11 ms·
Hey, sorry for all the name changes of Microsoft Defender. I work at MSec (Microsoft's security org). We ended up absorbing and acquiring a few companies to pr
by inglor 5y ago
Hey, sorry for all the name changes of Microsoft Defender. I work at MSec (Microsoft's security org).
We ended up absorbing and acquiring a few companies to provide a better offering and a lot of re-branding happened. For example Security Center's old portal for active threat protection, automatic remediation, incident investigation etc is all now absorbed into (the better) security.microsoft.com which is (to my understanding, just an engineer) the current and last (for the foreseeable future) rebrand. The team I work at started as one person working on the frontend for MDE (Microsoft Defender for Endpoint) and now has hundreds of people working on the security portal across India, Israel and the US (as well as a few other smaller sites contributing).
Also, as an engineer I have to say the offering is good. The anti-virus and the telemetry is worked on by some really smart people. Client information is sacred, logging into production takes multiple audits and PII is scrubbed (heavily) any time logs are needed. We still have a lot of room to improve but I am confident in Microsoft both delivering a good product and acting in good faith (and there is a clear business incentive in the enterprise security space to do so rather than benevolence).
- flower-giraffe 5y ago> Microsoft both delivering a good product and acting in good faith I’m going to call you out on that. Microsoft lost my trust to act in good faith with personal data when they started capturing my private OS user input (e.g. the history from Windows R (run) and forced me to link it to my personal identity.
- autoexec 5y agoWhile MS isn't collecting your run history (at least not as you type it) the point stands. They've decided to use their OS to collect personal info on users for their own profit. The extent to which this happens can be limited, but not disabled entirely (for most users). That's reason enough to not trust them.
- TedShiller 5y agoMicrosoft lost my trust in the 1990's. Never been happier without them since.
- tempnow987 5y agoWhat does this mean - can you link to something. If they are doing a keystroke logger (ie, capturing typed private user data) where are they logging this keystroke log too? Or is the run command history sent up? Are you talking about folks with Send my activity history to microsoft checked? I have a script that sets default privacy preferences to my own preference when I start using a machine, you might consider that.
- flower-giraffe 5y ago> I have a script that sets default privacy preferences Then you will probably notice that you no longer have a history for Win+R run history. It’s not unique to Windows to mine user input but it’s more recent than for example the search in iOS and less obvious than Google search. I believed that the “personal” in Personal Computer meant that it belonged to me, and that used to be true. We are sliding down the slippery slope of allowing the software vendors to own our devices. I think the staring point with Windows was product activation in XP, and that was quite legitimately intended to stop software licence abuse. I am still comfortable paying for closed source software but Microsoft seem to have given up on that business model.
- alexklark 5y agohello, they send anything you type in the start menu right into bing, and they cut every way to disable it. by lying they trick every inexperienced in their methods user to enable online/edge account so everything you type almost anywhere except may be notepad but pretty sure include office are linked to you, your payment and billing info, your ssn, your location, your purchases, and all people your interact with. and then they feed you with generic tabloid puke from enforced by spyware internet explorer site msn.com you also can’t remove easily from appearing at start. the amount of trackers on this site is staggering.
- gruez 5y ago>when they started capturing my private OS user input (e.g. the history from Windows R (run) and forced me to link it to my personal identity. Source? Searching for "windows run dialog telemetry" on google turns up this thread https://news.ycombinator.com/item?id=28598474 https://news.ycombinator.com/item?id=28598474, which has multiple people saying they can't reproduce it, and the author retracting the post: https://news.ycombinator.com/item?id=28608540 https://news.ycombinator.com/item?id=28608540
- flower-giraffe 5y agoI observed first hand that disabling sending telemetry also disabled the history for win+r. It’s also quite easy to observe that when you type anything into the start search interface you are steered or defaulted to searching Microsoft internet services.
- gruez 5y ago> I observed first hand that disabling sending telemetry also disabled the history for win+r. 1. Okay, but how's that relevant to my original question? Is the history being broken supposed to be smoking gun evidence that windows is sending your "history from Windows R (run)" to microsoft? 2. I just tried and failed[1] to reproduce this on a VM with a fresh install of Windows 10 Enterprise LTSC 2019 with "telemetry disabled". There isn't an universal standard for "telemetry disabled", but at the very least I have the "Allow Telemetry" and various search related group policies activated. I suspect what's happening is that you ran one of those "disable telemetry scripts", and that unintentionally broke it. [1] https://i.imgur.com/WkbnBlM.png https://i.imgur.com/WkbnBlM.png >It’s also quite easy to observe that when you type anything into the start search interface you are steered or defaulted to searching Microsoft internet services. but we were talking about the run (windows-R) dialog, not the start menu?
