Windows Error Reporting: Difference between revisions

Content deleted Content added
No edit summary
Privacy concerns and use by the NSA: ==Privacy concerns and use by the NSA== Although Microsoft has made privacy assurances, they acknowledge that personally identifiable information could be contained in the memory and application data compiled in the 100-200 KB "minidumps" that Windows Error Reporting compiles and sends back to Microsoft. They insist that in case personal data is sent to Microsoft, it won't be used to identify users, according to Microsoft's privacy policy....
Tags: Mobile edit Mobile web edit
Line 51:
 
==Privacy concerns and use by the NSA==
Although Microsoft
Although Microsoft has made privacy assurances, they acknowledge that [[personally identifiable information]] could be contained in the memory and application data compiled in the 100-200&nbsp;KB "minidumps" that Windows Error Reporting compiles and sends back to Microsoft. They insist that in case personal data is sent to Microsoft, it won't be used to identify users, according to Microsoft's [[privacy policy]].<ref>[http://oca.microsoft.com/en/dcp20.asp Microsoft Privacy Statement for Error Reporting]</ref><ref>[http://support.microsoft.com/kb/283768/ Description of the end user privacy policy in application error reporting when you are using Office]</ref> But in reporting issues to Microsoft, users need to trust Microsoft's partners as well. About 450 partners have been granted access to the error reporting database to see records related to their [[device driver]]s and apps.<ref>{{cite web | url = https://rcpmag.com/articles/2002/10/03/microsoft-error-reporting-drives-bug-fixing-efforts.aspx | title = Microsoft Error Reporting Drives Bug Fixing Efforts | last = Bekker | first = Scott | date = 3 October 2002 | website = Redmond Partner Channel | publisher = 1105 Redmond Media Group}}</ref>
 
Older versions of WER send data without encryption; only WER from [[Windows 8]] uses TLS encryption.<ref name="wsense2013-12"/> In March 2014, Microsoft released an update (KB2929733) for Windows Vista, 7 and Server 2008 that encrypts the first stage of WER.<ref>{{cite web|title=The first stage of the WER protocol is not SSL encrypted in Windows|url=http://support.microsoft.com/kb/2929733|publisher=Microsoft|access-date=10 January 2015|date=11 March 2014}}</ref>