 SUMware Premium join:2002-05-21
| Vista Harvests User Data for MS
From Softpedia Forget about the WGA! 20+ Windows Vista Features and Services Harvest User Data for Microsoft - From your machine! By: Marius Oiaga, Technology News Editor said by Softpedia : Are you using Windows Vista? Then you might as well know that the licensed operating system installed on your machine is harvesting a healthy volume of information for Microsoft. In this context, a program such as the Windows Genuine Advantage is the last of your concerns. In fact, in excess of 20 Windows Vista features and services are hard at work collecting and transmitting your personal data to the Redmond company.
Microsoft makes no secret about the fact that Windows Vista is gathering information. End users have little to say, and no real choice in the matter.
Windows Update, Web Content, Digital Certificates, Auto Root Update, Windows Media Digital Rights Management, Windows Media Player, Malicious Software Removal/Clean On Upgrade, Network Connectivity Status Icon, Windows Time Service, and the IPv6 Network Address Translation (NAT) Traversal service (Teredo) are the features and services that collect and deliver data to Microsoft from Windows Vista. By using any of these items, you agree to share your information with the Redmond Company.
Windows Vista will contact Microsoft to get the right hardware drivers, to provide web-based "clip art, templates, training, assistance and Appshelp," to access digital software certificates designed "confirm the identity of Internet users sending X.509 standard encrypted information" and to refresh the catalog with trusted certificate authorities. Of course that the Windows Vista Digital Rights Management could not miss from a list of services that contact Microsoft on a regular basis. If you want access to protected content, you will also have to let the Windows Media Digital Rights Management talk home. Windows Media Player in Vista for example, will look for codecs, new versions and local online music services.
The Malicious Software Removal tool will report straight to Microsoft with both the findings of your computer scan, but also any potential errors. Also, in an effort to enable the transition to IPv6 from IPv4, "by default standard Internet Protocol information will be sent to the Teredo service at Microsoft at regular intervals."
Microsoft has an additional collection of 47 Windows Vista features and services that collect user data. However, not all phone home and report to Microsoft. Although the data collection process is generalized across the list, user information is also processed and kept on the local machine, leaving just approximately 50% of the items to both harvest data and contact Microsoft. Still, Microsoft underlined the fact that the list provided under the Windows Vista Privacy Statement is by no means exhaustive, nor does it apply to all the company's websites, services and products.
Activation, Customer Experience Improvement Program (CEIP), Device Manager, Driver Protection, Dynamic Update, Event Viewer, File Association Web Service, Games Folder, Error Reporting for Handwriting Recognition, Input Method Editor (IME), Installation Improvement Program, Internet Printing, Internet Protocol version 6 Network Address Translation Traversal, Network Awareness (somewhat), Parental Controls, Peer Name Resolution Service, Plug and Play, Plug and Play Extensions, Program Compatibility Assistant, Program PropertiesCompatibility Tab, Program Compatibility Wizard, Properties, Registration, Rights Management Services (RMS) Client, Update Root Certificates, Windows Control Panel, Windows Help, Windows Mail (only with Windows Live Mail, Hotmail, or MSN Mail) and Windows Problem Reporting are the main features and services in Windows Vista that collect and transmit user data to Microsoft.
This extensive enumeration is not a complete illustration of all the sources in Windows Vista that Microsoft uses to gather end user data.
Event Viewer data is collected every time the users access the Event Log Online Help link. By using the File Association Web Service, Microsoft will receive a list with the file name extensions. Metadata related to the games that you have installed in Vista also finds its way to Microsoft. The Error Reporting for Handwriting Recognition will only report to Microsoft if the user expressly desires it to. Through IME Word Registration, Microsoft will receive Word registration reports. Users have to choose to participate in the Installation Improvement Program before any data is sent over at Microsof.
Ever used a print server hosted by Microsoft? Then the company collected your data through Internet Printing. Network Awareness is in a league of its own. It does not premeditatedly store of send directly information to Microsoft, but it makes data available to other services involving network connectivity, and that do access the Redmond company. Via Parental Controls, not only you but also Microsoft will monitor all the visited URLs of your offspring.
