this post was submitted on 03 Jun 2024
1300 points (96.4% liked)

Technology

59605 readers
3501 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] bassomitron@lemmy.world 8 points 5 months ago (8 children)

The snapshot feature is only going to be available on certain laptops that have the Snapdragon + AI chip. DoD will likely simply just not buy those laptops and ban any org from purchasing them, like they already do for certain hardware that have been found to be especially vulnerable. Additionally, this feature isn't turned on by default and costs a subscription fee (i.e. Copilot+), so people will have to consciously enable and pay for it. Lastly, in enterprise versions of Windows, I would bet money that it can be disabled via GPO, as it's not only the DoD that would have serious issues/concerns with this feature.

[–] OpenStars@discuss.online 2 points 5 months ago (2 children)

But do we know that the tracking part will not be enabled by default - and possibly in a hidden, highly obscured manner, where the system claims it to not be but it in fact is? The access to Copliot+ may cost money, but why would Microsoft turn away that source of free data? At the very least it is a strong temptation, which even if they start out being responsible with, in every future update there is the potential to change course.

And even if it were not enabled by default, I do worry that a 2-prong attack could first turn it on, then later exploit it to gather the data. If it for truly certain is limited to those chips though... then yes that provides security, thank you for mentioning that.

One good thing is that government systems are always at least couple versions behind, specifically to allow time for exploits to be discovered & patched, prior to upgrades - i.e. prioritizing safety & security over ease-of-use and being on the bleeding edge of "new features".

[–] bassomitron@lemmy.world 3 points 5 months ago (1 children)

I mentioned in another comment this would kill all trust in their product if it was found out that Windows was secretly doing all of that in the background in their enterprise products. There are other options, and as painful as transitioning to another OS would be, Microsoft being able to spy on everyone at any time would be worth the pain. This would absolutely destroy MS's stock within a year as their dozens of multi-billion dollar contracts with governments and corporations evaporated. There's no way the data they're spying on would be worth the hundreds of billions they'd lose in sales.

...Then again, we've seen corporations kill themselves in dumber ways before... I guess we'll see.

[–] OpenStars@discuss.online 1 points 5 months ago

"Oopsie, we didn't mean to leave the libraries in like that, and then for that update to switch ON the collection of all data after people stopped paying attention to it, and then after a lot of data has been collected for that still additional update to cause all that data to be sent back to our home servers..."

And perhaps it would not even be a lie - one malicious actor, working inside the company, might be able to sneak it in without the higher-ups knowing about it. Or arguably worst of all, not even realize themselves that they did it, until after-the-fact.

When working with something dangerous - e.g. explosives, or heavy like a car - it behooves us to treat it with special care. The fact that this data collection option now exists already warrants greater care in using Microsoft products in terms of security. Except, just how much do people care?

I could also see another alternative moving forward: the DoS simply freezes their Windows versions at the last version that did not include the data collection capability, and then never updates again. As the first years and then decades roll by, and they are using the equivalent of Windows 7, then XP, then 95, then 3.1, they simply lose out on having "computers". Possibly here I've gone too far into the doom-and-gloom, b/c while it's possible it's not terribly plausible, though it illustrates how Microsoft is not committed to the safety of a national government, but rather instead solely their own profits - and short-term ones at that.

load more comments (5 replies)