Quote from:
https://gist.github.com/xvitaly/eafa75ed2cb79b3bd4e9#gistcomment-2835441All text typed on the keyboard is stored in temporary files, and sent (once per 30 mins) to:oca.telemetry.microsoft.com.nsatc.net
pre.footprintpredict.com
reports.wes.df.telemetry.microsoft.com
Telemetry is sent once per 5 minutes, to:vortex.data.microsoft.com
vortex-win.data.microsoft.com
telecommand.telemetry.microsoft.com
telecommand.telemetry.microsoft.com.nsatc.net
oca.telemetry.microsoft.com
oca.telemetry.microsoft.com.nsatc.net
sqm.telemetry.microsoft.com
sqm.telemetry.microsoft.com.nsatc.net
Typing the name of any popular movie into your local file search starts a telemetry process that indexes all media files on your computer and transmits them to:df.telemetry.microsoft.com
reports.wes.df.telemetry.microsoft.com
cs1.wpc.v0cdn.net
vortex-sandbox.data.microsoft.com
pre.footprintpredict.com
When a webcam is first enabled, ~35mb of data gets immediately transmitted to:oca.telemetry.microsoft.com
oca.telemetry.microsoft.com.nsatc.net
vortex-sandbox.data.microsoft.com
i1.services.social.microsoft.com
i1.services.social.microsoft.com.nsatc.net
Everything that is said into an enabled microphone is immediately transmitted to:oca.telemetry.microsoft.com
oca.telemetry.microsoft.com.nsatc.net
vortex-sandbox.data.microsoft.com
pre.footprintpredict.com
i1.services.social.microsoft.com
i1.services.social.microsoft.com.nsatc.net
telemetry.appex.bing.net
telemetry.urs.microsoft.com
cs1.wpc.v0cdn.net
statsfe1.ws.microsoft.com
This behaviour still occurs after Cortana is fully disabled/uninstalled.
Interestingly, if Cortana is enabled, the voice is first transcribed to text, then the transcription is sent to:pre.footprintpredict.com
reports.wes.df.telemetry.microsoft.com
df.telemetry.microsoft.com
While the inital reflex may be to block all of the above servers via HOSTS, it turns out this won't work: Microsoft has taken the care to hardcode certain IPs, meaning that there is no DNS lookup and no HOSTS consultation. However, if the above servers are blocked via HOSTS, Windows will pretend to be crippled by continuously throwing errors, while still maintaining data collection in the background. Other than an increase in errors, HOSTS blocking did not affect the volume, frequency, or rate of data being transmitted.
http://archive.today/2016.06.09-060928/http://www.wilderssecurity.com/threads/list-of-windows-7-telemetry-updates-to-avoid.379151/page-3More:
sqm.telemetry.microsoft.com
telecommand.telemetry.microsoft.com
adaptv-pubnet.telemetryaudit.com
spc--cehhhdngdgedkhcfhekgjhje.telemetryverification.net
1009 spc--cehhhdngdgedkhcfhekgjhje.telemetryverification.net 1
This domain resolved normally. You can block this domain or block similar domains .1010 au--cebhjdeeihkhghcdcejcidada1.telemetryverification.net 1
1011 au--3b154063ceihcdihbdbgdejhbdcdhenea5.telemetryverification.net 1
1012 au--cebhjdeeihkhghcdcejcidadceihcdihbdbgdejhbdcdhenea2.telemetryverification.net 1
1013 au--ceihcdihbdbgdejhbdcdhenea3.telemetryverification.net 1
1014 au--cejehfjfchggmeidkfpenepgceihcdihbdbgdejhbdcdhenea7.telemetryverification.net 1
1015 au--cejehfjfchggmeidkfpenepga6.telemetryverification.net
au--3b154063a4.telemetryverification.net
**I don't think a hosts file can stop this crap. They just use random odd urls to use telemetry.
I really have done a great deal to stop all this and they still found ways around it. and this is just win7, imagine what 10 is doing**
http://archive.today/2016.11.12-050656/http://www.dslreports.com/forum/r30222844-Stop-Windows-10-From-Spying-On-You-36-DNS-Addresses-to-host-filehttp://archive.today/2015.09.15-020602/https://localghost.org/posts/a-traffic-analysis-of-windows-10http://archive.today/2016.06.09-060606/http://www.wilderssecurity.com/threads/list-of-windows-7-telemetry-updates-to-avoid.379151/page-2http://archive.fo/2018.02.14-202231/http://forum.notebookreview.com/threads/windows7-8-updates-to-hide-to-prevent-windows-10-upgrade-disable-telemetry.780476/