Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows 10 Complete Endpoints for GDPR Compliance #115

Closed
ghost opened this issue Jul 26, 2018 · 5 comments
Closed

Windows 10 Complete Endpoints for GDPR Compliance #115

ghost opened this issue Jul 26, 2018 · 5 comments

Comments

@ghost
Copy link

ghost commented Jul 26, 2018

A couple of days ago, Microsoft had publicly available documentation containing their GDPR compliance form. Unfortunately, it has since been removed, however I made a local copy of all of it prior to that. This compliance form requires them to provide a complete list of all endpoints for data collection/transmission. I have the document hosted publicly for r/Privacy and others here. Keep in mind this document is 438 pages long, so be ready for a long night. I've already done a bit of analysis on it, which I will summarize the primary details below;

  • This compliance only applies to builds >= 1709. See page 357
  • Total diagnostics shut off is indeed possible. See page 425.
  • Complete list of enterprise endpoints and associated data. See page 358.
  • Windows 10 Versions >= 1709 diagnostic data at the Full level. Contains an index of sources, reports, and associated data. See page 330.

Additionally, I originated the post in r/privacy on Reddit containing all the information and further links to additional released information. You can find that thread here. I will continue updating both the thread and this report as I further my analysis. Let me know if I can be of any assistance.

*Note: Issues #104 and #114 cover some of this, but only a small fraction.

@cedws
Copy link

cedws commented Jul 26, 2018

You can find a concise description of the all endpoints here.

@crazy-max
Copy link
Owner

crazy-max commented Jul 26, 2018

Endpoints doc links have been added to the wiki
I will take a look to the gdpr doc thanks a lot for your input

@beerisgood
Copy link

I upload it for guys which doesnt trust nor want use mega.nz:
https://framadrop.org/r/GpMYLe2rNJ#XxTLxAAIIncJ7kLK8Q9J5LPmChsm8CDXdCfCbvzsg5c=
(expire in 60 days!)

@ghost
Copy link
Author

ghost commented Jul 27, 2018

Thank you @beerisgood. I was debating putting it in an encrypted container before uploading it for those that wanted it, but didn't have the time yesterday to do so.

crazy-max added a commit that referenced this issue Aug 13, 2018
Update IPs for extra, spy and update rules
Update wilcard domains settings (Issues #114 #115)
Update some rules based on Microsoft endpoints docs (Issues #114 #115)
Move i1.services.social.microsoft.com to extra (Issue #116)
@crazy-max
Copy link
Owner

GPDR doc has been added to the wiki and rules updated so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants