> Microsoft developed the Recall feature under its new Secure Future Initiative (SFI) that the company has put in place to overhaul its software security after major Azure cloud attacks.
The irony here is thick enough to cut with a knife.
But good on Microsoft for changing their minds and deciding to make this opt-in. That's progress for sure.
Exactly, even if it shows being turned off you can't be sure it really is. And yeah they have a tendency to secretly turn malicious features on with little updates. One would really be naive to believe them after their past bad behaviour. It is just another step in slowly boiling the frog to death. Maybe it will be off by default only for as long as people get used to it and normalise it and then, next step turn it on again, more quietly of course.
It is pretty easy now if you use Rufus to create your installation usb.
It will prompt you (and select by default) to disable the need for an online account. I installed the Pro version and then just said I was setting it up for work or school, chose domain and then I set it up just fine as a local account.
I don't know for sure how much of this is rufas or the pro version. But I just installed Windows 11 within the last hour.
Pick one. "Normal" users don't use specialized software to create installation media. They boot the laptop with the OS already installed and go on from there.
Normal gamers aren’t representative of normal users on a whole. Gamers are just a tiny fraction of the overall user base. Normal users buy cheap-ass laptops with their manufacturers’ opinionated Windows installation, including boatloads of bloatware. And they don’t ever change any of the defaults.
That's the hidden joke. In early Win10 it used to be a simple dark-pattern screen with a prominent button "use a Microsoft account" and a text link in the corner "use a local account". Then they made it increasingly ridiculous with subsequent updates until the current point where you need a tutorial on how to even make the option visible.
Will have to wait and see if the extra security measures actually improve anything or not.
However regarding it being opt out… what would prevent a virus from just enabling it on a bunch of machines silently. Sure it would be caught but the damage done and most won’t be bothered to go in and disable it after.
Or Microsoft just decides they need to really market the hell out of AI and it gets turned on my default anyways.
Please stop with these kinds of made up fantasy scenarios.
There's no such thing as "accidental enablement" for stuff like this, as if it's a switch every employee at Microsoft has access to, and one of them one day can end up flipping by accident with their elbow and it ends up in production without anyone else noticing.
Either they decide to intentionally enable it or not. There are no accidents , when stuff like this needs to go through a committee of people for approval before it makes it into production.
> Either they decide to intentionally enable it or not. There are no accidents , when stuff like this needs to go through a committee of people for approval before it makes it into production.
Absolutely. And all of them decided to screw largely defenseless non-technical consumer to make short-term profits. That's not a fantasy, that's our reality.
Without Recall, an attacker needs to get a program to stay resident in memory to log keystrokes, screen contents, etc. for an extended period of time without getting detected. With Recall, they can get the same end effect by exfiltrating the Recall database file whenever it's convenient (i.e. an infected version of a text editor could send it while pretending to check for updates). This significantly lowers the barrier to entry for getting a victim's data, while also making it much easier to avoid detection.
This is all moot anyway because Microsoft has already said they are now going to encrypt everything behind Windows Hello making it as secure as my password manager.
Microsoft has made misleading statements regarding encryption [0] and it doesn’t help much. Encryption at rest doesn’t much matter if the user being logged in is enough for the data to be decrypted. This is the context malware runs in.
That's old information. This is how Microsoft is intending to change Recall based on these criticisms:
Microsoft will also require Windows Hello to enable Recall, so you’ll either authenticate with your face, fingerprint, or using a PIN. “In addition, proof of presence is also required to view your timeline and search in Recall,” says Davuluri, so someone won’t be able to start searching through your timeline without authenticating first.
This authentication will also apply to the data protection around the snapshots that Recall creates. “We are adding additional layers of data protection including ‘just in time’ decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so Recall snapshots will only be decrypted and accessible when the user authenticates,” explains Davuluri. “In addition, we encrypted the search index database.”
But I'm glad to hear they've committed to making changes. Given the misrepresentations they made regarding the initial rollout plan (the target of most criticism, mine included), Microsoft has to prove themselves here and I'll wait until qualified security folks get their hands on this before coming to any conclusions.
What we know is that the initial version was a non-starter, and this new info validates the concerns we've all been expressing.
I truly hope Microsoft does an acceptable job of addressing this. It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
> It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
It's possible this was the intention all along but as a early-beta feature this was just the MVP. The reason it was rolled out to early testers at all was to get feedback.
> It's possible this was the intention all along ... to get feedback
If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.
Microsoft is a big organization with different teams. It wouldn't surprise me if this front-end AI team didn't consider the larger security implications -- having it stored in your profile probably seemed sufficient. It's the same security all your documents have, your browser cache, etc.
If so, that's a problem. It might explain why this happened, but that doesn't mean it's an acceptable practice, especially after recently claiming that security is a primary focus for all project teams.
Security requirements often completely change the architecture of a product. Things can be built without security that are significantly more challenging to accomplish when strict data security requirements are in place. Architectures that assume no security often completely break down when security is tacked on top.
If this is a matter of a product not yet getting "security added", that again raises major concerns about how Microsoft is building products.
It doesn't sound like they're going to have significant problems adding more security to this product. For advanced as it sounds, it's not that complicated of a technology. It's just plugging together a bunch of existing technologies. I could probably MVP this app in a week myself given what is available.
I think that exploratory development is, in general, a good thing. Bogging down all development with middle-management procedures might certainly have caught this early. But that doesn't necessarily make that a better way to build products.
The scary thing about Recall isn't actually Recall itself. It's that AI makes this kind of product possible and really easy. I'm sure we're going to see implementations of this idea everywhere and not just on PCs. Imagine AIs watching security cameras.
Yeah, and places I work with ms stuff keep getting hacked (big important stuff) and leaking stuff and places with linux, or anything else as, far as I can tell don't. Or ar least not in the same number or quantity.
I have never seen a crypto locker ransomware on a server except for windows servers. I haven't seen another OS with ads. So many terroble things happen only in the windows/ms ecosystem that it really makes me wonderhow it sticks around but I have ideas about that and they will just make you think I am wierd.
Virus turns on recall, user might not notice much. A real Microsoft service is running. It can then just wait and activate later. If the user notices recall on, they'll just blame Microsoft. You can then just turn it on again. You can already see that many users are suspect that it'll go back to being on by default sometime in the future too. It's not uncommon to see system updates change settings.
The virus doing the same things as recall will be much noiser and much more suspicious. Making it much more likely to be removed.
Not to mention that once recall has been running a virus only needs to extract the data. It records far more than what a password manager does and is far easier to search through. It just makes a very large attack surface.
Basically, why would anyone develop keyloggers anymore? Microsoft did it for you. And it'll never be tripped by antivirus software because it's an official and legitimately signed program. You don't see a problem with this?
They can't even do their own infra securely, or did you forget a advanced persistent threat entity was in their system and minting certs to access all of azure recently?
On LinkedIn someone in my network pointed out that, apart from the security and privacy disaster, the name Recall was a bad choice because of negative events like product recall.
"Total Recall" in quotes makes me think you're trying to get your ass back to Mars and that you're trying to remember something because you had your memories wiped. It makes me think of nothing about a friendly service being offered forcefully upon you from your friendly and malevolent OS provider.
It's a story about false memories, and how that can change your identity. Regardless, it's the first thing I thought of when I heard about the feature.
It would actually be a fantastic name if this were a real concern. Imagine, a well-known feature to mask any searches of a product recall. The only problem with this theory is that computer QA is so incredibly shit that the concept of a recall more or less doesn’t exist in the first place.
Corporate is never on the bleeding edge of Windows feature updates. They bring security updates first, but feature updates are at least one generation behind, maybe more waiting for Microsoft to fix bugs and doing their own regression testing, plus they get to choose wich features employees receive or are enabled by default via group policy. In other worlds, recall was never making it into any corporation anyway.
This is generally true, but Windows is the standard for far more SMBs than larger enterprise customers, and in that context it’s not nearly so straightforward. I have a client, a health insurance benefits broker for other local businesses. They do very well for themselves, but it’s just 2-3 full-time people, so there’s never been much cause for a full-on domain with GPO policies to maintain a strict, stable state across their equipment. Traditionally, off-the-shelf systems with SMB-targeted software had been more than sufficient.
