Thursday, August 23, 2018

Russian Hacking Is Very Real-- Who's In Charge Of Directing The U.S. Targeting? Kushner?

>

Rohrabacher-- a poor fool doomed by his own inept allies?

The Republican gubernatorial candidate in Pennsylvania, Scott Wagner, joked that the Russian government will help him beat Tom Wolf in November. Polling indicates that that's basically the only way he would win. It's not actually that funny-- especially when Putin-Gate has spawned Putin-Gate II and that the GRU is now targeting conservatives as well as normal candidates. Microsoft claims to have uncovered broadening threats to Democracy. Microsoft president Brad Smith: "It’s clear that democracies around the world are under attack. Foreign entities are launching cyber strikes to disrupt elections and sow discord. Unfortunately, the internet has become an avenue for some governments to steal and leak information, spread disinformation, and probe and potentially attempt to tamper with voting systems. We saw this during the United States general election in 2016, last May during the French presidential election, and now in a broadening way as Americans are preparing for the November midterm elections."

Microsoft's Digital Crimes Unit, he wrote, is on the case. They're making headway against Fancy Bear (aka- APT28 and Strontium). "We’re concerned," he wrote, "that these and other attempts pose security threats to a broadening array of groups connected with both American political parties in the run-up to the 2018 elections." So what's this all mean?
A group affiliated with the Russian government created phony versions of six websites, including some related to the US Senate, with an aim to hack into the computers of people who were tricked into visiting, according to Microsoft.

...The effort by the notorious APT28 hacking group, which has been publicly linked to a Russian intelligence agency and actively interfered in the American 2016 presidential election, underscores the aggressive role Russian operatives are playing ahead of the midterm congressional elections in the US.

APT28 specialises in information warfare or hacking and disinformation operations. "APT" refers to "advanced persistent threat" in cybersecurity circles.

US officials have repeatedly warned that the November vote is a major focus for interference efforts.
Trump and his GOP enablers are purposely leaving the back door open for the Russians, refusing to fund statewide efforts to protect American voting systems and firing top level specialists in cyber-security. A question I've always had-- and will ultimately be answered (or not) by the Mueller investigation-- is who in Trump-world has been helping the Russians with their targeting? I had to laugh when the first reports came out that hackers-- presumably Russians-- interfered in two Orange County Democratic primaries, one to pick a candidate to run in CA-45 against lockstep rubber-stamp Mimi Walters and one to pick a candidate to run against Putin's favorite congressman (and possible Kremlin spy) Dana Rohrabacher in CA-48. Both operations were badly botched.

They were botched because of the targeting. Whomever told the Russians to go after Hans Keirstead in CA-48 and Dave Min in CA-45 were not doing anything to help their Republican opponents. Both Keirstead and Min looked good-- at least inside the Beltway-- on paper. But both turned out-- in real life outside the Beltway-- to be abysmal candidates. Keirstead has a great resume and the DCCC recruited him, but he was a total stiff on the campaign trail and the DCCC abandoned him and leaked opposition research about a sex scandal. Early on, someone clueless inside the Beltway could have easily imagined he would be the strongest candidate against Rohrabacher. As a consequence, they may have blundered into harming Rohrabacher's chances by boosting the much stronger candidate, Harley Rouder, who neat Keirstead narrowly and is likely to beat Rohrabacher in November.

A similar thing happened in CA-45, where a Schumer puppet, Dave Min, may have been perceived in DC (and thereby Moscow) as the stronger Democrat against Walters. But as the campaign unfolded, he turned out to be a miserable politician, way too nasty and vicious to win anything. If the Russian hackers were trying to help Walters, they doomed her by knocking out Min. Instead, Katie Porter, who won the primary, is likely to end Walters' political career in November. Sounds like Kushner-in-law's work. His fingerprints are all over these two collusion operations.


UPDATE: Will Putin Save The GOP From The Voters?

Trump seems to think so. Writing for Yahoo News today, Alexander Nazaryan reported that Trump asked the Senate to block a bill to strengthen the country's defenses against electoral interference. Trump got Roy Blunt (R-MO) to stop the bill in committee yesterday. To me this is way more impeachable than paying off hookers with campaign cash.
The Secure Elections Act, introduced by Sen. James Lankford (R-OK) in December 2017, had co-sponsorship from two of the Senate’s most prominent liberals, Kamala Harris (D-CA) and Amy Klobuchar (D-MN) as well as from conservative stalwart Lindsey Graham (R-S) and consummate centrist Susan Collins (R-ME).

...As it currently stands, the legislation would grant every state’s top election official security clearance to receive threat information. It would also formalize the practice of information-sharing between the federal government-- in particular, the Department of Homeland Security-- and states regarding threats to electoral infrastructure. A technical advisory board would establish best practices related to election cybersecurity. Perhaps most significantly, the law would mandate that every state conduct a statistically significant audit following a federal election. It would also incentivize the purchase of voting machines that leave a paper record of votes cast, as opposed to some all-electronic models that do not. This would signify a marked shift away from all-electronic voting, which was encouraged with the passage of the Help Americans Vote Act in 2002.

“Paper is not antiquated,” Lankford says. “It’s reliable.”
A paper trail is exactly what Putin and Trump-- and apparently, the Republican Party-- don't want. This is treason.

Labels: , , , , , , , , , , ,

Tuesday, September 08, 2015

Is Microsoft Integrating Windows 10–Style "Spyware" Into Windows 7 & 8?

>

Edward Snowden's infamous PRISM slide, showing Microsoft's collusion with the NSA starting in 2007.

by Gaius Publius

I mean that headline as a real question. Is Microsoft actually integrating Windows 10–style "spyware" into Windows 7 & 8? We've been looking (here and here) at the issue of whether Windows 10, the new Microsoft operating system ("OS" in tech-speak) is designed as spyware. I've personally concluded that it is, based on a number of reports, such as those detailed at the links above, and based on the giant holes written into their Privacy and License agreements.

After all, it looks like Microsoft is giving themselves the right to inspect your machine, all of its files, all of its peripheral hardware, watch both what you do and how you do it, and share any of what it finds about you and your data with "partners," whatever that means. Also, as quoted in the second of the articles linked above (my emphasis):
Section 7b – or “Updates to the Services or Software, and Changes to These Terms” – of Microsoft’s Services EULA stipulates that it “may automatically check your version of the software and download software update or configuration changes, including those that prevent you from accessing the Services, playing counterfeit games, or using unauthorised hardware peripheral devices.”
Does this mean it can install updates to itself to disable "unauthorized" hardware and software? In my opinion, the fact that it seems that way is concerning enough. How this gets interpreted and implemented by Microsoft, is ... well, all up to Microsoft.

The counter-argument to the Yes answer is that the Privacy agreement language is vague enough to be interpreted narrowly, and therefore less intrusively. The counter-counter-argument is, Why is the language so vague if they don't intend to take advantage of it?

As a result, I'm on the side of "I don't trust them because I don't know that I can." After all, there's that Edward Snowden PRISM slide (above), just in case you need a reminder of which side of the bread Microsoft's butter is on. (Hint: Their own. But feel free to click the links at the top and decide for yourself.)

Are Windows 7 and 8 Being "Updated" to Include Privacy Intrusion Capabilities?

As I said, this is a question that needs answering. There are just way too many reports like this one (emphasis theirs):
New Windows 7 / 8 / 8.1 updates spy on you just like Windows 10

Microsoft is pushing KB3075249 and KB3080149 updates for Windows 7 / 8 / 8.1 users which can spy on you

Windows 10 has been launched and already installed by more than 50 million users worldwide. It is now a known fact that Windows 10 user data is being reported back to Microsoft servers back in Redmond. The jury is still out whether this a good or bad practice but many of Windows 10 Apps like Cortana depend on getting your preferences correct to serve you better.

This being the case, many Windows users who are not happy with Windows 10 spying ways and have preferred to stay on with Windows 7/Windows 8 and Window 8.1 as the case might be. For these Windows 7/8/8.1 users there are a few updates which Microsoft has been pushing through last few days.

Namely, KB3075249 and KB3080149, if installed are known to report your data back to Microsoft servers.

KB3075249 update adds telemetry points to consent.exe in Windows 8.1 and Windows 7. The Microsoft support page gives following description for them :

KB3075249 “Update that adds telemetry points to consent.exe in Windows 8.1 and Windows 7 ” http://support.microsoft.com/kb/3075249

KB3080149 “This update aligns down-level devices on the same UTC binary that’s released in Windows 10. This update would enable all the down-level devices to receive the software updates, design updates, and additional power and performance tuning.” http://support.microsoft.com/kb/3080149

In simple words, both these updates, if downloaded and installed will snoop on you and report back certain data to the Microsoft servers. ...
Here's another, similar report:
The updates in question are KB3075249 and KB3080149. if installed, these updates are known to report your data back to Microsoft servers, without user interaction. KB3075249 Microsoft Update adds telemetry points to ‘consent.exe’ in Windows 7, 8 and 8.1, allowing for remote monitoring of everything that happens within the operating system. KB3080149 ensures that all “down-level devices” receive the same updates and treatment as Windows 10 boxes get.
Several words of caution:

    ▪ So far, these reports come from tech user forums, and are elevated from there to small tech-savvy (and very privacy-concerned) "geek" sites like the above. This does not guarantee their accuracy, nor their inaccuracy.

    ▪ But the number of reports is concerning. A simple web search on "KB3075249 KB3080149 spyware" produces quite a number of hits.

    ▪ Are these all echoes of a single source? It's possible. At this point, the users most concerned are the ones with most to fear — gamers with perhaps pirated software (and hacked hardware?); torrent users and sites; and, frankly, right-wing fear merchants and audiences, who are sometimes too eager to be afraid. One scary report may go through these communities like fire.

But the information in the reports above is pretty specific, and should therefore be subject to independent (i.e., not Microsoft-friendly) analysis. Does update KB3075249 add “telemetry points to consent.exe in Windows 8.1 and Windows 7"? If so, does it allow "remote monitoring of everything that happens within the operating system"? One would think those are answerable questions.

Even "Reasonable" Tech Sites Are Concerned

For an example of "reasonable" (non-fearful) tech analysis of Windows 10, consider this from ArsTechnica, which offers an even-handed exploration of Windows 10's "phone home" behavior:
Windows 10 uses the Internet a lot to support many of its features. The operating system also sports numerous knobs to twiddle that are supposed to disable most of these features and the potentially privacy-compromising connections that go with them.

Unfortunately for privacy advocates, these controls don't appear to be sufficient to completely prevent the operating system from going online and communicating with Microsoft's servers.

For example, even with Cortana and searching the Web from the Start menu disabled, opening Start and typing will send a request to www.bing.com to request a file called threshold.appcache which appears to contain some Cortana information, even though Cortana is disabled. The request for this file appears to contain a random machine ID that persists across reboots.

Some of the traffic is obviously harmless. [...]

Some of the traffic looks harmless but feels like it shouldn't be happening. [...]

Other traffic looks a little more troublesome. [...] 
Details of the deleted portions can be read at the link. The piece closes the list with this (my emphasis):
And finally, some traffic seems quite impenetrable. We configured our test virtual machine to use an HTTP and HTTPS proxy (both as a user-level proxy and a system-wide proxy) so that we could more easily monitor its traffic, but Windows 10 seems to make requests to a content delivery network that bypass the proxy.
The rest of the piece details attempts to get explanations from Microsoft. It ends this way (my emphasis):
We've argued recently that operating systems will continue to make privacy-functionality trade-offs. For many users, perhaps even the majority, these trade-offs will be worthwhile; services such as Cortana (Siri, Google Now), cloud syncing of files, passwords, and settings, and many other modern operating system features are all valuable, and many will feel that the loss of privacy is an acceptable price to pay. But the flip side of this is that disabling these services for those who don't want to use them should really disable them. And it's not at all clear that Windows 10 is doing that right now.
Again, perfectly reasonable. Would ArsTechnica or a similar site examine the Windows 7 and 8 updates listed above? I think too close an exploration of Microsoft might run counter to the financial interests of, frankly, an industry powerhouse, an 800-pound gorilla with a lot of money at stake in its just-released Windows 10. As a result, it may take awhile before this examination takes place. Stay tuned though, just in case it does.

This Brave New Tech-Friendly World

We've already entered the brave new world of what ArsTechnica calls "privacy-functionality trade-offs." Unlike voluntary use of "the cloud," Windows 10 (and 7 and 8?) now make these trade-offs at the level of the operating system, and not voluntarily, unless you volunteer not to use it at all.

How should we respond to that? What seems to be needed is:

(1) Solid exploration of the anti-privacy capabilities, not just of Windows 10, but Windows 7 and 8, as well as the next versions of Apple's iOS and Google's Android OS, as they follow close behind the Microsoft example;  

(2) Solid legal analysis of the new Microsoft Privacy statement and End User License Agreement (EULA);  

(3) A broader philosophical discussion of what commercial use this data can be put to, and the ethics of that use;  

(4) A broader discussion of the political capabilities and use of this data, since multi-billion-dollar tech companies have political objectives, not just commercial ones; and finally

(5) An examination of the role of the Pentagon's NSA in all this; by which I mean, to what degree does the NSA encourage, allow, and/or benefit from this level of high-volume user-profiling and data collection?

Until these examinations occur, we will have questions without answers — and frankly, given that we're talking about the data-hungry and money-mad tech industry, we'd be naïve not keep those questions front and center until they're answered successfully.

Side note: I'm starting to explore a switch to a Linux OS, likely Linux Mint. Linux is mature, easy to use, open source, and I'm told, can do almost everything users need done, with programs users already know, such as Firefox. More on this as it transpires; I may make these explorations public and let readers "look over my shoulder."

GP

Labels: , , , ,

Wednesday, September 02, 2015

Point–Counterpoint on Windows 10

>

Police officers monitor CCTV screens in the control room at New Scotland Yard in London. Photograph: Kirsty Wigglesworth/AFP/Getty Kirsty Wigglesworth/AFP (source)

by Gaius Publius

I got a very small amount of very energetic pushback from one corner of the consumer tech industry — the part that popularizes and teaches the use of consumer technology — regarding this article about whether Windows 10 is spyware. (My opinion is still that it is, but that's a function of your definition of "spyware." I'll offer my definition in a later piece, since I don't want to kitchen-sink this one.)

I have to say, I found the pushback interesting for a number of reason. One, that while it was genuinely worth considering, it was angry; not just reasoned, angry. And the anger was not just directed at me, as you'll see below, but directed at anyone who doesn't like the intrusiveness of this new operating system (sorry, "service"). Second, I found it interesting that the pushback seemed almost completely unaware of, and therefore dismissive of, the political dimension of all forced (or highly incentivized) data sharing.

Let me explain what I mean by "political dimension."

Do Cops Lie Under Oath? Your Answer Defines You

For example, would you put any of your data on "the cloud"? If you would, you don't see a problem with corporate access to everything stored there. If you wouldn't, well ... you're suspicious, to say the least, of corporate good intentions. In the tech world, that's a pretty big divide. Of those who aren't suspicious, some understand why people might be, and others, the angry ones, are highly upset that the critics are "dumb enough" (my phrase) to fall for "tinfoil" arguments (their phrase).

Because companies would never misuse your data, right? They may "blunder" (get hacked, say), but they're not ill-intentioned. After all, this is America, not some Third World dictatorship. And those who take, well, America, at face value, even though admitting some flaws, are a world away, a divide away, from those who just don't see the world as the one presented on TV. That's a quite a divide, and it leads to one side using dismissive phrases like "conspiracy theories" and the other side using terms like, well, "politically naïve."

Now let's look at issue in a more general context. In the same way, there's a huge divide between those who think cops almost never lie under oath when giving testimony — their world is the world of Law & Order, for example — and those who suspect (or think they know) that cops almost always lie under oath to secure convictions they can't secure any other way.

Let's run a test. Ask yourself these two questions before you read on:
  1. Do you think cops routinely lie under oath?
     
  2. If your answer is No, what do you think of those whose answer is Yes?
Done? Now consider, with your two answers in mind, the following, via the New York Times:
Why Police Lie Under Oath

... That may sound harsh, but numerous law enforcement officials have put the matter more bluntly. Peter Keane, a former San Francisco Police commissioner, wrote an article in The San Francisco Chronicle decrying a police culture that treats lying as the norm: “Police officer perjury in court to justify illegal dope searches is commonplace. One of the dirty little not-so-secret secrets of the criminal justice system is undercover narcotics officers intentionally lying under oath. It is a perversion of the American justice system that strikes directly at the rule of law. Yet it is the routine way of doing business in courtrooms everywhere in America.”...
A web search produces a lot more like the above. Is this thinking "tinfoil"? Not if former Police Commissioner Peter Keane, quoted above, is right. Yet many today would call this thinking "decidedly un-American" (another term that needs more careful definition). That's part of what I mean about the political dimension — not all, but part. Trust in our governance and governing institutions, in their right to be presumed well-intentioned, is a political position. As is dismissing distrust in others.

Keep all this in mind, both the technical aspects of the Windows 10 argument and the anger, as you read on.

The Pro-Windows Pushback

I want to start with the pro-Windows 10 pushback by offering one example below from a ZDNet writer, just to give you a taste of the way the discussion is going. No, I'm not singling out one writer, just offering an instance of several I could have chosen. And no, I'm not saying the writer is wrong because of the tone. I am saying, though, that the facts do need examining, and that examination is not a breech of good sense. The fact that quite a number of people are examining this issue seems to be a good reason for having it.

As the ZDNet writer quoted more fully below admits:
There is apparently a growing and very vocal population of people who believe that Windows 10 is basically a 1984 telescreen come to life.
"1984" is a reference to the "Big Brother is watching you" book and film. There is indeed a "growing and very vocal population" that's suspicious of Windows 10. Some think that using Windows 10, Microsoft is watching them. And some worry that Microsoft has set up Windows 10 so that they could be watching them if the company wanted to. The first assertion needs proving, but the second is almost a given, as we'll see. Is it "tinfoil" thinking to notice that?

Now a more complete quote from the piece referenced above. It starts:
No, Microsoft is not spying on you with Windows 10

The Windows 10 privacy agreement doesn't mean Microsoft is secretly stealing the data from your hard disk. Where do people come up with these crazy ideas?

Buy tinfoil futures.

I'm dead serious. There is apparently a growing and very vocal population of people who believe that Windows 10 is basically a 1984 telescreen come to life. They are convinced that with Windows 10 Microsoft has built a spying apparatus not seen since the height of the Cold War, scraping up every detail of your life and feeding it back to Redmond for who knows what nefarious purposes.

They're going to need lots of tinfoil.

They're also either wildly misinformed or deliberately agitating. Unless, of course, they're just crazy, which is entirely possible based on some of what I've read.

But most importantly, they are wrong, terribly wrong. And they're being whipped into a frenzy, or at least passively aided by the tech press. That group unfortunately includes ZDNet, which earlier this week unquestioningly repeated this incendiary allegation, posted on Reddit by someone who claims to be affiliated with an obscure torrent tracker, iTS:

Microsoft decided to revoke any kind of data protection and submit whatever they can gather to not only themselves but also others. One of those is one of the largest anti-piracy company [sic] called MarkMonitor. Amongst other things Windows 10 sends the contents of your local disks directly to one of their servers.

That's not true. It's wildly at odds with the facts, even. I keep tabs on a handful of well-established torrent sites, orders of magnitude larger than the ones complaining here, and none of them seem to have a problem with Windows 10.

There's literally no basis for that statement in fact. And yet you read it here. And on dozens of other sites, unfortunately, where a single lie gets repeated often enough to seep into the collective unconscious.

The bizarre belief that Windows 10 is a spying tool keeps popping up among conspiracy theorists. Via email, a reader sent me a link to this rant by an alternative medical practitioner who apparently is also an expert on the law and IT:

Windows 10's new license agreement ... gives Microsoft permission to Hoover up every particle of data on a doctor's hard drive. This will include any confidential patient-doctor emails that are stored there, any reports, any bills, and any short notes to staff through intra-network messaging (for example: "Spoke to Tom Mypatient today re gender dysphoria and desire to transition to female. Pls follow up with referral.")

No, it doesn't, doc. Here, take a sip of this calming tea and let's talk, OK? And let's get that torrent dude in here, too, because he needs someone to explain what's really going on. ...
I'm going to look at just two of the points made above and leave the rest for later. Do read the whole piece, though; I'm not saying it has no value, but the value is in evaluating its arguments on a factual basis, not in getting caught up in the ... well, politics of what's an OK question to ask, and how to evaluate anecdotal evidence that something is fishy with Microsoft's new operating "service."

Is Windows 10 Spyware? What Does the Privacy Policy Allow?

Because I don't want to turn this into an essay, let's look at just these aspects of the new Windows 10 operating system ("service") — concerns about the privacy policy, and concerns about interference with pirated and "unauthorized" software and hardware. (Yes, Windows 10 cares about "unauthorized hardware.")

First, about that new privacy policy, from another, more suspicious, technology writer. The piece is called "Windows 10: Here are the privacy issues you should know about." One of the issues discussed is this:
Microsoft can disclose your data when it feels like it

This is the part you should be most concerned about: Microsoft’s new privacy policy assigns is very loose when it comes to when it will or won’t access and disclose your personal data:

We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good faith belief that doing so is necessary to protect our customers or enforce the terms governing the use of the services.

I’m not suggesting Microsoft and its lawyers are alone in making provision for such sweeping power over your data, but we should all be very careful about relying on the “good faith” of corporations. I’m not even sure such a thing exists.
Again, note that the limits don't turn on absolute restrictions, but on belief in Microsoft's corporate "good faith." That belief is ultimately a political act. The ZDNet writer above appears to have that belief; the medical doctor he responds to in his piece — by saying, "No, it doesn't, doc. Here, take a sip of this calming tea and let's talk, OK?" — doesn't.

The privacy language allowing Microsoft to "access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders)" is pretty clear to me, and pretty scary. And I've already had a "calming tea."

Do Torrent Sites Have a Problem with Windows 10 and Its User Agreement?

Now let's look at concerns about Windows 10's search for and treatment of pirated software and "unauthorized hardware." Torrent sites are part of file-sharing peer-to-peer ad hoc networks that facilitate downloads of programs and data files, including legal and illegally obtained copies of software, games, music and movies. The ZDNet writer, who thinks people should not question Windows 10 in the way they do, wrote this (also quoted above) about whether torrent sites are worried about users running Windows 10:
That's not true. It's wildly at odds with the facts, even. I keep tabs on a handful of well-established torrent sites, orders of magnitude larger than the ones complaining here, and none of them seem to have a problem with Windows 10.
Why would torrent sites even consider worrying about Windows 10? Because they worry that the operating system (operating "service") could inspect users' hard disks, check to see if downloaded software and other files are "legal," and if not, delete or disable the files or programs; then report back to Microsoft anything it can find about how those files or programs were obtained.
In other words, to use the vernacular they worry that Windows 10 will spy on users, delete files it considers illegally obtained, then rat out the users to Microsoft and rat out torrent sites that distributed the files to the government and copyright holders. Our anti-tinfoil writer thinks this is a foolish worry. Do you think Microsoft is capable of this behavior? Isn't that like asking if you think most cops lie?

So what's actually happening with torrent sites and Windows 10? First, there are stories of software already being deleted and/or disabled, but they are anecdotal at this point. The reports are from small venues and haven't been verified. Second, a web search on whether torrent sites are concerned about the possibility produces a lot of articles like the following:
Windows 10 users are being banned from torrent sites

Some torrent websites are banning Windows 10 users over fears that the operating system is sending identifying information back to Microsoft.

Piracy sites are preventing users of Windows 10 from using their trackers. These are the servers that allow all of the computers downloading files using torrents to talk to one another, which allows them to find and request the files that they need. Without trackers, torrents won’t work.

Pirates have released statements that say, “Windows 10 sends the contents of your local disks directly to one of their servers.” They also claim that Microsoft is working with a company called MarkMonitor to identify people who are downloading from the internet.

There are genuine concerns that Windows 10 sends personal information about computers to Microsoft, even if users have changed all their settings to tell it not to do so. But there is less concrete evidence to support the pirates’ most worrying claims.

The controversy began because of a line in Microsoft’s service agreement. This allows Microsoft to issue updates that will stop users “playing counterfeit games,” according to TorrentFreak.
Notice that "MarkMonitor" is mentioned in the original writer's piece above, who also quotes his own publication as making this claim. The writer says his own investigations say otherwise.

Are torrents and torrent trackers really banning Windows 10 users? We're in he-said, she-said territory. Should they ban Windows 10 users just in case? That turns on what Microsoft decides to make of the language in its new User Agreement. One tech site characterizes that language this way:
Microsoft can disable your pirated games and illegal hardware

Updated terms let Microsoft invade your Windows 10 computer in search of counterfeit software

Microsoft’s updated End User Licence Agreement [EULA] terms and conditions let it disable any counterfeit software or hardware and, if you’re running a Windows 10 computer, you’ve just agreed to them.

Section 7b – or “Updates to the Services or Software, and Changes to These Terms” – of Microsoft’s Services EULA stipulates that it “may automatically check your version of the software and download software update or configuration changes, including those that prevent you from accessing the Services, playing counterfeit games, or using unauthorised hardware peripheral devices.”

The list of services covered by the agreement doesn't explicitly include Windows 10. However, it does include your Microsoft account, which is an extensive part of the Windows 10 experience, as well as core features like Cortana – and that implies Redmond can disable any games you’ve pirated or devices you’ve "unlawfully" hacked. Enable Cortana (which pretty much everyone using Windows 10 is going to do) and you're subject to the services agreement.

While it’s incredibly clear what Microsoft means by “counterfeit games”, the wording “unauthorised hardware peripheral devices” is a little hazy. Does this mean Microsoft can now block uncertified PC or illegally modified Xbox One and Xbox 360 controllers? Furthermore, Microsoft’s agreement doesn’t state whether it will also disable other counterfeit software, such as cracked versions of Office or Adobe Photoshop, or if it only cares about pirated Microsoft games.

I’ve reached out to Microsoft for a comment about these unanswered questions and will update you when more information becomes available. (UPDATE: More than five days after we initially published this story and we still haven't heard anything back. If anyone from Microsoft reads this, please get in touch!)
More at the link. Is there a problem now with pirated software and "unauthorised hardware peripheral devices" (whatever that means)? Some say yes, some say no. Could there be a problem in the future? Looks like it to me, depending on which of its "rights" Microsoft decides to exercise. Do you trust Microsoft? Should you?

Why Does This Matter? The PC Counterrevolution

Why go through all this? Because Microsoft is one of the largest tech companies on the planet, its operating systems are literally everywhere, and Windows 10 is a revolution in operating systems. It phones home with data no one can figure out, and has Privacy and License agreements that grant rights to the company that are both extremely broad and unprecedented.

But most of all, Windows 10 is not a program per se — not an operating "system," but a "service." The implications of that are huge. In the days of IBM mainframes and VAX terminals, what you had on your desk at work was one tentacle of an octopus owned and run by your company. You used what you were allowed to use. You were watched if they wanted to watch you. Your data was never just yours.

Then came the "PC revolution" — the revolution of the personal computer, a machine that was yours completely. You owned it, you owned the software on it, you managed it, and no one saw what you did with it but you, if that's the way you wanted things to be.

We've been eroding the "personal" (meaning, private) aspect of personal computing for a while, ever since the widespread use of the Internet, but that erosion has accelerated. Certainly, using "the cloud" means you voluntarily surrender the privacy of any data you put there. But by voluntarily upgrading to Windows 10, the rest of your surrender — the surrender detailed in my original article— may never be voluntary again.

In the Tarot, The Fool is a "path to wisdom" card.

If that was the PC revolution, this is a counterrevolution. Welcome back to the corporate-controlled computer, disguised as something you own. What will those corporations — Google and Apple are sure to follow suit — do with all that intrusive power and control? I don't think you need a tinfoil hat to worry about this, and on that I respectfully disagree with those who do.

