TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft is phoning home the content of PowerPoint slides

734 pointsby memorableover 2 years ago

66 comments

user3939382over 2 years ago
What I want is Little Snitch on steroids built into the OS where every process, including all native ones, including UI apps, are blocked from network connectivity by default, and the user gets an easy monitor of outgoing traffic with TLS&#x2F;SSL inspection built in (you&#x27;d need some OS API to enable that).<p>Kind of like granular oauth permissions, apps should have to declare which outgoing they have, a description&#x2F;why, and allow inspection of the actual traffic.<p>What Adobe CC, Google Chrome, MS Office, and macOS&#x2F;Windows itself do with this background network connectivity is completely out of control and abusive to the user. They get away with it because the vast majority of users are non-technical and don&#x27;t realize it&#x27;s happening.<p>I&#x27;ve profiled and decrypted the background traffic on a stock Android install and the volume was also appalling. Getting macOS to 0 background traffic involved blackholing large Apple IP blocks at the router, whereas some of their processes use random IPs from these ranges and don&#x27;t use DNS.<p>Just as the general public doesn&#x27;t have the awareness or ability to fight for their privacy rights I doubt any of this will ever be remedied.
评论 #33508574 未加载
评论 #33508243 未加载
评论 #33507664 未加载
评论 #33507972 未加载
评论 #33508901 未加载
评论 #33508194 未加载
评论 #33508104 未加载
评论 #33511022 未加载
评论 #33507557 未加载
评论 #33509428 未加载
评论 #33515299 未加载
评论 #33517351 未加载
评论 #33509895 未加载
评论 #33513139 未加载
评论 #33517603 未加载
评论 #33508321 未加载
评论 #33509358 未加载
评论 #33510223 未加载
评论 #33509012 未加载
评论 #33512602 未加载
评论 #33511176 未加载
评论 #33509497 未加载
评论 #33508459 未加载
评论 #33507811 未加载
Someone1234over 2 years ago
This is a one paragraph claim that doesn&#x27;t provide resources to show that their claim has basis. It could very well be entirely accurate, but there&#x27;s no information contained here to know one way or the other.<p>For example there have been numerous claims made previously that link ANY network traffic to a supposed invasion of privacy, but once you delve into the underlying traffic it isn&#x27;t nearly as nefarious as it initially seemed.<p>This article is telling you to &quot;open up the network monitor of your choice&quot; but network traffic and CONTENT are apples Vs. oranges, and yet we&#x27;re meant to draw conclusions from that? We&#x27;re meant to know Microsoft are taking your slide&#x27;s content whole-hog? Isn&#x27;t that yet to be determined?
评论 #33508610 未加载
评论 #33508033 未加载
评论 #33512309 未加载
semi-extrinsicover 2 years ago
I&#x27;ve raised this point repeatedly in different orgs. It&#x27;s met with some combination of indifference and lack of understanding and not-my-responsibility-ism, but I&#x27;m sure that this will eventually blow up hard in some company&#x27;s face - like 9-digit settlement for breach of contract, or worse things like breach of export control laws.<p>Enterprise data security on the &quot;MS Office level&quot; at this point is like driving 60 mph on a road with no lane dividers. You just pray that you never meet a drunk driver or someone texting in oncoming traffic who suddenly swerves into your lane. You pray that none of your employees click the wrong button and bankrupt the company.
评论 #33508027 未加载
评论 #33507241 未加载
评论 #33507281 未加载
评论 #33507724 未加载
评论 #33508337 未加载
评论 #33509251 未加载
评论 #33507351 未加载
pradnover 2 years ago
There&#x27;s a pervasive lack of precision in privacy discussions. There&#x27;s a difference between a network request that does some computation on the server side, one that does the same but may log errors and increment counters, and one that actually stores the data temporarily or for a long time. And in the last case, there&#x27;s a difference between the data being nigh-impossible for internal employees to access (perhaps only used as input for other automated systems), and data with few controls. What about the ability of the user to invoke a delete for all their data on the server side? There&#x27;s so many dimensions.<p>This is not a useless feature. I can imagine it might help someone make a better presentation. We have to weigh the <i>potential</i> privacy implications against that.<p>And asking the user to consent for every little thing isn&#x27;t the solution either. It&#x27;s so annoying to be pin-pricked by dialogs. At work, this sorta thing should be decided at the organization level, by setting appropriate fine-grained org policies for Office.
