Windows 10 Privacy - Keylogger


Recommended Posts

It seems pretty simple to me.  How do you expect Cortana or learn or inking to get better if they don't record those things?  I understand your privacy concerns, but people want "better and easier".  It's that simple.  If you don't like it, don't use it.

I must have missed where they made it a law to use Windows 10...

  • Like 2

I agree with Logical Apex its a worthy discussion, and a bad sign that asking such questions is met with responses like 'stop complaining' or ''abcd' do it too so its all good'

I was unaware inking was also sent also thought this was only applicable to the insider program, very surprised it's in the final release.

Clearly a lot of people aren't concerned with these topics and that's fine but i'd definitely like more information from MS on what is collected, how it is secured and if its tied to personal id.  Even basic things like how does it differentiate between collecting data regularly and not collecting your bank information?  Is inprivate mode a contradiction, what privacy do you have if its collecting data when in this mode?

That must be it. Microsoft wants your banking information. They intentionally put out a product that steals your personal information because that wouldn't totally screw up their reputation or anything.

Seriously, this is not a keylogger. Do you realize how stupid that sounds as a business decision? Microsoft shipping an OS that steals your banking passwords would be like Toyota intentionally giving you a car with no brakes. They'd go bankrupt over night if they did something like that.

It seems pretty simple to me.  How do you expect Cortana or learn or inking to get better if they don't record those things?  I understand your privacy concerns, but people want "better and easier".  It's that simple.  If you don't like it, don't use it.

I must have missed where they made it a law to use Windows 10...

This is why I am confused about the need for this feature. If you turn on Cortana I would expect certain amounts of privacy reduction as that is the nature of the feature, but this is separate from Cortana. This is recording your text and speech even with Cortana turned off. As I'm requested to enable Cortana after installation. Cortana isn't enabled by default, but this is.

That must be it. Microsoft wants your banking information. They intentionally put out a product that steals your personal information because that wouldn't totally screw up their reputation or anything.

Seriously, this is not a keylogger. Do you realize how stupid that sounds as a business decision? Microsoft shipping an OS that steals your banking passwords would be like Toyota intentionally giving you a car with no brakes. They'd go bankrupt over night if they did something like that.

No one said Microsoft wants your banking details, but they do want details. Irrespective of what Microsoft wants a system wide recording of keystrokes and voice data should be concerning to people. Even if Microsoft has no intention of doing "bad" things with the data (which I am sure they don't intend to do "bad" things) you're left wondering about the risks in face of the recent high profile hacking cases. Even ignoring the hacking scenario... I think it is a very large step in the wrong direction for MS to, by default, record such a wide berth of user data. The majority of users don't change the defaults and without them making use of things like Cortana this seems like a strong sign of how Microsoft intends to make back the "free" Windows 10 upgrade costs (by trying to rival Google in the ad revenue department due to their attempt at a richer profile of the user... Google gets search and browsing... Microsoft gets every typed and spoken word).

Since everyone keeps saying this isn't a keylogger... Please, enlighten me to the definition of a Keylogger... A keylogger doesn't have to be malicious, it just needs to record key strokes.

  • Like 3

User:  Microsoft, build us a better OS.

Microsoft: No problem!  We would like you to opt-in with anonymous data collection so that we can see how people are using the OS and cater to that.

User: Wha? Send you info about how I use my OS, No way!  Invasion of privacy! Keylogger!

Microsoft: ...so you want us to improve the OS, but not have a method to see how people use the OS now?

 

That my friends, is how we end up with OS atrocities.

There is no keylogger. The system is not watching key presses, but user-initiated typing prediction fixes. 

Read this twitter thread for all replies from Gabe Aul:

https://twitter.com/gabeaul/status/564291796935528448

https://twitter.com/GabeAul/status/605484176352026624

User:  Microsoft, build us a better OS.

Microsoft: No problem!  We would like you to opt-in with anonymous data collection so that we can see how people are using the OS and cater to that.

User: Wha? Send you info about how I use my OS, No way!  Invasion of privacy! Keylogger!

Microsoft: ...so you want us to improve the OS, but not have a method to see how people use the OS now?

 

That my friends, is how we end up with OS atrocities.

