8 ms·
I've been on Windows 10 for a couple of days now. VPN traffic doesn't leak if the default route is the VPN interface. I tried it and my firewall went silent ap
by blackbeard 11y ago
I've been on Windows 10 for a couple of days now.
VPN traffic doesn't leak if the default route is the VPN interface. I tried it and my firewall went silent apart from the tunnel.
I have absolutely no fucking idea what it is sending out though. It's always talking to something. I've turned everything off that is documented and use a local account and remove-appxpackage'd everything. Sorry but this release is a write off. My host/vm relation is being inverted to Ubuntu as a host this week rather than a guest.
If I don't know what it's doing, how can I trust it?
- Kenji 11y agoCan't you just redirect all that stuff it sends to 127.0.0.1 by editing your hosts file?
- blackbeard 11y agoYou can, but we have 450 workstations and about 600 servers. That somewhat multiplies the problems.
- pc86 11y ago> somewhat Yes I can see how that would complicate things a little :)
- EvanAnderson 11y agoIf they're using DNS to resolve the name of the "mothership" just put a bogus record (or zone) in your DNS. If they're not using any name resolution protocol and you can isolate the IP addresses they're talking to just blackhole them at your border.
- blackbeard 11y agoWe're already doing that but it's hard work keeping up with it all.
- a3n 11y agoAnd then Microsoft will fix that, ...
- EvanAnderson 11y agoDefault deny is the only viable strategy. (It's also completely impractical...)
- drdaeman 11y ago1000+ machines and no way to update a file with a few commands/clicks/whatever-your-configuration-management-system-uses? (Ok, at worst, making a batch file and scheduling its launch.) If so, I suppose you have big issues with your system administration team.
- blackbeard 11y agoYes they're factory pressed Windows administrators who are to be honest fucking useless unless it comes to pointing at someone else but that's another story...they're being replaced piecemeal by bits of Ansible and Linux machines. Realistically we don't want to deploy a host file and AFAIK it doesn't work anyway; we want to control the network itself which we do via firewalls and DNS but it's a compromise between flexibility (our users still need to use the internet) and security.
- zippzom 11y agoI've read somewhere that it ignores the hosts file for its microsoft communication.
- Bjartr 11y agoI've read somewhere it respects the hosts file for its microsoft communication.
- imglorp 11y agoWhat do you do about getting updates? You have to connect to hq sometime, and when you do, it will upload its intel.
- ultramancool 11y agoI've been trying to use a software firewall and here's what I've blocked so far... https://up1.ca/#JQqL3y0xqLZnxaOlYQ0s6A https://up1.ca/#JQqL3y0xqLZnxaOlYQ0s6A And this is on a machine running Enterprise with privacy settings cranked, and most stuff disabled via group policy. I'm trying to avoid blocking updates, but svchost is still out there talking to random microsoft servers. The worst part is that I can't differentiate between the servers used for tracking and the ones used for updates. I might have already blocked necessary stuff for updates. At this point I'm really tempted to just wipe the machine and go back to 7, I've never felt so little trust in a machine I own. Even when I've run malware, at least I knew or could easily find out what was happening. This is just a big unknown to me. I'm seeing claims that it sends idle mic data even with Cortana disabled too, which is making me very paranoid even though the claims look sketchy at best.
- cmdrfred 11y agoGlasswire huh? Good stuff.
- ultramancool 11y agoYeah, I'm not the biggest fan actually. Decided to try it out this run, but I used to run Outpost, which I liked a lot more as it could do per-host blocking and stuff. This feels more like a pretty network monitor than a real firewall.
- arm 11y agoAgreed. It is useful for monitoring things like system changes, but I wouldn’t depend on just GlassWire alone for a software firewall. In my case, I use a combination of GlassWire and NetLimiter (as mentioned here): https://news.ycombinator.com/item?id=10039125 https://news.ycombinator.com/item?id=10039125
- kuschku 11y agoHere’s an image link to your image that actually fucking works: http://i.imgur.com/i4ydV1a.png http://i.imgur.com/i4ydV1a.png
- jevgeni 11y agoHow can you trust any cloud service then?
- blackbeard 11y agoI don't and never have done for personal use. I literally have an IMAP box and nothing else.
- jevgeni 11y agoI assume from your answer, that you do use it for professional purposes?
- blackbeard 11y agoYes but not on recommendation. In fact the majority of what I do these days is legislative compliance and bringing teams and applications back onshore that the companies have fucked up. Currently digging a financial company out of a royal mess of 20 years of bad technical leadership leading to sprawling infrastructure and cloud dependencies.
- jevgeni 11y agoOh wow. This is a tough task. In your experience, what are the "worst" cloud dependencies? I'd imagine SalesForce and AWS would have very different impact?
- blackbeard 11y agoMoney is good though so that's some consolation :) Salesforce is the root of all evil. Once you're in the ecosystem, you're stuffed. You know it's bad when the entire business team start running round clucking when the EMEA salesforce instance goes down hard... AWS is fine. Most of the platform's concepts have real world parallels for example.
- otis_inf 11y ago
- irq-1 11y ago> If I don't know what it's doing, how can I trust it? It's not enough to examine software: if you don't trust the company, then anything they say or promise is worthless. Automatic updates can change anything, including the TOS! This is the same company that sells a 1984-Telescreen (XBox) with an always-on camera and microphone. _NSA shouldn't be forgotten. Oracle likes to tout Java as GPL, but what does that matter when we know the company can't be trusted? Who controls a software project is the key, not the licenses or corporate promises. There's no point in trusting iOS because we've examined it, we also have to trust Apple.
- sliverstorm 11y agoOr as I like to put it, at the end of the day you have to trust someone, somewhere in the chain. In the case of software vendors, you have to trust the vendor. You cannot independently verify everything. You do not have the expertise nor the bandwidth. Edit: and if you have the software audited, are you not then trusting the auditor?
- bad_user 11y agoI don't like this argument. It's not necessarily you who has to audit your software. You can pay other people to do it. Big companies can pay for it. Your government's institutions can pay for it. If on the other hand the software is closed-source, then that's not an option. And especially for governments and for big companies Windows is a security liability.
- TheOtherHobbes 11y agoTrue, but there's no logical fallacy in writing off companies and products if they're consistently untrustworthy.
- deleted 11y ago[deleted]
- bad_user 11y agoThe source-code in OpenJDK can be inspected and OpenJDK itself can be forked if Oracle's stewardship goes awry, which is the whole freaking point of open-source, so I don't see how that can compare with Windows or iOS.
- ams6110 11y agoI'm just about to untangle myself from my last client where I work with MS stuff. And I'm never touching it again.
- MichaelGG 11y agoI think I'll end up putting Win 10 as my host. It's just too annoying worrying about drivers and batteries on Linux. But I can just disable networking on the host (which shouldn't be running anything anyways), or at worse, route it though a VM. I'm more concerned about how to run it in a VM, since I need day to day Win dev tools with Internet access.