25 ms·
Microsoft’s enterprise products covertly gather personal data on users
- miaklesp 8y agoOMG! MS Office collects telemetry on how many times user clicked on toolbar and selected bold font! Breaking News! For websites to use Google Analytics is absolutely okay, but for desktop applications not? Microsoft is EVIL!
- amaccuish 8y agoThis displeased me recently with Office on the Mac. To even set the level of data to "basic", I had to fiddle with plists, and it's not even possible to switch it off completely. Luckily just finishing our migration to Libreoffice and ODF.
- naikrovek 8y agoGet ready for a world of pain if you interact with anyone using MS office. "LibreOffice" (FFFUCK I hate that name) will gleefuly just strip anything it doesn't understand in the documents it opens. It doesn't just ignore formulae that an MS Office user carefully wrote, it straight up deletes that stuff. Without notice. OpenOffice is cancer to MS Office users.
- Doxin 8y agoMS Office supports the open document format these days. LibreOffice does its best on the monstrosity that is docx if you ask it to, but you're better off using open formats.
- foepys 8y agoMaybe Microsoft will be the first company that has to pay 4% of their global revenue to the EU under GDPR. Microsoft will have a hard time arguing against a government report
- thrower123 8y agoIt's too bad Microsoft, Google, Apple, Amazon and Facebook won't ever stand firm together and tell the EU regulators to get bent and go home.
- bilbo0s 8y agoThere's, I'm guessing, somewhere between 5 and 600 million consumers, er, I mean, people- in Europe. I think that's a large part of the reason they don't stand up to the EU.
- DannyBee 8y agoI hope not for the EU's sake :) That really isn't that huge anymore, and it's definitely not growing that fast. I don't think you want to make a consumer argument because consumers buy expensive stuff everywhere. There are also larger and more growing consumer markets. The better argument would IMHO probably be "They need to sell business products and to businesses there, and the EU businesses are spending more than elsewhere". IE it's a concentration of business wealth. That is also likely to change over time.
- SmellyGeekBoy 8y agoI know, right? Someone has to stand up for the right of these corporations to collect and sell everyone's personal data to the highest bidder.
- adimitrov 8y agoIt's good, though, that the European countries stood together and told Microsoft, Google, Apple, Amazon and Facebook to get bent and go home! As an EU citizen, my response to "we're sorry not sorry but due to recent EU laws, we can't continue to offer you this service" is: get bent, go home. I hope we, as the software development community can finally understand and appreciate that the insane proliferation of personal data modern tech has become dependent upon is a Bad Thing.
- 8y ago
- grezql 8y agoThere was another case recently with Indian enterprise customers which had me worrying. https://www.theinquirer.net/inquirer/news/3065535/microsoft-shared-indian-bank-data-with-us-intelligence-without-warning-customers https://www.theinquirer.net/inquirer/news/3065535/microsoft-... At my work we are considering moving to the cloud with exchange and other services. I will make sure these articles will certainly be topic at next meeting
- esotericn 8y agoThe base version of Windows 10, their flagship product (if not in terms of revenue, then mindshare) is stuffed full of adverts and defaults on about 6+ options related to telemetry the last time I installed a VM. I think it would benefit large companies like Microsoft to realise that this sort of behaviour has knock-on effects. Every MS product is tainted by this because it ultimately has effects on trust. If it's not making them, or can't be linked to, significant amounts of revenue, it would surely be beneficial in terms of customer numbers to stop doing this. Why? I don't understand, or believe, that they're making significant amounts from this. It feels like bean-counter style decision making that doesn't take in to account the wider picture. Anyone from MS willing to chime in?
- bilbo0s 8y ago>Anyone from MS willing to chime in?... If MS is making money from this, the last thing anyone involved in it will do is tell you how much.
- swiftcoder 8y agoAnd since there's seems to be a GDPR violation in here, the only thing a microsoft employee would be authorised to do is refer you to the official press release.
- Tsubasachan 8y agoThe entire tech sector is being funded with advertising money. Monetization of personal data is the elephant in the room that nobody in the industry wants to talk about ever.
- saiya-jin 8y agoMaybe they want to be more like google, ad-driven - when you compare revenues and overall state of the companies, I can understand why some top managers decided for this. Also testing how much users will allow, which is a threshold constantly moving towards more apathy. Its dumb, dangerous to users and I hope they will get a massive slap on the wrists. But Win10 is out for long time and nothing is happening.
- 8y ago
- whatshisface 8y agoIs it possible to firewall Microsoft products using only the things that the average person has access to? (A telecom-supplied router and a Windows computer.)
- esotericn 8y agoI don't believe it's possible to firewall Microsoft products in the general case of a power user that has access to an edge router. You'd have to do something insane like IP whitelisting only for services you care about, hope that none of them use MS services like Azure, disable Windows Update entirely, etc. It might be possible in the abstract sense of "right now nothing is getting out" but they have root on your box, it's closed source proprietary software, and you've basically broken the OS with this firewalling anyway. You need to be able to trust them.
- bilbo0s 8y agoThis. The fact that you're running Windows means you are potentially already compromised.
- lwkl 8y agoYou can Firewall Windows services. There is a inbuilt firewall and there may be default rules but you can customize it the way you want. It would be a pretty big security flaw if they let their services bypass the firewall. They may be profit oriented but not stupid.
- vetinari 8y agoTo use Windows Firewall, you would have to know what to black- or whitelist. Even most powerusers do not know that, and it could change with every update anyway. Therefore, Glasswire/Little Snitch-type firewalls are being used, where you get an alert during connect() time, and you can create the rule on the spot. Windows Firewall cannot do that, and neither can UIs built on top of it, like TinyWall.
- pritambaral 8y ago
- moontear 8y agoNot commenting on the article itself, but the chosen title which is clickbait to me. The assessment is about Office ProPlus (actually called Office 365 ProPlus - I don't know why it's called "Office ProPlus Enterprise" in the article/assessment which doesn't exist as a product). The assessment also complains about Office collecting data so I wouldn't say it is fair to say that "Microsoft’s enterprise products covertly gather personal data on users" (which really includes a lot more products than just Office). The blog posts title is actually "Impact assessment shows privacy risks Microsoft Office ProPlus Enterprise" which is more specific than "enterprise products".
- deleted 8y ago[deleted]
- birksherty 8y agoI don't see "Office ProPlus Enterprise" in the article. >I wouldn't say it is fair to say that "Microsoft’s enterprise products It also includes sharepoint and onedrive which are used in enterprises in the article.
- mxuribe 8y agoAmong the recommendations is to not use SharePoint, and to not use oneDrive? Wow, those are kind of important products for many enterprises. I see the recommendations around these two as quite damning.
- lwkl 8y agoThe title is missleading. The report is about Office 365 and for the Dutch Government. Since they are a government they probably have stronger legal requirements than your standard small business owner around the corner. So they probably can‘t use the SaaS Sharepoint offering by Microsoft to store their data. I have worked for companies and with goverment contracts in the past and you had to use special hardware provided by the goverment to work on those projects. So it doesn‘t surprise me at all they they themselfes can‘t use SaaS offerings.
- Digital-Citizen 8y agoPerhaps but I think that point misses the underlying issue at hand -- with proprietary software users don't get any real control over the software. Even the corporate-friendly computer press reported plenty of stories about Microsoft's software which bear this out: Microsoft repeatedly switches a flag which urges Windows users to "upgrade" to Windows 10 when users had said no. http://www.computerworld.com/article/3012278/microsoft-windows/microsoft-sets-stage-for-massive-windows-10-upgrade-strategy.html http://www.computerworld.com/article/3012278/microsoft-windo... Microsoft forces some Windows systems to switch to Windows 10 by silently downloading Windows 10 https://www.theguardian.com/technology/2015/sep/11/microsoft-downloading-windows-1 https://www.theguardian.com/technology/2015/sep/11/microsoft... This forced "upgrade" had adverse effects on some users with poor connectivity. https://www.theregister.co.uk/2016/06/03/windows_10_upgrade_satellite_link/ https://www.theregister.co.uk/2016/06/03/windows_10_upgrade_... Once the switch to Windows 10 was accepted there was no way out https://www.theregister.co.uk/2016/06/01/windows_10_nagware_no_way_out/ https://www.theregister.co.uk/2016/06/01/windows_10_nagware_... Windows 10 is quite nasty for many reasons all of which boil down to being nonfree, proprietary software. For example, it by default sent core dumps to Microsoft or whatever organization Microsoft chooses. http://betanews.com/2016/11/24/microsoft-shares-windows-10-telemetry-data-with-third-parties http://betanews.com/2016/11/24/microsoft-shares-windows-10-t... Windows 10 ignores users' so-called "security" settings putting a fine point on how insecure they are. https://www.eff.org/deeplinks/2016/08/windows-10-microsoft-blatantly-disregards-user-choice-and-privacy-deep-dive https://www.eff.org/deeplinks/2016/08/windows-10-microsoft-b... and https://archive.fo/2ey80 https://archive.fo/2ey80 https://www.gnu.org/proprietary/malware-microsoft.html https://www.gnu.org/proprietary/malware-microsoft.html is filled with more references to still more stories of how Windows runs against user's security interests and control over their own computer. So when the Privacy Company "recommends admins of the enterprise version of Office ProPlus in the Netherlands (although many of them should also be applicable to other countries) [...] Apply the new zero-exhaust settings" there is no reason to believe that one gains privacy from Microsoft in so doing. Ultimately one's control over proprietary software only goes so far as the proprietor will allow. This remains true notwithstanding user's requirements or willingness to investigate and implement whatever the computer owner wants changed. Microsoft is merely illustrating the inherent and unjust control over one's computer proprietary software has. It is this power that is at the heart of what's so wrong with these recommendations, nothing to do with a relatively minor quibble over whether one set of users has different requirements for privacy or security than other users.
- laurent123456 8y agoMaybe governments should start looking at open source alternatives rather than being more and more vendor locked by US companies. It would take time to switch and won't be that easy but it's certainly doable, as the French Gendarmerie shown when they've switched everything to Linux.
- trendia 8y agoThere are many regulations that affect data, like HIPPA and ITAR. How can Windows be used in such an environment if the data collection can’t be stopped?
- josteink 8y agoIf the data collection is “anom-user-123456789 launched the built in email-client 20 times and sent 30 mails”, I suspect that’s not exactly HIPPA or ITAR-regulated data.
- sweetp 8y agoany word on VSCode? should I be worried and switch back to Atom
- artimaeis 8y agoJust a quick setting to flip: https://code.visualstudio.com/docs/supporting/faq#_how-to-disable-telemetry-reporting https://code.visualstudio.com/docs/supporting/faq#_how-to-di... And the relevant HN thread: https://news.ycombinator.com/item?id=18209082 https://news.ycombinator.com/item?id=18209082
- sweetp 8y agowoah, glad I asked. thanks for the links. I've updated my settings
- zarex 8y agoYou're looking for this repo: https://github.com/VSCodium/vscodium https://github.com/VSCodium/vscodium These people make a VSCode build without M$ telemetry/tracking enabled.
- tozeur 8y agoSerious question: Why do you care Microsoft (or any company for that matter) collects your code editor telemetry? Addendum: Check our Google Analytics, Hotjar, and Facebook ad targeting if you _really_ want to see “violation of privacy”. In reality, companies want to know how users use their products to make them better.
- deleted 8y ago[deleted]
- Quanttek 8y agoFull report [PDF]: https://www.rijksoverheid.nl/binaries/rijksoverheid/documenten/rapporten/2018/11/07/data-protection-impact-assessment-op-microsoft-office/DPIA+Microsoft+Office+2016+and+365+-+20191105.pdf https://www.rijksoverheid.nl/binaries/rijksoverheid/document...
- ljoshua 8y agoThe article didn't necessarily clarify what type of data was being reported back, which I think is key. It mentions diagnostic data (I'm assuming crash logs and such), but it says "personal data" without specifying. I think that would be a very helpful bit to surface before a solid judgement call can be made. Anyone with more info?
- ConceptJunkie 8y agoOf course, they do. Microsoft never fails to jump on other companies' bandwagons, and in this case they are imitating Google and Facebook.
