Can Microslops Winblows spying be mitigated by running everything through WSL?

  • onlinepersona@programming.dev
    link
    fedilink
    arrow-up
    1
    ·
    23 hours ago

    Someone recently wrote an article about how susceptible WSL was to hacks and how it was an excellent attack vector because windows didn’t check it. It was on one of the cyber security communities on Lemmy.

    I dont have WSL but based on that article, I assume you can circumvent a lot of winblows crap in WSL. If you can run GUI apps all the better!

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    2 days ago

    No because the traffic is still going through a Microsoft vswitch so it can see what’s going on.

    • Oisteink@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      2 days ago

      Oh, so even if i ditch windows and go linux my tplink router will see whats going on?

      • halfdane@piefed.social
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 days ago

        Yes, of course your router (that’s routing your network traffic) sees the traffic it’s routing - although these days almost everything is using https , so the router wouldn’t be able to inspect the content.

        However, the original question was about windows, and I don’t know of any router that uses windows, so I’m not sure if that addresses your actual question.

        • Oisteink@lemmy.world
          link
          fedilink
          arrow-up
          1
          arrow-down
          6
          ·
          2 days ago

          I was just trying to point out how stupid the comment about vswitch is. Everything in your network path can watch, and some of that equipment has poor security compared to the windows vswitch

    • lemmybefree@lemmings.worldOP
      link
      fedilink
      arrow-up
      10
      ·
      2 days ago

      I run a 100% Linux household for my personal devices. However, work does not allow the use of Linux devices, which is why I have this question. I am permitted to use WSL.

          • wizardbeard@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            6
            ·
            2 days ago

            Just run the Windows device using wired internet on a different (and isolated) subnet from everything else of yours and turn off wifi and bluetooth on it. Use a wired headset or a dedicated dongle like Jabra has for their headsets. That would prevent it from identifying other devices nearby.

            Beyond that, just don’t do any personal shit on your work device. If you’re providing your own Windows work device, then do it in a VM as already said.

            If your workplace allows WSL, then the main benefit is you could use more familiar software/tools through it. Your workplace is likely to be doing a hell of a lot more data collection than Microsoft anyway.

  • hexagonwin@lemmy.sdf.org
    link
    fedilink
    arrow-up
    2
    ·
    2 days ago

    mostly yes. it can even be mostly mitigated without going WSL, since the anti-features can be mostly disabled through group policy and registry hacks.