Hashes of your Peer Name tied to your IP address are published and periodically refreshed on a Microsoft server, courtesy of the Peer Name Resolution Service. Every time you install a Plug and Play device, you tell Microsoft about it in order to get the necessary device drivers. The same is the case for PnP-X enabled device, only that Windows Update is more actively involved in this case.
The Program Compatibility Assistant is designed to work together with the Microsoft Error Reporting Service, to highlight to Microsoft potential incompatibility errors. For every example of compatibility settings via the Compatibility tab, Microsoft receives an error report. The Program Compatibility Wizard deals with similar issues related to application incompatibility. File properties are sent to Microsoft only with the item that they are associated with.
"The personal information we collect from you will be used by Microsoft and its controlled subsidiaries and affiliates to provide the service(s) or carry out the transaction(s) you have requested or authorized, and may also be used to request additional information on feedback that you provide about the product or service that you are using; to provide important notifications regarding the software; to improve the product or service, for example bug and survey form inquiries; or to provide you with advance notice of events or to tell you about new product releases," reads a fragment of the Windows Vista Privacy Statement.
But could Microsoft turn the data it has collected against you? Of course, what did you think? "Microsoft may disclose personal information about you if required to do so by law or in the good faith belief that such action is necessary to: (a) comply with the law or legal process served on Microsoft; (b) protect and defend the rights of Microsoft (including enforcement of our agreements); or (c) act in urgent circumstances to protect the personal safety of Microsoft employees, users of Microsoft software or services, or members of the public," reveals another excerpt.
|
|
  swhx7 Premium join:2006-07-23 Elbonia
·RoadRunner Cable
| reply to SUMware Re: Vista Harvests User Data for MS
This was widely expected, but it's good that attention is finally being focused on the specifics.
There are Microsoft docs listing all the "phone home" behaviors in XP and 2000, so I searched for a similar page on Vista, and sure enough ther is one on the "Technet" site: »technet2.microsoft.com/WindowsVi···033.mspx
Is this disclosure complete? I wouldn't count on it. (Does anyone trust Microsoft anymore?) I look forward to a report from someone monitoring traffic from a box placed between a Vista PC and the internet. |
|
 Cairninator
join:2007-02-14 Sedona, AZ | reply to SUMware Well, I hope anyone using Firefox on Vista has broadband of some kind. Between them they will suck up a good portion of your bandwith calling home.  |
|
  wapu Broadband Ranger Premium join:2001-09-05 Germantown, MD clubs: 
| reply to SUMware Using the Terms "Transmitting Personal Data" is misleading and in my mind discredits the article. They are not transmitting social security numbers and banking information.
I can understand not wanting them to transmit anything, but deliberately misleading people to scare them into your point of view is not a good way of getting to a solution. -- When a friend asks me to choose between friends, I will always choose the friend that didn't ask me to choose. |
|
  ilago Premium join:2005-06-28 Australia
·Internode
| It's not so much about the transmission of personal data and information to Microsoft. Personal information is available to a wide variety of service providers, from your ISP to your TV repairman. It's more about the disclosure of this information being entirely at Microsoft's discretion and completely outside your control. They reserve the right to diclose your personal information to third parties of their choice and to use it in any way they wish.
quote: But could Microsoft turn the data it has collected against you? Of course, what did you think? "Microsoft may disclose personal information about you if required to do so by law or in the good faith belief that such action is necessary to: (a) comply with the law or legal process served on Microsoft; (b) protect and defend the rights of Microsoft (including enforcement of our agreements); or (c) act in urgent circumstances to protect the personal safety of Microsoft employees, users of Microsoft software or services, or members of the public," reveals another excerpt.
