Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Dear Microsoft

>Any critical or important class remote code execution, elevation of privilege, or design flaws that compromises a customer’s privacy and security will receive a bounty

Windows 10 has a major design flaw which compromises your customers privacy and security. You call it Telemetry and it can't be disabled completely(definitely a bug! Nobody would make such a stupid decision, amiright?).

Please send me further instructions on how I can claim my 250k.

Also: Why is there nothing for Server 2016?



Just like Apple, yet no one complains about them.


Where do you live where you're not hearing complaints about Apple?


Not Silicon Valley ;p.

I never hear anyone complain or hardly anyone even knowing about it.


Because you can disable it. No?


Yes, with some effort: https://github.com/drduh/macOS-Security-and-Privacy-Guide

You probably could with the same amount of effort for Windows, but at least Windows makes it more clear that it is happening.


Yep, windows has documented it fairly well with the possible configuration options: https://docs.microsoft.com/en-us/windows/configuration/confi...


As far as telemetry goes, there is a simple on or off checkbox in the Security and Privacy control panel.



I should have been clearer that I was referring to how one turns off telemetry on MacOS.


The real issue being that it is set to ON by default and that it tends to reset itself randomly after updates.


I'd say the real issue is that Windows 10 not only defaults to having telemetry turned on, but that it also does not allow a system administrator to turn it completely off.

However, I would agree that if preferences are changing without user intervention, that would definitely be a problem.

I haven't heard about users having that problem and can't find examples of it happening on the web. Do you have a citation?


Defending you here:

In this setting this is relevant even if funny.

I'll still downvote you for the same comment elsewhere.

And I mostly defend MS for enabling telemetry by default but I don't defend how absurdly hard they have made it to disable it.


I am mostly surprised by the absence of server 2016 as well


Windows servers are legacy - even SQL Server is on Linux now...ok jokes aside - might be PR move to not make nervous their old-school corporate customers


Don't know why you got downvoted for this on a hacker forum.


From the site guidelines (https://news.ycombinator.com/newsguidelines.html):

> Please avoid introducing classic flamewar topics unless you have something genuinely new to say about them.

For the record, I'm not the one who downvoted the parent for an honest question.


It is off-topic.

There are threads where it would be relevant, in this case they're just using this thread as a sounding board because the title contains the word Microsoft. Plus we have all read near identical posts and the corresponding discussion hundreds of times already, because they appear in every thread that brings up Microsoft.

It is kind of like Godwin's law, except instead of Hitler it is telemetry and Microsoft. If there is new information or new things to discuss, absolutely let's talk about it, but repeating the same complaint gets old after the nth time.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: