Earlier quoted context omitted.
Any reason why you believe it would respect those rules? Note the one example where a rule was dynamically added to the firewall in the tweets listed here.
That doesn't matter if you're using a DNS blackhole or hardware firewall. Of course, MS could hard-code some IP addresses, too.
Windows 10 Enterprise ignores various privacy settings
51–60 of 269 posts
Re: Windows 10 Enterprise ignores various privacy settings
#52The switch to Linux or other free operating systems is long overdue. If your excuse is hardware support, then (1) your hardware is probably supported these days and (2) you should not buy hardware that is incompatible with the operating system you plan to use. If your excuse is editing MS Office files, LibreOffice supports the formats and works great, and MS Office on Wine is an option. If your excuse is games, then…
Steam works great, and LibreOffice has been good enough to get the job done. I run Google Earth Pro and Sketchup in Wine, even World of Warcraft runs quite well in Wine.
I had a ton of issues with Wine until I found PlayOnLinux. Things still don't quite 'just work' -- but I've been able to use way more than I could before I found it.
KSP and WoW are my two big games, and they both work fine.
Re: Windows 10 Enterprise ignores various privacy settings
#53The connections in the first screenshot[0] aren't necessarily from Microsoft. This screenshot shows a DNS lookup for google-analytics.com followed by an attempt to use Teredo. If Chrome is installed then this could be from the Google Update service. It seems unlikely that Microsoft would send usage information to a Google site. [0] https://twitter.com/m8urnett/status/866353982217699328 Edited to omit needless words
Chrome is not installed according to this tweet: "Also note this is a system with minimal software install, all default windows store apps removed, and nothing running on it." https://twitter.com/m8urnett/status/866354381012189184
Edited to reword the second sentence.
Re: Windows 10 Enterprise ignores various privacy settings
#54I run Windows in a Parallels VM on my Mac. This VM needs to, on occasion, connect to the Internet. Any way I can--from the outside, without needing to trust Windows--be forced to whitelist what the VM is and isn't allowed connect to?
Re: Windows 10 Enterprise ignores various privacy settings
#55MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…
It seems unusual to me if any desktop systems are anywhere close to card data, IMHO usually you'd have in scope only a bunch of servers (so, Linux or Windows Server for normal businesses who don't have a reason to wrestle mainframes) in an isolated network, but most of company computers including all the user desktops shouldn't have a way to touch in-scope data or systems in any way whatsoever, so if they're properly isolated (as they should be anyway) they would be out of scope for most of PCI DSS requirements.
Re: Windows 10 Enterprise ignores various privacy settings
#56I run Windows in a Parallels VM on my Mac. This VM needs to, on occasion, connect to the Internet. Any way I can--from the outside, without needing to trust Windows--be forced to whitelist what the VM is and isn't allowed connect to?
EDIT: Just realized it was already mentioned by mcbridematt, and with more detail too! I’ll just leave this comment here for the Little Snitch link.
――――――
Re: Windows 10 Enterprise ignores various privacy settings
#57MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…
I went through the same thing last year. I spent two months trying to plug all the holes in the enterprise version, for a medium sized healthcare client, and eventually gave up. The LTSB edition looks promising but I haven't put it under the microscope yet.
I'm not sure if it's comedic or tragic that the version so very many users would want most, is not only the version with the worst name, but also the version Microsoft discourages people from adopting.
Critical patch support, infrequent updates, and excludes crufty bloatware. What's not to like?
Re: Windows 10 Enterprise ignores various privacy settings
#58MS Support consistently and repeatedly told me that enterprise allowed me to disable this stuff. If I can't control the egress then I can't verify PCI compliance. I've already had to revert a client to Win 7 because they failed a PCI compliance audit using Win 10 Enterprise. Which, by the way, is very expensive for small businesses. Win 10 Enterprise isn't viable for business. I have a bunch of small business clients…
But they keep coming out with respins of it to otherwise keep feature parity with CB Enterprise. A 2017 LTSB based on 1703 should be out soon.
Re: Windows 10 Enterprise ignores various privacy settings
#59Since the first release of W10 several registry keys and policies have changed in very confusing ways. I can't remember what exactly but I had to change my personal scripts several times based on the changelog of other tools. Privacy and settings like default apps were also reverted (reset to default) when you updated. They installed some apps like Candy Crush Saga on Enterprise. I don't see that much of a problem he…
I can't agree with this more. A client straight up failed a PCI compliance audit, replete with daily fines, for using 10 Enterprise. They decided to pursue legal measures against MS for false claims. I really hope this gets elevated because reverting to win 7 is a solution with a short life span. The other solution is to rebuild infrastructure on top of a different platform but that's prohibitively expensive.
Do you have a court case or docket you can point to?