5 ms·
More than that, what it installs fits any classical description of malware. Windows 10 comes with an OS wide key logger, that logs what you write in any applica
by lars 10y ago
More than that, what it installs fits any classical description of malware. Windows 10 comes with an OS wide key logger, that logs what you write in any application, and sends it to Microsoft.
(This usually evokes disbelief. If you think I'm wrong, please consider what you would do if it turned out I was right. Then, if you're on Windows 10, lookup your "speech, inking & typing" settings. This is where they ask permission to do this. It is turned on by default.)
- teacup50 10y agoNo joke: "We also collect your typed and handwritten words to improve character recognition and provide you with a personalized user dictionary and text completion suggestions." http://windows.microsoft.com/en-us/windows-10/speech-inking-typing-privacy-faq http://windows.microsoft.com/en-us/windows-10/speech-inking-...
- quickben 10y agoTyped character recognition... Unbelievable
- voidz 10y agoMakes you wonder if they are really saying profiling in obfuscated terms.
- vmateixeira 10y agoI wonder how does this hold against intellectual property rights... Can they own all the software I may produce on their OS? It sure seems like they can have an easy access to the source code..
- dhimes 10y agoI'm sure the TOS has you relieve them of liability and hold them harmless for any use they may make of the software that you wrote.
- Already__Taken 10y agoDoesn't every phone do this to make the swipe style keyboard work and autocorrect?
- wingerlang 10y agoYes, they do. Maybe not sending it to some server though.
- mattmanser 10y agoMaybe not sending it to some server though Those 8 words change are what we're talking about. A keyboard app obviously needs to use your data to improve auto-correct. When it starts sending that data off-device, however, that's a whole different ballgame.
- bad_user 10y ago> A keyboard app obviously needs to use your data to improve auto-correct. No, that's not obvious, in fact that would be the opposite of what a keyboard's auto-correct should do. Because the whole point of having auto-correct is for the keyboard to correct my mistakes, not learn from them or from the mistakes of other people that also don't know how to spell. For this reason for example Swype on iOS has been basically unusable for me, because it makes more mistakes than I do. And no matter the implementation, now every time I choose to override the auto-correct decision for a certain word, I always end up pausing because I fear that from then on, the word will be added so some personal dictionary that I don't want. Basically learning from what the individual types is a disservice to the individual. Also, on iOS custom keywords need explicit permission for accessing the Internet. And on Android I found no mention anywhere that Google's Keyboard sends telemetry to its parent. People just assume that for some reason.
- Nullabillity 10y agoThe point of auto-correct is to fix it when you fat-finger something, not when your belief of how to spell something is "wrong". There's a reason auto-correct isn't a thing on desktops.
- ryanlol 10y ago>More than that, what it installs fits any classical description of malware. Windows 10 comes with an OS wide key logger, that logs what you write in any application, and sends it to Microsoft. I've yet to see any actual technical evidence of this. Quoting their very unspecific legal documents is hardly evidence of anything.
- lars 10y agoGo to "speech, inking & typing" settings. The dialog literally says they will collect your typing history. The traffic is encrypted, and no one has been able to MITM it yet, as far as I know. But Microsoft has confirmed in the press that yes, they do this.
- ryanl0l 10y ago>Go to "speech, inking & typing" settings. The dialog literally says they will collect your typing history. And until someone bothers to do a MITM we really don't know what that means. >The traffic is encrypted, and no one has been able to MITM it yet, as far as I know. But Microsoft has confirmed in the press that yes, they do this. Are you sure? Unless they're specifically trying to prevent such you should be able to just drop in your own root certificate and MITM it with the tool of your choice.
- RaleyField 10y agoOne would hope they got their crypto right (I'd assume it's done via ssl with a pinned cert, but I haven't checked). More worrisome is what they do at their data centers - officially they might paint one picture of how well they have secured their system both technologically from outsiders and from employee insiders but behind this pretty picture could be a total shitshow behind the scenes and we wouldn't know. A rogue employee could socially engineer his way to data and dump it on the internet - similar to what happened to OkCupid. They could be infiltrated by Chinese with their infinite budgets and then you take a "voluntary" trip to China. They could be forced by USG to reveal data, and I'm all for nabbing terrorists, but USG has proven that they aren't any better at securing their stuff so China scenario again applies. Or Microsoft is after a few years pushed into corner even more and become really evil and start monetizing data to everyone with a dollar and it turns out they consulted lawyers to arrive at minimal method of data anonymization that would still be accepted by courts. In the end, it's customers who have bought their computers and should retain ultimate agency over their hardware and what Microsoft is doing isn't necessarily in their customers' best interest because it puts undue, poorly communicated risks on them. Most users aren't equipped with necessary background knowledge to evaluate these risks so aren't even capable of consciously accepting them. edit: oh it's you ryan. I'm sure you already know all this. :)