When Microsoft decided to push a feature upgrade last year that automatically enabled OneDrive backups for their home directories, it technically violated HIPAA by moving electronic patient health information contained within their scanned files folder onto OneDrive servers without any prior consent or authorization. They literally called me when they were unable to find their files, Microsoft had (laughably, if it weren’t so serious) placed a text file on the desktop titled “Where Did My Files Go.txt”, and then directed them to the OneDrive folders where it had moved their desktops, documents, and pictures without their knowledge or approval.
I have since moved them to Microsoft 365 accounts where I can apply GPO, but my clients were understandably unhappy about having a new annual subscription that didn’t add any tangible benefit, rather they’re now on the hook for a couple hundred bucks a year for what’s essentially a shake down. Pay for the new service that adds nothing meaningful to their experience, or else face the consequences of Microsoft ruining your business on a whim.
I would have agreed with you until revently. And now, everyone is throwing email, chat, code, everything into cloud based AI tools at a highly regulated company. This happened 6 months after they just locked everything down for actual employees because of an IP leak. Very strange times…
I bet there are a trillion companies and governments who want to know what all of their employees are doing every second of the workday. compliance won't stop them from trying.
Corporate clients get whatever they want. I am certain that their Windows 10 support won't be pulled in Oct 2025 as MS has threatened for everyone else. And when they migrate to Win11, it will almost certainly be a separate OS image free of the garbage bloatware and ads that the consumer devices are plagued with.
Am I just imagining their saying that Windows 10 would be the last Windows? I had thought they would be moving to an Apple-esque model where OS updates would just become iterative and avoid the old EOL/upgrade cycle. It’s how I justified all of their tangential money-grabs on other fronts.
You aren't the only one, from my understanding it was a misspoken thing by one higher up. It spread, so much so people I knew working at Microsoft spouted it as fact.
Any company that has compliance requirements to keep devices supported with security updates, it's the same as Win 7 to Win 10; you either update everyone to Win 11 or you pay for the security updates for Win 10 (IIRC you have 3 years to update before you can't pay anymore). Many will likely already be on Win 11 as the upgrade path is easier/quicker than Win 7 to 10.
Also they will not have the gunk installed anyway as they will almost certainly have Windows Enterprise which has more policies that can be set, and then they will also be ordering devices from an OEM or distributor that doesn't have the junk included.
Heck, if they aren't doing Autopilot from the OEM or distributor, they will almost certainly be applying their own Windows image.
Depends on the compliance. If this monitoring sucks up any personal data (I don't mean employees' data here—personal data owned by anyone) there are erasure and data subject access requirements, for instance.
Security compliance generally does not require a third-party company, unaffiliated with the corporation, to be sent a copy of everything shown on a user's screen.
I think on the product side it’s pretty straight forward. They saw RewindAI talking up a bunch of traction and people seemingly interested. Someone assumed customers wanted this because of that data, and it’s a pretty easy thing to build, so they went ahead. I am surprised it got past security reviews but I can understand how it came to be from the product side.
They’ll probably think twice before jumping into the fray again with the Microsoft branded Informant Wire (I mean AI wearable) ;)
I don't understand how Outlook isn't a compliance nightmare. Especially since it's moved to the cloud. The amount of very sensitive data Microsoft must have on just about every single business/industry thanks to outlook and excel is insane.
At one place I worked when the company replaced my old machine with a new windows 10 system it was configured to send every single keystroke back to Microsoft. There was zero concern over privacy or compliance, just an assumption that MS would never abuse that data for any reason. I did not have their faith and disabled that "feature" then changed a massive number of other policies to try and keep as much data out of Microsoft's hands as I could.
Doesn't Microsoft have a long history (and present) where they just enable privacy invasive "features" after a windows update even though the user has disabled or removed the "feature"?
Twitter used to do this all the time; they'd make the notification email options more granular and opt you in to the three new options that used to make up the one option you already unchecked.
Windows is soo low quality. It feels cheap. It feels like you are at a car dealership.
Fedora, feels like you are at some futuristic office that has buttons that do multiple steps. I was literally angry last year that it took me so long to learn about up-to-date linux. Canonical's marketing of debian-family linux gave Desktop Linux a bad name.
What exactly is a good usecase for Copilot Pro (I'm assuming Recall will be powered by that in some form)? I'm on the free trial and I'm not finding it to be any more useful than the free version, and pretty similar to ChatGPT.
It'll be the other way around I expect. Recall will provide more context to CoPilot.
It's not really about looking back at your own activity in case you forgot. But the AI will use it to learn about your habits, wants and hates, interests, people you deal with, usual schedule etc.
An assistant is after all much more effective if it knows you through and through. The one problem is: I don't want Microsoft to be that assistant and know all that about me. Even if "it's all local". They still control what gets done with that info and can change it at any time.
The reality is that most people who aren't tech people don't care about the changes Microsoft has done, and shareholders especially don't care. Clearly what Satya is doing is working.
without seeing an actual data file created by recall, i would expect it to quickly become large.
if so, i would not keep it on a system drive, when you can store it externally, to be plugged in when the owner feels they actually need recall data, and left physically out of band when its wise to do so
ideally it wouldnt be expanded, the whole point is to have definite denial of recording at any time, or a cut off period, such as archiving the system portion after 12, or 24 hours. this saves system storage space, and preserves data for the owner should they need what they were doing 6months ago.
I've been a Windows user since 3.1, but this was the straw for me. They have always provided an OS that just worked for my home needs, even with the creeping privacy invasions in the last update.
I've been dual booting for a while and last weekend I went full Linux at home. My day job revolves around being truly good at solving Windows issues, and I will happily continue doing that, but at home I'm still just liking for something that "just works" I hope I'm part of a trend, and that 2024 is the year of the....
No reason to use SteamOS, it's just immutable Arch with an A/B partition scheme. Modern SteamOS is designed specifically for the Steam Deck and they only ship it as a recovery image for the Deck.
You can install Steam on whatever distribution you want, I use the Flatpak, and just enable Proton in the compatibility settings.
And if someone’s after that console-like functionality, ChimeraOS is the right choice in this area. It behaves like SteamOS, but is more compatible with PC hardware.
I'm pretty excited for the Cosmic DE later this year. Here is a demo given by the CEO and the design lead. The audio isn't the best, but good enough. This is probably the most excited I've been to try out a new operating system since OS X Tiger. It is being developed by the Pop OS team, but they are making it so anyone can use it, Fedora plans on having a spin, I believe it's out there for Arch, and I'm sure others will have it as an option. Though I wouldn't use it as a daily driver until it's actually released.
Yes, it's a really tough thing to manage this whole Recall thing philosophically and it makes me concerned about this OS. Even if MS is backtracking somewhat, they have shown their cards now and how they prioritize positioning themselves as an AI company above even rudimentary privacy. It's hard to just regain trust as if nothing happened.
I'm considering Linux with a Windows VM for Visual Studio. I've had my Linux detours in the past and it honestly works pretty well for me. I personally enjoy Fedora with Gnome which I think strikes a good balance between stability, security, and freshness. But if being stable and worryfree is of top importance (like where you are "unpaid tech support", haha), why not just go Debian. :)
If you want Linux isn't "just working" over time, give macOS a look. My dad was a lifelong Windows user and sung the praises of Microsoft's monopoly over the industry. As much as he was disappointed and upset with Borland Software dying off, he thought the benefit of a single document format everyone used was a huge benefit for the industry early on when Word started to take over, and by extension all of the standardization through a single player rather than through actual standards. He always said it worked great and didn't see why he'd ever want to change, or why anyone would want anything different.
He ended up switching to Apple around 15 years ago after a series of bad experiences. He was very nervous about it, and really hedged his bets early on. It took him some time to get used to how the OS worked, to find new apps to replace some that he had used since the Windows 3.1 days, and sort out his workflows. He eventually gave up his Windows VM when he realized the only thing he ever used it for was to run Windows Update.
