5 ms·
Agree, this is large enough an issue to verify its validity. If true, however, it is very problematic and of questionable legality (e.g. unintended HIPAA data
by 16bytes 11y ago
Agree, this is large enough an issue to verify its validity.
If true, however, it is very problematic and of questionable legality (e.g. unintended HIPAA data disclosures etc).
Apparently people will have to start to invest in configuring outbound firewalls on their network to prevent various phone-home operations.
- knowaveragejoe 11y agoI have a feeling that there is a grain of truth in some of it, however the wholesale keylogging and what is basically searching for pirated content after keywords are typed is probably not real.
- blackbeard 11y agoI think that depends on what data people manage to sue out of them and then react upon...
- emodendroket 11y agoYeah... the backlash seems kind of predictable even for cartoonishly evil software companies.
- blackbeard 11y agoThe problem is that it's TLS encrypted traffic going from a black box component to a remote black box service so it's pretty hard to determine what is going over the channel. Without extensive and complex reverse engineering, you can only infer what is going over it and draw some hypotheses that need to be tested. I think that the article is spot on with respect to that. And of course there is no word from the horse's mouth (Microsoft) at all on ANYTHING related to this. Silence is always worrying.
- mahouse 11y agoTaking into account it is Windows, even if it the traffic is "encrypted", I suppose the part of the OS that encrypts it is not obfuscated in any way, so it should be easy to know what it really is doing.
- blackbeard 11y agoYou're right hence the extensive reverse engineering. I think you can expose call graphs and assembly with SoftICE or some product like that and infer which windows API calls are used so that's a starting point. However some of the things that talk are going to be heavily optimised binaries, code signed and difficult to poke inside.
- mahouse 11y agoI'm not sure of that, they could even be C# binaries, which are usually easy to disassemble and follow.
- blackbeard 11y agoPossible. I suspect anything interesting will be C++ however, possibly by design.
- balabaster 11y agoGenerally speaking you don't need to go to such lengths to intercept client/server communication from your own device. You can even have your wireless devices use your local WiFi, computer and Fiddler (which I think is roughly equivalent to Charles on Linux/iOS) as a proxy to intercept SSL and decrypt communication. You don't need to bust open the codebase itself to figure out what comms are occurring. You can stage your own MITM attack against yourself with a couple of home made SSL certificates and a router you have the ability to install your own software on.
- blackbeard 11y agoThat's true but then you still have to understand the data that is sent rather than where it is collected from. The of latter is much easier than the former from experience (I've had to reverse engineer a couple of protocols in my time)
- juliangregorian 11y ago
- Dylan16807 11y ago>The problem is that it's TLS encrypted traffic Unless you can just install a local certificate and proxy it.
- userbinator 11y agoNaturally, if they were following "security best practices", they will have pinned the certificates and made no option of overriding them with your own. It's all "for your security", of course.
- balabaster 11y agoExactly, it takes less than 5 minutes to figure out how to do this with Fiddler or Wireshark...
- brador 11y agoOr stop using Windows and we can put the final nail in once and for all. Linux, through Ubuntu, is (IMO) now ready for the prime time.
- robotkilla 11y agothe problem for me (and people like me) is that I'm running a gaming / game dev rig. I actually need Windows as most of the games I play are windows only - plus my current rig is way more powerful than any mac I can afford. I love linux and attempted to dev my games in pygame so that I would only need Windows to play games, but this isn't a good solution either as I prefer Unity. Guess I'll stick with 8.1 for now even though it is shit.
- benjaminjackman 11y agoSounds like my situation. I have been able to put Unity on the back-shelf because it's just a hobby for me. I have been experimenting with Phaser / PIXI / P2 + ScalaJS in the meantime while I wait for the Editor to come to Linux, which will hopefully happen in the near future [1]. As for actually playing games, a surprising amount of the ones I try have been ported over to Linux already. For the rest, I use Steam Live Streaming from a Windows 7 box which works pretty well. Steam can even stream non-Steam games (blizzard ones for example). I tried using it to stream the Unity Editor, but it was just too clunky for my tastes. 1: http://blogs.unity3d.com/2015/07/01/the-state-of-unity-on-linux/ http://blogs.unity3d.com/2015/07/01/the-state-of-unity-on-li...
- robotkilla 11y agoThankfully I have 2 gaming rigs, 1 outdated mac and 2 older custom rigs that are sitting around in pieces. I'm going to build and install a linux box for personal computing (all non-dev non-gaming related computer activity) and just keep it on right next to my gaming / dev rig.
- joshuapants 11y agoI say the following as a Linux enthusiast: Ubuntu is absolutely not "ready for the prime time," as you put it. It's not ready for home users, it's not ready for most businesses, it's not ready for anyone except a small number of users.