Live data from Hacker News

I noticed some disturbing privacy defaults in Windows 10

jonathan.porta.codes

501–510 of 596 posts

Re: I noticed some disturbing privacy defaults in Windows 10

#501
post #412

Earlier quoted context omitted.

So instead you use a browser from a company whose goal is to control all your purchasing? Yesterday one of my friends bought a mac. He needed a credit card before he could install vim... vim needs brew, which needs xcode, which needs the istore, which needs an appleid, which needs (well, wants) a credit card on file.

Hmm, I don't think you need a credit card on file. You can select "None" as your payment method. This should allow you to download anything that's free (they'll still ask you for a credit card if you try to download something paid, of course). You installed XCode dev tools and you're set.

You're probably quite right - I'm just going off my friend's report.

Re: I noticed some disturbing privacy defaults in Windows 10

#502
post #179
post #124

https://projectbullrun.org/surveillance/2015/video-2015.html... Of course MS wants to get in on surveillance-as-a-business-model. It keeps people tied to your Service as a Software Substitute, and as long long as most people are still ignorant about how technology works, they won't notice how the stalker-like nature of a lot of modern soft^H^H^H^Hmalware. As for the few nerds that notice, they can probably be shut up…

I'm increasingly believing that for privacy to live, a necessary (but not sufficient) condition is for free to die. By free I mean free as in beer, not free as in freedom. The problem is that if everything has to be free, there can never be any money in the actual maintenance and development of the product. User-centric and privacy-respecting business models are impossible if the product is free. It's necessary but n…

> User-centric and privacy-respecting business models are impossible if the product is free.

What about non targeted advertisement?

Re: I noticed some disturbing privacy defaults in Windows 10

#503

Wi-Fi Sense is a huge security hole, and even if you don't have windows 10, if anyone you trust with access to your network upgrades to windows 10, that person becomes a security problem for you. Obvious solution is to use a strong generated string for your password (so even if they get your password, they're not getting the password to anything else), and then configure your router to require each device connecting…

Hm. I'm genuinely curious - does it share passwords (as typed in) or actual PSKs?

That is, if I'd only let guests with Windows 10 to access network using WPS, would Wi-Fi Sense send negotiated secret or not?

(I suppose WPA2-EAP-PSK should also be an option - IIRC Windows supports 802.1x auth and I doubt they share those passwords... although not many SOHO routers know anything about RADIUS)

Re: I noticed some disturbing privacy defaults in Windows 10

#506

Earlier quoted context omitted.

You were always free to not use new MS operating systems. Nobody forced you to make any MS accounts or use Window 8,10 or whatever, so if you installed Windows 8 and didn't like it, that doesn't make MS evil, just don't use it. Anyone who inclined to use CentOS as their daily driver probably was never going to like MS OS's anyway. You probably only ever installed it just to find out what you hate about it.

The argument "Don't use it if you don't like it." certainly applies to many things, but when a company gets to the scale of Microsoft, Google, Apple, etc, the context is not the same. It seems reasonable to hold these behemoths to a higher standard than scrappy startups.

Imagine if we could bring them to court over bundling malicious software with their OS and not giving the user a choice.

Re: I noticed some disturbing privacy defaults in Windows 10

#507
post #20

Windows is now essentially a personalized, cloud-based operating system with the primary interface as a personal assistant, so I expected to see all these things as defaults. The advanced features just couldn't work without it. I'm glad there's at least an opt-out, but I do think that Windows needs an OS-wide incognito mode, just a simple switch to record or not record data. I generally use that on my browser for whe…

> Microsoft is generally one of the most restrictive companies when it comes to sharing data.

Citation needed?

Re: I noticed some disturbing privacy defaults in Windows 10

#508

Earlier quoted context omitted.

I like my software knowing what I like and what I'm interested in. It makes my life easier, which is what computers were invented for. Philosophical question: is it really your life, if your software may be subtly persuading you in a different direction than what you would've taken if it hadn't been making the suggestions to influence you? There is no doubt it will make things easier for you if all you do is effectiv…

> Philosophical question: is it really your life, if your software may be subtly persuading you in a different direction than what you would've taken if it hadn't been making the suggestions to influence you? No less so than if your friends, family, coworkers, and society at large may be subtly persuading you in a different direction than what you would've taken if they hadn't been making the suggestions to influence…

> No less so than if your friends, family, coworkers, and society at large may be subtly persuading you in a different direction than what you would've taken if they hadn't been making the suggestions to influence you.

I'd add to that list things like Toxoplasma gondii.[1] Who knows, maybe it is the viruses controlling us all. Maybe there are behaviour modifying viruses that cause little to no overt symptoms of infection, or maybe the viruses are changing the DNA of bacteria that impact all living creatures microbiomes. Scary stuff.

1. https://en.wikipedia.org/wiki/Toxoplasma_gondii

Re: I noticed some disturbing privacy defaults in Windows 10

#509

Imagine if you discovered an exploit for TLS and just listened in on a public / hotel network to tons of Windows machines sending keystrokes, calendar, contacts, etc to Microsoft in the background... At least in the Windows 95 days you had to write the key logger yourself and get it installed somehow.

> an exploit for TLS The world would end immediately.

Exploits for popular SSL libraries are discovered all the time. Surely you haven't already forgotten about "heartbleed" and the vulnerabilities that followed. I'm sure the NSA knows of several other exploits that they are keeping quiet so they can keep using it, and they may even attempt to deliberately introduce vulnerabilities. Furthermore, even without an exploit TLS connections can be decrypted by anyone with a trusted CA private key that can issue certificates. Connections could be decrypted plausibly by privileged employees of ANY certificate authority, disgruntled government officials that can compel those CAs to turn over keys, etc.

I know you're just joking (and I even laughed) but it's worth pointing out that the scenario I describe is very realistic.

Re: I noticed some disturbing privacy defaults in Windows 10

#510
post #269

Earlier quoted context omitted.

How do you believe auto-suggest works?

You're comparing Microsoft's request to send ALL typing and "inking" (I assume that means touch and stylus events) to Google logging search terms? No matter how you look at it, essentially reserving the right to install a key logger on your computer is unprecedented.

But reserving the right, or just saying 'Look, we don't know all of the cases where a programmer will say "and if the user corrects this, tell us we screwed up"' (for the optimist) is not the same as sending it all.
Post reply on HN