评论 #33509224 未加载
评论 #33511162 未加载
评论 #33509495 未加载
评论 #33548035 未加载
dougmwneover 2 years ago
This seems blindingly obvious? They use a cloud powered feature, then complain that information is sent to the cloud? According to this help article using designer for the first time will request permissions.<p><a href="https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;office&#x2F;create-professional-slide-layouts-with-designer-53c77d7b-dc40-45c2-b684-81415eac0617" rel="nofollow">https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;office&#x2F;create-profession...</a>
评论 #33511446 未加载
评论 #33519251 未加载
评论 #33512341 未加载
roody15over 2 years ago
The future of personal computing is really dark these days. I just attended an apple event for education and government. The amount of data tracking and the standardization&#x2F;normalization of this behavior is dystopian.<p>What happened to computers being just fun and a source of exploration and freedom?<p>Microsoft, Gooogle, Apple all constantly push their cloud based accounts … where everything is tracked.
评论 #33508248 未加载
评论 #33508794 未加载
评论 #33507721 未加载
评论 #33508645 未加载
dagmxover 2 years ago
This post is dubious at best. It makes a “do your own research claim” without sharing anything concrete.<p>Yet, this plays into people’s own confirmation biases so it’s already being taken verbatim by people here.
评论 #33509020 未加载
Waterluvianover 2 years ago
Obtaining user data should be a horrifying prospect for companies. They should obsessively work for alternative ways to not need it for their goals. And when they need it, to be ridiculously careful about it. (you could substitute &quot;user data&quot; for &quot;application state&quot; here)<p>But it&#x27;s not because there aren&#x27;t sufficient consequences. Memory leaks don&#x27;t properly crash the company as they should.
评论 #33509166 未加载
评论 #33508609 未加载
RajT88over 2 years ago
This doesn&#x27;t bother me too much (but it would if I worked at a different company - I&#x27;d have concerns over company secrets). It&#x27;s the browsing history which is by default sent to GOOG&#x2F;MSFT which bugs me. On by default, and I&#x27;d swear I&#x27;ve seen it get reset on Chrome.<p>Chrome:<p>Settings &gt; Sync and Google Services &gt; Make searches and browsing better<p>Edge:<p>Settings &gt; Privacy, Search and services &gt; Personalize your web experience
danukerover 2 years ago
LibreOffice FTW.<p><a href="https:&#x2F;&#x2F;libreoffice.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;libreoffice.org&#x2F;</a><p>It may be glitchy in some areas, but I&#x27;ve been using it since graduating high school, and I can do whatever I want with it.
评论 #33508374 未加载
评论 #33513777 未加载
评论 #33508902 未加载
评论 #33507584 未加载
NotYourLawyerover 2 years ago
Why doesn’t this article include the packet capture or whatever data he has that shows exactly what’s being sent?
评论 #33508389 未加载
评论 #33508249 未加载
评论 #33509366 未加载
评论 #33511608 未加载
dustedcodesover 2 years ago
Microsoft and Google have OneDrive and Google Drive where most slide decks are stored anyway so in some ways this is barely newsworthy, on the other hand I guess if someone purposefully selected Office instead of Google slides for their presentations and thought using an offline app which doesn&#x27;t save the files to their OneDrive would keep them secret might get surprised by this feature.
评论 #33508565 未加载
treeskneesover 2 years ago
I can&#x27;t say whether the blog is correct or not, as I haven&#x27;t seen the actual network traffic, but there are privacy controls that the author probably hasn&#x27;t configured [1]. If it was configured correctly, Designer wouldn&#x27;t even be available. So it&#x27;s not as though every user of PowerPoint will have their data collected by Microsoft.<p>[1] <a href="https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;deployoffice&#x2F;privacy&#x2F;manage-privacy-controls" rel="nofollow">https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;deployoffice&#x2F;privacy&#x2F;manag...</a>
评论 #33508717 未加载
teekertover 2 years ago
I guess since we all use MS mostly for business purposes we don&#x27;t care so much about privacy. It&#x27;s something our managers sign off on, in the name of security, features and really nice value for money. But oh boy, do they know a lot about us and our businesses. I mean, my office apps have &quot;LinkedIn services&quot; on by default [0], so they are linking all the things to all the things.<p>[0]: <a href="https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;office&#x2F;linkedin-in-microsoft-apps-and-services-6d7c5b09-d525-424a-9c18-8081ee7a67e8" rel="nofollow">https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;office&#x2F;linkedin-in-micro...</a>
jeroenhdover 2 years ago
Like I said last time:<p>&gt; Did we consent to this?<p>Yes, unless Microsoft doesn&#x27;t ask for consent in whatever country the author is from. There&#x27;s a consent popup that you need to click through that informs you that the content of your slides are shared with Microsoft. This is part of &quot;intelligent services&quot; in case you&#x27;re looking for the details.<p>The author should be able to turn this feature off easily, but yes, they did consent to this. They just might have done so months ago and forgotten about it.<p>Find out more about the &quot;intelligent services&quot; that also send the contents of your document to the cloud if you click on their respective buttons here: <a href="https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;deployoffice&#x2F;privacy&#x2F;connected-experiences" rel="nofollow">https:&#x2F;&#x2F;learn.microsoft.com&#x2F;en-us&#x2F;deployoffice&#x2F;privacy&#x2F;conne...</a>
评论 #33509800 未加载
评论 #33508933 未加载
TheRealDunkirkover 2 years ago
Is there any way to tell if your company has opted in? Mine makes a <i>huge</i> show of classifying Office documents and barking about the policies of what can be shown to outside people. It would be hilarious to find out that they&#x27;ve done this, and are letting Microsoft slurp up all the stuff that would get us fired if we sent it to an outside email address.
