Skip to main content

HP Caught Installing Spyware on Windows 10 PCs Without Permission.

HP has been caught installing a new telemetry-gathering system on its Windows 10 PCs without informing users it was doing or so requesting permission to gather data. In a recent update (it’s not clear if HP or Microsoft pushed out the software), multiple HP owners have reported the “HP TouchPoint Analytics Client” is connecting on a daily basis to upload various information to HP’s servers.

Detlef Krentz contacted Borncity to report the software, writing:

I noticed that HP secretly installed the program “HP Touchpoint Analytics Client” on all my HP devices on November 20, 2017.

The program connects every day to HP. The files sent can be found under “Program Data/HP/HP Touchpoint Analytics Client/Transfer Interface”.


Image by Detlef Krentz.

Earlier reports posted on BleepingComputerand Reddit date the installation to the middle of November. HP’s own website ironically states that it plans to disable TouchPoint Analytics because it’s rolled that feature into a different type of service. Specifically: “The HP Touchpoint Manager technology is now being delivered as a part of HP Device as a Service (DaaS) Analytics and Proactive Management capabilities. Therefore, HP is discontinuing the self-managed HP Touchpoint Manager solution.” There’s some evidence to suggest laptops are running significantly hotter thanks to this self-installed malware as well.

It’s Time to Nuke These Practices From Orbit

Over the past five years, an increasingly large number of companies have silently decided that every moment you spend on the internet is fair game for monetization and data harvesting. Microsoft has at least pulled backon its telemetry collection, provided you set the level to “Basic,” but many companies and websites have surged ahead with this practice. Facebook thinks it deserves to know where you are at every moment so it can serve you local ads and monetize your willingness to walk in the store. More than 400 websites track every single thing you type or delete on their pages, in real-time. Google has stopped sandboxing its data collection from its DoubleClick advertising business. Verizon now shares personally identifiable information within its own company, which is a huge deal considering it owns a number of web properties and its own abuse of zombie cookies. Vizio was caught uploading user data whether said users had agreed to participate in tracking or not.

There are, to be sure, still companies that clearly indicate what data they collect and offer users the option to opt out of any collection whatsoever, but they’re being overwhelmed. The same companies that would ardently stand up for the idea that intellectual property has value now argue that the most intimate details of your life have no value whatsoever, despite the fact that this information ought to be considered the intellectual property of the person to whom it belongs.

“As a service” has become code for “You don’t actually own anything, and we owe you nothing.” We see it in smart home technology and we’re seeing it here. The problem is not that HP is gathering telemetry; absent a full description of what it’s gathering, we don’t know if the practice is a minor, non-intrusive process that confines itself to error reports and troubleshooting, or an intrusive hoover of PII (personally identifiable information). The problem is that these practices have become so entrenched, Silicon Valley no longer feels it needs permission at all.

PCMag.com has more on uninstalling the service if you’ve been infected by it.

Comments

Popular posts from this blog

Google Authenticator, a formidable layer of protection to your account.

​Google Authenticator is a free security app that can protect your accounts against password theft. It's easy to set up and can be used in a process called two-factor authentication (2FA) offered on popular social media services like Gmail, Facebook, Twitter, Instagram, etc.  The app ( iOS / Android ) generates a random code used to verify your identity when you're logging into various services. The code can technically be sent to your phone via text message every time— but the Google Authenticator app provides an extra level of security.  SMS-based 2FA has a  known security flaw , and any devoted hacker can attempt to  socially engineer  an attack against your phone company. The Google Authenticator app eliminates the possibility of an SMS-based attack  using algorithms  to generate the codes on your phone. Here's how to set it up: 1. Download Google Authenticator from either the Apple App Store or the Android Google Play store. It's free. 2. Nex...

Floyd Mayweather Baby Mama Sues for $20 Mil ... He's a Despicable Liar

Floyd Mayweather could lose tens of millions of dollars from his big payday if his baby mama gets her way ... because she's just filed a lawsuit claiming he ruined her with lies to save his own ass. Josie Harris, who has 3 kids with Floyd, claims he lied through his teeth in an interview with Katie Couric just 2 weeks before the big fight ... when he claimed Josie was in a drug-fueled rage and he had to "restrain" her during their infamous 2010 domestic violence incident. Point of fact ... Floyd was convicted of domestic violence and spent two months in jail. Josie recounts her terror in the lawsuit, explaining how she and Floyd had broken up ... but he flew into a jealous rage that night, broke into her home and viciously attacked her while she was sleeping on her couch ... and her kids saw part of the beating. Harris says she is now labeled a drug addict thanks to Mayweather's lies -- and was embarrassed and humiliated on a global scale.   Her lawyer, Dan Friedl...

Google, harder to search for results from other countries

For a long time, there was an easy way to conduct a Google search in a country other than the one you’re in. If you wanted to get results specific to Japan, for instance, you would visit www.google.co.jp; to get Australian results you would visit www.google.com.au — but this trick no longer works. Google has announced that it will now always serve up results that are relevant to the country that you’re in, regardless of the country code top level domain names (ccTLD) you use. The reason given is a little bizarre. The search giant says that the change has been introduced because of the way people are using the search engine these days. It says: “around one in five searches on Google is related to location, so providing locally relevant search results is an essential part of serving you the most accurate information.” The argument seems counterintuitive, however. Anyone who has changed the ccTLD has done so consciously, and for a reason — for Google to override this decision is strange...