Re: windows update reporting info back to MS? (and .NET fw SP1)

From: Mike Coppins (mike@legolas.com)
Date: 08/06/02


Date: Tue, 06 Aug 2002 17:16:10 +0100
To: focus-ms@securityfocus.com
From: Mike Coppins <mike@legolas.com>

At 02/08/2002 23:02, Elan Hasson wrote:
>Think about it, Windows update doesn't set a cookie, it just verifies a list
>of predefined files (version #s of system files etc.) and sends back to MS.
>MS checks to see if they are up to date and spits out what updates you need.
>Its as simple as that. Who cares if MS knows you run WMP 6.0 instead of 7.0?
>I don't see a problem here. Get over it.

So when does it become an issue? What do you regard as 'private
information', such as what non-MS software you run, or [if you do fill out
the MS Wallet info, for example] personal information you store on your
machine?

Why was it the case before that update analysis was performed at the client
end, now on the server end? Why the signifcant amounts of undeclared SSL
traffic?

If the server-side got compromised, what kind of information would be
available for the attacker on Microsoft's fairly vast customer base?

Personally, I'd prefer it from a privacy/security point of view if Windows
Update worked like this:

  1 - the client plugins are installed on request (currently the case);
  2 - Core OS patch information is retrieved by registry hits;
  3 - Client is requested to check what other MS products they would like
to check for updates for (such as Office, SQL Server, IIS, IE, etc). This
information should only be stored remotely after user has confirmed OK
after a warning about identifying information);
  4 - plugin scans registry for patch info on those products;
  5 - the client requests the patches not detected to be downloaded and
installed (currently the case)

If MS want to be doing undeclared SSL transactions, then they should
release a tool that allows people to view what data is being sent before it
gets encrypted, to show that their intentions aren't to be gathering
"private information" without consent of the user.

-- 
Mike Coppins
mike@legolas.com
http://www.legolas.com/



Relevant Pages

  • Re: Windows Update 0x80072F78 error and workaround
    ... Same problem here with the v6 site: using terminal server access I got ... through as far as the install step but then the download failed with error ... successful and, as an added benefit, allowed one rogue XP client to access ... I'm receiving the following error when selecting the "Windows Update" ...
    (microsoft.public.windowsupdate)
  • More Java Network Programming
    ... I currently have a working concurrent server and client program, ... wher the client requests the time, and the thread handling the client ... how to start with the protocol format. ...
    (comp.lang.java.programmer)
  • Re: SUS & GP
    ... Microsoft MVP (Windows Server System: ... >I have setup SUS to run on a win2003 member server which> has joined the win2k Domain running AD.I am trying to use> GP on the w2002 AD server to have client PC's update> internally instead of using Windows Update. ... The clients> still appear to utilize windows update though. ... The log files for SUS indicate> no client updates are being done. ...
    (microsoft.public.windows.group_policy)
  • Re: Remoting confusion!!!
    ... I would suggest that the server only handles a list of the clients' objects. ... If a specific client requests an object, ... "Holger Kasten" schrieb im Newsbeitrag ...
    (microsoft.public.dotnet.framework.remoting)
  • SUS & GP
    ... I have setup SUS to run on a win2003 member server which ... GP on the w2002 AD server to have client PC's update ... still appear to utilize windows update though. ...
    (microsoft.public.windows.group_policy)