If we're going to hand out the "who's being foolish?" card, perhaps it should go to those who choose to ignore the implications of this counterrevolution — not to those trying to think it through, as politically out of the mainstream as those thoughts may become.

GP

Labels: , , ,

Thursday, August 27, 2015

Windows 10: Spyware Disguised as an Operating System

>


by Gaius Publius

If you're like me and work on a Windows-based system, you get these popups from time to time offering to "upgrade" you to Windows 10, Microsoft's latest and greatest, for free. Normally these upgrades cost $100 or so.

Me, I'm still on Windows 7, since like many I consider Windows 8 both half-baked for professional use and a data-suck for entertainment use. About the first, it was clear when Windows 8 first came out that you couldn't do serious work using that "tiles" screen, and the "Desktop" screen was so like Windows 7, why not just stick with Windows 7, which, after the Vista disaster, actually worked?

About the second, it was also clear that almost everything the casual user wanted to do from that "tiles" screen required (or strongly encouraged the use of) a "Microsoft account" — clearly an attempt to jump-start a massive Microsoft database to compete with Steve Jobs' "Apple account" database.

Most large businesses I work with have avoided Windows 8, and most new systems, like the one I'm using now, can even today be bought with Windows 7. In short, Windows 8, like Vista, was a failure. Windows 7 "fixed" Vista. Would Windows 10 "fix" Windows 8?

I decided to find out. And it didn't take long to discover that Windows 10 is not only worse than Windows 8, it is worse in a worse way. It's one thing to install an application that spies on you. It's another when that spyware application you just installed is the operating system, and controls the whole machine.

Is Windows 10 Worth Installing?

The answer is No, if you're asking me. In fact, it's worth never installing. I'd avoid it until the final minute you're forced to change, and even then, you should hesitate to upgrade. Reason? Under its default settings, Windows 10 is widely reported to be spyware, an operating system that watches you work, even offline, and reports back to Microsoft anything it feels like reporting. If you approve the licensing agreement — and how can you use any software without clicking "I Agree"? — you're giving Microsoft permission to collect any data they can get (based on your settings) and share it in any way they want.

Windows 10 is the ultimate privacy violator — an operating system that wants to watch everything you do and send back whatever it finds or figures out about you.

Windows 10: A Microsoft Spy That Runs Your Computer

I have no direct evidence of this, since I've not seen the OS, nor will I ever attempt to install or use it. But the reports are many. Here's one, posted to LinkedIn (a LinkedIn account may be required; my emphasis except where noted):
Windows 10 – Microsoft’s Big Data-grabbing (or spying?) OS

It’s been a couple of weeks since the launch of Windows 10 and the numerous voices raising concerns over privacy and how it uses personal data are not getting any quieter.

Many of the concerns stem from the fact that if users follow the software’s recommendations and stick to default settings while installing their free upgrade, they are effectively giving Microsoft permission to directly monitor pretty much everything they do on their machines. This includes offline activity such as editing files stored locally in private folders on your computer, as well as everything you do online.

It doesn’t stop there, though. As well as monitoring and storing records of this activity, people installing the upgrade are - perhaps unknowingly if like many they have become complacent about reading privacy policies – giving Microsoft permission to share it with unspecified “partners”, for unspecified reasons.

Although the terms and conditions are incredibly vague about why they are doing this, it’s become clear there are several reasons. These include collecting personal data for targeted advertising purposes (by Microsoft or their partners) as well as to gain a deeper understanding of how their products are being put to use by their millions of users.

Privacy in the cloud

Windows 10, running under its default settings, is clearly designed to learn as much about us as it can. The rapid spread of cloud-based software-as-a-service platforms, such as Microsoft’s own Office 365 and Adobe’s Creative Suite, has introduced us all to the idea of software providers gathering data on how we use their products. However integrating this kind of monitoring into the core of the OS (Operating System) takes things to a whole new level. We might have got used to the idea that our activity within the container of a certain program or service is being analysed somewhere, by someone, for some reason. But the fact that this level of scrutiny is now applied to everything we do on our computers is causing many commentators and online security experts to issue warnings.

Even the contents of your emails and documents stored in private, offline folders can be subject to scrutiny and “disclosure” (to unspecified parties), according to the wording of Microsoft’s privacy policies. Of course, it’s quickly become apparent that this is why Microsoft, which has traditionally charged users around $100 to upgrade to the latest version of their OS has, in an uncharacteristic act of generosity, given it away for free. $100 multiplied by the 14 million who updated in the first day alone is clearly a lot of revenue for them to pass up on. However, while the strategical soundness of some of Microsoft’s recent actions have been questioned, this was far from a stupid move on their part. And there’s no such thing as a free lunch. Of course Microsoft want payment for using their services, only this time they are happy to take it in personal data rather than cash.
There's more, including information about the Personal Advertising ID, a unique identifier that will follow you onto any MS system you use, including Xbox:
One new concept users are becoming aware of is the Personal Advertising ID. Every user on every installation of Windows 10 is assigned one of these, and if you use other Microsoft devices such as a phone, tablet or Xbox games console, your data will be scooped up from those too. By default, details on every web site you visit, your physical location, every command you type or speak to the computer and countless other data points are recorded and uploaded to Microsoft. From there, they will be shared with producers of apps you download and give permission to run on your system, as well as advertisers.
And yes, there's even more bad news than that.