Nice story, but Microsoft's Privacy Policy says that this isn't anonymous data collection. It is, in fact, tied to the user account directly...

But I guess the lawyers don't understand how it works?

There is no keylogger. Read this twitter thread for all replies from Gabe Aul:

https://twitter.com/gabeaul/status/564291796935528448

https://twitter.com/GabeAul/status/605484176352026624

As I stated above, the Privacy Policy states clearly that this is not anonymous data collection. That it is, in fact, tied to the user's account. MS claims to attempt to scrub it of certain data, but they aren't clear how they scrub it or any of those details...

But I guess MS' General Counsel doesn't have a clue?

Microsoft collects and uses data about your speech, inking (handwriting), and typing on Windows devices to help improve and personalize our ability to correctly recognize your input.

For example, to provide personalized speech recognition, we collect your voice input, as well your name and nickname, your recent calendar events and the names of the people in your appointments, and information about your contacts including names and nicknames. This additional data enables us to better recognize people and events when you dictate messages or documents.

Additionally, your typed and handwritten words are collected to provide you a personalized user dictionary, help you type and write on your device with better character recognition, and provide you with text suggestions as you type or write. Typing data includes a sample of characters and words you type, which we scrub to remove IDs, IP addresses, and other potential identifiers.  It also includes associated performance data, such as changes you manually make to text as well as words you've added to the dictionary.

Source: Windows Privacy Policy

I tend to trust the legal contracts more than random Twitter posts.

Can we move on to a discussion of the shift in Windows away from user privacy? And stop splitting hairs on the privacy reduction?

 

Nice story, but Microsoft's Privacy Policy says that this isn't anonymous data collection. It is, in fact, tied to the user account directly...

But I guess the lawyers don't understand how it works?

 

As I stated above, the Privacy Policy states clearly that this is not anonymous data collection. That it is, in fact, tied to the user's account. MS claims to attempt to scrub it of certain data, but they aren't clear how they scrub it or any of those details...

But I guess MS' General Counsel doesn't have a clue?

Source: Windows Privacy Policy

I tend to trust the legal contracts more than random Twitter posts.

Can we move on to a discussion of the shift in Windows away from user privacy? And stop splitting hairs on the privacy reduction?

Not anonymous?

So you are telling me they are classifying the data per user?

 

Riiiiight.

 

I must admit, what choices do we have as gamers and pc enthusiasts?

I play ESO, and some TF2, I'd drop Windows for Linux in a heartbeat, but i am no coder, while I get on with OSX I use that for work, and until I can find someone selling a psu for a EMC 2429 my iMac is out of action so I can't use that for gaming.

Long story short, we are stuck with Windows 10, I am on home though, that does concern me.

It's an important discussion. It is also one that will be impossible to have on Neowin. Pretty sad really.

Seriously... coming back to Neowin after a long time away and it just seems like the circle jerk reddit is....  IMO, if you don't have anything to contribute I don't know why people are bothering to post here...

 

OnTopic: This is concerning that it's enabled by default, but aslong as there is a clear method(easy to find in the UI, no tech experience needed) to disable these features that actually disables them(doesn't just appear to) then i'm okay with it.  I understand completely why Microsoft would want these features and I certainly see the value in it.  I think the responsibility lies on the end user here to know what they are running and turn the features off if they don't wan them on.

 

Would it be nice if I were informed and given the option at installation?  Sure... but I don't think its a "huge step in the wrong direction" just to have the default settings be the ones that benefit the most users and the company creating the software(and offering it for free) the most.  I certainly don't want my encryption keys in the cloud, but if im given the option to store them locally i'm good... I don't want my keystrokes or voice recorded, aslong as I can turn it off i'm good.

Overall, it'd be nice if they were a bit more transparent about it instead of throwing it into the ToS or w/e you agree to when installing the program that nobody will ever actually read(not that that's an excuse.. you're still agreeing to it); but at the end of the day if It can be turned off without jumping through hoops then I don't have any problems with it myself.

 

Nice story, but Microsoft's Privacy Policy says that this isn't anonymous data collection. It is, in fact, tied to the user account directly...

But I guess the lawyers don't understand how it works?

