22 ms·
The reason you have a bad feeling is it gives the FBI/FEDS a single point to collect your data, with a man-in-the-middle attack that you will have no idea is th
by deviantbit 4y ago
The reason you have a bad feeling is it gives the FBI/FEDS a single point to collect your data, with a man-in-the-middle attack that you will have no idea is there.
This is absolute BS they're implementing this.
- muricula 4y agoLike your internet service provider you already have??
- xboxnolifes 4y agoAn ISP is not a single point for all Windows users.
- BillinghamJ 4y agoCloudflare is probably not far off, though not an ISP in quite the same sense
- bisby 4y agoWhile I agree with the sentiment that ultimately we have to have some level of trust somewhere on the stack, there are a few minor differences. In theory anyway, I pick my ISP. If this was "support for using a VPN" instead of "we're injecting OUR VPN" I would feel a lot better. I'm aware Im using my ISP. Even someone who doesn't know much about computers knows their traffic is going somewhere. They might not know the repercussions of that, but if this is just transparently on in the background, effectively a keylogger, a user might never know this is happening. I give my ISP money. Back to the choice option. Some ISPs are bad and are trying to nickel and dime you to maximize profits. Some ISPs are actually good (I'm not swiss so I don't know for sure, but Init7 looks amazing https://www.init7.net/en/support/faq/privatsphaere/ https://www.init7.net/en/support/faq/privatsphaere/). I don't have to question with my ISP "how are they profiting off of me" because I give them money every month. They might be, but they don't intrinsically NEED to be scraping my data. I am not sure how Microsoft benefits from giving me a free VPN unless they are scraping my data. I can use a VPN to bypass my ISP monitoring if they do monitor. I have no idea how Microsoft's stuff is set up here. If the end result is that it gets routed through their VPN after my VPN, or instead of my VPN, or even through their stuff at all, but with stamped metadata, then there's not necessarily a great way to get around it other than "don't use Edge" In general, yes, your ISP isn't your friend. But an ISP is something I asked for, have a use for, and need. A Microsoft stealth VPN is none of those things.
- gfaster 4y agoThis was also how I could justify being more trusting of Apple. They didn't need all my data because that was paid for up front. The ongoing services that needed to make money I used were also paid for. Obviously that's no long quite true with Apple ramping up their ad business, but that attitude is still often the best you can do without a level of effort that I just am not willing to go through.
- vintermann 4y agoYup, a VPN is not a security measure at all unless you trust the VPN provider more than the site you're connecting to...
- Schnurpel 4y agoActually, with a VPN, you need to trust the VPN provider AND the site you're connecting to...
- bryanrasmussen 4y agowell you might have a reason to trust a VPN provider you pay for, but who is the customer for MS Edge.
- manholio 4y agoThe insane thing is that, because the VPN has a 1GB/month traffic limit, there is no way to enforce it unless they associate all traffic with a Microsoft controlled user identity. Cloudflare literally has to keep track of any sites you visit and associate them to your ID to make it work. Though, I do believe that for connections from public WiFi it's somewhat of an improvement. It establishes a minimal security baseline of: "ok, we'll sell your data and let FBI snoop on you, but we won't inject trojans in your downloads and then hijack your webcam to create ransom-porn (though the FBI/??? might)".
- rpgmaker 4y agoAnd not even then. Most VPN providers in the top 10 are actually very shady and their organizational structure is quite opaque.. to say the least. I wouldn't be surprised if at least half of the top providers are actually FBI fronts, like the ANOM chat app.
- smeagull 4y agoIt is so weird that they're 'VPN providers'. They're proxies. It's not really a VPN unless I'm in control, or they're providing servers in the VPN to connect to.
- at-fates-hands 4y agoI work for a very large corporation who has decided the default browser will be Edge. Getting another browser installed on your machine takes an act of congress and several upper level approvals. Does this mean they will also have the ability to collect corporate data from the browser in companies like mine?
- meltedcapacitor 4y agoJust compile Firefox or chromium to WebAssembly and run it inside Edge. :-)
- sheerun 4y agoFrom my experience, non-tech people just leave browser defaults. I'd argue this is better than letting them to use public wifi without VPN. If you really care about security you won't use it, of course
- dataflow 4y agoPublic Wi-Fi in the world of HTTPS is not exactly terrifying.
- gambiting 4y agoHTTPS is trivial to break with a man in the middle attack, yes you get a scary warning in your browser about an invalid certificate, but I'd bet that 90% of people will just click through it and ignore it.
- shepherdjerred 4y agoI highly doubt this prediction is accurate. Most people will think something is broken and call tech support. Aside from that, this isn’t possible for HSTS sites.
- gambiting 4y agoReally? Most people? I cannot think of anyone from my family who would even think about it for a second - they would just get annoyed they can't get to their bank website or whatever and just click continue. Also what tech support? Me?
- elcomet 4y agoBut now there is no button "continue", you have to click multiple buttons, which are not clearly labelled, in order to see the page. I'm sure 90% of people would not even be aware that you are able to continue. Even more, for self-signed certificate on chrome, there is no button to continue for example. Check https://self-signed.badssl.com/ https://self-signed.badssl.com/
- supernovae 4y agowhy is it ok if firefox and opera do this but no one else?
- api 4y agoIt's also a way to front run ISPs in the data market. Then these vendors can sell the data on the data broker market and pocket the cash the ISPs are getting by selling whatever browsing history data they can infer (from DNS and traffic). I suspect this is the corporate motivation. The increased state surveillance and control is a side effect.
- cyanydeez 4y agoCorporations have shown worse proclivities than the US government these days.
- drews64 4y agowhat makes you think its the US government you should worry about? EDIT: clarified "US" government, though I don't necessarily intend to suggest other governments are the worry.
- jwond 4y agohttps://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/Global_surveillance_disclosures_(2013%E2%80%93present) https://en.wikipedia.org/wiki/Global_surveillance_disclosure...
- jhchjdjsdh 4y agothey already have this at several points in your network. from ISP to target site. meh. the reason microsoft is doing that is because google is forcing their hand with Floc implemented in the browser. you wont be in ads next year unless you can slurp more traffic than the NSA. and only google can do that today, thanks to chrome + android. apple is a close second.
- dannyw 4y agoHow is FLOC relevant to this?
- jhchjdjsdh 4y agoHow do you think google competitors will have access to all those user to form the cohorts without having the browser or google analytics code everywhere?
- staticassertion 4y agoThey already have that with ISPs, right? I don't see this as worse. If anything ISPs are more scummy.
- discordance 4y agoI think there's more to it than that. Good for some and bad for others. A few rough off the top of my head: Good: * Better privacy from the intrusive ad motivated JS shit hole the internet has become. * Faster internet for those on slow connections * Protection from ISP MITM. Many countries now have mandatory data collection laws that ISPs have to follow. * Better than a lot of shady 3rd party commercial VPN providers. * Is opt-in (for now) * Potential to reduce Google's dominance Bad: * Obvious MITM choke point, as you mentioned * Potential control / monitoring by two large corporations * Business goals usually override users.
- Thorrez 4y ago>* Is opt-in (for now) Are you sure? >a VPN baked into Edge appears to be turned on by default, but only for certain use cases.
- datalopers 4y agoWait til you hear about Cloudflare
- devwastaken 4y agoCF removed kiwi farms from their services. If they're cooperating with FBI they would continue to host and intercept traffic to decloak users.
- datalopers 4y agoHoneypots outlive their usefulness. Take silkroad v2 that was actually ran by the FBI, yet they still shut it down.
- _the_inflator 4y agoThis reminds me of this here: https://en.wikipedia.org/wiki/EncroChat https://en.wikipedia.org/wiki/EncroChat However, there analogy is not 100% on point.
- still_grokking 4y ago> This is absolute BS they're implementing this. Out of the perspective of a PRISM Premium Partner this makes perfect sense.
- tekknik 4y agoWhile it doesn’t resolve all the issues, the single point to monitor is your internet connection where they have jurisdiction, not some arbitrary VPN provider. Then if they can force the IKE a certain way they decrypt. I think the other side of this is if you have FBI attention, do you really want to look more suspicious? Whatever fight you try with them you will not win.
- awill88 4y agoYep, a VPN baked into a browser like this is literally Microsoft stealing the network routes from your ISP, who is probably too embarrassed to complain that what’s happening is they are taking that sweet, sweet data with them. It’s like high-fructose corn syrup for targeted advertising imho. Who’s selling?
- mejutoco 4y agoIsn‘t this what they did with Skype (centralize it)?
- salawat 4y agoYup.