Windows 10 Wants to Share Your Wi-Fi Connection with Your Contacts

Here's another intrusion. Windows 10 wants to give users near you access to your Wi-Fi connection. This comes from Krebs on Security (emphasis in original; some links removed so as not to encourage upgrading):
Windows 10 Shares Your Wi-Fi With Contacts

Starting today, Microsoft is offering most Windows 7 and Windows 8 users a free upgrade to the software giant’s latest operating system — Windows 10. But there’s a very important security caveat that users should know about before transitioning to the new OS: Unless you opt out, Windows 10 will by default prompt to you share access to WiFi networks to which you connect with any contacts you may have listed in Outlook and Skype — and, with an opt-in, your Facebook friends.

This brilliant new feature, which Microsoft has dubbed Wi-Fi Sense, doesn’t share your WiFi network password per se — it shares an encrypted version of that password. But it does allow anyone in your Skype or Outlook or Hotmail contacts lists to waltz onto your Wi-Fi network — should they ever wander within range of it or visit your home (or hop onto it secretly from hundreds of yards away with a good ‘ole cantenna!).

I first read about this over at The Register, which noted that Microsoft’s Wi-Fi Sense FAQ seeks to reassure would-be Windows 10 users that the Wi-Fi password will be sent encrypted and stored encrypted — on a Microsoft server. According to PCGamer, if you use Windows 10’s “Express” settings during installation, Wi-Fi Sense is enabled by default.

“For networks you choose to share access to, the password is sent over an encrypted connection and stored in an encrypted file on a Microsoft server, and then sent over a secure connection to your contacts’ phone if they use Wi-Fi Sense and they’re in range of the Wi-Fi network you shared,” the FAQ reads. ...
There's a yes-but noted further in the article — Yes, but you have to opt in on a network-by-network basis. However, as the original writer notes, "many users are conditioned to click 'yes' to these prompts, and shared networks will be shared to all Facebook, Outlook, and Skype contacts (users can’t pick individual contacts; the access is shared with all contacts on a social network)."

Here's my yes-but to Microsoft — Yes, but why in god's earth do you want this information in the first place?

The Functionality of "Cortana" Comes With a Privacy Price

"Cortana" is Microsoft's name for its Siri-like "digital assistant." The problem is, to "serve" you better, Cortana learns everything it can about you (my emphasis):
Cortana is a personal digital assistant, a kind of silicon secretary who can help make your life easier. Instead of searching for things you ask Cortana - so if you want to know what the weather forecast is, how many pounds are in a kilo, who's winning the football or when Jim's birthday is, you'll ask and Cortana will give you the answer. ...

Cortana is designed to learn about you and store what matters in her Notebook. That means she'll silence your phone during your favoured quiet times, warn you about travel issues and remind you that your friends owe you money. ...

Cortana won't just listen to you, she'll understand you, and she'll be aware of everything from your location to your personal preferences.

So when you ask her to book a hotel, she'll find the kind of hotel you like in the kind of area you like to stay in at the kind of price you want to pay. If you're in an airport she'll anticipate that you need a boarding card and will have it ready when you unlock your phone.
To disable all that data collection, you apparently have to disable Cortana, though I'm not sure even that will disable the spying — and given Microsoft's history, I would never trust them to tell me the truth anyway.

Edward Snowden's famous PRISM slide. Notice the date of Microsoft's collusion.

There were even stories, unsearchable now, of Microsoft using Windows 3 to spy on its beta-test customers, to read their hard disks and report what it found. I can't verify those stories today, but I can verify that I heard them at the time.

Paying a Price for the iHipster Life

Will the current generation of Steve Jobs–loving, faux-hipster iCool people surrender all that privacy for a little "convenience" and some implied in-crowd self-branding? According to the original article above, 14 million people updated to Windows 10 in the first day alone. At $100 per registration, Microsoft surrendered almost $1.5 billion to get something from them.

What did Microsoft give back? Something like this?

iHipsters working at a control-freak company. Apple's counter-factual self-branding is brilliant (source).

My entirely personal advice? The hipsters are paying a very heavy price. Never use Windows 10 until you know for sure it can never spy on you. And even then give it a second thought. Make Microsoft and the NSA work to find out every fact of your online and offline life.

If they want to know what days you sleep in and why, make them come to the door and ask.

GP

Labels: , , , ,