Live data from Hacker News

Microsoft is phoning home the content of PowerPoint slides

rogermexico.bearblog.dev

91–100 of 391 posts

Re: Microsoft is phoning home the content of PowerPoint slides

#93

Earlier quoted context omitted.

Funny, I would have read that page and said that it was blatantly not obvious what was going on except that the privacy policy call out was a red flag. I wouldn't have thought anything of it needing to be enabled, lots of features are things that you might not want enabled by default. And having a privacy policy is definitely a red flag but it still doesn't say "we're going to send the content of your slides to Micro…

That is a help page guiding the user on how to use the feature. Of course it’s going to be “hidden” when turning on the feature is the smallest step to using it. If to use the feature you are explicitly asked to turn it on, with an option to view a privacy policy, that is “blatantly obvious”. It isn’t hidden or buried under a dozen other settings when you install PowerPoint, it’s done at time of use. How, exactly, wo…

IT has disabled the feature for us, and quick googling didn't turn up any screen shots, so I can't see the prompt myself, but given how it is described it doesn't seem adequate to me. When software asks permission it needs to say what it is asking permission for. Something like: "This feature will send your slide contents to Microsoft's cloud servers to search for relevant design ideas. See our Privacy Policy for more information on how we protect your data". It doesn't need red flashing lights, but the user shouldn't have to dig around to determine what/why the program is asking confirmation.

Re: Microsoft is phoning home the content of PowerPoint slides

#95

Earlier quoted context omitted.

And that the user may not have capacity to consent. That seems the salient issue today with regards to children and social media. Most of the giant social media companies profit from participants who cannot legally enrol.

By "participants who cannot legally enrol," do you mean minors? I'm not tracking what the Venn diagram between those people and those who "may not have the capacity to consent" is.

EDIT: I was talking about kids.

But Dogbert's comment actually deserves a bit more than "try using common sense instead of set theory" :)

I tried thinking of classes of adults who lack capacity, other than the mentally unfit, senile or criminally insane.

There's a lot of young people who are "deemed to consent" (the passive weasel-words of filthy scoundrels) in higher education. I've written about Turnitin in the Times and the "very dodgy circumstances" in which students are inducted into university and then find themselves coerced into tacit agreement to use tools which massively violate their privacy and other rights. The same applies to Microsoft products where institutions block choice and force students use insecure products that they would refuse if exercising their better judgement.

Re: Microsoft is phoning home the content of PowerPoint slides

#96
post #9

PowerPoint has a feature where it uses machine learning to suggest layout and design changes for your content. This feature most likely can be turned off, but of course it needs some data on what's on your slide to suggest changes. I hope this submission is flagged and removed. Just because you don't like Microsoft doesn't mean such misrepresentation is okay.

> I hope this submission is flagged and removed. Just because you don't like Microsoft doesn't mean such misrepresentation is okay. I don't think we know the motivation of the submitter and we should not assume any motivation beyond introducing the link to the community to consider and discuss the content. The article is very brief and seems to highlight that the designer suggestion needs to submit your slide content…

It does not highlight that the designer suggestion needs to submit your slide content. "Designer" is the name of a tab on PowerPoint.

Re: Microsoft is phoning home the content of PowerPoint slides

#97
post #56

I wonder what the NSA or any other of these three-letter agencies think about that, I can remember much of the leaked information consisting of Powerpoint slides.

It sounds (from other comments in this thread) like there's an org-level way to disable it, so they probably just use that to force it off.

Re: Microsoft is phoning home the content of PowerPoint slides

#98

What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS/SSL inspection built in (you'd need some OS API to enable that). Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description/why, an…

I believe the Mac OS networking APIs go a little bit of the way there - in Lulu, an open source alternative to Little Snitch, the connection prompts tend to contain (and let you filter) by the URL visited (including the query after the domain name). This isn't done through TLS interception, but I believe it's through the network extension API on MacOS receiving the URL requested, as long as the request comes through the regular APIs.

It's a long time since I looked, but I think some apps (mainly ones not using native APIs) only showed the hostname, rather than full URL/API endpoint path.

This also didn't show you the content, or method type (POST vs GET), but to do that you'd really need to start doing proper SSL inspection as you suggested.

Re: Microsoft is phoning home the content of PowerPoint slides

#99
post #73

Earlier quoted context omitted.

2023 is the year of Linux on the desktop?

It was quite some time ago. You didn't get the memo?

"The future is already here – it's just not evenly distributed."

Re: Microsoft is phoning home the content of PowerPoint slides

#100
post #14

Earlier quoted context omitted.

How about Grammarly? Or G-suite? They have access to most of the companies out there. I find it terrifying people use Grammarly and it has access to every piece of confidential word written.

G-Suite is a super interesting case in that you literally cannot use the product without handing over your data to Google. It certainly seems like companies would hate that, particularly those with data protection obligations. Google does theoretically require a Business Associate Agreement (BAA) if your use case is subject to HIPAA and you intend to store or transmit PHI using their services, but I don't know how th…

Since when does complying with data protection mean "you must own your entire tech stack and run it on prem"? Google[0] states that they don't use your data for anything more than running the service, and there are multiple pages detailing how they secure data on their servers from both employees[1] and attackers[the rest of the document].

0: https://workspace.google.com/learn-more/security/security-wh...

1: https://workspace.google.com/learn-more/security/security-wh...

Post reply on HN