- flower-giraffe 5y ago> I suspect what's happening is that you ran one of those "disable telemetry scripts", and that unintentionally broke it. I am 100% certain that’s not the case. — Yes - the point is when setting all the most private privacy options on Windows 10 stops keeping a win+r run history. I didn’t go as far as installing a custom root CA and intercepting binary telemetry data to prove that the data was being sent. I think the fact that the MRU list is disabled strongly suggests that the product team assumed or new that it was collected. If your experience is based on LTSC Windows/Office you probably have a different experience.
- nix23 5y ago
- inglor 5y agoThe inability to simply "see client data" even if you go through multiple bastions did kind of surprise me. I worked at several startups before Microsoft where just asking the client for permission was considered OK. This certainly makes debugging production issues much much much harder - there are certain environments whose data you simply can't access (either as a user or as an administrator) and you have to rely on telemetry (much of which you can't gather since it can possibly be used for PII - this is all an audited process) to debug issues (attaching a debugger is also prohibited since you can read data that way and the port is closed). Instead of trusting me - think of the corporate incentive to do well here. Consider how much it would cost a company like Microsoft if employees were exposed to confidential customer data (our customers can work with medical data, so a fairly expensive legal nightmare) vs. what the company gains (engineers have a slightly easier time debugging). At Microsoft scale I guess it simply makes sense to be super strict about this.
- ChuckNorris89 5y ago>Instead of trusting me - think of the corporate incentive to do well here. Unfortunately, when it comes to anything Microsoft related, due diligence research and logical thinking is rarely employed by the HN crowd, and instead replaced with anger and FUD. I've lost count of the amount of comments saying Microsoft is forcing TPM to spy on us. Not saying that the alphabet agencies or nation states couldn't misuse Microsoft's reach to get more private customer data, but that would apply to all US based corporations, not just Microsoft. And since AFAIK, Microsoft seems to never have been hacked for its customers' data to be leaked like it happened to Sony and Facebook, it seems they're doing a good job so far of keeping the amateur bad actors out and their customers safe. So thanks for commenting and sharing inside infos, as some big companies ban their employees from doing the same.
- nix23 5y ago>but that would apply to all US based corporations Thanks, no one said otherwise....but then it's no a quality standard per se ;)
- melony 5y agoDoes Microsoft offer favourable treatment or withhold patches when it comes to state level APTs? Can we trust Microsoft to be neutral and offer security patches in a timely manner and defend the interests of their consumer customers above all? With the whole conflict in Europe, the issue of state level adversaries is raring its head again.
- inglor 5y agoNot the opinion of my employer but: no. A state level attacker can likely acquire 0-day exploits that are not patched and bypass defenses. Microsoft's offering does some really cool stuff like: - Automatically detecting anomalous behavior in the network and isolating suspected devices/ips/machines/programs. - Have real time security engineers constantly monitoring your network and hunting attackers and suspicious activity. - Tools that automatically isolate possible attackers and help measure the impact of attacks. > Can we trust Microsoft to be neutral and offer security patches in a timely manner Yes, that for sure. Once an exploit is discovered it is typically very quickly identified. A lot of the times security patches don't come from Microsoft though - if you consider something like Log4Shell (the Log4J vulnerability) for example. > defend the interests of their consumer customers above all? I'm... not sure about "above all" since I am not sure what "all" is but if the implication is that Microsoft won't patch a security flaw for a state level APT then "yes". At least - if it ever happened it happened _way_ above my pay grade and if employees would learn of it there would be outrage. > With the whole conflict in Europe, the issue of state level adversaries is raring its head again. I think state level actors have consistently been a problem. Note again as already mentioned none of this represents the opinion of my employer, just my thoughts.
- KennyBlanken 5y ago> I'm... not sure about "above all" since I am not sure what "all" is but if the implication is that Microsoft won't patch a security flaw for a state level APT then "yes". At least - if it ever happened it happened _way_ above my pay grade and if employees would learn of it there would be outrage. cough NSAKEY cough Provided a backdoor for state security forces. Did it in NT, and then even after they were caught, did it again in Win2k. You underestimate people's moral flexibility, especially that of "patriots."
- chungy 5y ago> Hey, sorry for all the name changes of Microsoft Defender. Let's be fair, naming is not a strength of Microsoft. It seems that every product other than Windows and Office is renamed every couple of weeks; and even in those two examples, explosions of SKUs manages to muddle the waters just as well (Apple's "Choose a Vista" was very much on-point, even if you preferred Windows over Mac).
- matthewfcarlson 5y agoWhen I was at microsoft, I campaigned hard that we should name windows releases after dog breeds. Apple did big cats, who wouldn’t love to download windows 10 golden retriever? No one wants windows 10 fall 2021 update for creators.
- _AzMoo 5y agoAs an avid Apple user, I can't stand their naming conventions. I don't have any idea if High Sierra came before or after Mojave, or if Lion was before or after Mountain Lion. I would much prefer version numbers/years.
- spsful 5y agoBut they do? Each version of macOS is numbered. We're on macOS 12 right now.
- itslennysfault 5y agoHonestly, I had no idea. I recently had to have my MBP repaired (new logic board... as always). So, I got it back with the latest OS (Monterey). I needed to download some software that was for specific versions of MacOS, and I honestly didn't even know there was a OS 12. I thought I was still on "OSX". If it wasn't "Monterey" and was just MacOS 12 there would've been no confusion. I feel like it's always an exercise of looking up the code name to find the version whenever someone is like "Yeah, I'm on Big Sur" .... ok one sec, let me google what that even means.
- no_time 5y agoSaying "Client information is sacred" and stealing executables off all windows machines with the automatic sample submission on by default does not go well together.
- nix23 5y agoThat's normal and even kaspersky does it...but you can easily deactivate it, so your proprietary exe is not published ;) PS: And that function makes sense for "the public" don't you think?
- hackerfromthefu 5y agoWhile it has been normalized, the ops point is correct that the lip service to client data being sacred, does not match the actions of uploading clients data!
- no_time 5y ago>even kaspersky does it Thats an awfully low standard to set don't you think? I don't think it makes sense for the public. Stealing files from unsuspecting users without as much as a popup saying "hey, we just snatched this file without you knowing this is even a possibility" is just sad. EDIT: i just realized you are being ironic
- omegalulw 5y agoThat's whataboutism. I absolutely do not want Microsoft grabbing stuff from my PC without asking me, it's so insidious. And then they put the switches to turn these off behind so many loops and registry flags that's it's a nightmare to turn this crap off.
- tpmx 5y agoIt would be awesome if you reviewed the blog post's (https://0ut3r.space/2022/03/06/windows-defender/ https://0ut3r.space/2022/03/06/windows-defender/) recommendations for accuracy/meaningfulness/etc.
- inglor 5y agoI am not an expert - just a user and an engineer working on this. I'm happy to ask one of our PMs to review it they know and understand the product a lot better than I do. From reading the article everything "sounded right" but that's hardly an educated opinion since I only worked on _some_ parts of the product. Actually - I think I'll ask our red team or security guid - that's also probably a good source.
- pstuart 5y agoThat would be a great Tell HN post.
- huhtenberg 5y agoIt would, but realistically there's no way it's gonna happen.
- zeeZ 5y agoThe naming and, from what I've gathered, recent changes are a mess. Recently I looked at M365 business premium and thought that would only include Defender for O365 (why not M365?) and require a separate subscription for Defender for Endpoint, but now it looks like Defender for Business is included.
- alibert 5y agoHello, Anything being worked on the IO performance side of Defender? I’m still using a paid third party AV for this sole reason. The impact is so huge with NPM packages as an example…
- bob1029 5y agoIO impact is why I disable it on all my dev machines. Microsoft really needs to make this easier to turn off too. Right now, I have to use an undisclosed privilege escalation hack-around to force things my way.
- tomnipotent 5y agoYou can add folder and extension exclusions to Defender. I do this to the root of my source code folders and it helps immensely.
- jraph 5y agoOn the other hand, isn't node_modules the folder that shouldn't be excluded from antivirus scan?
- sundvor 5y agoPerhaps it's one better suited for periodic scanning? At least from a performance point of view. Perhaps one ought to have live scanning enabled when updating packages, then disabled when not. I look forward to seeing other replies.
- tomnipotent 5y agoThe challenge is that excluded folders/extensions apply to both real-time scanning and manual/periodic scanning. What we really need is the ability to disable real-time scanning on one set of folders/extensions, while still including them with scheduled system-wide scans.
- Beldin 5y ago> sorry for all the name changes As long as you guys are not going the route of google's approach to messaging, I'm sure we will forgive you. Nor the route of an NFC pay/wallet/money app that... You know what? Just don't do the thing where you launch products to consumers so that someone achieves a promotion internally, and then abandon the product. Frankly, MS has a long history of backwards compatibility, so signs are already positive.
- deleted 5y ago[deleted]
- shmoe 5y agoApology mostly accepted. It certainly makes it hard to discuss with people!
- askura 5y agoThat's good to know and you sound pretty earnest to be honest.
- ZYinMD 5y agoI recently had a new issue with the Defender: there are 2 apps I use that can delete files from disk, one is a mp3 player (foobar2000), the other is a video player (PotPlayer), both have a hotkey to "delete the current file being played". I've been doing it for years, but recently when I do it, the app will freeze for 5 seconds, meanwhile the CPU usage of window defender will shoot up in Task Manager. I tried to tweak all kinds of different settings in the Defender, and couldn't find a fix.
- MikeTheGreat 5y agoSo on the one hand I want to validate and recognize both that you're having this problem and that finding a real live person who might be able to help you with it totally, very reasonably, evokes a "hey, can I tell you my problem?" response. I don't want to minimize that, but I do want to (gently, good-naturedly) say that I think it's kinda funny. As someone who once worked at a big tech company I think it's totally hilarious how telling people "I work on X product at Y company" totally evokes this sort of response. Tell enough people where you work and you'll see some non-zero percentage of people respond like this. Like, when I was talking with a mover who was unloading my stuff and he asked "So, what brings to you these parts?" and I told him his first response was "Really? Y'know, I've got that software and it doesn't work for me under these very specific conditions. Why is that?" (At the time I think I mumbled something about "I don't know". In retrospect I was moving to start work there so I realistically couldn't have known yet). So - I hope you get your problem sorted out, thank you for giving me the opportunity to talk about this, and I think I'm gonna go chase some kids off my lawn now :)
- catmanjan 5y agoWait until you hear what happens when you say you’re a doctor, electrician, carpenter, builder, mechanic…
- greyhair 5y agoAs a mechanic in a previous career, I can verify that. The only answer I ever gave was: "Sure I can look at that, bring it into the shop, we're open eight to five Monday through Friday, eight to two on Saturday, and open until eight PM on Wednesday and Thursday, but only for drop off, pick up, and tire changes."
- deleted 5y ago[deleted]
- behringer 5y agoIt's so nice being able to tell my family and clients that yes, they really don't need a separate AV anymore. The name changes don't hurt anything. I just say Windows comes with AV built in and it does a fine job all on its own. MS really did well with it.
- deleted 5y ago[deleted]
- h0ek 5y agoThanks for this comment, means a lot for me. Fingers crossed.
- dncornholio 5y ago> Client information is sacred If you need to point this out, I get the feeling it's not. You are only saying this because a boss told you to do so. Is what I'm feeling from this.
- qwerty456127 5y agoFirst of all thank you for a great job. Since its Windows XP Security Essentials incarnation I consider it the best choice for Windows PCs protection. But bloody please add an option to turn off hunting for "hack tools". As an advanced user, SMB admin and private programmer I use NirSoft tools and also keygens for my own apps but Windows vigorously deletes NirSoft (and perhaps some SysInternals also, but I'm not sure) tools and every keygen it would notice. So I have to disable it. It has even deleted qBitTorrent once although it is a perfectly legitimate app and I use it to download legal things like Linux distros and legitimately purchased Humble Bundle stuff. Why can't I [with reasonable ease] configure it to only watch for real viruses/spyware/ransomware which really threatens to infect the PC? In my opinion we even have to consider actual pirates using really illegal keygens because this simple fact: there are many of such in mediocrely developed countries, they get confused, disable the protection, get infected and join the botnets. Even when there is a criminal we dislike to support and want to punish, we don't want them to get infected with anything and spread the infection further. There should be clear distinction between unquestionable malware everyone wants and needs to be protected from for everyone's good vs questionable apps some people (justifiably or not) actually want to use for sake of their pragmatic interest.
- dom96 5y agoHey, we (Nim programming language[1]) get constant false positives on Windows Defender. This has started relatively recently and we think is due to a recent increase in the number of whitehats using Nim but it really affects our community negatively. It seems that Windows Defender marks anything that looks like Nim[2] as being a virus which is very unreliable and causes many of our users to get hit by virus warnings as soon as they attempt to install Nim. We've attempted to submit the files concerned as false positives to no avail[3]. Can you or anyone else help resolve this? 1 - https://nim-lang.org https://nim-lang.org 2 - https://forum.nim-lang.org/t/7885 https://forum.nim-lang.org/t/7885 3 - https://forum.nim-lang.org/t/8196#53855 https://forum.nim-lang.org/t/8196#53855
- Tozen 5y agoThis false-positive problem is a major headache for a lot of open-source programming languages and programs, whose source code is also sitting right there on GitHub to be inspected and compared with. Think that Microsoft could do better with its false-positive review process, particularly doing something more for open-source developers and projects.
- BORG_VS_RESTIC 5y agoWhy are Windows updates such an absurd experience? All my Macs and Linux machines update without any hassle and without taking so much time, Windows always takes very, very long and what is even more annoying it not only takes forever, but even after waiting 20 minutes for updates and rebooting it still needs new updates. It is absolutely embarrassing and horrible. A bad, unusable system. Fortunately I replaced all Windows machines with actual operating systems, so I do not have to use that ugly joke system too much.
- gaia 5y agoIs there something you could say about complementing Defender with paid MalwareBytes? Is there too much overlap to justify this? Or is performance hindered more than the additional benefit accrued (not that I feel it, system is responsive enough)?