Live data from Hacker News

Windows 10 Enterprise ignores various privacy settings

twitter.com

11–20 of 269 posts

Re: Windows 10 Enterprise ignores various privacy settings

#11
Since the first release of W10 several registry keys and policies have changed in very confusing ways. I can't remember what exactly but I had to change my personal scripts several times based on the changelog of other tools. Privacy and settings like default apps were also reverted (reset to default) when you updated. They installed some apps like Candy Crush Saga on Enterprise. I don't see that much of a problem here, it's understandable since they are letting go of legacy stuff, bugs happens (even more after you cut your QA department). Now it's time to stop with all the excuses. Get your shit together.

From: https://technet.microsoft.com/en-us/itpro/windows/manage/con...

> Security. Information that’s required to help keep Windows, Windows Server, and System Center secure, including data about the Connected User Experience and Telemetry component settings, the Malicious Software Removal Tool, and Windows Defender.

I have all the possible settings configured, from registry to policies and I still see random connections everywhere. But it's ok because it's not telemetry, right?

> What is NOT telemetry?

> Telemetry can sometimes be confused with functional data.

Is anyone taking legal actions against Microsoft about all of this? Does anyone care? Not everybody can switch all their machines to Linux/VMs, this whole situation makes me angry.

Re: Windows 10 Enterprise ignores various privacy settings

#12
I read that Windows 10 uses peer-to-peer file sharing with any other Windows hosts it locates on the same network.

This way each Windows computer does not have to connect to Microsoft to download, e.g., the Windows 10 "upgrade". It seems like this could also be used to evade attempts by users to block such downloads by blocking Microsoft IP addresses.

Windows 10 could propagate itself through a network of Windows computers, like a ...

Seriously, how does this work in pratice?

Windows 10 does peer-to-peer file sharing automatically without requiring any user interaction?

Re: Windows 10 Enterprise ignores various privacy settings

#13
Frankly, “settings” in an OS don’t fill me with any more confidence than “settings” on Facebook: software has bugs, and other reasons for not working as advertised. A toggle switch coded with the best of intentions may still not be consulted everywhere that it should, and even software that is correct today can be wrong in 3 months when somebody important quits or a feature is added and nobody thought to check the setting for that new feature.

If this is important to you, demand more open and peer-reviewed source code, and demand that things run behind carefully-controlled walls like sandboxes and limited host files. Don’t just run your organization by trusting one software vendor.

Re: Windows 10 Enterprise ignores various privacy settings

#15
MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients and I've had to use a whitelist firewall to pass PCI compliance, someone said here that a whitelist firewall is borderline unusable. I've sunk so much time into that solution and I can attest, it's not viable.

Re: Windows 10 Enterprise ignores various privacy settings

#16
post #12

I read that Windows 10 uses peer-to-peer file sharing with any other Windows hosts it locates on the same network. This way each Windows computer does not have to connect to Microsoft to download, e.g., the Windows 10 "upgrade". It seems like this could also be used to evade attempts by users to block such downloads by blocking Microsoft IP addresses. Windows 10 could propagate itself through a network of Windows com…

Yes, this is called "delivery optimization" and it's on by default. By default, Windows Enterprise/Education only pull updates from Microsoft and the local domain, while Windows Home/Pro will also pull updates from other peers on the internet.

You can turn it off, or disable pulling from internet peers, but given the OP, who knows if MS actually respects that setting? I guess we have to roll the dice now.

https://privacy.microsoft.com/en-us/windows-10-windows-updat...

Re: Windows 10 Enterprise ignores various privacy settings

#17
post #12

I read that Windows 10 uses peer-to-peer file sharing with any other Windows hosts it locates on the same network. This way each Windows computer does not have to connect to Microsoft to download, e.g., the Windows 10 "upgrade". It seems like this could also be used to evade attempts by users to block such downloads by blocking Microsoft IP addresses. Windows 10 could propagate itself through a network of Windows com…

Windows has done this forever with enabled apps like SCCM. I think it was released in 2008.

It allowed us to remove hundreds of local depot servers unless there was an SLA on reimaging.

Re: Windows 10 Enterprise ignores various privacy settings

#18

Since the first release of W10 several registry keys and policies have changed in very confusing ways. I can't remember what exactly but I had to change my personal scripts several times based on the changelog of other tools. Privacy and settings like default apps were also reverted (reset to default) when you updated. They installed some apps like Candy Crush Saga on Enterprise. I don't see that much of a problem he…

I can't agree with this more. A client straight up failed a PCI compliance audit, replete with daily fines, for using 10 Enterprise. They decided to pursue legal measures against MS for false claims. I really hope this gets elevated because reverting to win 7 is a solution with a short life span. The other solution is to rebuild infrastructure on top of a different platform but that's prohibitively expensive.

Re: Windows 10 Enterprise ignores various privacy settings

#19

MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…

I don't think they do it on purpose. I think Windows is just a patchwork of cruft at this point.

I'm sure the Enterprise version shares all the code with the non Enterprise versions which have all the spying ... analytics... enabled, so bugs are bound to happen that let this escape into the Enterprise version.

Re: Windows 10 Enterprise ignores various privacy settings

#20

MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…

I don't think they do it on purpose. I think Windows is just a patchwork of cruft at this point. I'm sure the Enterprise version shares all the code with the non Enterprise versions which have all the spying ... analytics... enabled, so bugs are bound to happen that let this escape into the Enterprise version.

The fact that they renamed the telemetry setting from "Off" to "Security" is no coincidence.
Post reply on HN