I grew up on Windows, with the views from my dad instilled in me. In college I tried Linux and ultimately moved to the Mac about 21 years ago. I still used Linux on and off for the past 22 years (and currently have a music server running it). I do find Linux to still be much more finicky than macOS. No system is perfect, but macOS is more of a "just works" operating system than Linux (imo), likely due to the focus on polishing that last 10% of the user experience, that never seems to get the attention it needs in Linux. While I am excited to see what Cosmic has to offer later this year on Pop OS, I'm always ending up having to deal with some level of nonsense, even my most recent install of Mint just last week had a few annoying things where things didn't work, and they should have worked.
Company-wide internal push to shoehorn AI into every product and service. All recognition and rewards are given to the sychophants, no matter how ludicrous their proposals.
Even Principal and Senior developers are dragged into meetings with senior leadership to provide suggestions on how AI can be used in their microcosm. Whether it should be used is completely out of the question.
It’s a complete circus right now. Plenty of us just ignoring it and opting-out but it might reflect on our bonuses.
About a year ago my mom had said "you worked at these powerful international companies, I'd expect you to have confidence in the people working in their ranks to protect the things that you deem valuable", my response was "unfortunately that's exactly the reason why I have no hope that anyone will stand up".
Non-sycophant employees are shut down and ignored once the whole corporate culture has bought in to the hype du jour. If you are the sole dissenter, it can even make you look like a “bad” employee for not recognizing the “opportunity” that the new hyped thing will supposedly bring.
As someone who has tried to push back against what execs ask for many times, if they want it bad enough, it doesn't matter. They will push forward no matter what the objections are. And if the person objecting won't give in, they'll find someone else to do it.
I only have a windows partition for games. I would occasionally use it for other stuff because it's sometimes inconvenient to switch back and forth. After recall, I'm only using it for gaming and nothing else.
I'm surprised by how good proton is at running windows games on steamdeck. Because of this and nonsense like recall and the adverts in windows I'm considering just getting rid of windows all together, I'll just run mint Linux probably.
I run Ubuntu on nearly all of my machines, but I build it up manually from the Ubuntu Server installation to reduce bloat. If anyone was going to have problems with Proton on an Ubuntu machine, it's me. Yet, every game I've tried works fine. Everything from Among Us to Metro Exodus runs great.
Some games require a little fiddling, sure, but I've never had an issue that couldn't be resolved using some copy-pasting from ProtonDB. As you may have surmised from the way I set up my machines, I may have a higher tolerance for fiddling than most folks. YMMV.
I am curious about your Ubuntu setup. Any particular technical reason? Any especially thorny bits? Do you see improved performance or fewer background processes? I am well past the point of enduring this kind of OS pain, and will use the path well trodden by others.
I have always assumed that distros layer on so many extensions, customizations, etc that Gnome or KDE would be alien if naively installed.
Fully de-GNOME'ing desktop Ubuntu is Sisyphean. It's easier to build up Ubuntu Server from a plain terminal.
> Any especially thorny bits?
Nvidia drivers. Just check that all apt packages with the word "nvidia" in them have the same version number. Otherwise Xorg and/or torch will go boom.
> Gnome or KDE
I'm using neither! I have no login manager. I type my username and password into a login shell, run "startx" and that starts i3.
And yes, it is somewhat alien. GTK and Qt based applications will have no theme, so they all default to that black-on-gray circa Windows 95 look.
> Do you see improved performance or fewer background processes?
Yes and yes. With i3wm loaded, my desktop idles at about 100MB of RAM used. My desktop compares favorably to similarly-specced entries on openbenchmarking, especially in IPC-related tests.
It wont affect me personally, because I dont use crappy operating systems on my personal time. Microsoft products are just an efficiency loss, I still bill the same.
I literally get everything done faster on Fedora, no linux prayer needed anymore. Its just better.
It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database, and tracks what you do for the last 90 days. It's just a bit less visual, Incognito/Private modes work, and some users clear it more often.
But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
Browsing history doesn't contain what's displayed on the page, and what you input into the input boxes, or POST requests. It's sorta like telephone metadata.
On the other hand, I am always freaked out by Chrome extensions that "can read and change your data on all websites". Can't they have more granular permissions? You gotta have a lot of trust for those extensions LMAO. They can read your bank passwords, probably!! And if they are ever sold...
Exactly - knowing the content of each webpage is pretty easy if you're "big brother" surveilling millions of people, even more so if you have a Chrome extension to help.
It's "little brother" that benefits a lot here: bosses, spouses, parents, etc., who otherwise wouldn't click on 1000 links in your history.
To be fair for me the extensions that get that are uBO, Privacy Badger, and Tampermonkey.
I trust gorhill and the EFF to not fuck me over on my data, and Tampermonkey kinda needs those sorts of permissions to work. My password manager has read access to every website but I'm already trusting it with all of my passwords so...
These extensions should not store any data without a master password that you input every time.
What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate.
If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
>Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate.
Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has.
>If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
My threat model doesn't include state actors targeting me specifically. Not sure much of anything works against that threat model besides maybe iOS in Lockdown Mode as your only device.
Yes, they can change it, that's what Manifest V2 deprecation is about. It will break a lot of ad blockers, because they rely on being able to read anything and change anything on all websites. Many people feel that Google is doing it to make more people watch more ads, not to improve security.
Yeah, I think this entire debate is uninformed hysteria and manufactured outrage. "If an attacker has administrator access, they can see everything you have done on your computer!". OK? That has literally always been the case? "Attacker is root" is game over and always has been. The original writeup from DoublePulsar tried to justify that Recall is somehow different from other such scenarios, but I found it totally unconvincing.
I think it's the right move to have it off by default, but I'm just not convinced by the outrage here.
To be clear, I am not in favor of Recall or dismissing its intrusiveness. However, the correct comparison is not just "browser history". Google is also tracking your search history, passwords (built-in password manager), location history (Google Maps), ad clicks, and more. All-in, it's a LOT of data.
I'm with you -- I avoid Google products for the reasons you listed and am staunchly anti-surveillance capitalism. I just meant to say that even for a person with my very plugged-in perspective on these topics, Google's violations of my privacy still don't feel quite as invasive as Recall feels, even if on paper it's just as egregious and dangerous.
You’re missing the point. An attacker can only see the passwords in your Recall database if they have root, but if they have root there are (and always have been) a thousand other ways they can get your passwords. There is no new attack vector being introduced by Recall.
If an attacker got root with recall they might not need to wait the user to type their password and risk detection. The information they want to know might be already in the recall database.
I did read the article. The person I'm replying to claims the entire debate was "uninformed hysteria", which means they thought the previous security model already required admin.
Another big, big difference, anybody, not just some black-hat pro with a long kill chain of zero-days, has a fantastic source of data to exfiltrate.
Perhaps you didn't note before, or are one yourself, but this includes e.g. abusive spouses. Sure, maybe the abusive spouse could hire a black hat, but this is very different to a drunk low-life wife-beater casually snooping through "recall".
It might not be a "new" attack vector, but its absolutely a complete degradation to any computer security.
Except that before today you didn’t even need admin for access to the database, any process that is allowed to read things could access the Recall database.
In a typical bigcorp environment, laptops are loaded with silently installed spyware. Certainly equivalent to taking a screenshot every second or an always-on keylogger.
The horse is out of the barn for many people during work hours. But in the OS and on by default is a different story!
Someone with root access can't see anything that has been deleted, or the contents of secure web pages I've visited, like my banks, doctor, or email. Very different.
If there's AI involved, everyone's panic level skyrockets.
No one retweets "Attacker gaining root access reveals all user information", but instead "Attacker gaining root access reveals all user information collected by AI program" will go viral for sure.
I expect it does, if you're using Chrome outside of Incognito Mode. Iirc, there is an opt-out about "web history" on the google account - which then disables some other things so that it annoys enough people into keeping it on.
The vulnerability is that the first thing any malware that happens to run on the PC will do is upload the Recall database, giving the attacker your entire usage history since installation (and of any other user account on the same PC). This can then be analyzed for worthwhile targets for scams and blackmailing.
My browser history does. It's synchronized with every edge instance that I have running. I can open up the tabs from my mobile browser on my desktop and I could see the browser history from everything on everything.
no it isnt the same, you may know I went to my health care provider's website, maybe even to make an appointment depending on the url, but with recall, everything that is on the page will be stored, not just the url. It's totally different. So the message I sent my healthcare provider that is discussing some of my most sensitive medical issues will be available to read and a record is kept of it... not just the url. Do you not see the difference?
Yes, but one product cycle and there's metadata (like a background texture) that tells the OCR to skip this page. Or ask your local LLM if the user is talking about medical conditions? If you like the feature at all you can make these things work.
"If you like the feature at all you can make these things work."
It's not on the individual users to take steps to preserve their basic human dignity. It's not Microsoft to not take that dignity away by default as was their plan before this fiasco predictably blew up in their faces just like the Xbox One always-online Kinect requirement before it.
Your browsing history is unlikely to contain personal information, secrets, porn images etc. And if you use Chrome, they get your full browsing history by default.
I get your point, but Microsoft's Recall can capture anything onscreen - emails, personal info, porn, passwords and the like. And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
Perhaps. A key difference though - history files can include the individual pages I requested from the same host. Right now I have like 50 entries for the various posts I read just from HackerNews, all as separate line items etc etc.
In the case of the phone, one simply sees recipient of call, duration etc, regardless of how much information was exchanged. The phone I'm calling is arguably analogous to the server I request a page from, in the metadata context.
I'd argue browser history is significantly richer in some regards due to this. It's not unheard of for user identifiers to appear in URL paths either - try visiting https://news.ycombinator.com/user?id=<HN user name>... In my Chrome, that's instantly in the history file with my username.
The language spoken by participants during a phone call is also easily classified as “metadata” and could be defended as non-identifiable info with a straight face. So are the number of speakers on the call, the topics of conversation, the intensity of emotions displayed, voice stress levels, and the presence of certain keywords, if you squint a little. The lack of a literal call transcript does not matter much in terms of privacy.
I don’t know anything about this system, but the fact that screen shots are not ultimately stored on the user’s PC doesn’t mean anything if the content has already been classified and indexed. It will be fished.
> that little thought has gone into privacy or security.
I think the thought is proportional to the amount of thought a non-tech customer will put into it. Nobody seems to care about or understands privacy these days. Everyone knows they're being tracked everywhere they go physically and on the web. People use their real names, address, etc for every junk service they sign up for, without seeing any reason not to. If you tell people that their TV is tracking and taking screenshots of what they watch [1], they say "yeah, Netflix knows too".
It's literally, "how it's always been" for any non tech person under 30.
> I think the thought is proportional to the amount of thought a non-tech customer will put into it.
Part of me wonders if this is the consequence of how accessible tech has become, and the prevalence of increasingly non-technical product managers. I'm a former PM, and I'm not here to denigrate the PM role, but the fact that a product like Recall got shipped says a lot about the makeup of the product org that shipped it.
While I get that younger people tend to see privacy differently, I'd argue this isn't really a privacy issue, it's a security conversation, albeit with obvious privacy implications. Leaking what apps I use or what sites I visit is mostly a privacy issue. Leaking what I type into the boxes on those sites is a security issue. If the end result of leaking this info is the attacker can pwn all of my bank accounts, we're solidly into security territory.
The fact that this got shipped means that multiple levels of leadership either didn't think about the consequences or didn't care about the consequences. I hope it's the former, because that means they can learn from the backlash and hopefully recalibrate.
Microsoft is in a position of power that IMO requires a significant duty of care and responsibility to their customers, and lapses like this need to be judged through that lens, i.e. it is their entire business to make sure features like this are safe.
> The fact that this got shipped means that multiple levels of leadership either didn't think about the consequences or didn't care about the consequences. I hope it's the former, because that means they can learn from the backlash and hopefully recalibrate.
There was probably from lower decks, where they are closer to reality. However, people are scared for their jobs in this economy and likely didn’t take it farther.
I think it’s a good point - these are still privacy issues, and being fatigued with the impossibility of defending privacy is indication of a power imbalance, not an acceptable default for humanity.
It's not surprising once you consider that all the big tech firms hire MBAs for their PM roles. The ideal PM profile for these companies is someone with consulting experience who just finished an MBA.
As an engineer with an MBA and in an executive level twchnokogy role, an MBA is part of what I would consider a good background. That said, OP was talking about non-technical PMs. That is the issue. You can teach a tech person to understand business, vision, strategy, finance, etc. You cannot teach very well the business person who has all that the intricacies of technology.
> ... an MBA is part of what I would consider a good background.
Emphasis on "part." I'm totally guessing on this, but I think OP may have been talking about PMs where the MBA is their only notable feature rather than those where the MBA is just one part of a well balanced whole.
> You can teach a tech person to understand business, vision, strategy, finance, etc. You cannot teach very well the business person who has all that the intricacies of technology.
I'm inclined to agree with this. The thing about business degrees is that they are so minimal effort that actually understanding business isn't a prerequisite to being awarded one. I would know, I have 2 of them.
There's no guarantee a "business person" actually learned business, much less that they are capable of learning tech. Don't get me wrong, I'm not by any means implying that all business people are inept or that they are collectively unable to learn tech; it's often unrealistic, but not impossible.
When going to school for tech, such as an MS in engineering, CS, etc., typically requires enough effort that one will end up learning their respective field (I have met exceptions to this and interacting with them is infuriating) whereas going to school for an MBA is one of the easiest ways I know of to get government financing for a decade of partying.
> but the fact that a product like Recall got shipped says a lot about the makeup of the product org that shipped it.
Microsoft is just tripping over themselves right now bringing AI to market because they don't want to miss the boat. Their copilot for office 365 stuff is hardly working, it's real beta quality. No normal company would have released it to market in this state. But they're just terrified that Google will eat their lunch.
I don't think security and privacy concerns are much on the radar there anymore. They just want to establish their name in this new market at all costs. And I think in their eyes it makes sense, they've always succeeded because they had the biggest installed base, not because they were the best. It makes sense they see value in being first mover at all costs.
It's just a bit frustrating as a customer. As usual with something they launch it's more promise than substance. I have to say that usually they do have the follow-through to really make it a success. But it does take time.
> Everyone knows they're being tracked everywhere they go physically and on the web
That sounds good to some people. But if I mentioned it to most people in my family they would probably be rather weirded out by it. They probably also would have no idea of the scope of the size of it and how it is being used against them.
Do you listen to music only with earbuds? Do you cover your face when going outside? Do you transform your voice for each person you’re talking to? Are you buying only with cash that you handled with gloves?
Privacy is not a binary concept. There are actions and information that some people are ok being public, and there are some they prefer to remain private.
What is not OK is spying and exploitation. I should know what data you’re collecting and preferably specify which I’m ok with. I also should know what is intended for and preferably for most of it to be anonymized.
Most people expect reasonable privacy policies from companies and they believe that there’s some regulation in place.
> Most people expect reasonable privacy policies from companies and they believe that there’s some regulation in place.
Absolutely, but if you ask/inform these people they will say "Well, guess I have nothing to hide." because they can't comprehend going without all their devices/services.
Many here may be too young to remember when many consumer products came with a "product registration" card. This was basically a postcard that asked for all sorts of information, such as your name, address, phone number, birthdate, sex, SSN, marital status, annual income, interests, other products owned, whether you own or rent your home, etc.
People willingly filled these out and sent them in. All the info went into databases that were merged with other sources and traded around various marketing agencies on 9-track tape reels. Advertisers could get mailing lists segmented by age, sex, income level, geographical region or specific zip codes, etc. for their campaigns.
It's all much more pervasive and invisible now, but it's basically what has always been done.
I don't know, I don't think sending in product registration cards could/would often result in your bank account being drained...
> It's all much more pervasive and invisible now, but it's basically what has always been done.
So you admit it is far worse today than it was before? But the second half of your sentence seeks to disingenuously pretend that it has "always" been bad.
I can be sick with a cold or I can have stage-four brain cancer. People have "always" been sick but one is serious (terminal cancer) one is not (a non persistent cold).
> It's all much more pervasive and invisible now, but it's basically what has always been done.
Basically is doing a lot of work here, the level and degree of how much data is vacuumed, processed, and used for targeting nowadays is orders of magnitude of difference from these primitive ways.
A tent and a house are basically the same: a shelter.
Right, the pervasivenes today is much higher. But marketers/advertisers have always hoovered up and exploited as much information as was technically possible. That attitude isn't new.
Another thing that is absolutely new is the vast number of people using this data for things other than ads/marketing. The data on registration cards was never used to decide if you get a job or not, or how much you pay for a hotel room vs the next person, or how long you wait on hold when you call a customer service line, or how much your insurance rates go up, or whether or not you're a suspect in a criminal investigation, or if you get custody of your child in a divorce proceeding. The amount of things our data ends up being used for is on a scale that simply was not possible when people started filling out product registration forms.
I can't recall a time where I or anyone I knew filled those out and sent them in. I realize this is anecdotal but it a lot easier to not mail in a form than to try to find the opt-out option in some computer OS.
> And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
No, no. They thought about the privacy and security aspect. They decided that it's better for their bottom line if Windows users don't have privacy from the mother ship. Really, they already decided that way back when Windows Vista first came out and periodically asked Microsoft HQ if you should continue being allowed to use your computer.
I mean, you can't even install Windows 10 without it telling you several times that unless you opt out (again and again), it's going to send just about anything you do to Microsoft…
That was XP, and that was the beginning of my separation from Microsoft stuff in earnest. The Windows XP background and UI is a source of nostalgia for millennials just like Windows 3.x, old-school Mac, or Amiga would be for people my age... but I feel no nostalgia at all for it because I let that generation of Windows, and most subsequent ones, simply pass me by, fortune having smiled upon me and enabled me to work in Linux almost exclusively since around that time.
I think they actually did consider that - that's why they emphasized it was all on device. They thought about it, they just didn't think about how little we would trust that promise.
I'm perplexed that anybody thinks Microsoft were being dumb. They know exactly what they are doing and putting the pieces in place to violate users' security is the point.
Theyre just boiling the frog slowly. It'll be turned on by default soon enough and then theyll start looking for excuses to upload it.
This can be used to make them a shedload of money one day.
I agree, these decisions in 2024 are thoroughly vetted. I think the only thing these companies don't know is when the news cycle will pick up on something they're doing and they get blowback, and they'll have to pretend this was some little oversight.
Honestly, it has the smell of an NSA pressure campaign which would also rake in the money like nobodies business.. an easy choice for Microsoft. They are as guilty as sin for turning everything they create into a surveillance product.
I was just remembering today what they did to the security/encryption as soon as they bought over Skype… they removed it. And who would that benefit - the spies.
No-one cared about that. No-one ever cares. Except for this rare occasion - tides are turning and people are starting to care a tad more.
Adobe figures that if MS can get away with it why can't they? Companies will just keep chipping away at our privacy every chance that they get because our data is extraordinarily valuable and we can't stay hypervigilant and outraged forever. Eventually, they'll get what they want, and then they'll push a little more.
Even if they kept that promise and they never uploaded the data off our devices, someone else (a hacker, a cop, a stalker, a lawyer, a thief, an abuser) will. Their promise is that everything you ever do on your device will be stored anywhere and can be used against you at any time. It turns out that not many people actually want that.
As far as metadata versus data, the URL of a static image automatically discloses the image itself. The only way to claim that the history doesn't actually contain the image is if you assume that the site has gone defunct.
Unless, of course, you're willing to argue that a porn image stored on the local hard drive isn't contained in any folders on the same PC that soft-link it. You might have an interesting time trying to justify why it is contained in folders that hard-link it.
Am I confused about what browser history is or what? Unless you open a static image in a new tab to look at it or you download it (as opposed to simply looking at it on the page it's on), then how on earth would its URL show up in browser history, which by definition tracks user-visited webpages (i.e. top-level links) and not every single URL the browser makes a request to?
Sure, info about non-top-level links is extractable from e.g. request caches, but that's a different thing from the browser history SQLite DB.
That's not the URL of a static image, that's the URL of a web page that happens to have a static image as the only content of worth in it and puts the description of said image in the URL.
Calling it the URL of an image seems to me like quite a bit of confusion about how web pages work.
It's a turn of phrase; it doesn't mean literally no though at all!
On a more relevant note, how can it know when a private browser window is open in anything other than Edge? Same question with the password manager - is there going to be some new API that apps have to "opt in" to to enable Windows to recognise them?
At this point browser cache is known to everyone, and many people do clear it regularly. Browsers save passwords and form data but as far as I know they don't upload that data to Google. Still, chrome is very popular and it sends google people's browsing history and all their DNS traffic.
Yeah, but in theory Recall doesn't upload anything either, which is why it's analogous. And in fact Chrome does upload passwords, and they're not even E2E encrpyted in the default configuration.
The browser history may not, the cache and other local storage may well.
The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other.
Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.
The ickier parts are on the unintended capture side, like enabling "show password" on a site doesn't affect browser history but Recall may capture it in the clear.
Or from history you may see that you accessed a site, but not what you did on it (what comments you typed for example).
This is a horrible comparison. Browsing history doesnt show the contents of the page. It doesnt show you what you were doing on that page. It doesn't reveal anything other than you went there and maybe how long.
Publicly available content, yes. But not the content entered by the user themselves (security question answers, for example), and not contents behind a login, which is usually the case for sensitive information. Screenshots capture them all.
One difference is that Web browser history has been there 30 years, since before most people at the time had even touched a Web browser.
At the time, it wasn't very thinkable that someone would have the audacity to take and abuse that information.
It dates from when Internet people overall were more savvy about privacy than users overall today are, but it was also when the Internet was closer to a trustworthy environment, and before Wall Street sociopath types took over the tech and the culture.
Lots of kinds of abuse that today are routine and almost universal, for even startup tech companies, (e.g., embedding third-party trackers into Web site, and getting even worse from there), I think would've gotten them ostracized, and outraged demands for criminal charges.
During the dotcom gold rush, there was such a flood of totally new, posturing people, and so much money being thrown wildly at everything, that any remaining outrage was lost in the noise.
And now virtually no one knows any different.
But if you're trying to push some new abuse today, I think ordinary people are starting to have some awareness of what vicious sociopathic buttholes tech companies have become, and so acceptance might not be a slam-dunk.
1. Browsing history doesn't show what the user is doing on the page. There is a big difference between logging "user visited his e-banking app", and logging his actual credentials as they are entered.
2. Browsing history watches one app. Screenshots watch everything across the entire OS.
Not just credentials - account balances, account numbers, etc. There's a big difference between your browser history recording that you opened your bank or healthcare provider's web site and Recall recording everything that appeared on the screen while you did.
People might use Incognito mode to browse porn, but I imagine it's a lot less common when looking at other sensitive sites.
Continuing with the comparsion, Recall applies to the entire operating system not just one application. To avoid it, one has to avoid Windows.
Whereas to avoid browsing history, one only has to avoid the popular, graphical, advertising corporation browser. As I am not interesting in graphics, I do this everyday, with ease, because there are countless clients besides "Chrome/Safari/Edge" that work with the www for consuming information.
At least on macOS, I can't navigate to the directory holding Safari's data with other apps (without special full-disk read permissions).
There's also always private browsing, which exists specifically because people are aware of the implications of a browsing history and a persistent cookie jar.
That awareness will be much harder to build for an always-on screen recorder.
From the submitted article, it seems like Microsoft will change/secure the access (and maybe storage) in some way, though there's no details on the specifics.
I hate that most browsers do not let you set them to keep history for longer than 90 days.
I want to be able to find things I've seen before. Recall would've been great if using it didn't require me to update to a version of Windows that contains "Copilot".
All I can say is LOL. Off by default for Windows 11 24H2, on by default in Windows 11 25H2, impossible to disable in Windows 11 26H2 (except in enterprise versions of course). Microsoft's history with respecting the user's wishes speaks for itself.
