Hacker News new | past | comments | ask | show | jobs | submit login

That is putting a lot of faith in both Microsoft and the windows firewall, which has historically been very weak. Microsoft has also indicated that they're not adverse to bypassing users' obvious attempts to protect themselves from spying, for example: bypassing hosts file entries for telemetric data exfiltration. So while the firewall might work today, there is absolutely nothing preventing a future update from silently changing the rules of the game.



I think if that is your level of concern, you have to not use Windows, not try to patch over their control of the firewall.


Presumably Microsoft are worrying by now that corporate customers with knowledgeable IT departments will reach exactly that conclusion.


Wouldn't those users tend to have a hardware perimeter that they could use to verify the behavior of Windows?

Also, I think if Microsoft is actually worried about losing those users, it would choose not to subvert the firewall.


I suspect the problem will be if they have independent security tools near their network edge that MITM their own traffic, as discussed elsewhere on HN recently. If Microsoft are hard-coding addresses and certificate details for its online services within Windows itself, the security tools won't be able to inspect that traffic, and will probably be set to block it by default.

I suspect the kinds of organisations operating these tools would consider that "working as intended" in most cases, but if it interferes with the enterprise-grade configuration and update management tools then that could be an issue for them.


My point was that they will be able to detect if Microsoft is subverting the Windows Firewall, trivially. So it would be incompetent for Microsoft to subvert the firewall and expect those users not to notice and incredibly foolish for Microsoft to do it if they think those users will object by moving away from Windows.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: