Well, today was the day. I finally got my fill of this site.
Thanks for the memories HN, but this just isn't worth it. I could have been coding. From now on I will be.
Adieu.
HN user
Well, today was the day. I finally got my fill of this site.
Thanks for the memories HN, but this just isn't worth it. I could have been coding. From now on I will be.
Adieu.
You can actually customize a large part of it and turn all of it off.
You can't firewall it off, but you can learn how it actually works and just turn it off.
So, a second ago it was that you can't use a local account...but you can, so now it's..."The defaults are bad and people are dumb."
Literally all of the people who install it or buy a PC with it installed have the choice of making that decision or purchase.
And you're right, they won't change the defaults and that's not a travesty of some kind. It actually really doesn't matter to most people. Not because they don't understand it. They do, and they want to use it for one reason or another. People in our technical circles overestimate the importance of this stuff by some fairly crazy amounts.
I might just be tired of hearing the same arguments over and over, but it I did see the assertion that BitLocker shouldn't be used to keep your "secrets". As if the choice of which drive encryption software you use on your laptop should be your primary concern when securing yourself against an adversary. (The primary concern is to thoroughly evaluate your adversary and look at your available options for opsec and InfoSec. Maybe you need drive encryption. Maybe you need burners. Maybe you should only use public terminals. Etc. It also means seriously asking yourself if you actually have an adversary or just like to think that you might some day.)
Just sort of saying..."How can you trust MS NOT to have backdoored bitlocker just use Linux. Suck it NSA." Won't actually make you secure.
Some of it's pay as you go, oddly enough. But you are largely correct that more money equals more access to these kinds of things.
There is a company in China that paid them to install Office 365 in their data center. There is an amount of money that will make them install it in your data center, too.
I just think that there has never been more choice for end users and a lot of this stuff about privacy is disingenuous. There are a group of people that wouldn't be happy even if MS released their own version of TAILS and hosted part of the Tor network. (It would be "embrace, extend, extinguish!"..."Tor is part sponsored by the Navy...I be MS gives your Tor traffic directly to the NSA."...It's really not hard to imagine the BS.)
One other thing. A "pile of power over you"...that's not helping, man. They have some commercial legal arrangement that you don't particularly care for. They can't come and kick you in the shin and torture you. They can't beat you to death and plant a weapon on you or anything. We are talking about an issue that is squarely within middle and upper class privilege in an industry that literally could not exist without government defense funding.
Take, for instance, Richard Stallman is an Alumn of Harvard and MIT. There literally can't be a place that is more establishment. So all of that "freedom" is about being able to use an expensive commercial product that was developed with RnD money from the DOD...but somehow it's morally wrong to not ship source code to a compiler? Can you see where I'm coming from here? The moralizing is pretty arbitrary.
Furthermore, if they did give your content to the Government because of a national security letter how is that abuse of power? Should they not comply with the law? I disagree with a lot of the laws that have been passed in support the war efforts of the last decade, but that's kind of the way that democracy works. I lost, but I still have to live by the rules.
I just think that the privacy absolutism that everyone keeps bringing up isn't reasonable. Even Bruce Schneier says that the way that you actually change these things is through the political process.
Power is a boot on your neck. This is more of an inconvenience.
I just don't think that's an accurate picture. They aren't recording your voice and storing it somewhere. Browsing and search history are collected by other platforms for predictive browse ahead and autocomplete, and it's a useful feature. App usage is collected for diagnostic purposes.
You don't have to use a MS account. You can use a local account. 10 is different from windows 8 in that regard. You can take Cortana off the taskbar. Use a different browser in incognito mode all the time. Store your encryption keys in a TPM, smartcard, or Active Directory. There are actually lots of options. You have to actually look into it though.
There's an OS project run by Joanna Rutkowska and some other folks called Qubes that does exactly that. It's really interesting work by sharp people.
And what secrets are those? If you think that you are secure because you don't use bitlocker or windows AND THAT'S ALL that you do...you aren't secure, you just have bad UI.
That's not really accurate. Maybe we can reach out to someone at MS and they can explain exactly what is being sent. It certainly isn't virtually everything that you do...it's something, it's not accurate to say its everything.
MS people frequent this site. Maybe one of them could get some detail on the subject?
That looks like some amazing work. I'm going to give it a try.
It actually does run locally with access to API's that you authorize. Just saying...
Businesses actually have very different privacy arrangements than individual consumers. Its a function of how much they spend.
That's the thing, though. I find the constant kvetching about privacy the most cynical thing. None of these posts are news, new information, or even a new take on existing information.
I didn't mean to make it sound that way. I actually agree with you completely. I was trying to write for my audience there...my point was just that obviously they will want to gain something from the relationship as well.
You and I are in complete agreement on the subject...I just fell into hyperbole...
:)
businesses actually can get a very different deal when it comes to data "sovereignty" issues.
it's really consumers who have the least leverage. If you want an arrangement where your data is encrypted with keys that you store in a tamer proof hardware module you can. It's priced differently, but you certainly can have that. (It's not all that expensive in the scheme of things.)
I'm going off on a tangent?
YOU installed their software. You didn't have to. No one forced you to. Don't like the TOS? Call them and schedule a meeting to talk about coming up with a different arrangement...they will want money for that, but you can certainly have it.
The truth is that there is jack all that I or anyone else can say to you that would change your mind about any of this.
Also, I'm not willing to grant that you are reading the TOS correctly...so there's that point. No offense, but its pretty dense and things that are probably pretty reasonable come across as a privacy invasion to people that are really sensitive on the subject.
That's actually how it works. You give it permission to use your O365 account. You give it permission to use your location either at setup or in the config settings at a later date.
A whole host of the Cortana functionality is local that interacts with online services via API's that you authorize.
I don't think that really anything that I say is going to change your mind, but you could check out some of the video's on Channel9 where they go into it in detail. Some of it's pretty good and if you use headphones you can't hear your co-workers talk about stuff that makes you want to slap someone.
Those aren't even remotely the only two choices here. There have never been more options for an end user of technology.
You don't have to use agree to it. It's a trade off.
If you have different requirements they are more than willing to come up with a different arrangement with you. (Yes, for a fee.)
They aren't the government. They are an overblown bubble gum factory. It's up to you if you chew or not. And there have never been so many flavors!
You are completely free to not use it. I'm not trying to be a smart-a here. There have never been more options for end users.
You aren't signing away your rights to privacy without due process...that's your part to evaluate. "Is this useful enough to me that it's worth agreeing to this?"
Also, this is version dependent. The TOS for an individual consumer is different than a developer with an MSDN license, and a business with a volume agreement. Do you have different privacy requirements? Are you willing to pay for them? If they can't make money with the product that they built in the manner that they came up with then it isn't illegal, or really even remotely morally odious, for them to ask for a different payment arrangement.
Now. Do I like everything about life in a capitalist national security state? No way. But do I whine when some vendor doesn't do exactly what I want when I'm really not event scratching the surface of enough money to get their attention? Seriously, man.
It's insecure by a standard that you are setting. If they can demonstrate an audit log of every admin who has escalated their permission to logon to the container of your data and access it, including the files they accessed, would that be good? (Because they do that.)
Again privacy-violating by your, arguably, very narrow standard. I'm sorry friend, but you are stating these things as if there's no question as to what you say.
More accurately, you might say that there are higher privacy and audit-ability standards that you would require for your given situation or application. I wouldn't be able to argue with that at all.
I believe that you are mistaken. Could they turn over your BitLocker recovery key to the authorities that would then use it to decrypt your HDD that they have already taken from you? Yes.
Are they going to reach out over the internet and take your data? No. They are not going to do that. I follow this stuff really closely. I promise I haven't seen or heard of a capability where they can remotely take data from your machine and turn it over to the government.
Every company that has access to your encryption keys can be prompted to give them up with a warrant.
You can keep them from having the key. That's one way around it. Using hardware of some kind (and there are multiple.)
You are also free to use another solution that might meet your strict requirements to personally review the encryption, filesystem, device driver, and memory management code of your operating system to verify it's operating to your specifications. There have literally never been so many options for the privacy minded person with the time to pour through a metric ton of C code.
OK. What I'm trying to say is that backing up to OneDrive is optional. You get the choice. You can protect the key with a TPM or a smart card...It's not an all or nothing thing. You have options there, if you are interested.
The other thing is that it sounds like a lot of privacy minded people can't trust BitLocker despite any number of assurances from MS or code reviews by third parties. AND THAT'S OK. Use something else.
EDIT: I forgot to mention that if you are an admin or just operate your own AD installation you can store the key in Active Directory. The behavior is version specific, I think.
EDIT EDIT: I believe that the TOS you are talking about is specifically referring to online services. I don't have time to stop and read it right now, but I think that you are misconstruing the intent.
There are dialogs and UI hints that come up when the service is first accessed. Is it enough to placate someone who is seriously concerned with online privacy...probably not. It meets the minimum requirements to not be too sneaky.
But the entire point of the service was to use data mining techniques so that you could use natural language directives to say "add a reminder to my team's calendar to update some presentation in O365, etc"...
Maybe you don't find it that useful, but I think that a lot of people would. It will, in a future release, be genuinely useful. It's getting there.
I know. I think it's actually pretty cool. (Though it doesn't seem to work well with some builtin mic's.)
I really like the direction they are headed.
That's a new one on me.
Bitlocker keys can be backed up to onedrive if you want, but you can also store them in a TPM or a smartcard (physical or virtual).
Of course you did. Large companies have no vested interest in building systems that do the "right thing" for you as defined by tech types like us who are arguably more sensitive on this subject than most people.
They are building services that take your information and try to do something interesting enough with it to make it worthwhile...and why is it on by default? Because they want to make money off of the new features and deep integration with your information.
This isn't news. But it certainly may be another excuse to have the exact same conversation that nothing will come from.
Never mind that data generated and collected from cell phone usage will always make the privacy impinging features of your laptop look tame in comparison.
Never mind that the only way to stop companies from doing this is through the political processes that everyone seems to have written off.
EDIT: Downvoting because someone disagrees with the principal argument of the post is lame. Cheers.
I'll take that point. Cheers.