I saw a yellow dot alert next to the restart/shutdown button on my Windows machine the other day. Those historically indicate a request to restart to apply critical updates. But no, it was a message recommending I sign into a Microsoft account.
That was the last straw for me when it comes to Windows BS---designs that only serve Microsoft, and disrespects all the other times I've said no to their crap. I switched everything over to Linux the next day.
Their GA branch is now the annual channel, not the semiannual, so the next release would be "on by default in 25H2, impossible to disable in 26H2, not available in 27H2".
I'm a little more optimistic. Cortana was mandatory at first. Not easy for the average user to disable. Then Cortana was optional. Easy to turn off and uninstall. Then Cortana was just gone. Floated off to the big orbital in the sky.
If Recall continues to inspire grumbling and receives very little praise, I could see it unceremoniously removed in a Windows 12 26H2 Feature Update.
571 comments
[ 3046 ms ] story [ 4679 ms ] threadThe irony here is thick enough to cut with a knife.
But good on Microsoft for changing their minds and deciding to make this opt-in. That's progress for sure.
But this is a pretty cut and dry announcement. There isn’t any ambiguity they could stand behind if they are lying.
I would fully expect it will be disabled by default (for now)
It will prompt you (and select by default) to disable the need for an online account. I installed the Pro version and then just said I was setting it up for work or school, chose domain and then I set it up just fine as a local account.
I don't know for sure how much of this is rufas or the pro version. But I just installed Windows 11 within the last hour.
> use Rufus to create your installation usb
Pick one. "Normal" users don't use specialized software to create installation media. They boot the laptop with the OS already installed and go on from there.
It is also not uncommon for 'normal' gamers to use a custom built PC which would require installing Windows.
Maybe normal is the wrong word, but it would be a pretty quick and easy to understand guide to do this.
You've already scared away all the normal users
"microsoft office features y and j require Recall! please click here to enable it"
etc etc
However regarding it being opt out… what would prevent a virus from just enabling it on a bunch of machines silently. Sure it would be caught but the damage done and most won’t be bothered to go in and disable it after.
Or Microsoft just decides they need to really market the hell out of AI and it gets turned on my default anyways.
There's no such thing as "accidental enablement" for stuff like this, as if it's a switch every employee at Microsoft has access to, and one of them one day can end up flipping by accident with their elbow and it ends up in production without anyone else noticing.
Either they decide to intentionally enable it or not. There are no accidents , when stuff like this needs to go through a committee of people for approval before it makes it into production.
> unmercenary assumptions
Absolutely. And all of them decided to screw largely defenseless non-technical consumer to make short-term profits. That's not a fantasy, that's our reality.
Or it could just steal your cookies which are out there in the open.
The username/password you type in next time it expires is far more valuable.
And it might not even be necessary to obtain cookies or credentials if I can just see whatever you could see when you’re logged into various sites.
https://doublepulsar.com/recall-stealing-everything-youve-ev...
Microsoft will also require Windows Hello to enable Recall, so you’ll either authenticate with your face, fingerprint, or using a PIN. “In addition, proof of presence is also required to view your timeline and search in Recall,” says Davuluri, so someone won’t be able to start searching through your timeline without authenticating first.
This authentication will also apply to the data protection around the snapshots that Recall creates. “We are adding additional layers of data protection including ‘just in time’ decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so Recall snapshots will only be decrypted and accessible when the user authenticates,” explains Davuluri. “In addition, we encrypted the search index database.”
https://www.theverge.com/2024/6/7/24173499/microsoft-windows...
But I'm glad to hear they've committed to making changes. Given the misrepresentations they made regarding the initial rollout plan (the target of most criticism, mine included), Microsoft has to prove themselves here and I'll wait until qualified security folks get their hands on this before coming to any conclusions.
What we know is that the initial version was a non-starter, and this new info validates the concerns we've all been expressing.
I truly hope Microsoft does an acceptable job of addressing this. It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
https://blogs.windows.com/windowsexperience/2024/06/07/updat...
> It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
It's possible this was the intention all along but as a early-beta feature this was just the MVP. The reason it was rolled out to early testers at all was to get feedback.
If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.
This points to structural issues at Microsoft.
Security requirements often completely change the architecture of a product. Things can be built without security that are significantly more challenging to accomplish when strict data security requirements are in place. Architectures that assume no security often completely break down when security is tacked on top.
If this is a matter of a product not yet getting "security added", that again raises major concerns about how Microsoft is building products.
I think that exploratory development is, in general, a good thing. Bogging down all development with middle-management procedures might certainly have caught this early. But that doesn't necessarily make that a better way to build products.
The scary thing about Recall isn't actually Recall itself. It's that AI makes this kind of product possible and really easy. I'm sure we're going to see implementations of this idea everywhere and not just on PCs. Imagine AIs watching security cameras.
I have never seen a crypto locker ransomware on a server except for windows servers. I haven't seen another OS with ads. So many terroble things happen only in the windows/ms ecosystem that it really makes me wonderhow it sticks around but I have ideas about that and they will just make you think I am wierd.
The virus doing the same things as recall will be much noiser and much more suspicious. Making it much more likely to be removed.
Not to mention that once recall has been running a virus only needs to extract the data. It records far more than what a password manager does and is far easier to search through. It just makes a very large attack surface.
Basically, why would anyone develop keyloggers anymore? Microsoft did it for you. And it'll never be tripped by antivirus software because it's an official and legitimately signed program. You don't see a problem with this?
If that occurs, the malware won't have access to months or years of data to sift through.
Malware that scrapes it and malware that turn it don't need to be the same.
This is what will happen. And when you turn it off again, it'll be turned back on by the next update. Enjoy.
everyone else just gets a laptop, unboxes it, turns it on, uses it, does whatever they want to it
see: any retail location in a strip mall, any mom/pop business, etc etc
When Microsoft decided to push a feature upgrade last year that automatically enabled OneDrive backups for their home directories, it technically violated HIPAA by moving electronic patient health information contained within their scanned files folder onto OneDrive servers without any prior consent or authorization. They literally called me when they were unable to find their files, Microsoft had (laughably, if it weren’t so serious) placed a text file on the desktop titled “Where Did My Files Go.txt”, and then directed them to the OneDrive folders where it had moved their desktops, documents, and pictures without their knowledge or approval.
I have since moved them to Microsoft 365 accounts where I can apply GPO, but my clients were understandably unhappy about having a new annual subscription that didn’t add any tangible benefit, rather they’re now on the hook for a couple hundred bucks a year for what’s essentially a shake down. Pay for the new service that adds nothing meaningful to their experience, or else face the consequences of Microsoft ruining your business on a whim.
Once you have the Recall capabilities, it doesn't take much to start collecting and searching the data.
[1]: https://www.patrick-breyer.de/en/posts/chat-control/
Any company that has compliance requirements to keep devices supported with security updates, it's the same as Win 7 to Win 10; you either update everyone to Win 11 or you pay for the security updates for Win 10 (IIRC you have 3 years to update before you can't pay anymore). Many will likely already be on Win 11 as the upgrade path is easier/quicker than Win 7 to 10.
Also they will not have the gunk installed anyway as they will almost certainly have Windows Enterprise which has more policies that can be set, and then they will also be ordering devices from an OEM or distributor that doesn't have the junk included.
Heck, if they aren't doing Autopilot from the OEM or distributor, they will almost certainly be applying their own Windows image.
Compliance doesn't say "company can't watch employee" -- in many cases it mandates surveillance.
This just lets the employee leverage that too.
They’ll probably think twice before jumping into the fray again with the Microsoft branded Informant Wire (I mean AI wearable) ;)
At one place I worked when the company replaced my old machine with a new windows 10 system it was configured to send every single keystroke back to Microsoft. There was zero concern over privacy or compliance, just an assumption that MS would never abuse that data for any reason. I did not have their faith and disabled that "feature" then changed a massive number of other policies to try and keep as much data out of Microsoft's hands as I could.
https://www.privateinternetaccess.com/blog/microsoft-windows...
https://www.pcworld.com/article/423165/how-to-turn-off-windo...
we'll find a way to turn it on, and share it with our corporate partners
Softwar never changes.
