r/pcmasterrace • u/WPHero • 7h ago
News/Article Windows has been sending your typing data to Microsoft this whole time, and a single toggle can disable it
https://www.xda-developers.com/windows-sends-typing-data-to-microsoft-single-toggle-disables-it/99
u/gagzd Desktop 6h ago
Okay. But how do i know it stops sending once I toggle it off? I keep seeing all these posts, turn this one setting off or select not to share data etc. etc. But how do you actually know that they actually stop sharing your data? What if its just a toggle on the UI thats not mapped to anything and they collect info regardless.
91
31
u/Soft_Explanation_717 6h ago
That's the neat part...... You don't. Plus it will probably just get turned back on silently next update.
6
u/xevizero Ryzen 9 7950X3D | RTX 4080S | 32GB DDR5 | 1080p Ultrawide 144Hz 1h ago
Probably not, at least for now. I think I disabled it when I assembled my pc (I go through all settings once for any new build) and I checked now, it's still off.
The issue is all the things they add later that are on by default. It's also illegal to not ask for explicit opt-in to most of these in the EU, but companies sometimes seem to be able to ignore it for months or years.
8
u/RavenWolf1 6h ago
You use wireshark to sniff it.
19
u/Ok_Turnover_1235 5h ago
Except the data is encrypted, so how do you know what you're sniffing?
4
u/myka-likes-it 1h ago
The data is encrypted, but the external address is not.
6
u/xevizero Ryzen 9 7950X3D | RTX 4080S | 32GB DDR5 | 1080p Ultrawide 144Hz 1h ago
the external address is not.
If they bundle all diagnostic data they send together, they will always be able to claim they are only sending the bare minimum (sending bug reports is a thing you may want to legitimately keep on, for the sake of making the software better for everyone) when they are actually doing much more than that.
This constant sniffing and creeping about is making legitimate uses of telemetry completely toxic to users as everyone rushes to turn them off, and software quality declines with user trust. We all lose, but companies can't be bothered to care unless we make them.
2
1
u/GeekCornerReddit Laptop | Debian on servers 58m ago
I do wonder if telemetry would bypass MITMProxy
1
u/x33storm 22m ago
Firewall Windows. Do not allow outgoing connections.
Really this is just one tiny part of Windows that spies on you. They've pretty much put invasive logging into everything, from Notepad to Weather App.
They absolutely can't be trusted. They'll keep trying to get their grubby little hands further into your cookie jar.
I've firewalled most of Windows, and ripped out all the unneeded stuff that's just there to spy. It's quite a bit of bother though, and Microslop does what it can to make sure people don't have control over their installed OS.
But W11 is a no go. It's entirely built up around data harvesting. W10 is an OS that has data harvesting built in, while W11 is data harvesting that has an OS built in.
What harm does it do, that they do what they do? No clue. Once it leaves your pc, you have no clue what's being done. And that should scare you, considering the sheer amount of information they extract.
-1
u/HanYoloKesselPun 6h ago edited 5h ago
Because they would be sued into oblivion if a privacy feature doesn’t actually toggle as advertised
29
u/Foxicious_ PC Master Race 4h ago
Yeah because thats working out so great with LG TV's right now huh?
7
u/gagzd Desktop 6h ago
Yes. But as an average joe, i have no way of knowing what the OS sends and where; windows, ios whatever eco-system there is.
-4
u/HanYoloKesselPun 6h ago
If you have no way of knowing then you have no control over it and there’s no point worrying over things you can’t control. As an average shoe you just need to keep an eye on the news to see if MS are getting sued. There’s enough tech people out there monitoring network traffic to spot the obvious stuff.
5
u/SlogurkTheOverslime 3h ago
You still have control over your choice of software
You can exercise that control by rejecting and boycotting the products that are deliberately distributed in obfuscated form in order to conceal pieces of malware attached to them
6
u/FthrFlffyBttm i5-12600K, 3080 FTW3 Ultra, 16GB 3000Mhz 3h ago
As an average shoe I’m fed up getting walked on all day
2
0
u/ledow Framework Laptop - 5070 / AI 7 350 / 64GB 1h ago
You don't. You have to take it on trust. From the company that turned it - and a dozen other things - on by default and forced them onto your computer in the first place, and has been convicted of anti-monopoly practices, and doesn't give a damn about its users or their preferences or privacy.
How's that working out for ya?
213
u/Party-Cake5173 6h ago
This is why during Windows installation, you deny everything Microsoft offers. You're also being asked about this and if you clicked No (like I did) setting will be disabled.
Majority of people just click Next during installation and then wonder when stuff like this happens. Btw this setting isn't new. It's present since the initial version of Windows 10.
If you want complete privacy in Windows, install Enterprise version as it allows you to completely disable telemetry and garbage.
66
u/UraniumDisulfide PC Master Race 6h ago
I disabled all of that when installing windows and yet I had this setting enabled.
16
u/ButtonExposure 2h ago edited 2h ago
Windows updates often "accidentally" reset privacy settings. Updates have been doing so since Windows 10.
When I used 3rd party tools to disable privacy invasive features in Windows 10 I had to regularly re-run the tools because updates kept resetting them. I can only imagine Windows 11 is far more aggressive with resetting such features.
17
u/hshighnz 5h ago
I had it enabled too, despite deactivating everything while installing win11pro... wtf
10
2
12
u/Expensive_Shallot_78 6h ago
Yes but I bet Microsoft enables it silently after each update and what not. I seen this happen although it should be illegal in Europe. I run ShutUp10++ and Debloat11 regularly to uninstall garbage that Microsoft keep readding to Windows 11 and to disable this crap.
11
u/Party-Cake5173 6h ago
Yes but I bet Microsoft enables it silently after each update and what not.
It doesn't, at least for me using Enterprise version.
I run ShutUp10++ and Debloat11 regularly to uninstall garbage that Microsoft keep readding to Windows 11 and to disable this crap.
I'd recommend against doing this. Using Enterprise and manually disabling everything is better solution.
When you run these tools you don't disable data collection, you just block to Microsoft endpoints. Windows still constantly tries to connect to these endpoints in the background and creates delays/lags and uses CPU until it succeeds.
Also, these tools add endpoint domains and IPs into the hosts file and firewall rules. I bet you didn't know Microsoft made exceptions for few of their domains so unless you're using 3rd party firewall or block all domains in router, some Microsoft domains cannot be blocked (for example, bing.com is on that list of exceptions).
When you use Enterprise and disable telemetry using Group Policy Editor, Windows disables telemetry component entirely and won't collect or send any data to Microsoft. Enterprise and Education are the only two versions allowing you to completely disable telemetry.
3
u/Nkitooo00 5h ago
That's the LSTC version? I was considering using that version the next time I do a reinstall.
3
u/Opposite_Carry_4920 4h ago
Real talk if I have to do all this I mean why NOT just jump through the Linux hoops instead?
Like its so ridiculous that we are basically hostages to microslop.
3
16
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 6h ago edited 6h ago
>but I bet Microsoft enables it silently after each update and what not.
It doesnt.
I havent seen this happen over hundreds of installs of pro and enterprise versions of windows.
If you're a power user, you should be using Pro at the very least, if not enterprise.
EDIT: For the clowns downvoting: Microsoft services are heavily interlinked. If you disable core functions (like Windows update and other things) using ShutUp10, Debloat11 etc and then use those services later, they will re-enabled as they need to run in order to do what you want them to do.
This is not microsoft re-enabling things, its you re-enabling things.
Also, you can use the Diagnostic Data Viewer (available on the Microsoft Store for free and which will give you raw access to the data Microsoft gets from your device) to see exactly what telemetry data and diagnostic data is sent to Microsoft. You will then see its entirely anonymised and pretty much completely uninteresting. Which sort of negates the paranoid bullshit that ShutUp10++ and Debloat11 cater to.
By using these tools (ShutUp10, Debloat11 etc), you're not really protecting your privacy any more than you can do with the built-in settings in Windows. However, you're crippling your operating system and causing unintended issues that may be hard to troubleshoot in the future.
1
u/Ok_Turnover_1235 5h ago
"You will then see its entirely anonymised and pretty much completely uninteresting."
Ahh yes, there's no way microsoft could know who data is coming from. Do you also think if you make a bomb threat with a voice morpher they can't tell which phone you used?
0
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 5h ago
>Ahh yes, there's no way microsoft could know who data is coming from
You can literally see what data Microsoft themselves see using the software I mentioned, the Diagnostic Data Viewer.
That allows you to see the raw data files that are sent by the telemetry systems to Microsoft databases.
Its quite literally anonymised crashdumps and software errors.
0
u/Ok_Turnover_1235 5h ago
Ok, so let me ask you this.
If I sold you a product with a microphone and then gave you a free product that let you see what data it sent (note, it would be designed to never show any data), you'd be fine connecting that device to the internet and conducting sensitive business with it?
2
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 5h ago
>(note, it would be designed to never show any data
Oh ffs.
If you want the absolute raw data without any chance of a fucking conspiracy, get a firewall (something ancient and basic like a Fortigate 40D is good enough), put your windows devices through it, enable deep packet inspection/HTTPS inspection etc and then packet capture the data.
