I feel like a broken record, but no, if you can't turn this off, it is not a good thing! It means you can never use an HTTPS proxy and know exactly what data is streaming off of your computer.
Obligatory story about having control over your computing enviroment: https://www.gnu.org/philosophy/right-to-read.en.html
Disclosure: Microsoft employee
I lost trust in MS after they started inserting telemetry and ads, i.e. in the Win8 era, then silently added the Win10 forced-upgrade crap to security updates too.
You just "simple" don't trust Microsoft. What about other big companies, for example Google? Do you trust them or not? Why?
Do you trust Apple/Facebook/<put_here_another_big_company_with_users>? Why?
Google and Facebook offer services that I can choose to not use if I want to. The average user can't switch between OS' without at least a certain amount of knowledge, and Windows is taking advantage of its still gargantuan market share to snoop and embed things and install updates even after the user decides not to.
It's either a mistake/or English isn't their first language, regardless your wording and use of quotes makes this sound aggressive or insulting. (This sets the tone for the rest of the comment)
You understood what was meant.
>What about other big companies, for example Google? Do you trust them or not? Why? Do you trust Apple/Facebook/<put_here_another_big_company_with_users>? Why?
As for me personally, I don't trust most large companies very much. Many large companies have a goal to collect a lot of data on you and potentially sell that data, and that's ignoring Government snooping etc.
But I still use many of their services despite that. There's a trade off to be made and occasionally it can be worth it, I just try not to give out more data than necessary.
As for Microsoft and Windows/Windows 10 specifically the stakes are higher. Assuming I'm running a Microsoft OS I'm dependent that it's operating in my best interests, everything I do on a computer is run through the OS. If my OS is compromised by the vendor (in this case Microsoft) they can collect a lot of data about me and my habits against my will.
The counter argument is usually something around the lines of "Well Google/Apple is doing all this stuff and worse!" with their mobile operating systems, which may be true. The difference is I don't use my phone for critical tasks or the majority of them, partially for that reason.
We've already lost the battle with phones, but I still want my PC to be sacred, even though it might not actually be 100% possible.
And I trust Apple and OS X/macOS a lot more than Windows, because I can more-or-less understand what my Apple OS is doing and can control it accordingly. With Windows, I can't even turn off telemetry/sharing diagnostics with Windows without a bunch of unwieldy hacks.
Recent fork: https://github.com/Enteee/xt_sslpin
Someone's blog post about it: https://duckpond.ch/networking/security/2016/09/09/xt_sslpin...
/r/netsec discussion: https://www.reddit.com/r/netsec/comments/52me9w/xt_sslpin_ma...
I like the idea.
Most likely this feature is a response to incidents such as this: https://www.wired.com/2011/03/comodo-compromise/ (in which certs for login.skype.com and login.live.com were misissued by Comodo).
Blocking the domains in this list to prevent telemetry, as suggested in other comments, would prevent access to most of Microsoft's online services. This includes third-party websites hosted on Azure that aren't using their own custom domain (.azurewebsites.net), and all software updates, including critical security patches.
This is a list of user-facing sites.
If you have win10, you can add this to your hosts file. The optional portion of the list will block store items, the email client and even things like the Groove media player, so use it as you will.
Of course, this is not foolproof, and documenting the feature will just alert people they need to mock telemetry and this pinning feature first.
In all seriousness, I'm not sure this is a good thing.
So some are related to telemetry, but probably not all them
perhaps they no longer use -ppe?