Live data from Hacker News

Why We Can No Longer Trust Microsoft

pcmag.com

131–140 of 310 posts

Re: Why We Can No Longer Trust Microsoft

#131
post #110
post #100

Earlier quoted context omitted.

I don't think that would effect his chances. All of our latest presidents have admitted or have been proven to do illegal drugs of some sort. Not to mention that the U.S. government has done some crazy things with drugs, especially LSD. https://en.wikipedia.org/wiki/Project_MKULTRA http://www.cracked.com/blog/five-fun-facts-about-the-cia-and...

As I understand it, getting a security clearance doesn't especially care about whether you've done anything illegal, it cares about: 1. Whether you're likely to voluntarily leak any secure information. 2. Whether someone who dug up some dirt on you could blackmail you into leaking secure information. Or as the saying goes, it's fine to have a mistress, but having a mistress that your wife doesn't know about is a prob…

Having gone thru the sec clearance thing in the 90s, the third thing is if you have financial issues (like an expensive addiction with much income) and some foreign intelligence service can "help". So they're pretty interested in finances. Which wouldn't have been a problem for Jobs...

Re: Why We Can No Longer Trust Microsoft

#132
post #63

Earlier quoted context omitted.

Steve Jobs went through a background check for a top-level security check in the 80s. I wonder if he ever received it? http://www.wired.com/threatlevel/2012/06/steve-jobs-security... I find it hard to believe that the NSA didn't see one of the most valuable and popular companies in the world as a priority until 2012. I bet they were salivating as soon as the first iPhone launched.

With a public record as a LSD user, I wonder how they could have justified giving him clearance.

I remember an Australian talking about the various levels of clearance - confidential, secret negative (anything stand out in your history), secret positive (in-depth active examination of your history). He said that the process wasn't about finding dirt on you, it was about finding out if you had any dirt that could be leveraged against you. For example, if you were gay and being outed would be a problem, then that's leverage. If you didn't care and were clearly open about it, that's not leverage.

Re: Why We Can No Longer Trust Microsoft

#133
post #107
post #61

Earlier quoted context omitted.

It's conjecture, but it's likely. Apple as a company has put a high value on user privacy, which was heavily influenced by Steve. He was also known for maintaining a high degree of personal privacy for such a public figure (for instance, refusing to put plates on his car).

I thought you were joking about the number plates thing, but it's true (and apparently legal) ... http://thenextweb.com/apple/2011/10/27/mystery-solved-why-st... This reminds me of a friend of mine who proxies all his web traffic through something which strips user agents and referrers. It's very easy for me to tell when he visits my website, because the logs show "-" for each of these fields.

That's really interesting. It sounds like an easy way to get targeted by the people who do want to track you, though. Still -- do you have any idea what he uses for that?

Re: Why We Can No Longer Trust Microsoft

#134
post #110
post #100

Earlier quoted context omitted.

I don't think that would effect his chances. All of our latest presidents have admitted or have been proven to do illegal drugs of some sort. Not to mention that the U.S. government has done some crazy things with drugs, especially LSD. https://en.wikipedia.org/wiki/Project_MKULTRA http://www.cracked.com/blog/five-fun-facts-about-the-cia-and...

As I understand it, getting a security clearance doesn't especially care about whether you've done anything illegal, it cares about: 1. Whether you're likely to voluntarily leak any secure information. 2. Whether someone who dug up some dirt on you could blackmail you into leaking secure information. Or as the saying goes, it's fine to have a mistress, but having a mistress that your wife doesn't know about is a prob…

A friend in college wanted to be an FBI agent, so I got to hear alot about this.

I believed they polygraphed you about drug use, and I recall that they had a threshold number of "experimental" sessions with marijuana that were ok, as long as you disclosed them during the background check and polygraph.

Re: Why We Can No Longer Trust Microsoft

#135
post #81

Earlier quoted context omitted.

But who does inspect it, not me for sure. So, how safe actually is Linux? And how safe is any distribution?

The fact that it is available for everyone to inspect means it can be peer reviewed: http://en.wikipedia.org/wiki/Peer_review That doesn't mean you're supposed to review it or that it is reviewed at all, but it is a requirement for the open source development model. About the Linux kernel, see this example: http://kernelnewbies.org/UpstreamMerge From Quality control section: "Some of the world's best developers will…

It's definitely better then not open source, but still I'd love to know more about those "world's best" developers and who pays them.