- sarcasmOrTears 8y agoInstead of useless things like GDPR we need laws that prohibit forced telemetry in software. Instead of just a 20mil+ fine, we need a fine plus jail time for the people involved. This is malicious software. This is a person spying on you, stalking, industrial espionage, etc all in one. But of course, making a very simple and clear law would actually make life difficult for bug business. They would be forced to stop bad practices for real. Also goverments love the idea of having access to that sweet, juicy, "encrypted" data if needed.
- swiftcoder 8y agoI'm not sure that a blanket ban on automatic opt-in to telemetry is the right call. Most consumers don't have the requisite knowledge to make an informed decision when to opt-in. I would like to see laws requiring transparency in telemetry, though. Require all telemetry to be in plain text, and auditable by 3rd-party software (say, by antivirus/privacy software).
- isoprophlex 8y agoAdvice to corporate users (quote from the article) > Periodically delete the Active Directory account of some VIP users, and create new accounts for them, to ensure that Microsoft deletes the historical diagnostic data The fact that this is necessary is beyond retarded. Imagine you're a big corporate, paying money for a software product, and you have to jump through silly hoops to protect your privacy. I'd have a good laugh watching MS account execs explain this to me...
- OnlyRepliesToBS 8y agopattern of deceit
- driverdan 8y agoThis should be switched to the original source: https://www.privacycompany.eu/en/impact-assessment-shows-privacy-risks-microsoft-office-proplus-enterprise/ https://www.privacycompany.eu/en/impact-assessment-shows-pri...
- gerrard00 8y agoI definitely think this should be opt-in but I also think that it's silly to focus on just this scenario. I'd bet dollars to doughnuts that Google Docs and every other web based business tool use similar telemetry data to guide their UX and product investments as well as to preemptively address bugs.
- kenjackson 8y agoDon't ALL web/internet based products have to collect some base level telemetry to simply function?
- smacktoward 8y agoWhat’s new is having to think of your operating system as a “web/internet based product.”
- josteink 8y ago> Don't ALL web/internet based products have to collect some base level telemetry to simply function? No. Not at all. There’s no technical reason which drives such a demand. A big, fat no. But it can help making the company hosting the site money. By selling your data to others. And that’s another question entirely.
- deleted 8y ago[deleted]
- cptskippy 8y ago> Microsoft collects and stores personal data about the behavior of individual users I feel like this sentence is phrased maliciously. The adjective "personal" is applied to the more generic term data, rather than the more specific term behavior. By placing the adjective on data, it encourages the reader to imagine the worst possible scenario. By simply moving the adjective you can more accurately describe what Microsoft is doing and avoid allowing the reader's imagination to run wild. > Microsoft collects and stores data about the personal behavior of individual users You could also remove the adjective entirely because the term individual has the same implication. This makes it sound even more innocuous. > Microsoft collects and stores data about the behavior of individual users
- Wowfunhappy 8y agoPersonally, I don't find any of your revised phrases to be less disconcerting at a gut level. "Personal data", "personal behavior", etc is all the same to me.
- cptskippy 8y agoPersonal data could be anything like your SSN, CC# or other secrets. Personal behavior is a more specific classification like "user scratches his butt every morning" or "user picks nose". In the context of Office Applications it's going to be even more specific things like "user always tries to click on URLs in emails before CTRL+clicking them."
- TheRealDunkirk 8y agoAs someone who installed a bunch of Ubiqiti equipment at a large church, I can see that once we have 1000 phones in the building, there's a non-trivial baseline of network activity that I attribute to Facebook, et. al., phoning home. In my company of 46K employees, it can't be a non-zero cost to have this telemetry activity leaching on our WAN connections, many of which are struggling to keep up with demand already.
- pasbesoin 8y agoSeriously, could Microsoft work any harder to drive me away? People are going to look at their bottom line and decide this money-grabbing maximal-ism just makes them greedy, unconscionable bastards. Of course, that's never stopped their juggernaut, before. For my part, watching this behavior, I'm all the more convinced that de facto UEFI control and the like need to be ripped away from them. They will exploit anything. The problem is, who can and will serve as a neutral steward -- of implementations and not just theory and maybe design?
- yuhong 8y agoAFAIK SQM dates back to Office 2003.