My company is moving to Windows 11, I had one of my service desk teammates tell me that for an IT support person I’m very critical of change
Before Windows 11 I was critical of change because every change came with no new training for my team and a giant email to the company explaining very lazily about the changes and with the same text at the end of every email… “Any problems call the service desk”.
Now we’ve lost active directory… Now I’m in a position where an incredibly incompetent IT security have restricted our access to intune and Entra and then the business wants me to still perform my daily duties as normal.
Upside is that same IT security is getting removed in the next few weeks.
Probably to be replaced by someone else even worse.
I just want to learn how to use Entra and Intune… Everything Microsoft touches turns to shit.
Active directory just worked… It was built when people at Microsoft actually knew how the operating system worked… None of those people are still at Microsoft…
If you enjoyed how AD worked, you’ll love how I tune and AAD don’t.
And the workarounds for them… Like local management… Only get harder.
Good luck.
Smug Reddit-level takes left and right in this thread. The kid successfully hacked a website, you can assume he knows what he’s doing better than you and followed all the best practices short of not using Windows. They didn’t get his account from his Edge credential store. He probably used some Firefox-derivative. Tor browser if he was stupid. He probably “hardened” Windows every way he could think of, again, short of disconnecting from the internet. Windows simply does a good job of spying on you, that’s all it is.
There are even people in the thread recommending running Windows games on Linux as a way to avoid this surveillance. If you put Microsoft Flight Sim on your Linux computer, then that’s now a Windows computer. Microsoft owns that computer, same as the Windows one. If you install Nvidia drivers, Nvidia owns that computer, and the USA can ask Nvidia for your accounts and whereabouts instead of Microsoft. If you put Steam on your Linux computer, that’s now Steam’s computer and the USA can ask Steam.
There is no “safe” amount of malware.
Why tor if he was stupid? I am stupid.
The security of Tor is built on the assumption that one actor owning a majority of the nodes is improbable to the point of being written off as a non-concern. The tool has always been run and maintained by the USA government. When they opened access to the public, they owned the majority of the nodes, and with the amount of compute available to the NSA (look up the size of their official data-centres, add in their hacked bot-farms), it’s almost certain they still do. If it wasn’t their plan to always have supremacy, they aren’t doing their job. The purpose of Tor is to hide traffic from USA’s enemies. A few tens of thousands of private users is just reducing their power bill and painting targets on their own backs, not successfully hiding from the NSA.
I appreciate the explanation. If not Tor, for very obvious reasons you specified, what is the better alternative?
There isn’t a 1-step perfect solution as far as I know. You can use Tor in combination with other technologies, and it’ll likely help you avoid a lot of surveillance, just not specifically the NSA. (Also keep in mind anyone/commercial actors can run Tor nodes with the intention of spying on Tor users. You need a lot of nodes to catch anyone, but I wouldn’t assume it never happens).
The main thing is to own your software and hardware, and disconnect what you don’t own from the internet. If you can’t meet those conditions, then it’s impossible no matter how vigilant and knowledgable you are.
My recommendations is to play your computer games on an offline computer via GOG purchases, or if you want Steam games, then just give up on securing that device. Have two networks. Have your secure computers for your general online tasks and chatting, and have the unsecure computer for interacting with DRM and services that lose a lot of functionality if the surveillance vectors are blocked.
Bad attempts at hardening often don’t work, and have the adverse effect of making you more unique for fingerprinting. It might be worth foregoing some hardening advice if you can think of workarounds the hostile actor might use, which you don’t know how to counter-act.
Hacker
Uses windows
He got what he fucking deserved



