CIAC: XP Error Reporting Bad for Privacy

The Department of Energy Computer Incident Advisory Capability (CIAC) has advised against using the error reporting technology included in Office XP, Internet Explorer 5.0 or higher, and Windows XP. Based upon its own internal testing, the agency concluded that potentially sensitive and private information can be divulged along with a memory dump that is passed along to Microsoft. Initially, CIAC reported that default product settings automatically prompted users to submit error reports, but the bulletin has since been updated to reflect the fact that Microsoft's default selection is "don't send."

For its part, Microsoft claims that the technology is intuitive, presenting customers with a clear indication of everything that will be sent to the servers in Redmond while guiding them through the submission process. Product documentation on the "feature" is also available via the Web.

Microsoft spokesperson Rick Miller told BetaNews that protocols were in place aimed at limiting data access to a select few, and that the company strictly adheres to its privacy policy under penalty of law. The same privacy policy applies to third party software vendors who are contractually obliged to follow the same standards. Microsoft says that it works with its partners, allowing them to benefit from what the reports reveal about the underpinnings of their applications.

According to Microsoft, the reasoning behind its use of the technology is sound. "We think this is a great new technology that will allow us to understand the reasons for crashes and allow us to be able to fix them," said Miller. When proposed with the suggestion that .NET alerts may be used to notify customers of the status of the bug that they encountered, Miller commented that such a system would be a perfect example of integration benefiting consumers.

Miller acknowledged that government agencies such as the Department of Energy routinely deal with classified information and should not send the error reports. CIAC has provided step by step instructions on how to disable error reporting in its advisory.

74 Responses to CIAC: XP Error Reporting Bad for Privacy

© 1998-2024 BetaNews, Inc. All Rights Reserved. Privacy Policy - Cookie Policy.