评论 #33507746 未加载
评论 #33507573 未加载
system2over 2 years ago
Dear Lazy OP,<p>Please use wireshark or something else to explain what those packages are. It might be downloading design features or some other data it requires.<p>100 word article really doesn&#x27;t do it for me.
dhruvdhover 2 years ago
PowerPoint has a feature where it uses machine learning to suggest layout and design changes for your content. This feature most likely can be turned off, but of course it needs some data on what&#x27;s on your slide to suggest changes.<p>I hope this submission is flagged and removed. Just because you don&#x27;t like Microsoft doesn&#x27;t mean such misrepresentation is okay.
评论 #33507006 未加载
评论 #33506900 未加载
评论 #33506890 未加载
评论 #33507014 未加载
评论 #33506908 未加载
评论 #33506880 未加载
评论 #33506913 未加载
评论 #33506915 未加载
评论 #33507430 未加载
sheerunover 2 years ago
The next era will be of Offline Apps because of stuff like this
评论 #33507333 未加载
评论 #33506932 未加载
评论 #33512600 未加载
评论 #33507314 未加载
评论 #33507081 未加载
deafpolygonover 2 years ago
You did consent to it, in the fine print. Unfortunately.
评论 #33506997 未加载
评论 #33508836 未加载
评论 #33506761 未加载
Mo3over 2 years ago
I wonder what the NSA or any other of these three-letter agencies think about that, I can remember much of the leaked information consisting of Powerpoint slides.
评论 #33507650 未加载
评论 #33508158 未加载
评论 #33507493 未加载
dudeinhawaiiover 2 years ago
This post seems to lack any useful information to come to the conclusion of &quot;phoning home the content of PowerPoint slides&quot;. That said, if you use the tool in question, you&#x27;ll notice that it only suggests layouts and these seem to be fairly generic. They don&#x27;t seem to take into account the content so much as how the content is laid out.<p>This could be as &quot;simple&quot; as Microsoft phoning home with the layout of the data (bullets vs title vs paragraph of text) combined with perhaps hash codes of any topical features (things that indicate technology vs food).<p>I&#x27;ve never been &quot;surprised&quot; by the feature the way I am with Github Copilot where it sometimes feels like it&#x27;s reading my mind. The Designer is just a simple way to click a button and get back 5+ recommendations on how you can layout the data.<p>Without some kind of evidence, my explanation is just as valid as the blog. That which can be asserted without evidence can be dismissed without evidence.
klyrsover 2 years ago
Well that&#x27;s cool, it&#x27;s just like Copilot but for confidential and proprietary information! I wonder if I can get a sneak peek into my competitor&#x27;s quarterly reports using this suggestion feature...
6stringmercover 2 years ago
Just because it is phoning home data doesn&#x27;t mean automatically it&#x27;s sending your data - more than likely it&#x27;s a block of stuff representing what is your data, because nobody wants to traffic in your copy&#x2F;pasted email FW:FW:FW:FW graphic at 6MB you use on every slide for your company logo. It&#x27;s just not practical to me, and if you don&#x27;t like that generic thing, well, disable Design suggestions. Pretty sure there&#x27;s a switch for that somewhere. Usually there is with Microsoft.<p>Paint: having Admin rights when you can find it since Windows 95
CarbonCyclesover 2 years ago
This is a fascinating multi-faceted problem...there is the outright concern of how much of the data is being exposed, but there is also a much more subtle action at play.<p>It appears that MS is using our data to continuously train their large DL networks to provide these recommendations...so what is to prevent a bad actor from cunningly constructing an asset that may trick the recommender into leaking insights from another company (or possibly poisoning the network itself)? These adversarial attacks have been well documented in academia.