Windows is soo low quality. It feels cheap. It feels like you are at a car dealership.
Fedora, feels like you are at some futuristic office that has buttons that do multiple steps. I was literally angry last year that it took me so long to learn about up-to-date linux. Canonical's marketing of debian-family linux gave Desktop Linux a bad name.
It can't really do anything.
Can someone smarter than I chime in on this?
It's not really about looking back at your own activity in case you forgot. But the AI will use it to learn about your habits, wants and hates, interests, people you deal with, usual schedule etc.
An assistant is after all much more effective if it knows you through and through. The one problem is: I don't want Microsoft to be that assistant and know all that about me. Even if "it's all local". They still control what gets done with that info and can change it at any time.
The reality is that most people who aren't tech people don't care about the changes Microsoft has done, and shareholders especially don't care. Clearly what Satya is doing is working.
if so, i would not keep it on a system drive, when you can store it externally, to be plugged in when the owner feels they actually need recall data, and left physically out of band when its wise to do so
I've been dual booting for a while and last weekend I went full Linux at home. My day job revolves around being truly good at solving Windows issues, and I will happily continue doing that, but at home I'm still just liking for something that "just works" I hope I'm part of a trend, and that 2024 is the year of the....
You can install Steam on whatever distribution you want, I use the Flatpak, and just enable Proton in the compatibility settings.
I got set on SteamOS as i was contemplating buying an SBC with similar hardware and giving it a custom case.
But this looks better!
https://www.youtube.com/watch?v=JHLfsWhDvz0
I'm considering Linux with a Windows VM for Visual Studio. I've had my Linux detours in the past and it honestly works pretty well for me. I personally enjoy Fedora with Gnome which I think strikes a good balance between stability, security, and freshness. But if being stable and worryfree is of top importance (like where you are "unpaid tech support", haha), why not just go Debian. :)
He ended up switching to Apple around 15 years ago after a series of bad experiences. He was very nervous about it, and really hedged his bets early on. It took him some time to get used to how the OS worked, to find new apps to replace some that he had used since the Windows 3.1 days, and sort out his workflows. He eventually gave up his Windows VM when he realized the only thing he ever used it for was to run Windows Update.
I grew up on Windows, with the views from my dad instilled in me. In college I tried Linux and ultimately moved to the Mac about 21 years ago. I still used Linux on and off for the past 22 years (and currently have a music server running it). I do find Linux to still be much more finicky than macOS. No system is perfect, but macOS is more of a "just works" operating system than Linux (imo), likely due to the focus on polishing that last 10% of the user experience, that never seems to get the attention it needs in Linux. While I am excited to see what Cosmic has to offer later this year on Pop OS, I'm always ending up having to deal with some level of nonsense, even my most recent install of Mint just last week had a few annoying things where things didn't work, and they should have worked.
It’s a complete circus right now. Plenty of us just ignoring it and opting-out but it might reflect on our bonuses.
About a year ago my mom had said "you worked at these powerful international companies, I'd expect you to have confidence in the people working in their ranks to protect the things that you deem valuable", my response was "unfortunately that's exactly the reason why I have no hope that anyone will stand up".
Some games require a little fiddling, sure, but I've never had an issue that couldn't be resolved using some copy-pasting from ProtonDB. As you may have surmised from the way I set up my machines, I may have a higher tolerance for fiddling than most folks. YMMV.
I have always assumed that distros layer on so many extensions, customizations, etc that Gnome or KDE would be alien if naively installed.
Fully de-GNOME'ing desktop Ubuntu is Sisyphean. It's easier to build up Ubuntu Server from a plain terminal.
> Any especially thorny bits?
Nvidia drivers. Just check that all apt packages with the word "nvidia" in them have the same version number. Otherwise Xorg and/or torch will go boom.
> Gnome or KDE
I'm using neither! I have no login manager. I type my username and password into a login shell, run "startx" and that starts i3.
And yes, it is somewhat alien. GTK and Qt based applications will have no theme, so they all default to that black-on-gray circa Windows 95 look.
> Do you see improved performance or fewer background processes?
Yes and yes. With i3wm loaded, my desktop idles at about 100MB of RAM used. My desktop compares favorably to similarly-specced entries on openbenchmarking, especially in IPC-related tests.
I note that my Ubuntu derived system idles at multiple gigs of ram
>My workplace
It wont affect me personally, because I dont use crappy operating systems on my personal time. Microsoft products are just an efficiency loss, I still bill the same.
I literally get everything done faster on Fedora, no linux prayer needed anymore. Its just better.
But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
On the other hand, I am always freaked out by Chrome extensions that "can read and change your data on all websites". Can't they have more granular permissions? You gotta have a lot of trust for those extensions LMAO. They can read your bank passwords, probably!! And if they are ever sold...
It's "little brother" that benefits a lot here: bosses, spouses, parents, etc., who otherwise wouldn't click on 1000 links in your history.
I trust gorhill and the EFF to not fuck me over on my data, and Tampermonkey kinda needs those sorts of permissions to work. My password manager has read access to every website but I'm already trusting it with all of my passwords so...
These extensions should not store any data without a master password that you input every time.
What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate.
If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has.
>If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
My threat model doesn't include state actors targeting me specifically. Not sure much of anything works against that threat model besides maybe iOS in Lockdown Mode as your only device.
I have seen Metamask update itself randomly, and it has access to read every website
I think it's the right move to have it off by default, but I'm just not convinced by the outrage here.
In comparison browser history is nothing.
https://x.com/GossiTheDog/status/1798832390070276500
Perhaps you didn't note before, or are one yourself, but this includes e.g. abusive spouses. Sure, maybe the abusive spouse could hire a black hat, but this is very different to a drunk low-life wife-beater casually snooping through "recall".
It might not be a "new" attack vector, but its absolutely a complete degradation to any computer security.
The horse is out of the barn for many people during work hours. But in the OS and on by default is a different story!
No one retweets "Attacker gaining root access reveals all user information", but instead "Attacker gaining root access reveals all user information collected by AI program" will go viral for sure.
It's not on the individual users to take steps to preserve their basic human dignity. It's not Microsoft to not take that dignity away by default as was their plan before this fiasco predictably blew up in their faces just like the Xbox One always-online Kinect requirement before it.
Most of us know that the public Internet is based on surveillance capitalism, no matter if we hate it or are just complacent or ignorant.
OS wide is far more problematic and of low value to the user.
I get your point, but Microsoft's Recall can capture anything onscreen - emails, personal info, porn, passwords and the like. And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
In the case of the phone, one simply sees recipient of call, duration etc, regardless of how much information was exchanged. The phone I'm calling is arguably analogous to the server I request a page from, in the metadata context.
I'd argue browser history is significantly richer in some regards due to this. It's not unheard of for user identifiers to appear in URL paths either - try visiting https://news.ycombinator.com/user?id=<HN user name>... In my Chrome, that's instantly in the history file with my username.
I don’t know anything about this system, but the fact that screen shots are not ultimately stored on the user’s PC doesn’t mean anything if the content has already been classified and indexed. It will be fished.
I think the thought is proportional to the amount of thought a non-tech customer will put into it. Nobody seems to care about or understands privacy these days. Everyone knows they're being tracked everywhere they go physically and on the web. People use their real names, address, etc for every junk service they sign up for, without seeing any reason not to. If you tell people that their TV is tracking and taking screenshots of what they watch [1], they say "yeah, Netflix knows too".
It's literally, "how it's always been" for any non tech person under 30.
[1] https://themarkup.org/privacy/2023/12/12/your-smart-tv-knows...
Part of me wonders if this is the consequence of how accessible tech has become, and the prevalence of increasingly non-technical product managers. I'm a former PM, and I'm not here to denigrate the PM role, but the fact that a product like Recall got shipped says a lot about the makeup of the product org that shipped it.
While I get that younger people tend to see privacy differently, I'd argue this isn't really a privacy issue, it's a security conversation, albeit with obvious privacy implications. Leaking what apps I use or what sites I visit is mostly a privacy issue. Leaking what I type into the boxes on those sites is a security issue. If the end result of leaking this info is the attacker can pwn all of my bank accounts, we're solidly into security territory.
The fact that this got shipped means that multiple levels of leadership either didn't think about the consequences or didn't care about the consequences. I hope it's the former, because that means they can learn from the backlash and hopefully recalibrate.
Microsoft is in a position of power that IMO requires a significant duty of care and responsibility to their customers, and lapses like this need to be judged through that lens, i.e. it is their entire business to make sure features like this are safe.
There was probably from lower decks, where they are closer to reality. However, people are scared for their jobs in this economy and likely didn’t take it farther.
Emphasis on "part." I'm totally guessing on this, but I think OP may have been talking about PMs where the MBA is their only notable feature rather than those where the MBA is just one part of a well balanced whole.
> You can teach a tech person to understand business, vision, strategy, finance, etc. You cannot teach very well the business person who has all that the intricacies of technology.
I'm inclined to agree with this. The thing about business degrees is that they are so minimal effort that actually understanding business isn't a prerequisite to being awarded one. I would know, I have 2 of them.
There's no guarantee a "business person" actually learned business, much less that they are capable of learning tech. Don't get me wrong, I'm not by any means implying that all business people are inept or that they are collectively unable to learn tech; it's often unrealistic, but not impossible.
When going to school for tech, such as an MS in engineering, CS, etc., typically requires enough effort that one will end up learning their respective field (I have met exceptions to this and interacting with them is infuriating) whereas going to school for an MBA is one of the easiest ways I know of to get government financing for a decade of partying.
Well this wasn't in the brochure. Best look into it!
Microsoft is just tripping over themselves right now bringing AI to market because they don't want to miss the boat. Their copilot for office 365 stuff is hardly working, it's real beta quality. No normal company would have released it to market in this state. But they're just terrified that Google will eat their lunch.
I don't think security and privacy concerns are much on the radar there anymore. They just want to establish their name in this new market at all costs. And I think in their eyes it makes sense, they've always succeeded because they had the biggest installed base, not because they were the best. It makes sense they see value in being first mover at all costs.
It's just a bit frustrating as a customer. As usual with something they launch it's more promise than substance. I have to say that usually they do have the follow-through to really make it a success. But it does take time.
That sounds good to some people. But if I mentioned it to most people in my family they would probably be rather weirded out by it. They probably also would have no idea of the scope of the size of it and how it is being used against them.
Privacy is not a binary concept. There are actions and information that some people are ok being public, and there are some they prefer to remain private.
What is not OK is spying and exploitation. I should know what data you’re collecting and preferably specify which I’m ok with. I also should know what is intended for and preferably for most of it to be anonymized.
Most people expect reasonable privacy policies from companies and they believe that there’s some regulation in place.
Absolutely, but if you ask/inform these people they will say "Well, guess I have nothing to hide." because they can't comprehend going without all their devices/services.
Many here may be too young to remember when many consumer products came with a "product registration" card. This was basically a postcard that asked for all sorts of information, such as your name, address, phone number, birthdate, sex, SSN, marital status, annual income, interests, other products owned, whether you own or rent your home, etc.
People willingly filled these out and sent them in. All the info went into databases that were merged with other sources and traded around various marketing agencies on 9-track tape reels. Advertisers could get mailing lists segmented by age, sex, income level, geographical region or specific zip codes, etc. for their campaigns.
It's all much more pervasive and invisible now, but it's basically what has always been done.
I don't know, I don't think sending in product registration cards could/would often result in your bank account being drained...
> It's all much more pervasive and invisible now, but it's basically what has always been done.
So you admit it is far worse today than it was before? But the second half of your sentence seeks to disingenuously pretend that it has "always" been bad.
I can be sick with a cold or I can have stage-four brain cancer. People have "always" been sick but one is serious (terminal cancer) one is not (a non persistent cold).
Basically is doing a lot of work here, the level and degree of how much data is vacuumed, processed, and used for targeting nowadays is orders of magnitude of difference from these primitive ways.
A tent and a house are basically the same: a shelter.
No, no. They thought about the privacy and security aspect. They decided that it's better for their bottom line if Windows users don't have privacy from the mother ship. Really, they already decided that way back when Windows Vista first came out and periodically asked Microsoft HQ if you should continue being allowed to use your computer.
Theyre just boiling the frog slowly. It'll be turned on by default soon enough and then theyll start looking for excuses to upload it.
This can be used to make them a shedload of money one day.
I was just remembering today what they did to the security/encryption as soon as they bought over Skype… they removed it. And who would that benefit - the spies.
No-one cared about that. No-one ever cares. Except for this rare occasion - tides are turning and people are starting to care a tad more.
I don’t have any friends that care about their own security and privacy. Wanna be my friend? Lol
Of all the places on your computer that might contain porn images, that would be one of the very top candidates.
Unless, of course, you're willing to argue that a porn image stored on the local hard drive isn't contained in any folders on the same PC that soft-link it. You might have an interesting time trying to justify why it is contained in folders that hard-link it.
Sure, info about non-top-level links is extractable from e.g. request caches, but that's a different thing from the browser history SQLite DB.
Here is the URL of an image as it appears in your browser history: https://cheezburger.com/10357071872/if-i-fits-i-sits
See if you can figure out what image I was looking at.
Calling it the URL of an image seems to me like quite a bit of confusion about how web pages work.
(I really wish they followed the “standard” keyboard shortcut)
On a more relevant note, how can it know when a private browser window is open in anything other than Edge? Same question with the password manager - is there going to be some new API that apps have to "opt in" to to enable Windows to recognise them?
The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other.
Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.
Or from history you may see that you accessed a site, but not what you did on it (what comments you typed for example).
At the time, it wasn't very thinkable that someone would have the audacity to take and abuse that information.
It dates from when Internet people overall were more savvy about privacy than users overall today are, but it was also when the Internet was closer to a trustworthy environment, and before Wall Street sociopath types took over the tech and the culture.
Lots of kinds of abuse that today are routine and almost universal, for even startup tech companies, (e.g., embedding third-party trackers into Web site, and getting even worse from there), I think would've gotten them ostracized, and outraged demands for criminal charges.
During the dotcom gold rush, there was such a flood of totally new, posturing people, and so much money being thrown wildly at everything, that any remaining outrage was lost in the noise.
And now virtually no one knows any different.
But if you're trying to push some new abuse today, I think ordinary people are starting to have some awareness of what vicious sociopathic buttholes tech companies have become, and so acceptance might not be a slam-dunk.
2. Browsing history watches one app. Screenshots watch everything across the entire OS.
People might use Incognito mode to browse porn, but I imagine it's a lot less common when looking at other sensitive sites.
Does your browser history store pictures of your family?
Whereas to avoid browsing history, one only has to avoid the popular, graphical, advertising corporation browser. As I am not interesting in graphics, I do this everyday, with ease, because there are countless clients besides "Chrome/Safari/Edge" that work with the www for consuming information.
There's also always private browsing, which exists specifically because people are aware of the implications of a browsing history and a persistent cookie jar.
That awareness will be much harder to build for an always-on screen recorder.
Recall seems to be storing its info locally in an unencrypted SQLite database as well.
At least, that's according to the instructions here on how to access and view the contents:
https://www.heise.de/en/news/First-experiences-with-Recall-9...
From the submitted article, it seems like Microsoft will change/secure the access (and maybe storage) in some way, though there's no details on the specifics.
I want to be able to find things I've seen before. Recall would've been great if using it didn't require me to update to a version of Windows that contains "Copilot".
That was the last straw for me when it comes to Windows BS---designs that only serve Microsoft, and disrespects all the other times I've said no to their crap. I switched everything over to Linux the next day.
> on by default in Windows 11 25H1, impossible to disable in Windows 11 25H2
If Recall continues to inspire grumbling and receives very little praise, I could see it unceremoniously removed in a Windows 12 26H2 Feature Update.