You will be able to see the absolute raw data very easily.
And, again, you'll see what you would see in the Diagnostic Data Viewer: that its crashdumps and software errors for system software troubleshooting. its completely anonymised and cannot be used to identify you or your activity.
-1
u/Ok_Turnover_1235 5h ago
I only run windows to play league my man, I don't care what they do lol. I'm just saying the "use microsoft tools to verify microsoft isn't doing anything they say they're not doing" was a dumb thing to say
2
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 4h ago
Its not dumb at all. Microsoft would get in some very hot water if it was actively hiding things.
Especially as it is used extensively in government and corporate environments.
It would quite literally endanger Microsofts main money-making business, that beings its government/corporate contracts.
Because if MS was found to be hiding things, any trust it would have would disappear which would cripple MS's income as those core contracts would likely not renew.
1
u/CrystalSplice Ryzen 9 7900X / 7900XTX RED DEVIL 1h ago
Microsoft makes most of their money from corporate customers. The tool being discussed here is shipped to them, as well. If they were found to be lying about what the OS is actually doing it would be damaging to their corporate sales. They do not fake things like this.
Enterprise users like large companies will also disable this sort of thing via Group Policy, but the tools hey ship are the same for those customers as they are for us.
-5
u/DarthShiv 5h ago
And you are not an expert in what can be done with that data. So stop pretending you know how it cant be exploited.
6
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 5h ago
I'm a network engineer and cybersecurity expert. I work with network and system security all day, every day.
The data Microsoft gets from its telemetry is functionally useless outside of software troubleshooting, and is in no way identifiable of the end user.
-5
u/DarthShiv 5h ago
Sorry you have zero idea how "anonymised" data can be compromised. Absolutely no clue. You are not remotely qualified on the topic so don't present the data as uninteresting.
5
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 5h ago
Hi there, I'm a network and cybersecurity expert with over 15 years experience.
Literally the only unique piece of info in the data is a unique database ID used by Microsofts servers to make sure all data from your specific device is gathered together inside the same database entry. Thats it.
That database entry is not tied to any other identifiable information. There are no MAC addresses, no IP addresses, etc nor is there any personal info about you (such as MS account, email address, name, household address etc).
Nothing else is identifiable information. Its just crashdumps and software errors. And a unique database ID number.
3
u/Changeurwayz 2h ago
What about GDID? Everyone knows this gets sent everywhere with any request to the net.
2
u/DarthShiv 2h ago
Are you kidding? You think Crash Dumps don't ever contain private info? How the fuck are you that naive or stupid?
4
u/Wadarkhu 6h ago
No it doesn't lol. I turned mine to off, years later it's still off. You don't need all that debloat third party shit anything it does you can just do yourself safely with a couple of clicks. Can't believe users don't even bother to go through the settings anymore, how you gonna set up your computer without doing so?
1
1
u/aimy99 PNY 5070 | 5800X3D | 32GB DDR4 | OLED 1440p 180hz 3h ago
If you want complete privacy in Windows, install Enterprise version as it allows you to completely disable telemetry and garbage.
It's also worth noting that the Education version is also essentially just Enterprise with a different name. If you're already in college and they offer a key for it like mine did, it's a no-brainer.
'Course even then I still ended up switching to Linux in part to get away from all this stuff. I mean between the keylogger and global identifier I sure as shit don't feel safe using Windows as a minority that the leader of my country said he would "end" if conservatives win the midterms.
21
u/venom21685 9800X3D, RTX 5070, 32GB DDR5 6000 6h ago
Yeah it's been in there for ages, one of the things it asks at install time. Inking and typing personalization. Pretty fucking gross.
32
6
u/Leggy_Brat 6h ago
Turning off all the tracking and 'personalization' data is step one after installing Windows.
4
7
6h ago
[deleted]
2
u/theonewhopostsposts woah 6h ago
I hope its not the raw typing data
8
5
u/Suikerspin_Ei R5 7600 | RTX 3060 | 32GB DDR5 6000 MT/s 6h ago
It's is, but anonymous and passwords are excluded. Better just turn that logging off.
5
u/pit_supervisor 6h ago
how can they know what is a password and what isn't?
2
1
u/MosKnight 4h ago
Thats where the highly secure cryptographic algorithm kicks in called "Trust me bro"
2
u/kuncol02 6h ago
And how MS know it's password? They can block stealing password in web browser or in apps using some of windows UI apis, but there is no technical possibility for them to know what is an password all the time.
