4 ms·
This is one thing makes me tend to distrust Microsoft regardless how many people are chanting "MiCROsoFt is ReAlLy ChAnGed FoR ThE BeTTer". No, they always trie
by nirui 6y ago
This is one thing makes me tend to distrust Microsoft regardless how many people are chanting "MiCROsoFt is ReAlLy ChAnGed FoR ThE BeTTer". No, they always tries to grab something from you, little things here, little things there.
I got a Windows 10 Phone, and Edge is the only web browser that is available (Version 38.14393.2551.0 currently). According to my setting, Google should be the default search engine rather than Baidu which is an unremovable option for Chinese user.
However, from time to time (randomly I'd say), when I open Edge, the Baidu homepage pops up with a mystical tail "?tn=<a number>" in it's URL (while my setting is Google remind you).
Now, maybe you're thinking "Ha! this guy got a malwared Windows 10 Phone, kudos!". Well, guess what, thanks my slow Internet, I caught the redirector address hosted on go.microsoft.com right before it opens Baidu.
If you curl the address, which is https://go.microsoft.com/fwlink/?LinkId=625115 https://go.microsoft.com/fwlink/?LinkId=625115 to be specific, you will found:
$ curl -v --head https://go.microsoft.com/fwlink/?LinkId=625115
......
* Server certificate:
* subject: C=US; ST=WA; L=Redmond; O=Microsoft Corporation; OU=Microsoft Corporation; CN=go.microsoft.com
* start date: Sep 6 19:37:21 2019 GMT
* expire date: Sep 6 19:37:21 2021 GMT
* subjectAltName: host "go.microsoft.com" matched cert's "go.microsoft.com"
* issuer: C=US; ST=Washington; L=Redmond; O=Microsoft Corporation; OU=Microsoft IT; CN=Microsoft IT TLS CA 5
* SSL certificate verify ok.
> HEAD /fwlink/?LinkId=625115 HTTP/1.1
> Host: go.microsoft.com
> User-Agent: curl/7.58.0
> Accept: */*
>
< HTTP/1.1 302 Moved Temporarily
HTTP/1.1 302 Moved Temporarily
< Content-Length: 0
Content-Length: 0
< Location: https://www.baidu.com/?tn=80035161_1_dg
Location: https://www.baidu.com/?tn=80035161_1_dg
......
Well, to be completely fair, it's not the dirtiest little game that they've played during their entire existence. And, at the very least, they are indeed redirecting me to the HTTPS service rather than HTTP one. So I guess I should thank them for the merciful and care?