Skip to: Site Navigation | Search | Content

Legit Reviews

Product Reviews - Industry Facts - Technology Issues

Legit News

UPDATED: Windows 8 SmartScreen Raises Serious Privacy Concerns

Windows 8 has a new feature called SmartScreen, which is designed to protect your computer from malicious software in a similar way to User Account Control (UAC) in Vista and 7, but goes one further in that it contacts Microsoft at each attempted software install.


However, the way that Microsoft has implemented it raises some serious privacy concerns. In particular, "The big problem is that Windows 8 is configured to immediately tell Microsoft about every app you download and install. This is a very serious privacy problem, specifically because Microsoft is the central point of authority and data collection/retention here and therefore becomes vulnerable to being served judicial subpoenas or National Security Letters intended to monitor targeted users. This situation is exacerbated when Windows 8 is deployed in countries experiencing political turmoil or repressive political situations."

To make matters worse, the SmartScreen server at Microsoft was initially configured to use SSL v2 which has known vulnerabilities, allowing the encrypted communication to potentially be intercepted. However, this has now been fixed, with the server now using SSL v3 instead.

Nadim Kobeissi is the developer of Cryptocat and regularly writes in his personal blog, linked to below.

UPDATE Microsoft has since countered this, saying that they do not build a historical database of program and user IP data "We can confirm that we are not building a historical database of program and user IP data. Like all online services, IP addresses are necessary to connect to our service, but we periodically delete them from our logs. As our privacy statements indicate, we take steps to protect our users' privacy on the backend. We don't use this data to identify, contact or target advertising to our users and we don't share it with third parties."

Kobeissi still believes that Microsoft could improve in this area however, since the application information is stored on Microsoft servers. He believes that a better solution would be to store that data locally on the user's PC and update it regularly. This would eliminate the need to contact Microsoft at all, thus removing any possible leverage by powerful entities such as governments and rich copyright holders chasing users for copyright infringement.

Windows 8 has a new featured called Windows SmartScreen, which is turned on by default. Windows SmartScreen’s purpose is to “screen” every single application you try to install from the Internet in order to inform you whether it’s safe to proceed with installing it or not. Here’s how SmartScreen works:

1. You download any application from the Internet. Say, the Tor Browser Bundle.
2. You open the installer. Windows SmartScreen gathers some identifying information about your application, and sends the data to Microsoft.
3.If Microsoft replies saying that the application is not signed with a proper certificate, the user gets an error that looks something like this.

Nadim Kobeissi

Posted by | Mon, Aug 27, 2012 - 02:45 PM


blog comments powered by Disqus

Recent Articles
  • Fractal Design Node 605 Silent HTPC Case Review
  • AMD Kabini Mainstream APU Notebook Platform Preview
  • OCZ Vertex 450 256GB SSD Review
  • Gigabyte Shows Off Upcoming Intel Z87 Motherboards
  • MSI Z77A-GD65 Gaming Series Motherboard Review
  • ASUS Xonar DGX and Xonar DSX Audio Cards Reviews
  • WD My Passport Ultra 1TB Storage Drive Review
  • ASUS PCE-AC66 Dual-Band 802.11 AC PCIe Wireless Card Review
  • Kingston MobileLite Wireless Card Reader Review
  • Seagate Desktop HDD.15 4TB vs WD Black 4TB Hard Drive Review
Recent News
  • EVGA Precision X 4.2.0 Released
  • Apple 1 1976 Computer To Be Auctioned This Weekend
  • NVIDIA Releases GeForce 320.18 WHQL Video Card Drivers
  • OCZ Launches the Next Generation Vertex 450 Series SSDs
  • Inno3D GeForce GTX 780 HerculeZ 2000 - Custom Card
  • ZOTAC Introduces GeForce GTX 780
  • NVIDIA Launches GeForce GTX 780 Video Card
  • AMD Announces New 2013 Mobile APU Series
  • Xbox One Reveal 2013 Highlights
  • ASRock Intel 8 Series Boards Are Waterproof - Conformal Coating

Socialize

  • Facebook
  • Twitter
  • YouTube

Search

Hot Topics

  • Ozeri Touch 440 lb Digital Bath Scale $29 Shipped
  • EVGA Precision X 4.2.0 Released
  • Fractal Design Node 605 Silent HTPC Case Review
  • OCZ Technology Partners with NETGEAR
  • USB 3.0 PCIe Card For $3 AR
  • NVIDIA Releases GeForce 320.18 WHQL drivers
  • OCZ Launches the Next Generation Vertex 450 Series SSDs
  • Velocity Micro announces desktops powered by GeForce GTX780
  • Inno3D GeForce GTX 780 HerculeZ 2000
  • ZOTAC Introduces GeForce GTX 780

Explore ::

  • News
  • Articles
  • Editorial
  • Interviews
  • Events
  • Folding
  • Forums

Content ::

  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • Bluetooth
  • Cooling
  • Miscellaneous

About ::

  • Contact
  • About Us
  • Disclaimer

Copyright © 2002-2013 Legit Reviews™ & LegitReviews.com - All Rights Reserved.

  • Home
  • Forums
  • Favorite
  • RSS Feeds
  • Shopping
  • Processors
  • Video Cards
  • Motherboards
  • Storage
  • Mobile
  • Memory
  • PC Cases
  • Cooling
  • Misc