Live data from Hacker News

Microsoft is phoning home the content of PowerPoint slides

rogermexico.bearblog.dev

211–220 of 391 posts

Re: Microsoft is phoning home the content of PowerPoint slides

#211
post #81

LibreOffice FTW. https://libreoffice.org/ It may be glitchy in some areas, but I've been using it since graduating high school, and I can do whatever I want with it.

If you deal with csv (or their tab separated cousins..) libre office sheets (spreadsheet) is really great.

I'm on linux desktop now and this lets me read and write MS office files and works quite well.

Re: Microsoft is phoning home the content of PowerPoint slides

#212

This is a one paragraph claim that doesn't provide resources to show that their claim has basis. It could very well be entirely accurate, but there's no information contained here to know one way or the other. For example there have been numerous claims made previously that link ANY network traffic to a supposed invasion of privacy, but once you delve into the underlying traffic it isn't nearly as nefarious as it ini…

I was expecting at LEAST some screenshots lol

Yes. OP's post doesn't present any evidence that those packets being sent actually contain your personal data. Show us some data from an actual packet or GTFO.

That being said, I don't doubt that they do :)

Re: Microsoft is phoning home the content of PowerPoint slides

#214

Like I said last time: > Did we consent to this? Yes, unless Microsoft doesn't ask for consent in whatever country the author is from. There's a consent popup that you need to click through that informs you that the content of your slides are shared with Microsoft. This is part of "intelligent services" in case you're looking for the details. The author should be able to turn this feature off easily, but yes, they di…

At least in some countries, it legally may not constitute actual consent if the text is so unintelligible to a normal user that they don’t understand what exactly they’re consenting to. And we all know that most users just click “Agree” without understanding what exactly they’re agreeing to because that’s the only way they can get their work done.

Re: Microsoft is phoning home the content of PowerPoint slides

#215

Earlier quoted context omitted.

> is like driving 60 mph on a road with no lane dividers That’s somewhat funny, because a Landesstraße in Germany has no lane dividers and the speed limit is 100 km/h (about 60 mp/h). Unless I’m misunderstanding and lane dividers mean the printed lines.

the bar to drive in Germany is significantly higher than in the united states. Requirements for getting a drivers license in America is ridiculously lenient because the American lifestyle is completely car centric. taking someone's license away is tantamount to sentencing someone to poverty.

Germany makes you get a license to play golf. It sounds extreme at first blush but when you start to think about it...

Re: Microsoft is phoning home the content of PowerPoint slides

#216

Earlier quoted context omitted.

> What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). If you want to you can do that with Linux. Sure you'd need to use the CLI, and a combination of tools but you can…

Not quite. For this to work well, all your apps need to run with not being able to do their own TLS, but to various (reasonable) reasons a lot of applications today do their own TLS. You also don't want to add self-signed certificates, but grab the traffic _before_ it gets encrypted IMHO. In some cases it's still quite viable, like if they dynamic link to OpenSSL (or similar) you could create a facade which allows gr…

> You also don't want to add self-signed certificates, but grab the traffic _before_ it gets encrypted IMHO.

that would be ideal but self signed + added to trusted store works

> Additionally there are quite a bunch of use-cases where the encryption is not TLS, like e.g. with some WebRTC applications it's not uncommon to have an encrypted channel we could access to a broker server but in that channel E2E encrypted messages are send e.g. using libsodium statically compiled in.

yeah youre right.

In other cases the only options we have are ld_preload to catch encryption lib. If that doesnt work we can still use ptrace to capture syscalls but encryption will be done in userspace so capturing network activity wont help us with encryption.

Like the other guy said, the info we can gather is still useful.

Reverse engineering + modyfing the binary is a possibility too but it gets complicated fast, especially if they intentionally try to protect it. I feel this isnt really an issue with jvm or interpreted langauges but with the others its hard especially if theyre statically linked. C/C++ have good enough decompilers that its still possible, I don't know about Go/Rust tho.

Re: Microsoft is phoning home the content of PowerPoint slides

#217

Earlier quoted context omitted.

What I want is Little Snitch on steroids built into the OS where every process, You cannot trust an OS you cannot build yourself. That's why I see Linux as the only option for professionals and privacy minded people.

With the compiler that you verified and built yourself :)

I believe this is a reference to: http://wiki.c2.com/?TheKenThompsonHack

Re: Microsoft is phoning home the content of PowerPoint slides

#218
post #112

What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, an…

The Little Snitch would be asking the OS to please tell it about network traffic. Microsoft's OS. It would be asking Microsoft's OS to tell it about traffic Microsoft's software wants to keep secret. I'm sure there's a world where that isn't a laugh line, but I certainly don't live there.

What indication is there that Microsoft wants to keep this traffic secret? The OP was able to detect and inspect this traffic with standard network monitoring software.

Re: Microsoft is phoning home the content of PowerPoint slides

#219
post #149

Earlier quoted context omitted.

Joking aside I think we are getting close, Photon did a lot to bridge with Windows in terms of gaming, GUI is often times at least on par with Windows/MacOS, if not better (obviously thats subjective), and reliability/performance has already been there for a while. That being said, I still think theres more work to do, and arguably the hardest work is ahead.

Linux is on par with Windows kind of but not really. It's a little ghetto For example, desktop environments are just wonky and buggy most the time, random games don't work, WINE is the worst piece of software on the planet, drivers suck, other random weird issues.

> For example, desktop environments are just wonky and buggy most the time, random games don't work, WINE is the worst piece of software on the planet, drivers suck, other random weird issues.

When was the last time you have tried linux? With exception of wine, which on its pure form is indeed annoying, nothing else is true. Gnome/KDE/Cinnamon are just fine (not my cup of tea but far from buggy/wonky). I have no problem gaming even on i3. For driver on many distro you can check a box to install the proprietary Nvidia driver.

You can use lutris to easy the pain of wine, and if you use proton on steam you are just have to click install like windows. You can check here the compatibility:

https://www.protondb.com/

Also let's not pretend that windows is walk in the park. I have had my share of problems with drives/games not working on windows as well. That is just the nature of trying to run games on PC. It ain't never gonna be as easy as on consoles.

Re: Microsoft is phoning home the content of PowerPoint slides

#220

I've raised this point repeatedly in different orgs. It's met with some combination of indifference and lack of understanding and not-my-responsibility-ism, but I'm sure that this will eventually blow up hard in some company's face - like 9-digit settlement for breach of contract, or worse things like breach of export control laws. Enterprise data security on the "MS Office level" at this point is like driving 60 mph…

Yeah, I'm surprised every healthcare related business doesn't either ban PowerPoint or block this "feature" somehow. HIPAA is a hell of a drug.

If you work in healthcare you know not to put HIPPA data in PowerPoint slides to begin with.
Post reply on HN