The app automatically installs Bing Visual Search and includes code to decrypt cookies saved in other browsers, Rivera said, and it also brings a “free” geolocation web API to the system.

The developer discovered “many” nasty tricks Microsoft integrated in Bing Wallpapers, which include trying to change the browser’s settings and set Edge as the default system browser. If the default browser isn’t Edge, the app will open the default browser after some time asking to enable the previously installed Microsoft Bing Search for Chrome extension.

  • Scubus@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    12
    ·
    3 hours ago

    Why would you download bing wallpaper app anyways? First rule of computers: only install from trusted sources

  • 𝕸𝖔𝖘𝖘@infosec.pub
    link
    fedilink
    English
    arrow-up
    30
    ·
    5 hours ago

    Haven’t we already categorized windows as malware and Microsoft as a malware company? We really shouldn’t be surprised that they put out another piece of malware. It’s their MO.

      • red_pigeon@lemm.ee
        link
        fedilink
        English
        arrow-up
        17
        ·
        edit-2
        4 hours ago

        I’m not a windows fan boy, in fact I haven’t used one in years, and have no intentions to.

        But this is a weird way of thinking about MS shenanigans.

        • Hate it or like it, windows update is still an update to your system, to fix security vulnerabilities even. I wish they had implemented it in a user friendly way. But it is NOT a thing that disrupts you with ill intent as you mentioned here.
        • That is a task manager running some process. But no indication on what the process is !
        • Enabled by default is an horrible design decision no matter who does it. I agree on that. But this is NOT unauthorised access. You signed up for it when you decided to use windows.

        Again I don’t like MS. Hate them for their bad decisions, but don’t hate them by misrepresenting them.

        (My comment is only about this screenshot posted here)

  • bitjunkie@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    ·
    8 hours ago

    “Megacorp learned nothing from Active Desktop being an utter fucking security disaster.” Yeah, no shit. Everything old is new again.

    • JWBananas@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      Active Desktop was entirely ahead of its time. Let’s not forget that it was only around a decade later that JIT-compiled JavaScript engines like V8 paved the way for web apps, including the iPhone which at launch only supported third-party apps as web apps.