This was also recently brought to my attention: https://news.ycombinator.com/item?id=9973629 Windows 10 RTM has peer to peer updates over the internet as the default. I could swear it defaulted to local-only in the preview, so I didn't even check it until now after doing a clean install of RTM.
P2P by default except on the enterprise edition, in which case it's local network only. They also claim to disable P2P if they detect your internet connection is metered (I'm not sure how that's done).
I noticed some disturbing privacy defaults in Windows 10
551–560 of 596 posts
Re: I noticed some disturbing privacy defaults in Windows 10
#552Earlier quoted context omitted.
> Otherwise, what's insecure about XP? Or more secure about 7, 8, 8.1, or 10? Windows XP had no UAC and most users were surfing as admin, which was inherently more insecure. Also, XP does not have a bunch of security features the newer Windows had, see http://superuser.com/a/739204 . And now without the updates, since security issues are not patched, the system should be open to all kinds of drive-by attacks and what…
I read the link and got nothing out of it. I don't even know what the acronyms mean. I don't understand "drive by attacks": My XP computer has nothing wireless, not even the keyboard or the mouse. Wireless, essentially everything about everything wireless looks to me like a gigantic security problem. Right: I have no smartphone; I have a cell phone someone gave me, but I've never used it and intend never to use it. I…
> My version of Flash is a bit old and, that means that Flash never runs except when I explicitly permit it to run, and I only do that on no doubt fairly safe Web sites.
That does not help. There were flash-exploits for which the click to activate function of browsers were useless against.
> I have a copy of Office 2003 -- with lots of patches, and that's fine with me.
Office 2003 is not supported anymore as well and might contain equally big security bugs (I did not look that up). You open word documents with it, you might be infected.
If you want to stay on a secure system for years where the UI does not change, you will have to migrate to Linux with one of the custom Window Managers like Openbox.
Re: I noticed some disturbing privacy defaults in Windows 10
#553Earlier quoted context omitted.
Also makes decent voice calls, which seems to be more than most smartphones can manage ;-) PS Are you sure it doesn't have Bluetooth?
Yes. It's as dumb as a 3310.
I checked and it did have Bluetooth on the Nokia 103 menu.
Re: I noticed some disturbing privacy defaults in Windows 10
#554I'll bet everything in my pocket that Windows 10 does not keylog every stroke and send it back to Microsoft servers for storage. It's intellectually dishonest to think that's what s going on, because it ruins the conversation about what they're actually doing.
Re: I noticed some disturbing privacy defaults in Windows 10
#555Earlier quoted context omitted.
How's that different from listening to any other human you interact with? Is it somehow worse because it's a computer rather than a human? That's the kind of bigotry that gets you robot uprisings.
It's different in the sense that you know that your firend cares about you, where as for software you can't be sure if it's in your interests.
Re: I noticed some disturbing privacy defaults in Windows 10
#556Earlier quoted context omitted.
I read the link and got nothing out of it. I don't even know what the acronyms mean. I don't understand "drive by attacks": My XP computer has nothing wireless, not even the keyboard or the mouse. Wireless, essentially everything about everything wireless looks to me like a gigantic security problem. Right: I have no smartphone; I have a cell phone someone gave me, but I've never used it and intend never to use it. I…
Drive by attacks in that context does not mean wireless. It means exactly what you think is not the case: That just by being in the Internet you are vulnerable. Exploits like http://www.computerworld.com/article/2488674/malware-vulnera... get patched in Windows 7+, but they stay as a gaping hole in your OS. Nothing you described helps just a bit against that. > My version of Flash is a bit old and, that means that Fl…
Thanks for a definition of "drive by".
The link was for a lot of versions of IE, some of which don't run on XP. I try not to use IE. Sometimes I had to use it at some Microsoft Web sites. Okay.
Mozilla will let me install a new version of Firefox, but Microsoft won't let me install a new version of IE or let me patch an old version of IE. Bummer.
I'd be reluctant to let my 2003 copy of Word open a file from an untrusted source. I do next to nothing with Word.
Occasionally I run the 2003 version of Excel: I generate the data outside of Excel using whatever software I write and then pull the data into Excel for graphing. I don't try to use Excel files from other people.
So, Flash can hurt even if I don't run it! Wow. Looks like Adobe worked really hard to help the hackers.
Does Microsoft really want the their security holes fixed?
Gee, in a big company, how can people pass around Word, Excel, and HTM files? One infected file, and many of the computers in the company can get infected.
Whatever happened to the idea that a program that reads data checks to see if the data is okay and makes sure that bad data can't cause the program to hurt anything? That was the long the implicit, expected standard, right?
If someone can send me a DOC file for Word and, reading that file, Word infects my computer, then Word is junk, and Microsoft writes junk software. Bill and Satya need to get on the case here.
Microsoft's infected toxic-ware? It's been a long time, Microsoft -- time to fix this stuff.
On time sharing, it was the case that any user could write and run any software at all with no damage to the operating system or to any other user. Why is it possible at all to run software as a user on Windows and hurt Windows? Bummer.
Microsoft, we need some guarantees, or at least strong assurances with, say, a major bounty program, that such things just are not possible. How about a bounty of $1 for the first bug and for each subsequent bug double the bounty? How 'bout that Bill? Risk your fortune or fix the bugs?
Re: I noticed some disturbing privacy defaults in Windows 10
#557Earlier quoted context omitted.
See http://thenextweb.com/microsoft/2015/07/29/wind-nos/ ; "Windows 10 automatically encrypts the drive its installed on and generates a BitLocker recovery key. That’s backed up to your OneDrive account." Together with the ToS: "We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good…
Read this warning on release day, went to read this myself and haven't found such statement neither in ToS, nor in Privacy Policy. This paragraph (about private communications and files in private folders) seems to be gone from their Privacy Policy. Google cache confirms it was present (in PP, not ToS), but I suppose MS spotted had this insane statement and removed in a hurry - or hid somewhere else, deeper in small…
$('.learnMoreLabel').click()
If you search the page for "disclose", you'll see that that exact wording is no longer present, but very similar wording is in the "Reasons We Share Personal Data" and "Skype - Partner companies" sections.[1]: https://www.microsoft.com/en-us/privacystatement/default.asp...
Re: I noticed some disturbing privacy defaults in Windows 10
#558Earlier quoted context omitted.
> what data is actually sent? It's important to remember that it doesn't matter what MS is doing today. What matters is what the force-updated version will do in the future. Or did everybody forget that you cannot prevent updates in this version?
Think about this... If more things forced auto-updates, we might not have been forced to support ie6 for so damn long. It's a trade off. Instant security patches, instant support for new standards, etc, all without having to worry about all of those users who just will not press that "update" button. Sounds like a pretty decent plan to me. I would be fairly surprised if Microsoft didn't re-display TOS after each upda…
And my options as a user are then what exactly? Accept the new TOS or have the device rendered unusable and lose access to all my data? That's definitely the basis for an unbiased, informed decision.
Re: I noticed some disturbing privacy defaults in Windows 10
#559Earlier quoted context omitted.
> an exploit for TLS The world would end immediately.
Exploits for popular SSL libraries are discovered all the time. Surely you haven't already forgotten about "heartbleed" and the vulnerabilities that followed. I'm sure the NSA knows of several other exploits that they are keeping quiet so they can keep using it, and they may even attempt to deliberately introduce vulnerabilities. Furthermore, even without an exploit TLS connections can be decrypted by anyone with a t…
This is only true using a man-in-the-middle from the initiation of the connection. SSL/TLS sends random PKI keys at the start of a connection. The trusted CA keys are used only for identity (so you know you are really connected to xyz.com). After all, you can have SSL/TLS connections without a trusted CA. It basically works like this: When you make an SSL/TLS connection, each side generates a random keypair, whereafter each sends its public key to the other side. Using these public keys, each side sends a new random symmetric key back again to the other side, whereafter the actual data transmission begins.
Re: I noticed some disturbing privacy defaults in Windows 10
#560I think that Microsoft are crazy to think that can control the pcs of users because launch Windows 10 upgrade for free. Tks Microsoft for the upgrade, but not is with it that the enterprise will buy my privacy, control my PC, what I install, what I do with my computer, etc, etc, etc, the machine is mine and I want to continue owner of it. I not want show to me many things that I not want to see, install app that I not want and use in my pc, use of the my internet connection to send things to internet. Want my collaboration, ok I can think in this, but when I want, not when Microsoft want.
Sure have many users that not understand what are happens, but are much users that are advanced users and know what happens and how neutralize this privacy invasion.
My first impression in these day about Windows 10 is cool for other side. I think that can be the right successor of Window 7, but ... no using the unilateral ideas to force users share all with Microsoft, that Windows 10 will be a good OS. Need respect the privacy of the users. If not is like windows 8, 8.1 that not win the market because try to force all to have new hardware, etc. If go in this direction we have Linux, Windows 7 to use and who know, Android OS to PCs, is now a good time to this smiles. Yes, this is a technological war, users in a side and Google, Microsoft and others in the other. But who buy computers, OS, software are the users. The true own of market. Sorry for errors english not is my native language, but I think that is possible understand.