Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is an overkill I believe. Are Android devices banned from torrent sites? Chromebooks? Windows 10 is a cloud-based operating system, as is Android and ChromeOS -- most of the code runs locally, but it heavily relies on cloud functionality.

It is extremely naive to think that if MS tells you in the EULA that many services in the OS work based on the user behavior suddenly opens up new doors for spying. If MS wanted to spy on you, they could have done that already (they might or might not, I don't know, but it's certainly not the EULA that prevents them from doing that).

/snarky comment:

I guess most people on the torrent sites already give full permissions to the torchlight app on their phone.



Privacy issues is all about scale. When groups of people can be mapped, it allows for discrimination and prosecution and that thought scares people into submission. Android and ChromeOS users are small minorities, while if you monitor all Windows users you more or less can map out the whole community, and that is a very scary thought for a lot of people.


> Privacy issues is all about scale

I absolutely agree, but I don't see why Android users would be a minority -- I don't know the latest numbers but I guess there are more Android users already than Windows (10) users.


How many of those Android users use their Android devices for torrenting?


I'm pretty sure that people won't use their 3G / 4G mobile plan to download movies, music or the latest Linux ISOs from torrent sites on their smartphone with 16 / 32 GB of total storage.


But they might just use their wifi connection ;)


It's not overkill when a company scans every single file you have in your PC, keeps those logs on its servers, and then eventually can and likely will share that information with others, from law enforcement to MPAA or even advertising companies.

Microsoft has already admitted in its "privacy" policy that it can and will do such thing:

> “We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), --- when we have a good faith belief that doing so is necessary to ---.” [1]

I mean - are you kidding me? Like "whenever we'll feel like it"? That's so reassuring that you respect your customers's privacy, Microsoft...Really solid privacy policy right there.

[1] - http://www.rockpapershotgun.com/2015/07/30/windows-10-privac...


You left out the circumstances under which they will share your data.

> comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies;

> protect our customers, for example to prevent spam or attempts to defraud users of the services, or to help prevent the loss of life or serious injury of anyone;

> operate and maintain the security of our services, including to prevent or stop an attack on our computer systems or networks; or

> protect the rights or property of Microsoft, including enforcing the terms governing the use of the services - however, if we receive information indicating that someone is using our services to traffic in stolen intellectual or physical property of Microsoft, we will not inspect a customer's private content ourselves, but we may refer the matter to law enforcement.

https://www.microsoft.com/en-us/privacystatement/default.asp...

Additionally, the privacy policy section you and I are quoting applies to many Microsoft services, including, for example, OneDrive. Otherwise, the "private folder" data they're talking about could only be whatever bits and scraps telemetry and Windows Defender picks up, based on my reading.

That seems perfectly reasonable and also confirms they won't be sending any of your data to the MPAA.


> That seems perfectly reasonable

No that's not , and what is shocking is that you find it "perfectly reasonable".


That's literally a bog-standard privacy policy clause.

You can find the essentially same four points on everything from Ubuntu to Wikimedia.

Can you be more specific about which part of it you find particularly unreasonable? Can you explain how the claims that the privacy policy allows MS to share data with the MPAA are founded?


Normally these kinds of terms appear on web services where the scope of disclosure is contained to the information you upload to the service (e.g. repos you upload to Github or posts you make to Reddit). Windows 10 is fundamentally different because the scope becomes everything the OS can suck up including everything on the hard drive and keystrokes from the keyboard.

You no longer have the option not to disclose something because anything that shows up on the PC may be fair game. Privacy is all about controlling who gets to see what information. Windows 10, being an OS, removes your ability to control what is shared in any meaningful way with its privacy policy.


> [...] becomes everything the OS can suck up including everything on the hard drive and keystrokes from the keyboard.

Not just on the machine.

It can scan the whole local network, understanding about LAN, devices, services, all of which could be hard to reach from WAN.


> Can you explain how the claims that the privacy policy allows MS to share data with the MPAA are founded?

The MPAA could be a Microsoft "customer" that needs protection from piracy. The MPAA could run a service with Microsoft that needs protection from being "defrauded". There are holes in the policy large enough to drive a fleet of buses through.


"Comply with legal process": i.e. if they are subpoena'd for this information.


If you use Dropbox or Google or any other cloud service the same applies. Google actually goes further and makes some nice sounding TOS text at first glance, but if you read carefully you will find that it carves out a super-vague disclosure for "technical" reasons loophole which can easily mean "because we feel like it, technically".

Furthermore, if you actually bothered to read the damn Microsoft TOS rather than seance over the tea leaves of copypasta confetti, you would see that this is clearly in the context of the cloud services that can be enabled in Windows 10, not Windows 10 as a whole.


I understand that there are legal barriers around it per the privacy policy but the fact that someone at Microsoft can just decide that they need file X off my laptop and then fetch it is way beyond the pale. If someone wants the files off my laptop, they can get a search warrant and successfully convince my lawyer that I am legally obliged to decrypt.


There is no evidence that Microsoft currently has the ability to arbitrarily fetch files from your computer.

If your argument is that they could implement such a capability, that's always been true for any OS, including free operating systems, unless you audit the code and compile it yourself.


The issue isn't whether the functionality is currently built-in (it'd be trivial to add later). The issue is that Microsoft states its intent to do so (relevant section underlined):

>we may access, disclose and preserve your personal information, including your private content (such as the content of your emails, other private communications or ______files in private folders______), when we have a good faith belief that doing so is necessary...

I understand that you'd have to do a full code audit of every application that has permissions to read files off your local disks to ensure this wasn't already being done by someone, but at least as a Linux user, I'm not used to software openly expressing its intent to feed private files off to any like-minded entity that asks for them. Definitely a red flag for me.


> The issue is that Microsoft states its intent to do so (relevant section underlined):

The quoted section is from the privacy header which also applies to Onedrive, which is essentially Microsoft's version of Dropbox.

They're not stating their intent to collect files in private folders on your computer aside from bits that have always been collected, like whatever parts of a crash dump Error Reporting sends on.


The doc is at https://www.microsoft.com/en-us/privacystatement . It says:

>It applies to Bing, Cortana, MSN, Office, OneDrive, Outlook.com, Skype, ___Windows___, Xbox and other Microsoft services that display this statement.

It appears that you're making an assumption that they only intend this to apply to OneDrive, but they explicitly state it applies to Windows too. My Linux installation definitely didn't come with such boilerplate.


They list what data they collect under the Windows section. They don't collect arbitrary files in personal folders.


> has the ability to arbitrarily fetch files

Haven't they in the past done exactly this in order to do people a favour by removing certain malware via windows update?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: