AI Code & Improving Windows 11 Privacy
It sounds like an oxymoron: using data-scraping LLMs to build Windows privacy tools. But here we are, playing around with what all the "cool kids" are using.
Recently, I've been testing various Large Language Models (LLMs) to see what they are capable of, and I'm suitably impressed. These systems qualify as artificial intelligence in a way prior technology simply couldn't. That being said, I don't think it's the same as human intelligence. While very impressive, I consider our current systems to be advanced representations of accumulated knowledge. When trained and harnessed properly, they allow us to statistically extract that knowledge and apply it. They have been fed representations of human actions, giving them the ability to simulate behavior when prompted. That is what makes this really interesting (and scary for the doomsayers.)
Updating the Anti-Spy Script
I've been working on two projects with it quite extensively: a system integrity monitor, and an update to a privacy script I threw together in the past (which you can find earlier on this blog). You can find the updated privacy script at https://github.com/TimHanneman/no_ms_spy. It's a neat little script that toggles settings to disable telemetry and improve privacy on various Windows operating systems, most notably Windows 11.
There are other tools out there that are likely better, but there is one feature I've included that might be of interest. Windows regularly dials out to verify internet connectivity and check DNS resolution. The script creates a scheduled task to rotate those DNS providers so no single organization gets a complete picture of when you are connecting online. Also, if you've set up a recursive DNS resolver, this allows the system to check connectivity without dialing into Microsoft to let them know you're using a recursive resolver. It's a minor privacy feature, but an interesting one to implement.
Under the Hood: DNS Rotation
If you're curious how it works, it targets the Network Connectivity Status Indicator (NCSI). Instead of just turning it off (which breaks things), the script rotates the connectivity checks through different captive-portal detection endpoints. It even spoofs the User Agent so the checks blend in with normal Firefox or Apple traffic.
Here is a snippet of the PowerShell logic from ncsi_rotate.ps1 showing the provider pools and the registry updates:
$ncsiKey = 'HKLM:\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet' # Web check providers. The reply must match the pattern. # The user agent is the one each provider receives most, so the check blends in. $webPool = @( New-WebProvider 'http://www.msftconnecttest.com/connecttest.txt' '^Microsoft Connect Test$' 'Microsoft NCSI' New-WebProvider 'http://detectportal.firefox.com/success.txt' '^success\s*$' 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:{firefox}.0) Gecko/20100101 Firefox/{firefox}.0' New-WebProvider 'http://captive.apple.com/hotspot-detect.html' '<TITLE>Success</TITLE>' 'CaptiveNetworkSupport-481.100.1 wispr' New-WebProvider 'http://nmcheck.gnome.org/check_network_status.txt' '^NetworkManager is online\s*$' 'NetworkManager/1.48.0' ) # DNS check names using root servers so a recursive resolver can answerWithout asking a third-party resolver. $dnsPool = @( New-DnsName 'dns.msftncsi.com' '131.107.255.255' 'fd3e:4f5a:5b81::1' New-DnsName 'a.root-servers.net' '198.41.0.4' '2001:503:ba3e::2:30' New-DnsName 'b.root-servers.net' '170.247.170.2' '2801:1b8:10::b' # ... more root servers ... ) # [Logic omitted: The script tests a random provider from the pools to ensure it answers] # Update the registry so Windows uses the new provider for its background checks Set-ItemProperty -Path $ncsiKey -Name ActiveWebProbeHost -Value $entry.Host Set-ItemProperty -Path $ncsiKey -Name ActiveWebProbePath -Value $path Set-ItemProperty -Path $ncsiKey -Name ActiveWebProbeContent -Value $result.Text
That being said, I've tested on Windows 11 24H2; untested on 10, so if anyone stumbles upon it, what you see is what you get. (Though AI makes it really easy to diagnose and update things if you run into snags.)
The Hyper-Literal Collaborator
Which leads me to my thoughts about LLMs and their current abilities. I've found that interacting with these systems is a bit like talking to a hyper-literal compiler or a pedantic savant. This literalness is fantastic for STEM and science, but not so much for interpersonal nuance. When coding or giving instructions, I need to put on my pedantic detail hat to get good results.
LLMs are very good at simple scripts, writing isolated code blocks, and finding syntax problems. They're not so good at fixing structural problems gracefully or understanding the broader architecture of code—which, to be fair, many companies ignore anyway in favor of getting products out quickly. LLMs seem to share the tech industry's bias toward "moving fast and breaking things."
I've also tested them out on tracking my exercise routine, job applications, interview prep, debating religion, pushing guardrail boundaries, and analyzing my diet and supplements. What I've found is that they often overfit to what I'd call the "common consensus" of the internet. For example, when discussing religion, one LLM felt very Catholic, while another was pretty agnostic, which I chalk up to different training data. There is some bias, which might make for an interesting empirical study.
Diet and exercise are other good examples. Neither is an exact science, and there are multiple modalities to achieve "health" or "fitness." I often have to debate the AI to get it to record and assess things correctly. When I exercise, it has a tendency to criticize my routine for essentially not being "Body-Builder" enough or "Ultra-Endurance Athlete" enough. My routine isn't for massive muscles or marathons, and the AI struggles with a modality that isn't as common. What it suggests isn't necessarily wrong, just misapplied.
That lack of nuance probably wouldn't be noticed by someone less educated in the subject. This leaves me a bit concerned when I hear some of my peers quoting AI and saying, "just ask ChatGPT." (For the record, I currently find Claude a bit better for coding tasks, though that could change quickly in today's market.) I guess this isn't too different from just accepting the first result you find on a search engine, which is what people did before.
The C-Student Knowledge Revolution
Flaws aside, the leap in capabilities over the last year has been impressive. If I graded its performance on tasks on par with my graduate school assignments, I'd give it a "C". But depending on the specific prompt, it either scores an "A" or hardly hits the target with a "D-". Considering the number of people who could average a "C" across nearly all subject areas at a graduate level, its baseline knowledge capabilities probably exceed the average person.
I predict that in the future, it will likely cause a knowledge revolution similar to the Industrial Revolution. Just as you don't find too many Coopers, Cobblers, Chandlers, or Coachmen today, the question becomes what knowledge-worker skills LLMs will eventually replace. The Industrial Revolution didn't happen overnight, and neither will an AI revolution, but if the past is anything like the future, the transition will likely be bumpy.
P.S. (I used Gemini to be my editor for this post. Besides correcting a hallucinated code block it was too good. I had to tell it to let my unprofessional training in writing uniqueness come through.)
Comments
Post a Comment