Disclosure to law enforcement agencies will vary between countries. This does not:
quote: The personal information we collect from you will be used by Microsoft and its controlled subsidiaries and affiliates to provide the service(s) or carry out the transaction(s) you have requested or authorized, and may also be used to request additional information on feedback that you provide about the product or service that you are using; to provide important notifications regarding the software; to improve the product or service, for example bug and survey form inquiries; or to provide you with advance notice of events or to tell you about new product releases
|
|
 SUMware Premium join:2002-05-21
| reply to swhx7 said by swhx7 :There are Microsoft docs listing all the "phone home" behaviors in XP and 2000, so I searched for a similar page on Vista, and sure enough ther is one on the "Technet" site: » technet2.microsoft.com/WindowsVi···033.mspx Nice link.
said by wapu :Using the Terms "Transmitting Personal Data" is misleading They are not transmitting social security numbers and banking information. Please explain how you know that.
Interesting that apparently in your universe only SSN and banking info qualify as personal info. MS clearly states that it has a broader definition of what constitutes "personal information" than you do.said by microsoft7 :The personal information we collect from you will be used by Microsoft and its controlled subsidiaries and affiliates Microsoft may disclose personal information about youPersonal information collected by Microsoft softwarefeatures of Windows Vista that transfer personal information over the Internetdecide what personal information you wish to provide. how Microsoft will use your personal information |
|
 technovert Premium join:2007-06-14 Canada clubs: | reply to SUMware None of this information seems particularly personally identifying, and is fairly typical of other applications that contact their authors to relay a variety of useful information. |
|
  La Luna Surviving Ashraful Premium join:2001-07-12 Warwick, NY clubs:
·Optimum Online
·Vonage
1 edit | reply to wapu said by wapu :Using the Terms "Transmitting Personal Data" is misleading and in my mind discredits the article. They are not transmitting social security numbers and banking information. I can understand not wanting them to transmit anything, but deliberately misleading people to scare them into your point of view is not a good way of getting to a solution. If someone has to "embellish" to try and make things look more nefarious than they are, the credibility level drops to zero. I also didn't see one thing in there that indicates "personal data" (as most people would define that term) is being transmitted, and the use of that type of language to insinuate that it is disingenuous.
Microsoft makes no secret about the fact that Windows Vista is gathering information. End users have little to say, and no real choice in the matter.
Also incorrect. Users absolutely have a choice....switch to Linux. Please. -- ~~"As long as America is an infidel enemy, terrorizing it is a duty." Sayed Imam Abdul-Aziz el-Sheriff~~
|
|
 SUMware Premium join:2002-05-21
| said by La Luna :Users absolutely have a choice....switch to Linux. Exactly. |
|
 Mele20 Premium join:2001-06-05 Hilo, HI
| reply to wapu said by wapu :Using the Terms "Transmitting Personal Data" is misleading and in my mind discredits the article. They are not transmitting social security numbers and banking information. I can understand not wanting them to transmit anything, but deliberately misleading people to scare them into your point of view is not a good way of getting to a solution. Whether it is my social security number, my phone number, or anything else it is still personal information and it should be my choice whether or not it is transmitted to Microsoft. The user can "choose", for instance, whether or not to send information to Microsoft in the event of DrWatson needing to run or when viewing Event Viewer. But in the case of both, one cannot get further information about the event in an easy manner without choosing to send the information to Microsoft. Microsoft didn't have to tie information to your personal details like they did. At least, Microsoft does usually warn you when the really "personal" information is to be sent so you can say no.
But to get simple information on an Event you have to send info from your computer to Microsoft. That is not right. You can avoid that by taking the event code and going to a site like Event ID.net but why can't Microsoft provide the information in Event Viewer without you having to send anything to them? It can be VERY Personal Data. It could include your Social Security number or banking information depending on what you were doing when, for instance, Explorer crashed. Usually you are warned if the info being sent is "delicate" but not always and how many users bother to read all the details about what is being sent?
The above is just one example of how Microsoft collects information when unnecessary. I have never once seen any benefit to me as a user of Microsoft collecting event information. If, by rare chance, Microsoft has enough information collected to send me to a web page that says "xxx event was caused by Avira Antivirus. Please contact the vendor for help" that doesn't tell me anything I didn't already know.
Folder Share should be added to list of services that collect user data. It's being touted as the way to share with friends. I'd far prefer my ISP to allow larger attachments.