 

As I stated above, the Privacy Policy states clearly that this is not anonymous data collection. That it is, in fact, tied to the user's account. MS claims to attempt to scrub it of certain data, but they aren't clear how they scrub it or any of those details...

But I guess MS' General Counsel doesn't have a clue?

Source: Windows Privacy Policy

I tend to trust the legal contracts more than random Twitter posts.

Can we move on to a discussion of the shift in Windows away from user privacy? And stop splitting hairs on the privacy reduction?

My guess is that maybe they classify it as 'anonomous' because it's only tied to our user account which doesn't necessarily identify you?  One could easily have a fake user account(not tried to SSN).... it's almost like the whole 'open wifi' ordeal as far as legal permissibility of it goes.... but I do understand that that's a pretty weak way of putting it.  I'm also completely ignorant to the legal precedence here with regard to what constitutes anonymous on the internet... but i'd imagine MS's general counsel has a pretty good idea..

...... you're still agreeing to it); but at the end of the day if It can be turned off without jumping through hoops then I don't have any problems with it myself.

The problem is it can't be turned off without going through hoops. This is where people are having issue. If it was a simple setting to turn off sending telemetry, this topic would have ended on the first page itself. But Microsoft is being unethical and profiling it's users probably more than what Google does.

The problem is it can't be turned off without going through hoops. This is where people are having issue. If it was a simple setting to turn off sending telemetry, this topic would have ended on the first page itself. But Microsoft is being unethical and profiling it's users probably more than what Google does.

 

 

Thank you for the clarification, some of the comments I had read implied that it could be easily turned off.  I do agree that this IS a significant issue under these conditions... free or not I want my data to stay local unless I explicitly say otherwise.

 

How so? A Keylogger is a program that captures key-presses...

Source: https://en.wikipedia.org/wiki/Keystroke_logging

 

It is a keylogger... Obviously, I don't think Microsoft aims to log into you bank account using the data, but it is an important thing to discuss at any rate... From a privacy perspective it is worthy of a question.

 

I'd disagree... Discussing the loss of privacy and the implications of a keylogger in the OS is valid. Especially with the extent and frequency of recent data breaches. It is a valid discussion. How does Microsoft limit its data collection? Do they tie it to user accounts? What do they do to limit capturing of passwords and usernames and the like. Again, worthy of a discussion as this is a major shift for the computing industry...

But I do understand that discussions can often be hard to have. Judging by the lack of one here. I'll just conclude that privacy is a non-issue. At least among the crowd here...

true in definition, i'm just used keylogger being related to something malicious!

If you're religiously attached to the idea that there is literally a "keylogger" here instead of the collection of user-initiated typing/inking corrections made to keyboard autocomplete suggestions in order to update the local user suggestion dictionary and improve the default prediction system for other users over time (you would see this with periodic input windows updates since years ago) that has existed in Windows for over a decade, particularly for use with the CJK IMEs, and has simply been extended to the other language keyboards, despite all evidence to the contrary, then there's no discussion to be had, as we'd be unfortunately entering FUD territory, grasping for any evidence to support a predetermined conclusion/conspiracy. It's disappointing to see this kind of willful misinterpretation, although seeing this credulously reported as news clickbait on a tech site wouldn't be surprising.
 
Incidentally, the CJK IMEs have been extended further in win10 with online prediction, as well, but this requires an opt-in checkbox to be set in an obscure dialog box to enable: http://windows.microsoft.com/en-us/windows-10/advanced-input-methods-for-east-asian-languages#v1h=tab02

User:  Microsoft, build us a better OS.

Microsoft: No problem!  We would like you to opt-in with anonymous data collection so that we can see how people are using the OS and cater to that.

User: Wha? Send you info about how I use my OS, No way!  Invasion of privacy! Keylogger!

Microsoft: ...so you want us to improve the OS, but not have a method to see how people use the OS now?

That my friends, is how we end up with OS atrocities.

yes because recording what users do on their computer is the ONLY way software can ever be improved....makes you wonder how we ever made software beforehand!!

Sarcasm aside, the one dimensional arguments of some of you guys are worrying. 

Even worse that if this is the ultimate way of getting user feedback and Windows 10 is the best result we can expect, we should all be collectively disappointed.

  • Like 2

So is this suggesting that the method on the first page (of this thread) doesn't properly disable the data collection? or is it suggesting that turning it off via the GPE only does nothing unless you are on an enterprise version?

yes because recording what users do on their computer is the ONLY way software can ever be improved....makes you wonder how we ever made software beforehand!!
Sarcasm aside, the one dimensional arguments of some of you guys are worrying. 

Even worse that if this is the ultimate way of getting user feedback and Windows 10 is the best result we can expect, we should all be collectively disappointed.

Anyone or any company who claims they can determine the needs and wants of a large user base without data collection is a liar.

  • Like 2

Anyone or any company who claims they can determine the needs and wants of a large user base without data collection is a liar.

I must have missed the conversation where someone, even myself suggested software improvements could be done without data collection. 

If I ask you did you "did you miss learning critical thinking at university?" and you responded 'yep' I've just collected data.  On the other hand I could collect all your posts and use that as a basis of determining if you have critical thinking abilities. 

Both are forms of data collection, and there are a lot more ways in between both of those extremes of the spectrum.  Crazy to imagine a world where there might be more than one tool and one way to do things isn't it....

I must have missed the conversation where someone, even myself suggested software improvements could be done without data collection. 

If I ask you did you "did you miss learning critical thinking at university?" and you responded 'yep' I've just collected data.  On the other hand I could collect all your posts and use that as a basis of determining if you have critical thinking abilities. 

Both are forms of data collection, and there are a lot more ways in between both of those extremes of the spectrum.  Crazy to imagine a world where there might be more than one tool and one way to do things isn't it....

 

 

  As for what you missed, you are the one who said it, despite your attempt to hide it with snark.

yes because recording what users do on their computer is the ONLY way software can ever be improved....makes you wonder how we ever made software beforehand!!
Sarcasm aside, the one dimensional arguments of some of you guys are worrying. 

Even worse that if this is the ultimate way of getting user feedback and Windows 10 is the best result we can expect, we should all be collectively disappointed.

So quick to forget.

Edited by adrynalyne

User:  Microsoft, build us a better OS.

Microsoft: No problem!  We would like you to opt-in with anonymous data collection so that we can see how people are using the OS and cater to that.

User: Wha? Send you info about how I use my OS, No way!  Invasion of privacy! Keylogger!

Microsoft: ...so you want us to improve the OS, but not have a method to see how people use the OS now?

 

That my friends, is how we end up with OS atrocities.

I'm pretty sure they don't need to know what's on my calender to make the OS better.

This topic is now closed to further replies.
  • Posts

    • Signal accuses UK government of using child safety as cover for mass surveillance by David Uzondu Recently, the UK's Home Office announced a sweeping set of proposals to make Britain the "first country in the world" where children cannot share or view nude photos on their smart devices, an initiative that authorities claim will protect children from online predators and combat pornography. In response, Signal believes that while the government must keep children "safe" and "protected," it should do so through social services and education, not by "surveillance, funding cuts, and cover-ups." The company called the plan "dystopian" and warned that it violates everyone's fundamental right to privacy, arguing that scanning on the presumption of nudity will only strengthen the market dominance and data control of giant corporations like Apple and Google. The statement continues by accusing the government of hiding its true intentions under the guise of child safety. Signal argues that the Home Office is building an invisible surveillance infrastructure that remains ripe for exploitation by future administrations and authoritarian regimes. According to the company, this aggressive approach completely ignores the actual needs of young people, such as properly funded schools and mental health services. Tech companies like Apple and Google have a three-month window to implement these mandatory device-level filters across the United Kingdom. If these tech firms refuse to comply with the mandate, the government will pass emergency legislation to force them to comply, threatening massive fines and even going after the CEOs of these companies with criminal charges. The technology will work by blocking explicit images directly on the operating system of all smartphones and tablets by default. This system monitors the device camera and third-party apps to intercept nudity before anyone can upload or send the image. Adults can still view explicit content, but only after completing a strict age verification check to unlock their devices. Several bodies like the NSPCC and Barnardo's praised the Home Office's decision, arguing that device-level intervention stops the cycle of grooming before it starts. The Internet Watch Foundation (IWF) also supported the policy, claiming that tech companies can implement on-device checks "without threatening privacy or collecting any data."
    • Did you watch the keynote? It is way beyond what is described in this article. Looks interesting. Now it is time for them to deliver unlike what happened in 24.
    • It pretty much has to be compatible with MS Office or it is going nowhere. The rest of the world runs office including Europe. If it is not compatible it will not survive.
    • Incredible deal gets you free NVMe 512GB SSD with AMD AM5 B850 motherboard for only $150 by Sayan Sen Earlier this week we covered the story of an interesting PC case wherein you can build two full-size computers inside it as in it can house and run an AMD and an Intel system simultaneously. Speaking of building PCs, these are hard times to make one for sure as prices are often very high except during flash sales or discounts. If you are in the market for a 1080p gaming PC then Nvidia's 8GB RTX 5060 Ti is currently on sale for just $330 and you get the latest James Bond game too, for free. Speaking of which, right now there is another incredible sale going on as we can get a free 512 GB NVMe SSD from TeamGroup in the form of the G50 alongside the purchase of an AMD B850 socket AM5 motherboard for only $150 (purchase link under the specs table down below). Getting an AM5 motherboard now in 2026 will be a wise investment for sure, especially since AMD confirmed its commitment to support the socket till at least 2029. The MSI PRO B850M-P WIFI is a micro-ATX motherboard that is compatible with AMD Ryzen 9000 series processors. Since it is AM5, the motherboard works with DDR5 memory and includes MSI’s Memory Boost technology, along with EXPO and XMP support. Connectivity features include built-in Wi-Fi 7 paired with a 5G LAN solution. The board offers a PCIe 5.0 M.2 slot with MSI’s EZ M.2 Shield Frozr II thermal solution, that is said to help maintain SSD performance by providing ample cooling against overheating. The technical specifications of the MSI PRO B850M-P WIFI motherboard are given in the table below: Specification Value Form Factor Micro-ATX (mATX), 243.84 × 243.84 mm Chipset AMD B850 Socket AM5 Supported Processors AMD Ryzen 9000, 8000, and 7000 Series Desktop Processors Memory Slots 4 × DDR5 UDIMM Max Memory 256 GB Memory Speed DDR5 8200–5600 MT/s (OC), DDR5 5600–4800 MT/s (JEDEC) Display Outputs 1 × HDMI 2.1 (up to 4K 60Hz) 1 × DisplayPort 1.4 (up to 4K 60Hz) PCIe Slots 1 × PCIe 5.0 x16 (CPU) 3 × PCIe 3.0 x1 (Chipset) Audio Codec Realtek ALC897 Audio Channels 7.1-Channel High Definition Audio M.2 Slots 3 × M.2 slots M.2_1: PCIe 5.0 x4 (CPU) M.2_2: PCIe 4.0 x4 (CPU) M.2_3: PCIe 4.0 x2 (Chipset) M.2 Device Sizes M.2_1: 2280/2260 M.2_2: 2280/2260 M.2_3: 2280 SATA Ports 4 × SATA 6Gb/s RAID Support SATA: RAID 0, 1, 10 NVMe: RAID 0, 1, 5, 10 Rear USB Ports 4 × USB 2.0 2 × USB 5Gbps Type-A 1 × USB 10Gbps Type-A 1 × USB 10Gbps Type-C Front USB Headers 4 × USB 2.0 4 × USB 5Gbps Type-A 1 × USB 10Gbps Type-C LAN Realtek 8126VB 5Gb Ethernet Wireless Networking Wi-Fi 7 (802.11 a/b/g/n/ac/ax/be) Tri-band 2.4GHz / 5GHz / 6GHz MU-MIMO, MLO, 4KQAM Up to 2.9Gbps Bluetooth Bluetooth 5.4 Internal Power Connectors 1 × 24-pin ATX Power 1 × CPU Power 1 × PCIe Power (8-pin) Cooling Headers 1 × CPU Fan 1 × Combo Fan/Pump 3 × System Fan RGB Headers 3 × Addressable RGB Gen2 (JARGB_V2) 1 × RGB LED (JRGB) Additional Internal Headers 2 × Front Panel (JFP) 1 × Chassis Intrusion (JCI) 1 × Front Audio (JAUD) 1 × COM Port (JCOM) 1 × JDASH Tuning Controller 1 × TPM 2.0 Header The free TeamGroup T-FORCE G50 NVMe SSD is a PCIe Gen4 and as such it promises to deliver sequential read speeds of up to 5,000 MB/s, helping accelerate game loading, file transfers, and everyday computing tasks. The SSD features an InnoGrit controller and SLC caching technology to support consistent performance. An ultra-thin, patented graphene heatsink is included to aid in heat dissipation. The NAND flash is based on TLC which means it has plenty of endurance up its sleeve. The random performance may not be as amazing as other drives with DRAM though. Still it should be very good since it can access system memory via HMB to use it as its DRAM cache. The technical specifications of the TeamGroup 512GB G50 NVMe SSD are given in the table below: Specification Value Model / Part Number TM8FFE512G0C129 Form Factor M.2 2280 Interface PCIe Gen4x4 with NVMe Sequential Read Speed Up to 5,000 MB/s Sequential Write Speed Up to 2,500 MB/s Endurance (TBW) 325 TBW DRAM Cache No Cache Technology SLC Cache Controller InnoGrit Controller Solution Operating Temperature 0°C to 70°C Storage Temperature -40°C to 85°C Weight 7 g Dimensions 80.0 × 22.0 × 3.7 mm Vibration Resistance 80 Hz ~ 2,000 Hz / 20G Shock Resistance 1,500G / 0.5 ms MTBF 3,000,000 hours Get it at the link below: MSI PRO B850M-P WIFI AM5 AMD motherboard + Team Group T-FORCE G50 TM8FFE512G0C129 512GB SSD (free gift): $149.99 (Sold and Shipped by Newegg US) This Newegg deal is US-specific and not available in other regions unless specified. This is a first-party seller link (at the time of article publishing); ensure that you also purchase from a first-party seller link only. If you don't like it or want to look at more options, check out the previous deals that we have covered, OR you can also visit Amazon US deals page. Get Prime (SNAP), Prime Video, Audible Plus or Kindle / Music Unlimited. Free for 30 days. As an Amazon Associate, we earn from qualifying purchases.
    • RapidRAW 1.5.7 by Razvan Serea RapidRAW is a beautiful, non-destructive, GPU‑accelerated RAW image editor designed for speed and simplicity. It uses a lightweight (~30 MB), efficient code base built with Rust, React and Tauri. Ideal for Lightroom workflows, it offers rich editing tools—exposure, contrast, highlights, shadows, whites/blacks, tone curves, HSL mixer, dehaze, vignetting, film grain, sharpening, clarity and noise reduction—processed in real-time on the GPU. Features include intuitive masking (brush, linear, radial, AI-powered subject and foreground detection), generative edit layers (via ComfyUI), 32‑bit precision, and full RAW format support through rawler. RapidRAW also provides library management (folder navigation, ratings, metadata, EXIF viewer), batch operations, export presets (JPEG/PNG/TIFF), sidecar editing (.rrdata), undo/redo history, customizable UI themes, smooth animations, resizable panels, and preset copy/paste. A modern high-performance Lightroom alternative with polished UX and creative tools, RapidRAW brings powerful photo editing to photographers seeking speed, responsive GPU feedback, and streamlined workflows. RapidRAW v1.5.7 release notes: This update serves as a direct follow-up to the core architectural migration introduced in v1.5.6. While the transition to a more modular state management system marked a significant step forward for RapidRAW's stability and long-term maintainability, it also introduced several edge cases and regressions within the library and editing workflows. This release focuses on addressing those issues, with a particular emphasis on a complete overhaul of library performance to ensure smooth and responsive browsing following the refactoring. It also resolves inconsistencies in the copy-and-paste workflow and expands RapidRAW's accessibility by adding support for eight additional languages. [full changelog] Download: RapidRAW 1.5.7 | ARM64 | ~20.0 MB (Open Source) View: RapidRAW Home Page | Screenshot | Other operating systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      PsYcHoKiLLa
      223
    3. 3
      ATLien_0
      87
    4. 4
      Steven P.
      80
    5. 5
      +Edouard
      80
  • Tell a friend

    Love Neowin? Tell a friend!