Windows 10 Enterprise ignores various privacy settings
111–120 of 269 posts
Re: Windows 10 Enterprise ignores various privacy settings
#112Earlier quoted context omitted.
It's kind of interesting, is it common for you to have Win10 systems in scope for PCI compliance? It seems unusual to me if any desktop systems are anywhere close to card data, IMHO usually you'd have in scope only a bunch of servers (so, Linux or Windows Server for normal businesses who don't have a reason to wrestle mainframes) in an isolated network, but most of company computers including all the user desktops sh…
Wouldn't call centers for online retailers need compliant desktops? How do they deal with customers who prefer to call an agent and read their card number over the phone?
Re: Windows 10 Enterprise ignores various privacy settings
#113Most of his configuration is invalid, due to his misconfiguration of group policy. For example, he disabled the Teredo policy. But here's the help text for that policy: "If you disable or do not configure this policy setting, the local host settings are used." He made this error countless times, rendering the entire experiment a failure. Oops.
But to show how easy of a mistake this is to make, here is what Microsoft's documentation from https://docs.microsoft.com/en-us/windows/configuration/manag... says:
Enable the Group Policy: Computer Configuration > Administrative Templates > Network > TCPIP Settings > IPv6 Transition Technologies > Set Teredo State and set it to Disabled State.
Reading that, it seems as though you should disable the policy but in fact you should first Enable the policy, then go into the policy settings and Disable the setting there. And even with that mistake, I had it manually disabled in both HKCU and HKLM so if disabled means it uses the local host settings then it should use that.
Nevertheless, there are some serious concerns here:
1. Why is it even connecting to facebook, msn ad services, google analytics, etc when nothing is running?
2 Why is it doing this by default on an Enterprise operating system?
4. Why is this the default setting that requires dozens of group policy settings (and knowledge of group policy) to disable?
5. And why is there no option to opt out completely?
Re: Windows 10 Enterprise ignores various privacy settings
#114Most of his configuration is invalid, due to his misconfiguration of group policy. For example, he disabled the Teredo policy. But here's the help text for that policy: "If you disable or do not configure this policy setting, the local host settings are used." He made this error countless times, rendering the entire experiment a failure. Oops.
It's a huge bummer that the (wildly implausible) results he got didn't discourage him from spreading them widely. He later said they were 'unexpected' and he was working on verifying them from scratch reproducibly, but that comes only after misinformation about telemetry is spreading around the web. :(
I haven't published results anywhere and many people, including in the comments here, have corroborated what I saw.
The results are the results. I am re-verifying before I publish anything on this and to provide a script so that others can reproduce the results. That certainly does not make it wildly implausible.
Re: Windows 10 Enterprise ignores various privacy settings
#115Earlier quoted context omitted.
>This is where you start going off the rails. People did buy hardware that was compatible with the operating system they do use. It is super presumptuous and weird to try this sleight-of-hand in your argument. Make new purchases more intelligently. >You are now off the rails and airborne. Excel is still largely unsupported and breaks nontrivial spreadsheets. The UI is also, IMO, a huge step backwards from Office and…
I've been using Linux as a daily driver for fifteen years. I have shot my share of trouble and the next two guys' too. It's not a good experience . It's bad . Even when things aren't breaking left, right, and sideways (which, to be clear, definitely happens less often today than five years ago, with the corollary that that breakage is usually something a mere mortal can't do too much about), it feels kinda...well, sh…
How about being much easier to keep up to date for the average user? A single tool updates everything and doesn't leave a million bundled copies of various low level libraries in every app that uses them. It's much easier for a normal person (or advanced user) to keep a linux system patched. Keeping your OS and applications takes a lot of effort on windows.
Another is that it comes with a lot more great tools out of the box than windows, users don't have to navigate the web trying to find software or rely on OEM crapware.
UI wise it provides a much more consistent experience and it stays out of your way a lot better (no focus stealing shit everywhere).
Re: Windows 10 Enterprise ignores various privacy settings
#116Earlier quoted context omitted.
It's a pretty broken configuration system that makes it needlessly difficult to do things the correct way.
Agreed. It should read "unconfigured" -- not "disabled" Some of the GPO settings make me feel like I'm reading a contract written by a lawyer out to get me. I don't have any concrete examples, but I swear I've stumbled across settings like this : Setting - Disable Windows Error Reports. Description: Disable the submission of error reports Options: Unconfigured - Use client settings. Disable - Send only minimal inform…
Re: Windows 10 Enterprise ignores various privacy settings
#117Earlier quoted context omitted.
It's a huge bummer that the (wildly implausible) results he got didn't discourage him from spreading them widely. He later said they were 'unexpected' and he was working on verifying them from scratch reproducibly, but that comes only after misinformation about telemetry is spreading around the web. :(
I actually didn't spread them widely, I tweeted them. If you follow me you would know I tweet things like that all the time. I observed these connections and showed the settings I have set that should have prevented them. I haven't published results anywhere and many people, including in the comments here, have corroborated what I saw. The results are the results. I am re-verifying before I publish anything on this a…
I don't know if this will be of any help but https://news.ycombinator.com/item?id=13727712
Re: Windows 10 Enterprise ignores various privacy settings
#118The switch to Linux or other free operating systems is long overdue. If your excuse is hardware support, then (1) your hardware is probably supported these days and (2) you should not buy hardware that is incompatible with the operating system you plan to use. If your excuse is editing MS Office files, LibreOffice supports the formats and works great, and MS Office on Wine is an option. If your excuse is games, then…
It boils down to "it works for me, and if it doesn't work for you because of X, Y and Z, then you should just stop doing that".
You can judge for yourself just how persuasive this argument really is by looking at desktop Linux market share over the past 20 years.
Re: Windows 10 Enterprise ignores various privacy settings
#119MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…
I went through the same thing last year. I spent two months trying to plug all the holes in the enterprise version, for a medium sized healthcare client, and eventually gave up. The LTSB edition looks promising but I haven't put it under the microscope yet.
There's apparently some new LTSB on its way but this aside it is not the panacea this thread makes it out to be.
Re: Windows 10 Enterprise ignores various privacy settings
#120The connections in the first screenshot[0] aren't necessarily from Microsoft. This screenshot shows a DNS lookup for google-analytics.com followed by an attempt to use Teredo. If Chrome is installed then this could be from the Google Update service. It seems unlikely that Microsoft would send usage information to a Google site. [0] https://twitter.com/m8urnett/status/866353982217699328 Edited to omit needless words
Also note that the only third-party software running at the time was wireshark, DNSQuerySniffer, and Glasswire.