3 ms·
Your grandma comment is misguided. Your parent comment has a good point. If a system is sending out sensitive data, there is a way to figure it out by setting
by foo101 8y ago
Your grandma comment is misguided. Your parent comment has a good point.
If a system is sending out sensitive data, there is a way to figure it out by setting breakpoints and reverse engineering the payload that is getting encrypted.
Once a researcher finds whether or not sensitive data is being sent, the researcher can publish the information so that your grandma can know about it and she can have the transparency and fair dealing she needs.
- vetinari 8y agoOr, you know, demand from the vendor to supply a system that doesn't need a researcher, who was able to secure a funding for such an endeavor. Meanwhile, the point still stands: windows phones home, sends out the data, which are encrypted in transport, obfuscated inside, and the user has zero control about it. Requiring the user to prove which data were send and which weren't is dishonest; it is the vendor who has the source code and knows exactly the answer for what is being asked of the user.
- AnIdiotOnTheNet 8y agoProblem is that Microsoft still enjoys a practical monopoly on workstations and desktops, so there's very little pressure for them to actual do what people are asking. Case in point: we still have forced updates and ads in the start menu. If there were a worthwhile competitor, I know a lot of people who would switch in a heartbeat, but even then Microsoft probably wouldn't care. I am increasingly convinced that it is Microsoft's unstated goal to kill off desktop personal computing entirely so they can push people into a subscription-based cloud service for everything.
- foo101 8y agoIf the vendor supplied such a system or provided the answer to your question, would you trust it? Why? You always need independent researchers to verify vendor's claims.
- vetinari 8y agoThat's where the transparency comes in. In most linux distribution, when you have a crash and the crash reporting is enabled, you can peek into what exactly is going to be sent. If you have smallest of the doubt, you can opt to not send anything. Or opt out of sending anything, ever. Of course, seeing that the data you submit is used to solve your specific problem, and not disappearing into black hole just to feed some analytics, helps with the motivation to submit. No need to debug the constantly changing code. Even if your researcher verifies, that a specific release sends only such and such data, the next months release can send something else. The verification would take longer than a month, and given the cadence of releases, would be permanently out of date.
- foo101 8y agoIf the vendor wrote crash reports which you could review before sending, would you trust that the crash report is actually what is being sent? If you opted out of sending anything, do you really trust that the vendor is not sending anything? You still need to research what is going on at the low level to be sure if something is being sent or not and what is being sent. Your grandma is going to rely on the information obtained from independent researchers. Yes, the behavior of Linux distributions are also independently audited by independent researchers.