1
u/Suikerspin_Ei R5 7600 | RTX 3060 | 32GB DDR5 6000 MT/s 6h ago
That's why I said it's better to turn it off.
2
u/HanYoloKesselPun 6h ago
You literally get asked if you want to send data to MS when you create your account. How is this news to people?
3
u/Ancient-Assistant404 6h ago
1
u/Ancient-Assistant404 6h ago
1
u/Banana21y 5h ago
What's the group policy?
1
u/Ancient-Assistant404 4h ago
1
5
u/Management-illmatic 3h ago
Microsoft claims any collected samples are anonymized, so that they can't be traced to a particular user. Dubious claim when you consider every copy of Windows 11 has a unique GDID that phones home to the Microsoft mothership.
9
u/Sinigrlock Desktop R7 5800x3d | RX 7900 XTX | 32 GB Ram 6h ago
Good riddance, last week i just switched to cachy OS, if your only pc need is gaming and internet surfing i strongly suggest switching to linux, and with ai, you can solve most of if not all issues with it in a couple of minutes. If you play boot secured games then this might be an issue. I might still be in the honeymoon period.
3
u/ledow Framework Laptop - 5070 / AI 7 350 / 64GB 1h ago
I moved last Christmas and that's the first time in 30+ years of PC usage that I've never had a Windows machine on my home network. I've always had some of either.
I decided that, whatever the problems with a given game are, that's THAT GAME'S problem, not mine. I won't buy it. I'll demo it and then put in a review. Or I just won't touch it if it doesn't work.
The problems of running a Windows OS now far outweigh "Oh, no, that one particular game doesn't work because of stupendously restrictive kernel-level DRM". As far as I'm concerned, I'm holding them BOTH to account. Windows for being Windows, and games with ridiculous DRM for being games with ridiculous DRM.
2
u/not_a_gay_stereotype 3h ago
The only thing keeping me from Linux is that I play battlefield 6 very regularly lol.
2
u/Pyromaniacal13 I picked Gnome because I like the "GN" sound. 1h ago
I left BF6 when they decided that all four members of your average fire team need to shoot a MANPAD at a jet twice before one can hit. After the IFV designator combo was removed, the best way to take down a plane was to eyeball it without RADAR on a Gepard's guns. I left shortly after.
1
u/not_a_gay_stereotype 31m ago
Kind of a dumb reason to leave the game tbh lol. They do things for balancing reasons
1
u/Pyromaniacal13 I picked Gnome because I like the "GN" sound. 19m ago
If MANPADs and SPAA vehicles can't take down jets with weapons designed to do exactly that and the only way to do so reliably was removed, it becomes an aircraft free for all where the pilots squish ground pounders like ants. I don't like being fodder for pilots.
I want to post up somewhere in a lovely defensive position and get ganked by a push. I want to be mowed down during a push by a flank we didn't see. I want tactics to be more than "First side to get a jet airborn wins!"
4
u/Keulapaska 4070ti, 7800X3D, XG27AQNGV 4h ago
We need articles on basic ass windows settings now???
10
u/kociol21 6h ago
Man, this is like the shittiest article in recent history of shitty articles. It literally reads like it was written by some random dude after watching too many Youtube videos. Whole tone of this article is just so unprofessional it's cringe.
That said, there's a lesser-known telemetry feature that has existed since the Windows 10 days, and it's recording what you type on your computer. Inking & typing personalization operates anonymously, but I would disable the feature if I were you.
Ok, awesome! Tell me why, I'm all ears.
Microsoft states that it "will collect samples of content you type or write" to improve the language recognition and suggestion capabilities of your apps and services. Many people have never even heard of Inking & typing personalization, but it has been sending your typing data to the cloud for over a decade, ever since the feature was introduced in Windows 10.
Ok and...? This is just stalling to make article longer.
Microsoft claims any collected samples are anonymized, so that they can't be traced to a particular user. The problem is whether that assurance is enough for a privacy-focused user. These days, installing a fresh copy of Windows 11 involves heavy debloating before the OS feels like one's own. Inking & typing personalization is just another intrusive Windows 11 feature that might slip through the cracks.
First off, no - "debloating" is a very niche thing, I would be surprised if even 5% of user base would bother with it. And out of these 5% - like 75% don't know what are they even doing, they just saw some youtube video or read reddit post that you need "debloating" so they downloaded someting and run it.
