KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Stop the Windows Vista Features and Services Harvesting User Data for Microsoft


section: windows, for your questions: KezNews forum, 19.8.2007

There is a constant flow of communication between Windows Vista and Microsoft. A collection of features and services across Microsoft's latest desktop operating system exchange data with locations on the Internet, including those belonging to the Redmond company.




Even though end user privacy is yet to have an internationally standardized model built to benefit the consumer, with Windows Vista, Microsoft has striven for a certain degree of transparency. The company did publish an extensive list of all the features associated with the data collection and use practices of Windows Vista, and additional Microsoft services involved in transmitting and serving the information collected from end users to Redmond. The full and printable version of the Windows Vista Privacy Statement, including the supplementary information related to specific items on the platform is available for download here.

However, Microsoft is as transparent as it is translucent, and the list only "focuses on features that communicate with the Internet and is not intended to be an exhaustive list. It does not apply to other online or offline Microsoft sites, products or services." One important aspect to keep in mind is that end users do have a choice in the matter; although Microsoft's perspective is somewhat of a shift from such a scenario, while still having the end users' best interests at heart, of course. "To make Windows Vista work better with the Internet, some features that do not collect personal information are turned on by default. You can choose to disable these features," reads a fragment posted under Your Choices in the Windows Vista Privacy Notice Highlights. Yes, your choices... rather ironic... because since you do have a choice in the matter, the company went ahead and enabled a plethora of features in the operating system designed to support the flow of data between your copy of the operating system and Microsoft.

A couple of months ago, you have been able to read about all the Vista features and services harvesting user data for Microsoft from your machine. Now I am going to take it one step further and revisit the subject. This is nothing more than to provide a response to the feedback asking for methods to stop Vista from harvesting data for the Redmond company. But while doing so, you also have to consider the fact that the data flow between your copy of Vista and Microsoft is indeed beneficial, and that the automatic input that your operating system is providing is used to evolve the company's products and ultimately improve your users experience. "We use the information collected to enable the features you are using or provide the services you request. We also use it to improve our products and services," the company promises in the Vista privacy statement.

Controlling Vista's Communications with Microsoft

Ultimately, it all comes down to control. And Windows Vista brings to the table the means to limit and even isolate the operating system from Microsoft. Of course that taking your Vista machine offline is the best way to cut the operating system off from the Redmond company, but that is no option at all. In fact, there are very few viable scenarios of computers not connected to the Internet, mainly in corporate environments. And it is at the corporate level that Microsoft is providing the necessary resources to control the communication between Vista and the Internet via the options built into features or into the platform, or through server configuration management features. Essentially, Microsoft focuses on Windows Vista Business and Windows Vista Enterprise editions. This because some of the limitations involve making use of Group Policies and tasks not meant for the end user, but for administrators. However, while Windows Vista Starter, Home Basic, Home Premium, and even Ultimate are not specifically addressed, the methods of controlling Vista communications with Microsoft also extend to them.

Windows Vista Activation

Windows Vista Activation is mandatory. And there a single, legitimate way to bypass it. While of course there are documented methods for circumventing the Vista activation mechanism, they are also illegal, and that is not the scope of this article. But skipping the activation process entirely is possible only if you acquire a computer with the operating system preinstalled. In such cases, Vista is intimately connected with the machine's basic input/output system (BIOS). Activation is a general Microsoft anti-piracy measure set in place to bound a product key with the computer hardware running a copy of Vista, and as such cannot be disabled. A Vista copy on a computer not behind a modem will access go.microsoft.com via port 80 and using HTTP during the activation process. Through a modem, Vista will connect to sls.microsoft.com making use of port 443 and HTTPS.

Microsoft revealed the information that is being transmitted by Vista during activation:

• Request information, that is, protocol information necessary for successfully establishing communication with the activation server.
• The product key and supporting validation data.
• A group of hardware hashes (non-unique numbers generated from the computer's hardware configuration). The hardware hashes do not represent any personal information or anything about the software. They are based on the SHA-1 message-digest hash algorithm, and they consist of a combination of partial SHA-1 hash values of various computer components. The hardware hashes cannot be used to determine the make or model of the computer, nor can they be backward-calculated to determine the raw computer information.
• Along with the hashes, information about the algorithm used for the hashes is sent.
• An XrML license that uses public key encryption.
• The operating system being activated and the version number of the activation software.

