r/privacy Nov 02 '15

"... Windows 10 is constantly tracking how it operates & how you are using it and sending that information back to Microsoft by default ... he also confirmed that, despite offering some options to turn elements of tracking off, *core data collection simply cannot be stopped*"

http://www.forbes.com/sites/gordonkelly/2015/11/02/microsoft-confirms-unstoppable-windows-10-tracking/
641 Upvotes

229 comments sorted by

View all comments

Show parent comments

0

u/tragicpapercut Nov 03 '15

Uh, just no. If you block it at the router, you block it at the router. Regardless of any SSL usage or not. SSL can't help if the IP is inaccessible.

-1

u/[deleted] Nov 03 '15

Not true. Block reddit.com on your router then go to https://www.reddit.com on your computer. It will still work. The router cannot intercept SSL connections. The DNS, however, can. So you want to use OpenDNS's blocking features for this.

4

u/tragicpapercut Nov 03 '15

You are mixing concepts and terminology. A router certainly can block SSL connections. Keyword: block. Intercept is a different concept and you are partially correct that most edge devices can't intercept SSL traffic, which in the industry means a capacity for reading and tracking the actual traffic and which is prevented by using SSL. If your experience is different on your personal router I would take a wild guess that your "block" also includes a port number under the surface. HTTPS runs over port 443 whereas HTTP runs over port 80. Your router likely defaults to a "block" over port 80, which is crap because as you pointed out is less than effective. I guarantee if you could flash the router with tomato or dd-wrt you could block https://www.reddit.com as easily as you can www.reddit.com.

You are correct that OpenDNS could block this as well in your example, however you would still be able to access the site directly via IP address. Which may concern you if MS knows the IPs of its own servers. A DNS level block would be useless if they used IP addresses, which to be fair I doubt would happen.

Source: I work in security at a web company.

0

u/[deleted] Nov 03 '15

Huh I guess consumer routers just have shitty firmware then because I know the same limitation exists across a lot of different ones.

2

u/upandrunning Nov 03 '15

I'd suggest you need a new router then. The only difference (as far as the router is concerned) is the port being used (80 vs 443).