Open source is the necessary but not the sufficient condition. It needs to be reviewed by independent people, otherwise the open source part is useless.

Re: Why We Can No Longer Trust Microsoft

#136
post #117

I don't think native MS apps running on a local machine are a risk, I imagine (with a little nieviety) that if MS apps/OS were phoning home on a regular basis with the content of ones documents - someone would have noticed and raised a flag (or did I miss it). Nor is exchange BCC a copy to the NSA - again someone would have noticed. Cloud services excluded. PS. It's *buntu that spins my propeller. PPS. I'd be interes…

Windows natively has several data collecting operations on any machine with Windows installed. Each time you visting a page, IE sends the URL over to be "checked" by Microsoft. Each update, a summery of all installed packages are collected and sent to Microsoft in order to "improve the experience". WAT collects your hardware specification, including the serial number of your hard drive. Each time you connect your ope…

>Each time you visting a page, IE sends the URL over to be "checked" by Microsoft.

Huh? Are you talking about hashes being sent for malware check similar to the ones in Chrome or Firefox? If not its a serious privacy issue.

The ones you mentioned about Updates is also true for Chrome updates. [1]

>Microsoft can forceable push new executable code as updates, regardless if settings has turn of updates.

Any source on this?

>Microsoft word (and Outlook?) do also collect information.

With Office 365, this is more or less a reality.

>Then we have semi-native application such as massager or skype. Both has messages being "scanned".

Are you talking about URL scanning? So does FB, Gchat etc. Expect your messages to scanned or stored no matter what 3rd party service you use. Always use client-side encryption for secure communication.

The most important one you left out is SkyDrive. I remember installing it on my computer and then signing onto the web interface to find out I could even access files outside of my sync directory. Sure you can turn "off" the feature, but I promptly uninstalled it instead.

I don't trust Microsoft with privacy in the cloud but neither do I with any other 3rd party.

[1]https://www.google.com/intl/en-US/chrome/browser/privacy/

Re: Why We Can No Longer Trust Microsoft

#137

Earlier quoted context omitted.

As long as you also "boycott the hell" out of: Yahoo Google Facebook PalTalk YouTube Skype AOL Apple Who have also been mentioned as complicit in this whole scandal. Just to be fair :-) By the way, I actually agree with you and have been slowly switching all my home stuff to linux and trying to get away from Google Dependence (although I type this in Chrome on a Win 8 laptop... damn work computer)

If you think a company has behaved badly, why are you under any obligation to be fair to them? It might be extremely difficult to boycott every company involved, so why not choose one to make an example of? The idea that you must boycott all or none appears irrational.

A boycott is supposed to carry a sheen of justice, and this suggests at least a nod towards being fair.

Re: Why We Can No Longer Trust Microsoft

#138

Earlier quoted context omitted.

As long as you also "boycott the hell" out of: Yahoo Google Facebook PalTalk YouTube Skype AOL Apple Who have also been mentioned as complicit in this whole scandal. Just to be fair :-) By the way, I actually agree with you and have been slowly switching all my home stuff to linux and trying to get away from Google Dependence (although I type this in Chrome on a Win 8 laptop... damn work computer)

If you think a company has behaved badly, why are you under any obligation to be fair to them? It might be extremely difficult to boycott every company involved, so why not choose one to make an example of? The idea that you must boycott all or none appears irrational.

You're an idiot if you can't see why this would be unreasonable.

Re: Why We Can No Longer Trust Microsoft

#139

The reason is obvious in China. Google is blocked by GFW, but Bing is not. So, there must be some dirty business between Microsoft and government of China. If Microsoft can do this in China, they can do this anywhere, even in USA.

So isn't DuckDuckGo but that doesn't mean anything. Maybe Bing and DuckDuckGo isn't used enough to catch the attention of Chinese officials.

Re: Why We Can No Longer Trust Microsoft

#140
post #3

This is a financial disaster waiting to happen. Microsoft is oblivious if it is not doing something to divorce itself from the NSA. Apple, on the other hand, could have come out smelling like a rose, but following the death of Steve Jobs, who apparently refused to play ball with the NSA, it stupidly jumped on board to join the PRISM club. According to the Prism slides, it really looks so: "Dates when Prism collection…

"And can you just imagine how much more sales Apple would get now for not being on that list?"

Barely any change at all, I'd bet. And not worth the legal hassle they could have been up against if it came to a knock-down, drag-out battle with the US Government over .

Post reply on HN