission to logon to the container of your data and access it, including the files they accessed, would that be good? (Because they do that.) Again privacy-violating by your, arguably, very narrow standard. I'm sorry friend, but you are stating these things as if there's no question as to wh…

If they can demonstrate an audit log of every admin who has escalated their permission to logon to the container of your data and access it, including the files they accessed, would that be good? (Because they do that.)

They are legally prevented from showing you such an audit log if a National Security Letter is involved.

Re: I noticed some disturbing privacy defaults in Windows 10

#156
Wi-Fi Sense is a huge security hole, and even if you don't have windows 10, if anyone you trust with access to your network upgrades to windows 10, that person becomes a security problem for you.

Obvious solution is to use a strong generated string for your password (so even if they get your password, they're not getting the password to anything else), and then configure your router to require each device connecting to be authenticated. Whitelist for MAC addresses + GPG + ?

Re: I noticed some disturbing privacy defaults in Windows 10

#157
post #120

Earlier quoted context omitted.

> For most users, this protects them to a useful level. Most users don't think losing a password is a big deal and would be very upset to learn their data is lost because they forgot. That's an anti-feature. "Would you like to store a backup for your drive encryption password on Microsoft OneDrive? If you choose not to do so, and you forget your password, all of your data will be lost. [Yes/No]" And none of that warr…

>"Would you like to store a backup for your drive encryption password on Microsoft OneDrive? If you choose not to do so, and you forget your password, all of your data will be lost. [Yes/No]" You know when most people care about whether or not they can recover their data? It's not when someone asks them a Yes/No question, it's when they can't recover their data. And responding with "Well, remember 2 years ago when yo…

Then, don't make it a [Yes/No] question, make it an [Okay] with a barely noticeable "Change Advanced Settings" link; much like the dialog that the TFA complains about.

Re: I noticed some disturbing privacy defaults in Windows 10

#158
post #132

This looks like all the same sort of stuff Google defaults you into on Android. I mean, not that it's any better because of that, but this is the state of things now. You're not going to find better unless you install FOSS. Unless you're ready to go full-in on one of the BSDs or a Linux-that-isn't-Ubuntu, navigating the waters of figuring out how to get a phone that has all the features you want with such an OS, figu…

Excuse me if I just don't fully comprehend your argument, but isn't FOSS an orthogonal issue to this? After all, even if software is open source, that doesn't stop it from mining your data. You just know that they are doing so. I suppose you can remove that feature, but it seems you're also able to disable the features here as well. In any case, I'm all for FOSS but it doesn't seem to be a solution to this problem, w…

Yes, I agree that it's not really a problem for everyone. The issue isn't actually privacy. The issue is "find a reason to bash on MS for this month".

Now, I think the incentive structures for FOSS projects are a little different such that the FOSS environment isn't going to converge on the idea of collecting such data. But clearly, throw any sort of system that wants to make money into the mix, coupled with the fact that users just refuse to pay for software anymore, and every giganto corp from Mozilla to Canonical are going to independently come to the same conclusion of collecting this sort of data.

The problem is not that privacy is important. The problem is that privacy isn't as important to people as not having to pay cash for software. So the people who are complaining about this are never going to be happy with anything Microsoft does. Either MS collects too much data, or they are tone-deaf to the market and aren't keeping up with cutting edge features. Either MS "hides" non-default settings, or they are falling behind in the state of the art of UI design.

I mean, Apple or Google wouldn't have even given you the little link that people have been complaining about as "hidden", even though it's right there on the screen. They would have expected you to hunt the setting down in some settings dialog somewhere. What MS has done here is standard MS UI design theory, has been for over two decades.

But it's cool to bash on MS. And the only way such people are going to be satisfied and stay consistent, is to completely bail out of any software where anyone involved has a need to make income.

Re: I noticed some disturbing privacy defaults in Windows 10

#160

"Send typing and inking data to Microsoft to improve the recognition and suggestion platform" "Typing data" sounds like keylogging. If it's what it sounds like, that's really emphatically not okay; that would include all passwords and the contents of all emails sent. Would someone with actual knowledge care to chime in and say what data is actually sent? If it turns out that Windows 10 really is sending keystrokes to…

If it's not explicitly excluded, then it's something they can do and might do in the future without notice.
Post reply on HN