A4ET8a8uTh0over 2 years ago
What I am kinda waiting ( and it is coming ) is for someone to find out that Excel actually gathers all interesting data under guise of automatic analysis ( ala copilot ). The financial sector will tremble as almost the entire human population existing in the spreadsheets in one form or another ( as long as they are on o365_v2 ) will have their data harvested daily and banks will be unlikely do anything about it.<p>Oh, look. We don&#x27;t need enter Jenkins account. Everything auto populates. And we did not even map it yet...
ttrrooppeerrover 2 years ago
&gt; Did we consent to this?<p>I did. I guess the author didn&#x27;t read the T&amp;Cs.
评论 #33506903 未加载
jklinger410over 2 years ago
&quot;We use MS products for our business because it provides enterprise level security&quot;
评论 #33507801 未加载
beckingzover 2 years ago
I look forward to the day when PowerPoint is banned due to enterprise security concerns.
评论 #33506871 未加载
评论 #33506941 未加载
评论 #33508772 未加载
评论 #33507787 未加载
Terrettaover 2 years ago
&gt; <i>Did we consent to this?</i><p>Yes, explicitly, and not in 60 pages of legalese, in a dialog box.
nokyaover 2 years ago
Microsoft and confidentiality of your data are two incompatible concepts.<p>Microsoft is basically the editor of a set of tools designed to make employees more productive. As long as you use Microsoft products with this in mind, there&#x27;s no ambiguity: you give Microsoft the data you work on, and it gives you productivity in return.<p>Unless you are the actual CEO of a company involved in trade secrets (or a defense organization), you shouldn&#x27;t care about Microsoft snitching the content of your slides, and everything else you write or see, to its own servers on the justification that it will make your experience better.<p>It&#x27;s not worth entering the debate, and if you accuse Microsoft you will probably need to accuse its competitors.<p>Just remember to keep out of anything Microsoft when you process anything strictly personal, and you will be more than fine.<p>P.s.: I almost forgot to answer your question. Yes, you approved this. And again, if it&#x27;s not your company, your boss very likely approved it and wouldn&#x27;t even consider the effort of looking into this, so it&#x27;s not your business. Literally.
kolbeover 2 years ago
If I were ever in a position to tell investment banks what to do, I would demand every pitch of theirs happen in a jupyter notebook.
squokkoover 2 years ago
Oh, the humanity! When you CLICK THE SLIDE DESIGNER button it sends your slides to a Slide Designer service? What hath God wrought?
trap_goes_hotover 2 years ago
This isn&#x27;t a black&#x2F;white issue. How about we let each person evaluate it for themselves? I find this feature useful, but if I were a sysadmin, I&#x27;d probably block it. Not because I don&#x27;t trust MS, but just that it opens up a vector that I would not want to manage.
didipover 2 years ago
Can you imagine, receiving all powerpoint content from your competitors (the rest of FAANG) in real time?
评论 #33507791 未加载
Tozenover 2 years ago
It&#x27;s not just PowerPoint, but other Microsoft products too. Their browser (Edge) is known for being on constant phone home, close doesn&#x27;t really mean close, self-update without user interaction, odd settings that cause privacy problems, after it updates itself makes changes to settings without user permissions or breaking various security-related extensions, etc...<p>It&#x27;s a pattern of general disrespect for user privacy and exploitation of unaware users for corporate and 3rd party entity benefit. Look no further than Microsoft&#x27;s Copilot, which is in the spotlight, and arguably has no respect for users copyright.<p>That PowerPoint (and other Office products) are phoning home users data, should be of no surprise whatsoever.
DerekBickertonover 2 years ago
On Windows there is Glasswire[0] for blocking applications that phone home. Just find the offending process and block it. It&#x27;s not a perfect solution though as Windows 10&#x2F;11 has hundreds of things that phone home and blocking them has unintended side effects (things crash randomly if they can&#x27;t talk to the Internet).<p>[0] <a href="https:&#x2F;&#x2F;www.glasswire.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.glasswire.com&#x2F;</a>
MasterYodaover 2 years ago
I use &quot;simplewall&quot; [1], a firewall to windows. What I like about it is you get a popup window every time a new program want to send data out, then you could block or accept it or temporary accept it. It&#x27;s crazy how many programs that wants to talk to the internet constantly.<p>[1] <a href="https:&#x2F;&#x2F;www.henrypp.org&#x2F;product&#x2F;simplewall" rel="nofollow">https:&#x2F;&#x2F;www.henrypp.org&#x2F;product&#x2F;simplewall</a>
NicoleJOover 2 years ago
Microsft windows store does the same thing, but worse.<p>Check out the developer panel to see for yourself.<p>Windows store downloads are accompanied by mouse trackers, keyloggers, and more.
matternotover 2 years ago
How it was determined that it phones back the content of the slide ? From my understanding it&#x27;s just exchanging some network packets.
bastardoperatorover 2 years ago
Meanwhile half the slide decks I see are built on Google. You can&#x27;t even get to the slides without phoning home.
nunobritoover 2 years ago
Office itself is a cloud service nowadays. That phoning home feature is part of the online saving so that you can resume work from a browser or contribute collaboratively with other users across the network like a google docs, but on the desktop.<p>Does it beam home? Yes Do I like it? No<p>We have LibreOffice for decades. Be the change.
someweirdpersonover 2 years ago
With all data stored on a sharepoint or onedrive, and powerpoint running in a browser... where&#x27;s the news?
2b3a51over 2 years ago
Just wondering along the lines of &#x27;perhaps a cigar <i>really</i> is a cigar&#x27;.<p>What would Microsoft be doing with the text of every PowerPoint presentation once they have analysed the style&#x2F;font&#x2F;content information?<p>Must be thousands of slides per hour 24&#x2F;7 for years. How long is this information kept?
aaghaover 2 years ago
Step 3 - Turn it off:<p><a href="https:&#x2F;&#x2F;www.avantixlearning.ca&#x2F;microsoft-powerpoint&#x2F;how-to-stop-design-ideas-in-powerpoint-disable-powerpoint-designer&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.avantixlearning.ca&#x2F;microsoft-powerpoint&#x2F;how-to-s...</a>
bitwizeover 2 years ago
Microsoft Office is, in general, straight up spyware now. It reports usage statistics back to your boss. Marietta can now see exactly how long YT&#x27;s mom took to read that toilet paper memo, and make disciplinary decisions accordingly.
HardwareLustover 2 years ago
Yes, you consented to this when you clicked through the TOS without reading it.
matternotover 2 years ago
how was it determined that it is phoning home the content of the slides? One thing is to exchange network packets with a remote server, and another thing is to claim that it&#x27;s leaking slide content.
midislackover 2 years ago
Well, you do agree to license Microsoft any intellectual property you create with their software, for free, in perpetuity. So it’s kind of on YOU if you still use their products.
taubekover 2 years ago
I don&#x27;t have PowerPoint on my computer so I don&#x27;t know if it works without Internet connection. Can someone tell me what happens if there is no network access?
评论 #33509390 未加载
pjmlpover 2 years ago
While this isn&#x27;t acceptable, millions enjoy sharing the content of their documents every day with Google, with a document suite running on their servers.
heikkilevantoover 2 years ago
So, what is the best way to game the system? Make many offensive Power Point presentations or silly layouts and hope the system starts to recommend them to others?
cm42over 2 years ago
&quot;Informed Consent is just a theory. Besides [other app] already spies on you so who cares? Whaddareya doing in PowerPoint that&#x27;s so sekret?&quot;
评论 #33506866 未加载
评论 #33506977 未加载
评论 #33506804 未加载
评论 #33506821 未加载
alfiedotwtfover 2 years ago
So when US politicians say TikTok needs to be banned because it&#x27;s effectively spyware, why are they silent when the same happens from US companies
评论 #33518933 未加载
changoplataneroover 2 years ago
I always assumed they built these features by scraping publicly available powerpoint presentations using their index from Bing.
ZebusJesusover 2 years ago
This is one reason i use NextDNS, they have a list of Microsoft and apple servers ready to be blocked with a simple toggle.
adamsmith143over 2 years ago
This seems kind of shocking, is MS really hoarding the trade secrets of like every Fortune 500 company on their servers?
mslaover 2 years ago
And governments think Microsoft doesn&#x27;t spy on them, that it&#x27;s impossible to hide communications.
thedudeabides5over 2 years ago
Is this why the default fonts in my office randomly changed the other week?
SanjayMehtaover 2 years ago
I don&#x27;t even allow browser search suggestions; this is beyond the pale.
ZebusJesusover 2 years ago
NextDNS for the win, great filter lists for Microsoft and apple.
Mikeb85over 2 years ago
Lol of course they are. Never change MS.
shmerlover 2 years ago
LibreOffice is an option.
ramonover 2 years ago
That is the price of AI, if you want you can move to an Amish town and give up on internet.
underscore_kuover 2 years ago
use Linux... it&#x27;s free and doesn&#x27;t spy on you
twstdzpprover 2 years ago
Y&#x27;all sound a little too paranoid. Chill