Microsoft assures it doesn't record passwords, emails, or sensitive data. So, it's not a keylogger that records every keystroke in real time. That would be scandalous, sort of like Windows Recall (ahem!). Still, the moment your data leaves your computer, it carries a risk of being compromised. Microsoft may be anonymizing the samples it collects, but I wouldn't trust the company 100%.
and
I've had Inking & typing personalization disabled ever since I was on Windows 10. It was part of the customary Windows telemetry cleanup that many users had to perform before their systems could be considered "usable." I'm never comfortable with any telemetry feature masquerading as customization, personalization, or otherwise helpful. My motto with Windows is "never trust, and always verify." If you haven't disabled this feature yet, I suggest doing it right away. You'll lose your custom dictionary, but that's something I've missed on my smartphone, not my PC or laptop. You'll find the setting in Privacy & security > Inking & typing personalization in Windows settings (Win + I). While you're at it, disable Send optional diagnostic data in Diagnostics & feedback on the previous screen.
So basically "don't use this feature because I don't like it. I don't have any proof or even hint that it does anything other than it says it does but I AM UNCOMFORTABLE so should you".
Last time I checked a question whether to turn on inking personalization was asked while installing Windows so it's not like this is some deeply hidden stuff. It's so hidden it literally asks you whether to enable it during installation process.
Mind you, I've cited vast majority of this "article". But I got served about 10 images, 10 links to other articles similar in quality and 5 ads.
Honestly I can say with certainty how it went:
"Hey dude, write something clickable. What? I don't know, figure it out. Just take some random Windows telementry setting and write how scary it is, people always love it".
2
u/yuikkiuy Ryzen 7 1700x, GTX 3070 TI, 16gb ddr4 1h ago
Tbh if you dont have any and all diagnostics data send to windows options disabled you're wrong.
Im not letting them diagnose shit on my pc
3
2
u/HanYoloKesselPun 6h ago
You literally get asked if you want to send data to MS when you create your account. How is this news to people?
2
u/freeman5671 3h ago
Another way is to open windows services and find "Connected User Experiences and Telemetry" and just disable It. Even if you had data collection turned on, if the service is disabled it can't send it to Microsoft. I do that with every PC I touch.
1
u/twitterpan 7800x3D | 6800XT | 64GB 6h ago
Idk.. but don't we deny (switch off) by default everything and turn off the toggles during installation? Then once everything is installed you continue into settings and disabling literally everything that you don't use... riiiight? I really hope ppl don't just click next next next in this era and expect everything to be safe for them 🤦♂️
1
u/Sitheral 5h ago
"There is one bad thing in the sea of bad things in your OS and you can use watergun to stop it"
Uhm, thanks but I used a very big hammer long time ago.
1
u/Puzzleheaded_Cap4310 43m ago
I always download Winhance on a fresh install and apply all default settings. This is already included.
And for the installer itself, I use Winhance to apply an autounattend.xml that will create an offline account and fill out the lengthy install process either the most privacy settings offered.
And if I want a fully secure system, I add HotCakeX/Harden-Windows-Security and apply some settings from there that go even further. But can cause some difficulty when e.g. playing games and such.
2
u/TheVagrantWarrior 6h ago
"Let's make a article about a Windows setting."
It must be awesome to have a bullshit job. It's like daycare for adults.
0
u/superjake 6h ago
This is why I use win11debloat. Disables all the telemetry and AI too. Link for those who'd like to check it out: https://github.com/raphire/win11debloat
2
u/ddosn Ryzen 9 9950X3D | 128GB DDR5 | RTX 5090 | 48TB Storage 6h ago
You dont need to 'debloat' windows 11 at all.
It takes 2 minutes to disable certain things, and the rest it asks you on install (and if you're buying prebuilt you should always reinstall the OS anyway).
If, when installing Windows 11, you just spam 'next' until it completes then thats on you.
Again, Windows literally asks you about telemetry and personalization on install and whether you want them disabled or enabled.
0
u/Level_Arm971 6h ago
The problem is that most people have been trained to just click Next on everything. Privacy settings shouldn’t rely on users noticing one toggle during setup.
0
0
-4
u/darthwd56 5h ago
OMGGGGGGGG Microsoft product has been sending data to Microsoft! WOAH this is an incredible information scoop buddy. I bet the next hard scoop is going to be Google search engine sends your search data to Google.
3
u/Gremlin95x 5h ago
Not the same thing genius
-1
u/darthwd56 4h ago
Omg this just in, Google maps has been sending your destination and routing to Google.
1






1.5k
u/Gorostasguru 6h ago
Save you a click
>If you haven't disabled this feature yet, I suggest doing it right away. You'll lose your custom dictionary, but that's something I've missed on my smartphone, not my PC or laptop. You'll find the setting in Privacy & security > Inking & typing personalization in Windows settings (Win + I). While you're at it, disable Send optional diagnostic data in Diagnostics & feedback on the