• wuffah@lemmy.world
    link
    fedilink
    English
    arrow-up
    194
    arrow-down
    1
    ·
    edit-2
    15 hours ago

    Fun fact: Microsoft will try to guess your passwords to open and scan your encrypted archives when uploaded to OneDrive.

    Microsoft also hands your BitLocker recovery keys to the government on request.

    Microsoft also uses your local machine’s GDID to deanonymize and track you across the internet for the government.

    These are paid surveillance services Microsoft provides to the government, paid for by your tax dollars. No wonder they desperately want to force you to use OneDrive.

    • Bytemeister@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 hours ago

      Pay for it twice actually, Microsoft charges you to install that spyware on your computer as well.

    • CosmoNova@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      edit-2
      8 hours ago

      Zipping files was never enough to secure them in the cloud. It‘s always recommended to properly encrypt sensitive data properly before you upload it. Whether you use OneDrive, Google Drive, Proton drive or whatever.

      Still amazing how far Microslop goes to sniff through your stuff preemptively, though. Your cloud storage should be none of their business but sadly it‘s their entire business now. Privacy laws should definitely extend to digital space you rent no matter the circumstances.

      If cloud providers argue that‘s too dangerous then they simply shouldn‘t be in business. If a government says it‘s too dangerous then they shouldn‘t be in power. Obviously they don‘t trust in the people who voted for them. Therefore they don‘t trust democracy and are therefore fundamentally undemocratic and a danger to the people.

      • blackbeans@lemmy.zip
        link
        fedilink
        English
        arrow-up
        9
        ·
        8 hours ago

        ZIP encryption can be pretty strong, as long as you use aes-256 and not zipcrypt. AES256 had been supported for ZIP files since 2003, just not in the built-in Windows zip handling.

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      10 hours ago

      Wow, that’s how it managed to find “malware” (not actual malware) in a password protected rar that I shared

      • black0ut@pawb.social
        link
        fedilink
        English
        arrow-up
        11
        ·
        9 hours ago

        To be fair, a lot of platforms just flag any encrypted archive file (not just rar) as malware. Their argument is that those files are commonly used to get past malware detection, which is kinda true. Still a pain for everyone who has a legitimate need for the feature.

    • kescusay@lemmy.world
      link
      fedilink
      English
      arrow-up
      32
      arrow-down
      4
      ·
      13 hours ago

      Hey now! I can honestly say Microsoft has never done that with any of my computers!

      (Why yes, they do all run Linux. How did you know?)

      • notfromhere@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        22
        ·
        edit-2
        9 hours ago

        If any of your Linux machines use SystemD, then Microsoft has done that then there’s something to be aware of with those machines. SystemD has a global system ID that can be used like the Windows GDID apparently.

        Edit: not MS

            • Whostosay@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              5
              arrow-down
              1
              ·
              edit-2
              10 hours ago

              Okay but correlate that with the same methods and usage and by the same threat actor (MS) in this case.

              Or any of the combination, as a treat

              I’m not saying it’s impossible, but it’s extremely implausible.

                • Whostosay@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  9
                  ·
                  edit-2
                  9 hours ago

                  To be fair, yeah that shit is egregious.

                  But that’s not at all what I asked you or what you claimed. Those are technically two different things. And not technically like yes or no. Those are entirely different security fronts.

                  You’ve got to back that claim up or take it back, and I have a feeling you’ll be taking it back.

                  It’s okay to be cautious, and it’s especially okay to warn others of trajectories that could lean into privacy or security issues, but it’s not okay to make shit up.

                  Lastly it’s no longer an init system. It’s a system that happens to handle init.

                  • notfromhere@lemmy.ml
                    link
                    fedilink
                    English
                    arrow-up
                    2
                    arrow-down
                    1
                    ·
                    9 hours ago

                    That’s fair. I didn’t mean MS was the threat actor, just the seed from which this grew. I definitely take that back after reading up more on where machine-id grew out of.

                    However, I don’t concede that machine-id is theoretical for user fingerprinting. Any software installed can read it, especially a browser. That’s the vector for tracking across the web. Do I have instances of this occurring, no. Seems plausible and the more we can sandbox things, especially “web browsers” (untrusted app runners more like it) the better.

                • ViatorOmnium@piefed.social
                  link
                  fedilink
                  English
                  arrow-up
                  5
                  ·
                  10 hours ago

                  To support and to need are two different verbs. Linux also needs your phone number in the user metadata by the same standard.

    • XLE@piefed.social
      link
      fedilink
      English
      arrow-up
      10
      ·
      15 hours ago

      Well if I’m already paying for Windows, I might as well use it, right? /s