4 ms·
Ah, CNIL. What counts as "excessive"? Apparently whatever someone at CNIL thinks is excessive. I can imagine that Microsoft learning what apps you download is
by sievebrain 10y ago
Ah, CNIL.
What counts as "excessive"? Apparently whatever someone at CNIL thinks is excessive. I can imagine that Microsoft learning what apps you download is inevitable given their reputation based malware detection scheme: no way for that to easily work except by IE checking in with Microsoft to find out if a program is known malicious or not. And figuring out if a program is actually interacted with or not seems like a pretty good signal to determine if a new, unknown program is a silent botnet or not.
"4-PIN limit is insecure, because there's no limit on the number of accesses" is exactly the kind of bureaucratic central-planning nonsense that France has so many problems with. You do not need absolute counted limits on a password/PIN system to make it secure. You just need to take other steps to make brute forcing infeasible, like throttling the rate of attempts. Why is CNIL attempting to micro-manage the code for the Windows authentication systems, something they are clearly not qualified to do? The details of Microsoft's security system is their concern alone: if users dislike the way Microsoft do it, then they have other alternatives they can easily switch to.
I suspect Microsoft may do what other big companies do and simply ignore CNIL completely. They can only hand out relatively small fines and it's easy for big companies to just pay them off to make them go away. Their rulings have a long history of being completely unreasonable so it's usually the easiest path.
- zeroer 10y ago> if users dislike the way Microsoft do it, then they have other alternatives they can easily switch to. All evidence seems to suggest that the French are not big fans of the free market, because that would create winners and losers.
- liotier 10y ago> What counts as "excessive"? Apparently whatever someone at CNIL thinks is excessive "Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés" is quite specific about collection & processing of personal data. A good example of what falls foul of this legislation: logging everything for unspecified purposes to cross-tabulate it with other unspecified records in case it might be useful in some way (which might not be in the user's direct interest) within an undetermined timeframe, without letting the user know about it precisely nor letting him opt out. CNIL is annoying and their enforcement is spotty for lack of budget (so they have to focus on landmark cases) - but their actions are well grounded in legislation and actually protective of people. > I suspect Microsoft may do what other big companies do and simply ignore CNIL completely Please do that - I'm off to fetch some popcorn !
- sievebrain 10y agoThe use is always specified: usually something like "running existing services and supporting the development of future services". Oh, that's not good enough? Well now you are back to what I said: it's simply central planning nonsense where a regulator makes up rules on the fly. I have seen no evidence that CNIL or indeed other bodies like them protects people from anything. Please show me one, completely unambiguous case of someone who was clearly suffering whose suffering was rectified by CNIL forcing some change to a privacy policy somewhere. And I mean really has a problem, not some emotional airy-fairy feeling that they'd prefer things to be different, I mean concrete, quantifiable issues: like monetary loss. There is no need for popcorn. I think the biggest fine CNIL can usually hand out is like 300,000 EUR or something. Just pay it Microsoft and get on with things.
- pdkl95 10y ago> What counts as "excessive"? That should be obvious: any data the user hasn't given their specific informed consent to be collected. How is this even in question? No, hiding blanket statements in a privacy policy is not specific consent, and dissembling about spyware details in an vague or misleading option description is not an informed choice. This is how you bring bad regulation to an industry; if businesses cannot police their own ethics, event laws will be written to fix the problems. > malware detection scheme Not everyone uses that, and there are other ways to implement malware detection that are not privacy leaks. > Microsoft learning what apps you download Or run, or interact with... > good signal ...which then claim is a good thing. Microsoft (or anybody else) can ask the user if they would like to track that specific data. > they have other alternatives The cost to change platforms - which may include replacing an existing investment in software - can be large. Forcing a Hobson's Choice on users indicates it's time to open up another antitrust investigation.
- sievebrain 10y agoYour post lays out exactly the central planning madness that privacy advocates have created. Governments: "Collecting data without informing people is bad" Companies: "OK, we inform users what is collected in our privacy policy" Them: "Nobody reads them. Make sure they opt in." Companies: "OK, we have put up an interstitial that asks people to opt in after showing a summary of what is collected." Them: "Still not good enough. Ask specifically for everything." Companies: "..... we list specifics in the privacy policy. That's what it's for. And we ask people to agree to it when they sign up." Them: "Too late. Pay us a big fine" This is a stacked deck. Nobody providing user services on the internet can ever win this game, ethics has nothing to do with it. There are no standards and nothing is ever considered sufficient. Badly thought out, vague and rambling approaches to privacy laws are how you get cookie popups everywhere. Makes no sense!
- Spivak 10y agoLet me take a stab at a set of rules that would satisfy privacy advocates. Feel free to critique or say I've missed something. Data collection and storage must be... * Off by default and opt-in. * Completely granular. - For what is collected. - For what collected data may be used for. * Agreeing to one form tracking or data collection cannot cascade to another. * Preference for sharing/selling data to 3rd parties must be off by default and opt-in. * A users preferences on your service must extend to 3rd parties. * Must have a non-persistence option. (i.e. data is only stored for the minimum amount of time required to render the service) * Tracking can be discontinued at any time at the users request. * Deletion commands must be honored in a reasonable time frame. * Deletion commands must be propagated to all 3rd parties. * Agreeing to tracking or any data collection cannot be a requirement for use of a service. * User must be allowed to view and acquire all data collected about them. * Cannot be misleading or place any undue burden on a user attempting to exercise their rights.
- scribu 10y ago> if users dislike the way Microsoft do it, then they have other alternatives they can easily switch to. So tell me about all those alternative OSes that can run all the same applications that run on Windows. Before someone suggests it, running a Linux distro + Wine is not an easy switch by any stretch of the imagination.
- sievebrain 10y agoNearly everyone I know uses Macs these days. It's clearly possible.
- wornohaulus 10y agoThe net marketshare for Desktop OS tells otherwise !! sadly.. :( ..