Windows Online Crash Analsysis (OCA) Security








Today when I was using MS word to edit a document, I encountered an error which hangs my application. By forcing it to quit, Windows XP started Microsoft Online Crash Analsysis (OCA) and asked me to send an error report to Microsoft. OCA has been with us for sometimes and I usually clicked on “OK” with an urge to start working as soon as possible. However, today I looked into what was happening behind the simple click and found something unexpected.

Opening 5MB file generated by OCA with a notepad, I was stunned to find my entire document appear in plain text (see the figure below). The error-reporting module actually transfers the document I am editing to Microsoft. Immediately, I checkout their privacy website to find out if is declared and it is (see the red circle).

At this moment, a lot of questions pop up
1. Most importantly, are the document content necessary for the error investigations?
2. I believe with million of error reporting, Microsoft and their staff will not have the resources to look at the content. But what is their retention policy?
3. Should Microsoft display a more clear warning message? Instead of in a privacy statement with small fonts.

I believe companies should disable OCA or use firewall to block this type of traffic. More studies need to be done on FireFox quality feedback program.

Below is Microsoft Privacy Statement
http://oca.microsoft.com/en/dcp20.asp

Comments

Popular posts from this blog

Risk on Radio

One source of poverty

Root Certificate update and software design