Live data from Hacker News

Microsoft's Software is Malware

gnu.org

171–180 of 185 posts

Re: Microsoft's Software is Malware

#172

Earlier quoted context omitted.

It's not FUD. Your comment is FUD. The fact is that MS has well tested security patches sitting on their hard drives for software used by lots of people, which they are only selling for prices so high that 99.9% of people won't get it. That is completely different than deciding not to write the patches. And it's also just pointing out another instance of proprietary software and why it's bad, which if that is fud, we…

> MS has well tested security patches How do you know this? I find it likely that they tested them for the specific use cases of the 0.1% who are actually going to receive the patches, since they are providing a specialized solution. > And it's also just pointing out another instance of proprietary software and why it's bad, which if that is fud, well the core of linux and gnu are fud too. You can want to use free so…

> use cases of the 0.1% who are actually going to receive the patches

It seems highly unlikely. They are not writing custom ordered security patches. They are selling general security support to whoever can afford it.

Re: Microsoft's Software is Malware

#173
post #89

Earlier quoted context omitted.

In Android you can deactive all phone home and cloud features, also most Android device manufactore add various apps that require no cloud connection at all. The same goes for iOS were it is even easier. In contrary to Windows 10 were you can't deactivate several phone home and cloud features. Severals apps are only shipped as cloud-only. The Windows update is forced on you and cannot be deactivated. And to top it, e…

It takes a lot more than cutting Google out of the OS to truly make it secure and private: https://blog.torproject.org/blog/mission-impossible-hardenin... --- Report finds Android/iOS apps regularly 'spy on users' http://www.bbc.co.uk/news/technology-34732514 Researchers from the Massachusetts Institute of Technology (MIT), Harvard, and Carnegie-Mellon universities studied 110 apps available on Google Play and the Ap…

You can configure the Android firewall, done.

Win10 firewall especially has a hardcoded whitelist for Microsoft phone home IP address ranges and domains - how evil is that? You would have to patch the kernel mode network driver dll to make sure Win10 won't phone home, a software firewall would still have to rely on Microsofts kernel mode dll. And why would one trust them anymore - they were the first company that handed over their data (Hotmail/Outlook.com) as we learned last year (neither Apple nor Google cooperated). And I always thought Microsoft has a solid business and has no reason to rely on advertisement business and therefor label the user data as products, things have changed since Ballmer. Fact is Win10 on PC and mobile is impossible to secure without running it behind a hardware firewall (or Enterprise license) - and who is running around with a hardware firewall device connected to their phone/notebook?

Re: Microsoft's Software is Malware

#175
post #92

I had the opportunity to try Windows 10 last week. I was surprised to find that Windows now has pop-up advertisements for Office and Bing embedded in the OS itself that recur during day-to-day usage and cannot be dismissed. That seems wild to me. Also, contrary to opinions that I have heard on HN and elsewhere on the web, Windows 10 is typical poor quality Microsoft software, not one of the "good" Windows like XP and…

Using Windows10 since launch, never ever had I've seen a single pop-up.

Are you sure you don't have malware?

Re: Microsoft's Software is Malware

#176
post #166

Earlier quoted context omitted.

These things are dismissed because they are dismissible. For example, the article says: > Windows 10 sends identifiable information to Microsoft, even if a user turns off its Bing search and Cortana features, and activates the privacy-protection settings. And links to an Ars Technica article. If you follow this link, you will find that it says nothing of the sort: Windows 10 doesn't send identifiable information to M…

I read a few parts of the article and already saw this: "For example, even with Cortana and searching the Web from the Start menu disabled, opening Start and typing will send a request to www.bing.com to request a file called threshold.appcache which appears to contain some Cortana information, even though Cortana is disabled. The request for this file appears to contain a random machine ID that persists across reboo…

It's a GUID (as far as I know) that is randomly generated every 30 minutes. I mean, if people think that's a serious privacy problem, then they shouldn't be using any Internet protocols at all. I mean, you yourself draw the IP address comparison, so where do you draw the line? I mean, doesn't it bother anyone from the so called "FOSS" people that cell phones regularly identify themselves to supporting towers?

(As a brief aside: I don't like calling the FSF supporters in this particular case FOSS people. FOSS is a broad field and not all of it are anti-commercial zealots)

So this leaves me with a problem of defining what "personally identifiable" is. If it's comparable with an IP address, then the argument is so watered down, it's a non-starter. If you say that sending a random 128-bit number into the Internet somehow severely violates my privacy and degrades the usefulness of the software, then it's wrong.

