Live data from Hacker News

Retiring Windows 10 and Microsoft's move towards a surveillance state

scottrlarson.com

211–220 of 514 posts

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#211

Nobody thinks this is a weird reaction to an OS update that's been out for years at this point and barely makes a difference over the previous version? There's no 'Recall'. Co-pilot isn't all over in your face so removing it isn't really a priority. Edge isn't forced on you, it's just part of the bundled software just like a bunch of other items as in every Windows for decades. Not saying it doesn't get hairy if you'…

I've started running windows 11 lately because I've gotten some laptops that had it, and after removing all the microsoft pushed apps including removing OneDrive at least twice... It just doesn't feel very good.

a) the lock screen gets stuck from time to time if you hit enter to get to the password entry, until you turn off all the pushed content on the lock screen. Which ok, I'm happy I turned that off... but then I had to log out and back in for that setting to take effect. Now that I know about that setting, I turned it off on my windows 10 machines, and it takes effect instantly.

b) I like my windows round on the top and square on the bottom. It's cutting off the bottom left character in my putty windows; you used to be able to undo that in the registry, but now you need to force load dlls (maybe putty can fix it?)

c) I don't want notepad to have tabs or autosaving

d) it feels like keyboard focus gets lost to the ether a lot more. I had this happen in new style apps on 10 (like the new calc), but it happens at the desktop from time to time on 11.

I had been using linux as my main desktop at home for years, and went back to windows 7 when gnome2 ended. 7 was very good, but it's been downhill since then, especially since Microsoft killed off SDET roles. I'll probably keep windows on the laptops (useful for FRC), but when support for 10 runs out, the desktops are going to move to FreeBSD and I dunno, fvwm maybe?

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#212
post #202

Earlier quoted context omitted.

> if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM I had a Win 7 system and just entered a password on boot, this decrypted the disk. It was supported without mods or TPM (maybe some registry tweaks though). On Ubuntu I do the same, no need for TPM. Am I missing something? My disk is encrypted. If they take it apart, they need my p…

> Am I missing something? My disk is encrypted. If they take it apart, they need my password to crack the encryption. You’re not protected from an evil maid attack. An attacker with physical access could make your device boot their own payload to capture your encryption key and install a rootkit.

So what happens when they use their physical access to turn off secure boot or just replace the component/device with one that looks the same, prompts for your password and sends it to them?

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#213

Earlier quoted context omitted.

Make sure libreoffice is included, and ublock origin. Show them how much faster it is, with fewer ads, and no subscription to Microsoft required just to write a document. The business customers might want to know that databases are a lot cheaper on Linux, especially for small business. Literally spoke to an automation company the other week that told me "we have to delete a bunch of stuff every time the database gets…

> Make sure libreoffice is included Probably an unpopular thing to say here, but in my experience pushing non-tech people to use libreoffice as part of a Linux transition is a fast track to getting them to hate Linux. Using Google Docs has been much more welcoming in my experience. Something about libreoffice doesn’t resonate with a lot of non-tech people.

I agree with this despite being a libre office user. The introduction should be gentle, not dogmatic. No harm in using a browser based web application for this use case.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#214

Earlier quoted context omitted.

What are the arguments for Office at the small business or individual level, as opposed to Libre Office? For most users, they'll be able to reacclimate in a matter of hours to near 100% competence. And they now are in an ecosystem that won't constantly try to squeeze you for rent. I think this is even more true in the era of LLMs, because on the rare difference somebody might get hung up on - there's no longer real n…

Sadly in small business Microsoft have a lock because no SMB wants to be the awkward outlier whose IT makes them hard to do business with. For example, to be that supplier that whose documents never quite look quite right or who always struggles with the docusign /PDF /email /spreadsheet /whatever whatever. For an SMB, fitting in with the de facto IT herd that is represented by your customers and partners is essentia…

> Sadly in small business Microsoft have a lock because no SMB wants to be the awkward outlier whose IT makes them hard to do business with.

Which, as companies switch away from using Microsoft products, are now the people using Microsoft Office.

Everybody can open a PDF. Do you want to be the ones having problems sending Office documents to companies that have already stopped using it?

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#215

Earlier quoted context omitted.

> I would say that specifically with Secure Boot, Microsoft actually promoted user choice: A Windows Logo compliant PC needs to have Microsoft's root of trust installed by default. Microsoft could have stopped there, but they didn't. This was not the case with the initial rollout of Secure Boot, it was combined with locked BIOS to lock PCs so that they could only boot Windows 8 on some devices. This was the case on W…

> There is also a real potential for abusing TPMs or cryptographic co-processors to enforce remote attestation. People here REALLY need to start understanding this issue. Remote Attestation is the kind of tech that if abused will end free computing over night.

And it's already happening in the form of Google play integrity API. Many apps already require it. It's just a matter of time before they push similar tech to the desktop. And on mobile it hurts more because many banks now require a mobile app for 2FA.

Personally I think any form of attestation is evil.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#216
post #79

Earlier quoted context omitted.

On the face of it they're just security features, and I don't deny they are, but the industry as a whole are using those features to implement device verification systems that are being used to lock down their platforms and centralize control over their software ecosystems. Being able to install another OS isn't much good if critical applications and websites refuse to run on it.

>Being able to install another OS isn't much good if critical applications and websites refuse to run on it. The battle has already been lost on this. Just look at all the companies that are app-only and don't offer a web version.

That the battle is lost doesn't mean we should stop fighting. Even the war being lost isn't a reason to. The equivalent in the real world is resistance.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#217
post #41

I agree with all of the articles points except for the first one: TPM and Secure Boot do not reduce user choice or promote state or corporate surveillance. If you want to be able to prevent root kits you need secure boot, and if you want to store secrets that don't need a user password to unlock and can't be stolen by taking apart the computer, you need a TPM; or you need substantially similar alternatives. I would s…

I am starting to see the benefits to secure boot and TPM from a gaming perspective. I realize this can still be tampered with but it eliminates so many casual cheaters that the edge case is practically irrelevant.

I don't see how my TPM module will prevent me from using the machine the way I want. The offer of a cryptographic assurance to a 3rd party is something I happily provide in order to gain access to a competitive gaming resource. Cheaters really fucking suck and if this is what it takes to ruin their day, then fantastic. I'm looking forward to TPM3.0 now after seeing how ruinous this has been to their schemes. These tools are effective.

Battlefield 6 is especially problematic for malcontents because its developers also enjoy using statistical methods to detect cheaters. TPM2.0 + statistical methods + $69.99 per try = probably can't afford to play this game unfairly for very long. Even if you can afford it, the in game progression takes an eternity. You're gonna need that 8x scope if you want your "undetectable" frame scanning aimbot to be of any use.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#218

Funny seeing this here at the exact moment my frustration has boiled over with windows. I'm just completely baffled at the hostility and disdain Microsoft is showing it's customers. These issues are on top of just the disregard that people actually use these products for work and business so force-updating and breaking them so often, just so they can re-force you to accept their surveillance bloatware. My feeling tod…

The camel's back is already broken, it just so happens that changing OSs is very hard. MSFT has a leak; once they lose a customer, and that customer has figured out alternatives, they are never getting them back.

See this for all OSs/platforms: https://gs.statcounter.com/os-market-share#monthly-200901-20...

See this for Desktop OSs: https://gs.statcounter.com/os-market-share/desktop/worldwide...

They are on a slow death spiral. Their solution to raise revenue when their marketshare goes down is to squeeze harder. So they lose more users and the vicious cycle continues. In 10-15 years, they'll dip below 50% of marketshare, at which point there will be various alternatives which will accelerate their downfall. This already happened in tablets/phones.

It might also happen faster since they have a stronghold in Asia and China is now looking to accelerate the building of alternatives.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#219
post #202

Earlier quoted context omitted.

> Am I missing something? My disk is encrypted. If they take it apart, they need my password to crack the encryption. You’re not protected from an evil maid attack. An attacker with physical access could make your device boot their own payload to capture your encryption key and install a rootkit.

So what happens when they use their physical access to turn off secure boot or just replace the component/device with one that looks the same, prompts for your password and sends it to them?

There is no password. The machine will fail to boot and decrypt you hard drive.

Re: Retiring Windows 10 and Microsoft's move towards a surveillance state

#220
post #95
post #79

Earlier quoted context omitted.

>Being able to install another OS isn't much good if critical applications and websites refuse to run on it. The battle has already been lost on this. Just look at all the companies that are app-only and don't offer a web version.

I honestly have only come across one company that is app only. That was because I was with them when they changed over, otherwise I would never have signed up. This was my local gym which sacked their front desk staff and moved to app access only, and with an app infested with trackers at that. Needless to say I don't go to that gym anymore.

Want another exemple as fresh as yesterday?

I'm on a move, had to pay some transport company to move some stuff for me, pick-up date tomorrow. Paid online, website asked for a confirmation from my bank's app (N26), fair enough. Opened the app, just to be greated with "Please Update. The latest app version includes new features, enhancements and stability improvements" with the only choice: "Update now".

Being confronted with an app designed to refuse to work was irritating enough (for context, I'm from a generation were we used to own our devices), but I clicked on "Update" anyway, just to be told by apple store that there was no update for my iPhone 7.

Ok, the writting was on the wall. You know, I own one iphone and 2 android phones already, all of them several years old but in pristine condition. That's how I am, I care for things. I'm not going to buy yet another one, if only because I hate waste and fear mismanagement of natural resources. That's how I am, I care for things.

Now you are mandating me to add more e-waste? There is no way I'm going to do that, so I decided to connect to N26's wensite, but guess what? You need the app to login. Well, if you insist you can also login with a short message, which I did, just to check that there was no way to confirm a paiement on the website.

But you can contact "support", so I tried that. To their credit, the robot bouncer was quick to admit incompetence and to connect me with a friendly fellow human, who was unfortunately only allowed to lecture me about why those "new features and enhancements" were essential to my account's security, while being unable to tell me exaclty what they were or what was the problem with the current version, and suggested I login from someone else's phone instead.

Security? Whose security?

To anyone working in tech, let me remind you what an actual threat model is.

My actual threat model in the actual world is that your company might stole my money, or prevent me from access it which amount to the same thing. Data points: Despite all the stories on the news about mischievous hackerz from russia and china, I've been stolen money only twice in my life, not a lot of but at the time I needed it, and twice by banks.

My threat model is that the electronic gadget that I bought and carry with me all the time stops obeying me and starts obeying some adversarial company. And that, in perfect novlang mastery, you want me to call this a "trusted device".

My threat model is that our civilization might drown in e-waste.

Want another exemple of app only service? Wait for a days or two, as I'm confident I will face the same issue soon.

Post reply on HN