I'm not sure though that Vista users have "little say and no real choice in the matter". If they have a Pentium IV and a non compliant monitor then I do believe they can turn off, stomp on, get rid of much of the offensive behavior in Vista. I would think WMP and WDRM could be killed ...maybe not removed entirely but killed, auto updating disabled, WU disabled, Windows Time Service can be turned off, etc. All the web based crap like clip art and templates can just be avoided. Who would let Microsoft update hardware drivers? That would be suicide. Turn that off. What can't be turned off can be killed. You may have to go look for a crack to kill it but it can be killed....that is as long as you don't have a CPU or monitor that collaborates with Microsoft to spy on you.
-- "The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason |
|
  EGeezer Go Bobcats Premium join:2002-08-04 Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage
| reply to SUMware Sounds like Vista is broken unless it is connected to the internet periodically. I wonder if it would even function if it were loaded on with an isolated system, or on one with with no NIC.
Having been victimized by following MS driver recommendations, I don't feel real fuzzy about trusting them to figure what's the correct driver for, say, a RAID controller or tape adapter on a server. -- The society which scorns excellence in plumbing as a humble activity and tolerates shoddiness in philosophy because it is an exalted activity will have neither good plumbing nor good philosophy: neither its pipes or its theories will hold water.
|
|
  badab99
join:2001-08-26 Austin, TX clubs: | »www.forensicideas.com/tools.html
run it save a log, read it, scare the crap outta yourself then install linux.  |
|
 OZO Premium join:2003-01-17
| It looks like it's capable of providing this dialog box only:
 PSExplorer v.2.0.0.12
-- Keep it simple, it'll become complex by itself... |
|
  Portmonkey scurvy Premium join:2004-04-09 Southern IL
| reply to SUMware I can't think of any way this will negatively affect things, other than the small amount of resources it takes to collect and send the data. I joined the Customer Experience Improvement Program, Microsoft SpyNet, and pretty much anything else that pops up wanting to send info to Microsoft. Maybe if more people did so, we would see improvements in current and future Microsoft products come about a little quicker and with fewer potential bugs. Sure, any of us could have gone with Mac, Linux, or whatever but for one reason or another most people have cast their lot with Microsoft, so why wouldn't most people want to do what they could to make sure their choice continues to be the best choice? -- Eating a steady diet of government cheese and livin in a van down by the river. |
|
  jansson_mark Markus Jansson Premium join:2001-08-05 Finland
| reply to SUMware 1) Use WDE to protect information hidden into Windows. 2) Use external firewall rules to block all traffic to anything related to Microsoft (except windowsupdate) OR use SOCKS proxy with username/password to prevent anything else than what you want to from communicating to net. -- My computer security & privacy related homepage »www.markusjansson.net Use HushTools or GnuPG/PGP to encrypt any email before sending it to me to protect our privacy. |
|
  salzan Experienced Optimist Premium join:2004-01-08 WA State | But will Vista still function if you do this? |
|
  major marco Res Firma Mitescere Nescit Premium join:2003-02-13 Stepford, CA clubs:
| reply to SUMware said by SUMware :From SoftpediaForget about the WGA! 20+ Windows Vista Features and Services Harvest User Data for Microsoft- From your machine! By: Marius Oiaga, Technology News Editor al Certificates Oh look. Yet another extensive list of reasons why I switched to Linux and refused to be assimilated into the Microsux universe. Only a matter of time before Vista is transmitting home what time you went to bed, how long you had sex, who you had it with, when you woke up, when you left for work, where you went to work, and what time you came home. All it has to do is check the logs and other data recorders in Vista. -- The Toll
|
|
  Kill DRM
@rr.com
| said by major marco :Only a matter of time before Vista is transmitting home what time you went to bed, how long you had sex, who you had it with, when you woke up, when you left for work, where you went to work, and what time you came home. The real question here is, who gives a schittt ???????? |
|
  major marco Res Firma Mitescere Nescit Premium join:2003-02-13 Stepford, CA clubs:
| reply to major marco Unfortunately for the MS shill troll on this board, I don't read anonymous posts. |
|