Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most of his configuration is invalid, due to his misconfiguration of group policy.

Yeah, it's his fault that he didn't properly navigate the Kafkaesque nightmare that Microsoft has created in order to thwart people from disabling all this spyware.



It's pretty basic Windows GPO knowledge. Lots of them work this way.


It's a pretty broken configuration system that makes it needlessly difficult to do things the correct way.


Agreed.

It should read "unconfigured" -- not "disabled"

Some of the GPO settings make me feel like I'm reading a contract written by a lawyer out to get me.

I don't have any concrete examples, but I swear I've stumbled across settings like this <not a real setting, just an example, probably exaggerated>:

Setting - Disable Windows Error Reports.

Description: Disable the submission of error reports

Options: Unconfigured - Use client settings.

Disable - Send only minimal information in error reports.

No - Do not send any error reports.

Yes - automatically send full error reports.

So when you Enable the "disable windows security reports" option, it Enables sending of the security reports, and when you "Disable" the option, it still sends reports.

Many of them are extremely confusingly worded like this. It takes several reads to figure out which option actually disables it.

edit: fix formatting


Plus I have been doing this for 20+ years and have found many times settings that were incorrectly documented--it's even confusing to them.


Here's a fun example: to enable tlsv1.2, you had to enable "Turn off encryption" http://www.bauer-power.net/2014/06/how-to-enabled-tls-11-and...


Yup, it's awful. But it's not some nefarious new trap to steal all your data- this has been needlessly difficult for a decade.


It's a pretty shoddy security researcher that doesn't read the documentation before posting a lot of falsehoods to Twitter.


> pretty shoddy security researcher that doesn't read the documentation

What an unnecessary insult. If you can read the incredibly confusing Microsoft documentation better than him (or any of us), then please post the definitive step-by-step instructions for turning off all telemetry and privacy-invasive connections in Windows 10.

Then we'll see if your insult was warranted.


So, I search for "teredo group policy" and here's the second link I find, a TechNet article with detailed screenshots about how to disable IPv6 via Group Policy, which is one of the things he talks about:

https://social.technet.microsoft.com/wiki/contents/articles/...

It shows how there's an Explain box that describes what the various settings do.


That's 1 item[ * ]. I'd still like to see your definitive step-by-step instructions for turning off all telemetry and privacy-invasive connections in Windows 10 -- which is what the OP was attempting to do.

[ * ] How do you know that it even works? Plenty of times I've followed instructions from Microsoft's TechNet that didn't solve the problem it purported to solve.

And by the way, that's a helluva lot of steps to disable IPv6. Multiply that by a hundred other things you need to do, and probably a hundred you don't know about, and changes that get undone by updates, and you have a nightmare trying to create a privacy-respecting Windows 10.


IPv6 isn't even part of telemetry per say, it's an IETF standard that can be used to connect with any server that supports it. Yes, some OS-level services require IPv6. Shutting off IPv6 as a way of disabling those services is like... using leeches for bloodletting but for IT practices. If you want to disable telemetry and you're on a supported Windows SKU for Group Policy, here's Microsoft's directions on what you can configure:

https://docs.microsoft.com/en-us/windows/configuration/confi...


It all started with a pretty casual tweet, can we stop crucifying the guy?

No matter your opinion about the subject at least we are talking about it now and from what I can tell he's going to make a more reproducible test with a script so we can all tear it to pieces.

If not, I hope someone else do it. Even better if it's somebody with the proper credentials some of you all are requiring (from a freaking tweet).


Shoddy or realistic? I'd hope more security researchers work with systems that aren't perfectly configured because they won't be in the real world.


There's a difference between "testing things on a reasonable reproduction of real-world systems" and "claiming Windows doesn't work correctly because you don't read the documentation."


The world where no one reads the manual is a faithful reproduction of the real world.

Sensible defaults matter.


i can't explain how infuriating that comment is without violating the rules here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: