Live data from Hacker News

Microsoft will switch off Recall by default after security backlash

wired.com

361–370 of 572 posts

Re: Microsoft will switch off Recall by default after security backlash

#362
post #194

This is nothing. An abusive spouse will easily switch it to on. It's very likely Windows will downright push you to do so anyways. How does Microsoft intend to mitigate that harm? Because AirTags worked out just fine: > AirTags have been a tool for stalkers and domestic abusers since Apple launched them in 2021. Police records show that this is a problem, and the legal system has failed women who were targeted by sta…

You are trying to appeal to morally corrupt people.

Instead you should hurt their business. Ditch Windows, switch to open source solutions, do not but their product and services. This is the only language they understand.

Re: Microsoft will switch off Recall by default after security backlash

#363

Earlier quoted context omitted.

What value is that? My auth cookies are far more valuable than anything I typed out in the open today.

Your auth cookie expires. The username/password you type in next time it expires is far more valuable. And it might not even be necessary to obtain cookies or credentials if I can just see whatever you could see when you’re logged into various sites.

This is all moot anyway because Microsoft has already said they are now going to encrypt everything behind Windows Hello making it as secure as my password manager.

Re: Microsoft will switch off Recall by default after security backlash

#364

Do we know anything about Linux support for Snapdragon X.. Personally, I don't trust Qualcomm with Linux support. Their WiFi adapters don't work properly with Linux. Their mobile SoC that supposedly have mainline support only have the CPU part working, but GPU, modem, Bluetooth, etc. won't. Also, wasn't their history of closed source drivers and their short support timeline was the reason Android devices only ever go…

Here's what Qualcomm is saying: https://www.qualcomm.com/developer/blog/2024/05/upstreaming-... They claim they're all in on making Linux work seamlessly on the Snapdragon X. I'll leave it up to you on whether or not to believe them.

Funny enough, that's the article I read before commenting. They've made bold claims in the past and failed to deliver.

Re: Microsoft will switch off Recall by default after security backlash

#365

Maybe a bit off-topic, but I sure wish they'd do this for OneDrive! I installed Windows for personal use for the first time recently (although I use it exclusively at work) and it drove me ABSOLUTELY BONKERS that my home drive was mapping to C:\Users\atribecalledqst\OneDrive. What I hated the most was that the File Explorer just calls the folders in there e.g. "Documents" and "Pictures" without showing the full path.…

Yes, Onedrive started out as a pretty useful tool but has turned into a deceptive trojan that tries to force whatever growth metric MSFT managers are currently chasing through a combination of dark patterns (like hiding true file paths from view) and also simply refusing to operate in obviously useful ways which many users want and expect (like not having a built-in way to back up only specific sub-folders on differe…

[dead]

Re: Microsoft will switch off Recall by default after security backlash

#366

Maybe a bit off-topic, but I sure wish they'd do this for OneDrive! I installed Windows for personal use for the first time recently (although I use it exclusively at work) and it drove me ABSOLUTELY BONKERS that my home drive was mapping to C:\Users\atribecalledqst\OneDrive. What I hated the most was that the File Explorer just calls the folders in there e.g. "Documents" and "Pictures" without showing the full path.…

Hang around kids and even though they can be pretty good at using a computer, they have no clue how the thing actually works. They don't know what a file is anymore. Everything is a shiny little icon in a shiny little magic folder. Not trying to make this sound like a value judgment, more an observation. But it makes you wonder, what do we lose by excessive abstraction.

This isn't excessive abstraction - this is just different abstraction. Files and folders are a human invention, and there's no law of nature forcing us to continue using them. It's like complaining about people forgetting how to use MS-DOS commands, when Windows (until PowerShell) was built on GUIs through and through and MS-DOS commands were only still there for compatibility. You don't have to learn MS-DOS command to copy files, you learn to use Explorer to copy files (which to a small extent is like using the MS-DOS command).

Or like complaining people forgot how to use teletypes. We didn't have to keep using teletypes, and we didn't keep using them. Our Linux terminals are still modeled after teletypes, but not in a way that has anything to do with using a real teletype. You don't learn teletypes, you learn terminals (which to a medium extent are like teletypes).

It isn't like when people don't learn to add numbers or how Quicksort works or assembly code. Those are still fundamental truths that help people understand things. It's more like not learning to write Roman numerals, or not learning ALGOL 60. Nothing is really lost except the ability to read old things. You don't learn Roman numerals, you learn western Arabic numerals, and they're better, not worse. You don't learn ALGOL 60, you learn C11, and some people would argue whether it's better, but it's not worse.

Re: Microsoft will switch off Recall by default after security backlash

#367

I don't understand how recall even got launched. No one should have spent money developing it. Yes, the idea is cool. But even if you trust Microsoft it's obviously a privacy and security nightmare. How many people would install a keylogger on their own system? And then make that keylogger trivial to search through? It just makes windows computers extremely valuable targets for hackers and I'll ban them on my network…

> I don't understand how recall even got launched. No one should have spent money developing it.

I disagree. I would feel quite comfortable using functionality like Recall on my personal computer, on which I of course run Linux, if it was opt-in. It's a great idea.

The problem is that it's an idea that's just not compatible with how Microsoft is running the Windows platform, the relationship the company has with its customers, and that it was originally announced as impossible to disable.

Recall as default-on for managed corporate devices is preposterous, for example.

Re: Microsoft will switch off Recall by default after security backlash

#369
post #360

Earlier quoted context omitted.

I recently tried to fully rid myself of OneDrive and it took me over 48 hours to accomplish. The only working method I found involved fully enabling OneDrive, signing in, and waiting for a full sync. Only then was I able to tell it to stop syncing and finally remap Documents, Downloads, Pictures, etc. The fact that I needed to log in, wait 24 hours for my account to unlock due to inactivity (!!!), and enable sync in…

That is truly insidious, but FWIW, you don't need to abandon Windows entirely because of this. There are ways of creating a custom Windows installation disk that removes OneDrive, along with other bloatware, spyware, and pretty much anything else you don't like. Look into tools such as Tiny11 Builder, MSMG Toolkit, NTLite, etc. This is a decent guide[1] for setting all of this up. The process is quite tedious and tak…

[dead]

Re: Microsoft will switch off Recall by default after security backlash

#370
post #58

It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database, and tracks what you do for the last 90 days. It's just a bit less visual, Incognito/Private modes work, and some users clear it more often. But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual att…

They're quite obviously very different, as browser history doesn't tend to include things like financial details or information subject to an NDA.

The browser history may not, the cache and other local storage may well.

The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other.

Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.

Post reply on HN