The reason why I call FSF zealots arrogant, is that they don't seem to ever consider the needs of users, but rather try to dictate them. They assume some moral and technical superiority and never consider the possibility that people are OK with the proprietary software's trade offs. I use Windows 10, OS X, and Adobe Creative Cloud among other things. Open source alternatives to those products (in my opinion) are shit. I really don't miss literally days of configuration -when I used to run Linux and FreeBSD machines exclusively 7 years ago- and still being in a constant state of subtle, changing brokenness.

But it is a logical thing. FOSS is a philosophy, and not a business. Expecting it to produce polished end-user products is wrong: it is very hard and people doing it would like to get paid regularly, thank you very much. But that's the economics of it. Look at Ubuntu: they start to move towards a more polished, more coherent product, they become less libre and more commercial. Should we criticize them for it? No.

So unless Windows 10 is tracking my bank transactions, I'm OK with it broadcasting a different GUID to the Internet now and again. If I'll get paranoid about my privacy, I will buy a rugged laptop, put OpenBSD on it and start living in the wilderness.

And if people really want to commit to FOSS, then they should focus on writing clear and good software under public domain or MIT license and stay away from the cheap, patronising, rms-inspired politics.

Re: Microsoft's Software is Malware

#177

Earlier quoted context omitted.

So let me get this straight... you think that a legal requirement should be secret ?

I don't think that at all - where did you get that? I'm referring to national security letters, which any regular reader of HN should know about and which require you to hand over information like this and keep it a secret. If Microsoft had government mandated backdoors, there's a good chance they'd be required to keep the intentions hush-hush as well.

Weren't NSLs found unconstitutional?

Re: Microsoft's Software is Malware

#178

Earlier quoted context omitted.

I don't think that at all - where did you get that? I'm referring to national security letters, which any regular reader of HN should know about and which require you to hand over information like this and keep it a secret. If Microsoft had government mandated backdoors, there's a good chance they'd be required to keep the intentions hush-hush as well.

Weren't NSLs found unconstitutional?

Possibly - not sure which cases have dealt specifically with national security letters and which have dealt with other aspects of the related programs. However there have definitely been cases which the government lost initially and then won on appeal, and as I've discussed on here before, I'm not convinced that inherently secret agencies will actually not do illegal things once they lose the case. They may still send letters to intimidate people and just won't be able to enforce it so easily. So the concept is still relevant IMO. We can't assume companies are allowed to disclose such backdoors if they exist.

Re: Microsoft's Software is Malware

#179
post #173

Earlier quoted context omitted.

It takes a lot more than cutting Google out of the OS to truly make it secure and private: https://blog.torproject.org/blog/mission-impossible-hardenin... --- Report finds Android/iOS apps regularly 'spy on users' http://www.bbc.co.uk/news/technology-34732514 Researchers from the Massachusetts Institute of Technology (MIT), Harvard, and Carnegie-Mellon universities studied 110 apps available on Google Play and the Ap…

You can configure the Android firewall, done. Win10 firewall especially has a hardcoded whitelist for Microsoft phone home IP address ranges and domains - how evil is that? You would have to patch the kernel mode network driver dll to make sure Win10 won't phone home, a software firewall would still have to rely on Microsofts kernel mode dll. And why would one trust them anymore - they were the first company that han…

So did you actually read any of the links?

> to make sure Win10 won't phone home

Windows 10 is "Windows as a Service" and is continuously updated from the web, based on telemetry. It also runs on smartphones and games consoles. It includes notifications, cloud (OnDrive) integration and an intelligent assistant (similar to Siri, Google Now and Alexa).

Re: Microsoft's Software is Malware

#180
post #77

And after reading that, let's take a deep breath and think about Android. From my personal opinion, it's not better than and maybe worse : - Obligation of having a G+ account. Disable it is NOT straighforward at all and it will try to recreate himself often. - Personal content publicly uploaded/displayed in G+ account I had the bad surprise, and few friends also to see that the photos taken with my android phone were…

Yes, let's talk about Android. First, let's try and get a few things correct before we talk about it. 1. There is no need for a Google+ account. Why you would say this makes me wonder if you even use the platform. 2. You don't even need a Google account and can use the phone without one. 3. Getting back to the Google+ account. If you don't want one or would like to delete your existing one then there's a simple way t…

Agreed However, as a lambda user, by buying an android phone and following the default "init procedure" you would have a G+ account without really asking it.. If you disable it, if you try to do something on YouTube, your G+ account will come back as herpes comes back...

The problem is not really what is possible to do but how much effort is needed to protect his privacy using google tools.

Post reply on HN