3 ms·
You can get access with customer permission for a limited time window which is audited. In the normal course of business no.
by sabarn01 3y ago
You can get access with customer permission for a limited time window which is audited. In the normal course of business no.
- graypegg 3y agoThe reality here is that no one will trust a pinky promise. Especially not from Microsoft. You’re fighting a good fight but it’s a losing battle no matter how locked down it feels from your POV. “Can we have access to X, but don’t worry, we don’t let anyone look at X unless Y happens” is a bit suspicious when “grant X permission when Y happens” isn’t an option. Even worse when the access to X is only disclosed to users living in a jurisdiction requiring it. Microsoft’s many brand and marketing folks have a big uphill battle if they want to convince me otherwise. Or they can just stop collecting data.
- sabarn01 3y agoLike telemetry? We have to collect customer data that's what we get paid for. As for pinky promises we are SOC compliant and externlly audited. https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2 https://learn.microsoft.com/en-us/compliance/regulatory/offe...
- JohnFen 3y ago> We have to collect customer data that's what we get paid for. Which is one of the many reasons why I will not allow Microsoft products on my machines.
- sabarn01 3y agoIf you write a document and store it in sharepoint online we have to keep that data as does any online offering.
- JohnFen 3y agoIs that what you were referring to? The phrase "we have to collect customer data" implies a different thing entirely, so I misunderstood. My objection to Microsoft's methods in this regard isn't the data that customers voluntarily and knowingly store on Microsoft servers, it's the collection of data about customers, their machines, and the use of their machines that happens behind the scenes.
- sabarn01 3y agoWe collect telemetry about user actions and the successes of our service. All the data we collect is about how the service runs and we only look at it via aggregation. Internally we have training every year about what you can and can't collect and under which scenarios. It gets stricter every year.
- graypegg 3y agoI would imagine it gets stricter every year due to this generally common opinion of Microsoft among these circles. Wish you all the best though, a Microsoft people trust would do good for the world.
- mysterydip 3y agoWhat are you using instead? Open source offerings generally work for me, it's when I have to share the results with others that formatting etc problems appear.
- graypegg 3y agoWelcome to my local bakery! We have to collect your credit card number before you enter. No one can access your credit card number though. I write it on a piece of paper and put it in a safe. Here, look at this list of people that have seen me put credit card numbers into a safe! I’m sure you understand, we need to collect your credit card number because that’s how we make money at this bakery. No I will not explicitly explain how. Don’t you feel like I’ve improved your experience?
- sabarn01 3y agoThe document I linked explains how why and when. It also explains how we verify that and who does the verification. Also O365 customers have access to audit logs and the rest. At some level everything is about trust there is no way you can verify any large organizations activities.
- graypegg 3y agoThat’s a big document with lots of acronyms and references to specific standards for compliance that law professionals might be familiar with, but is otherwise completely meaningless. You also mentioned that collecting user data is how Microsoft is paid in the GP comment. That’s pretty clear to me. I thought when I paid Microsoft, that was the main revenue stream. The document provided in theory communicates what you said so succinctly before, but with more legal and confusing language. If it says the opposite, then just asking me to assume that this document that’s extremely difficult to read explains why outlook should ingest information I wasn’t told about, since I live in a jurisdiction where Microsoft doesn’t need to, and why that’s actually a neutral or possibly “good” thing for me, is a bit silly. — Edit: if I’m misunderstanding what you said earlier by: > We have to collect customer data that's what we get paid for. Then I’m sorry. I don’t mean to frame you as saying something you don’t mean to.
- sabarn01 3y agoI should have been more specific. We have lots a data classifications we maintain and we have different rules for different classifications. Customer content we can't access without customer consent. We are paid to store customer content. Customer content is like your work doc stored in one drive. Some classification are only accessed in aggregate. Some are easier to access but cleared after a short period ect. We all have to go though a large training every year about the different classifications and that's not easy to communicate in a short comment. We store data everywhere to meet european GDPR standards regardless of where you live. We have logs but they can only contain sanitized information. Any document which attempts to describe how a large origination handles data is going to large and complex. As sometimes different standards conflict. For example we have to keep records of anyone who changes the system for some period of but we also have to delete data that has end user identifiers. When stuff like that happens we have to go to lawyers and have language that describes how we handle thoes conflicts. That doesn't lead to a small doc.
- autoexec 3y agoAre these external audits just SOC checklists where they're basically just looking at policies and processes for employees or are teams of auditors routinely coming into each office and data center to physically examine servers and trace network cables while taking an independent inventory of all the hardware that sensitive data touches and the software running on that hardware? SOC compliance and external audits can help keep things reasonably secure and prevent the totally careless/incompetent handling of data, but I'm skeptical that they would typically be robust enough to detect Microsoft's own equivalent of Room 641A let alone the actual hardware installed by the feds which MS itself isn't allowed to touch.
- sabarn01 3y agoI don't know if I can say what we have to turn over to the auditors that isn't in the public document. As to verifying the hardware we buy our hardware from other companies who have their own controls. If you dig far enough down everything ultimately comes to trust as no one can verify everything.
- nyc_data_geek1 3y agoAll the more reason to only ever trust a corporation to do what is in the interest of their bottom line, including lie to your face, collect and sell your data, and violate the law whenever the financial disincentive is less than the profit potential.
- jjulius 3y ago>The reality here is that no one will trust a pinky promise. Especially not from Microsoft. I'll just chime in to say that, while I appreciate the sentiment the user is conveying, I certainly don't trust a Microsoft pinky promise.
- WarOnPrivacy 3y ago> You can get access with customer permission for a limited time window which is audited. In the normal course of business no. Right but no one is saying your department is violating our privacy. I'm not sure why you feel a need to defend it. I think we can safely say that MS's methods of violating our privacy are all automated and that you + coworkers aren't eyeballing our personal data. So we can move on from that. If you'd like to speak to the privacy violations that are referenced in the article, we're all ears. Education guesses about methods or who some of the 3rd parties are would be terrific.