- bakuninsbart 4y agoMaybe a dumb question, but isn't that already a given when using a browser? To me it always seemed a bit absurd to use VPN as it basically just gives another person all your info, but just assumed browsers and the big 5 just got most of the data anyway.
- frankfrankfrank 4y agoThe only thing I can see working is pollution, pollution of our data. There are some current extensions that do some of that, but they are likely not enough and what we really need is a kind stream of data and requests that your own requests are simply merged into. The thing is that it would need to be smart enough to prevent pattern recognition, e.g., it cannot just be random data because your specific searches and string of searches or actions will stand out quite obviously. Yes, it would place a severe tax on the internet and a few things could be done to minimize that, but I currently do not see any other better option. I could see it implemented where your activities online are merged with and threaded into those of related or similar communities, e.g., be it family and friends, the YC community, or a combination of different groups. The effect would come from the proximity to similar but not exact activities. To use a common example, if your legal free speech activities could make you a target, those online activities are muddled and polluted by being merged with other people's legal free speech activities, and your activities would be merged with those of others. Consider it a kind of mutual compromise of society in order to provide protection/obfuscation in numbers ... the zebra in a herd, if you will. They can't arrest/target everyone if everyone has activity data that looks like they defy the ruling powers.
- autoexec 4y ago> The only thing I can see working is pollution, pollution of our data. this is a terrible and dangerous idea. Nobody cares about the accuracy of the data they collect on you. Stuffing your dossier with random things won't cause anyone to throw it away just because there might be errors in it. Instead all of that data, random/accurate or not, will be used against you all the same. Your clever browser extension might have been responsible for browsing to a bunch of fast food websites, but your health insurance provider won't care. They'll just see that in your internet history and quietly raise your health insurance premiums anyway. If your legal free speech activities make you a target, adding more free speech activities to your permanent record just means you'll also now be targeted for those activities on top of your own. You can't know what will prejudice someone else against you. You might not be gay, or Muslim, or a heavy drinker, or an Andrew Yang supporter, but your browser extension pulls in the wrong data that gets you flagged as being one and it could cost you your job, get you denied housing, etc. You might not be looking into getting an abortion, but anti-abortion activists who buy up the data of anyone who appears to be trying to get one, or looking for support after getting one, will still see you listed and you will still get harassed by them or dragged into a texas court room. You might not be rich, but data brokers and consumer reputation services will see that you've been interested in expensive vacation spots and online stores will start charging you more than your neighbors for the same items on the assumption that you are. If you want to try to hide in the crowd look into a VPN or TOR (although be aware device/browser fingerprinting can still get your traffic associated with you). Just please understand that giving others more ammo to use against you isn't helping yourself or anyone else. Adding more and more data to your internet history just increases your risks substantially because no matter if you deserve it or not your life will be impacted in countless ways by the data you surrender and none of that data, "pollution" or genuine, ever goes away.
- princevegeta89 4y agoBesides the unremovable junk they fill on the homepage, now this. Uninstalled and will be moving to Brave
- mc32 4y agoAlso Epic.
- w0m 4y agoI'm all for pushing for more privacy/etc; but is Brave what we want to advocate for as an alternative? They did some pretty heinous link jacking relatively recently. I'm not sure FF/(/chromium) have been caught doing anything worse than that yet.
- drews64 4y agoFirefox with uBlock Origin and HTTPS only works beautifully with Pocket disabled. Only thing I have to pull out Chrome for is corporate intranet.
- Datagenerator 4y agoOr the privacy focused Librewolf (fork of Firefox)
- darig 4y ago
- smoldesu 4y agoUsing a browser that monetizes itself in any way seems like a slippery slope to me. I'd rather use Ungoogled Chromium/Bromite or even LibreWolf if it came down to it. Saying "that's it, I'm moving to Brave!" is basically declaring that you're moving your data from Microsoft(1) to Microsoft(2).
- ramesh31 4y ago> Using a browser that monetizes itself in any way seems like a slippery slope to me. I'd rather use Ungoogled Chromium/Bromite or even LibreWolf if it came down to it. The problem with this approach is that it’s impossible to get a safe binary that isn’t downloaded from “libfree.cxcc.gg” or whatever. The other option being to build from source, which is an absolute nightmare for Chromium.
- dheera 4y agoIt's because they are shareholder-driven, not customer-driven. Clueless shareholders on the 59th floor of JP Morgan who don't even use Edge see "oooh VPN, me like buzzwords" and upvote the stock.