With the exception of preinstalled OEM Vista, all other copies of the operating system, be them retail or volume license, have to be activated. For end users, the process is straight forward and completely automated. In corporate environments, the options are activation through Key Management Service (KMS) servers (reactivation required twice a year) or Multiple Activation Key (MAK) through Microsoft activation servers or using a MAK Proxy Activation (each MAK has assigned a limit of activations).

Device Manager and Hardware Wizards

The Device Manager and the hardware wizards in Windows Vista communicate to Microsoft, volunteering your system configuration and the adjacent devices integrated with the operating system. With Vista, Microsoft is offering device drivers through its Windows Update infrastructure. Device Manager is a system management tool providing an overview on the hardware installation and configuration across a system, but also on the interactions between the hardware and the software deployed, as well as a centralized location for handling settings, updates and troubleshooting. In contrast, hardware wizards streamline the process of installing a driver associated with a certain device. In this context, the Found New Hardware Wizard will search the Windows Update Web site, and download and install the necessary drivers if available, but only with the consent of the user. Of course that, if the Automatic Updating feature is installed, Vista will perform the tasks associated with device driver search, download and installation alone, taking the user out of the equation.

Device Manager is tied to the Update Driver Software Wizard, which in its turn is configured by default to search Windows Update. Plug and Play devices will launch the Found New Hardware Wizard. Windows Update device driver searching and prompts can be limited from the Control Panel. Just make your way via Start, Control Panel, System Maintenance, System, Advanced system settings, select the Hardware tab and then Windows Update Driver Settings. Here you can opt for one out of three options:

• Check for drivers automatically.
• Ask me each time I connect a new device before checking for drivers.
• Never check for drivers when I connect a device.

Of course that turning off the automated mechanism set in place in Windows Vista for device driver retrieval and installation could result in a depreciation of user experience and is not recommended, but make no mistake about it, Microsoft will get your hardware configuration in the process.

Dynamic Updates

Ever installed Windows Vista from Windows XP? Well if you did, you have undoubtedly noticed that the Setup for Windows Vista asks you for permission to check online for new Setup files, drivers and other files. Dynamic Update will automatically connect to Microsoft and use updated setup software, new drivers available and high-priority updates to features of the operating system, instead of the resources on the installation media. Dynamic Update sends to Microsoft the exact operating system version and information about network, video, audio, and mass storage hardware for the necessary drivers to be downloaded and deployed. In order to prevent Dynamic Updates from contacting Microsoft, just choose not to use the feature when prompted.

Event Viewer

Event Viewer is a system tool that keeps track of all the hardware and software issues and the security events on your machine, also permitting the users to manage and view event logs. The utility can be accessed by entering Event Viewer in the search box under the Start menu, and pressing Ctrl + Shift + Enter in order to launch it with elevated privileges. Event Viewer will only sent Microsoft information if the user clicks on the Event Log Online Help link that will access the http://go.microsoft.com/fwlink/events.asp site. "To access the relevant Help information provided by the link in the Event Properties dialog box, the user must send the information listed about the event. The data collected is limited to what is needed for retrieving more information about the event from the Event Log Online Help. User names, e-mail addresses, and names of files unrelated to the logged event are not collected," Microsoft informed.

The Redmond company will receive information related to the company name and software vendor, the date and time, the name and version of the product in the even log, and the ID, source and locale for the specific event. However, the user has to access the Event Log Online Help for Microsoft to receive the data.

File Association Web Service

The File Association Web Service in Windows Vista also whispers in Microsoft's ear. The service is designed to bridge the gap between files with specific name extensions and the default application or the operating system feature used to manage them. Windows Vista creates an automatic association between a file and a program, and stores it locally on the computer. If the operating system has to deal with a file that is not connected with a specific program to open it, Vista will send a query to a Microsoft website. "If you want to limit the flow of information from the file association Web service to the Internet, you can use your firewall to block access to any Web site that contains the following string: http://shell.windows.com/fileassoc/" Microsoft reveals.

Help and Support Features

Online Help, Help ratings and feedback and the Help Experience Improvement Program all constitute the support features that Windows Vista has to offer. All the examples enumerated above communicate with Microsoft when accessed by the end user. Windows Help and Support comes with the option to also search online for user queries, in addition to the data that is available on the local system. Via the Help ratings and feedback, users can choose to provide Microsoft with their input while the fully optional Help Experience Improvement Program will transmit to the company customer information related to Help search topics and navigation. Users can simply open Windows Help and Support by typing the words in the search box under the Start menu and from the menu in the upper right hand corner select Settings and then uncheck the "Include Windows Online Help and Support when you search for help" option. Additionally, also take care that the Join the Help Experience Improvement Program box is cleared.

Microsoft informed that in order to "help determine the correct Help topic to display, certain information is collected from the user’s computer and uploaded to a server at Microsoft that hosts the updated Help topics". Following is a list of the information collected:

• The search text string entered by the user (if the user is searching) or the unique identifier for the topic to be displayed (if the user has clicked on a topic link;
• The language/locale identifier, for example, en-us for English (United States)
• The version of the operating system installed, for example, Windows Vista Business
• A standard parameter that specifies that the topic should be downloaded in a compressed form (CAB file) if available, and uncompressed if not;

Plug and Play

According to Microsoft: "Plug and Play in Windows Vista provides the following functionality:

• Detects a Plug and Play device and determines its hardware resource requirements and device identification number (Plug and Play ID).
• Locates an appropriate device driver for newly installed devices.
• Allocates hardware resources.
• Dynamically loads, initializes, and unloads drivers.
• Notifies other drivers and applications when a new device is available.
• Handles stop and start processes for devices during hibernation, standby, and startup and shutdown operations (in conjunction with power management).
• Supports a wide range of device types."

In order to prevent the Plug and Play automatic wizard from accessing Microsoft with information related to the device you want to integrate with Windows Vista, make sure to enable the "Never check for drivers when I connect a device" option in Windows Update Driver Settings in Control Panel, under System Maintenance, Advanced system settings and Hardware.

Make sure to check back in next week for the second part of how to stop Windows Vista features and services from harvesting user data for Microsoft.

source: news.softpedia.com

send email Send link 2 friend  |  Permalink
<< previouse article
What’s New in Microsoft Land: 13th – 17th August 2007
next article >>
PC Tools ThreatFire 3.0.0.15 Beta

MORE RELATED ARTICLES:
Microsoft tries to stop more ‘Vista-capable’ e-mails from going public || Microsoft Urges Users Stop Using Safari In Windows Platform || Microsoft Launches Windows Live Services || Microsoft decouples SharePoint Services from Windows Server 2008 || Windows Vista Multilingual User Interface Available for Download

Comments(21)

The guy who typed this is paranoid

By Jake on 19.08.2007 - 23:08
seriously...

it's truth

By Ben on 20.08.2007 - 00:08
xcuse me jake! any informations is a most wanted stuff on the earth in 21 century.

At Ben

By Jake on 20.08.2007 - 00:08
looks like your paranoid too.

you do realize that pretty much all of the information that goes to microsoft never sees the light of day, think of all the windows vista's sending info to microsoft, i don't know about you but i think that is a lot of data being sent every nanosecond, no one has the time or money to go through it all, it gets sent and then microsoft servers examine the data and then send the data that your computer needs back, much like what is happening when you are exploring the internet.

I Think Jake is Right

By Ericko on 20.08.2007 - 01:08
it's not like microsoft is stealing our credit card numbers.

DO YOU TRUST MICOSOFT

By spittenkittens on 20.08.2007 - 01:08
i think everyone should be a little paranoid.do i trust microsoft or anything on the web? microsoft has the capability to collect any information they want.i do not allow cookies on my computer.i use all the free software like spybot etc.so far so good.dont give anyone personal information they dont need.

"i do not allow cookies on my computer."

By Mark on 20.08.2007 - 03:08
wow, the internet must be horrible for you because most sites require them to operate properly. paranoia indeed.

Not Reallly

By spittenkittens on 20.08.2007 - 03:08
most sites do not require cookies.including this one.only a few sites that i use require them.in firefox its easy
to enable them and delete them.i dont ley people snoop in my house,why would i let them snoop in my computer.its really not anyones business what i do on the internet.i have actually complanied to some secure web sites about tracking cookies and they have stopped using them.newegg is one of my favorite webites.i have complained about the spyware.if enough people complain they will stop.

Information is valuable

By Joe on 20.08.2007 - 03:08
unless they pay you for it, it should not be given out for free. this is the information age. all data is worth something. microsoft is not paying you for it therefore they should not get it for free.
as for you jake, i guess you never heard of data mining. all the data is stored for later queries run against it. either that or you work for ms or a tla.

Data mining?

By Steve on 20.08.2007 - 04:08
what are you people talking about? how is a hardware hash for example of any value to them? all it's used for is to make sure you're running your copy of windows on unique hardware. none of this information is personal or worth anything to anyone. microsoft should pay you for a bunch of numbers made by using an algorithm on your hardware? lmao!!! even cookies, they just save your preferences or keep you logged into web sites. did you know that every web site you visit logs your ip address and there is nothing you can do about it? omg everybody panic!!

people can get a lot more information about you out of a phone book. jake is right, this is all just a bunch of paranoid nonsense.

SOLVED

By Speedy_B on 20.08.2007 - 06:08
do not ever connect to the internet, just stare at the screen and look at the pretty background.

Microsoft must be clear!

By Alfa on 20.08.2007 - 12:08
i think microsft must publis clearly what they do wiyh these gathered information.
does linux also such "unfriendly" activities?

Obviously not

By Soldant on 20.08.2007 - 12:08
of course linux isn't that unfriendly, who the hell is it going to send data to? if somebody wanted to, they could probably hax it into a distro.

this article is paranoia. it's just collecting hardware information for activation and driver searches. if you think microsoft are going to bother sifting through this information, much less bother to track it to you, you may as well put on the tin foil hat and disconnect entirely.

you have no choice

By you have no choice on 20.08.2007 - 13:08
here is the deal. wake up people. ms has had bush pass laws so you can not sell your old coa to anyone. infact it is dead even if you want to use it on another unit(unlike with win2000 when you could)! they make the laws, they set the price, they will come and fine you if you pirate, they will have the feds send you to jail! just bend over and enjoy the rape, and no they will not use a condom, they don't have to thank$ to bush and law on their side!

Data Mining!

By Tesla on 20.08.2007 - 17:08
i have news for you! that is exactly what they are doing, using and selling info. data is run through large computers, shifted, sorted, linked to you name and demographics, and sold. oh did i mention the little data line running directly to n s a. homeland security and all. you’re in denial because you can face the facts. you have no rights anymore.

market says

By bubba on 20.08.2007 - 18:08
linux is good, mac is good, but most people target the 85% or whatever windows has, even if its not the best

Basnets

By Da_Foker on 20.08.2007 - 18:08
i agree with spittenkittens, they have no right to be sticking there effin noses into my private buisness, i have nothing to hide, but i don't want them knowing i have nothing to hide. spyware of any sort should be outlawed with a minimum penalty of being burned upside down at the stake.

Gatesy the snoop

By Crosswire on 20.08.2007 - 18:08
let's all go around billy gates house and have a shuffty though his draws, see how he likes it.

sdsde

By fdsf on 20.08.2007 - 19:08
dsdfsdfsffdd

not a point

By Ben on 20.08.2007 - 23:08
they don't interested you. you buy some product in a shop, you have inside a box passive chip. lot of backside barcode sticker have passive chip. in most box you buy you have a chip. they tracking all, everyday and everywhere: shopping, our life, network . i have also nothing to hide but they do that. they have right? if you buy any os you have no choice if you install it- you must accept eula. some day you wake up in a jail because you trust. don’t panic them! nothing else matters. you have only free software installed on your pc? maybe little one piece you used illegal – tell us. what is a google? they spying all of us for all of us. any word you typing online is tracking by google, gov, nsa, fbi, etc. isp collected your data too. nothing to hide- is not the point of that. you hear about gmo? perhaps little bit. nothing to hide? this is the world you living. anyone, any gov, any corp have some to hide like night pissing, patent data, callgirl or lover s** 22 august at 10pm. they watching you and me but i f****** all of that. is not a point. wakeup people!

Paranoid?

By tenten on 22.08.2007 - 13:08
paranoia is merely a heightened sense of awareness. but, what m$ is doing, and what they could be doing ain't the same. only you rich gomers (you know who you are) should worry. the rest of us fly below the radar.

Just because

By Billtron on 26.08.2007 - 03:08
just because your paranoid doesnt mean they are not out to get you


No new comments are allowed for this article.

For your questions use our KezNews Forum