Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

91–100 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#91

This is not a must have feature for me, but I am interested to see how it unfolds and I can definitely see it being useful in the future. I do think they bungled the launch by not thinking through the security implications, and particularly how many sensitive threads this crosses. That being said, they took a risk, it did not go over well, and they’re adjusting. I am sure I will get flamed, but I appreciate the appro…

I think there's more to it than that. After a while, they say "We're going to send some of your information into the cloud to give you a better experience." Then a while after that, you have to click the button giving permission to send all your information to the cloud or you can't use Windows.

In spite of claims often made on this site that nobody understands or cares about privacy, people do care and understand when it's something this obvious and this extreme.

Re: Microsoft to delay release of Recall AI feature on security concerns

#92
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

> I've not seen anything to make me think this feature is intended for surveillance

It's published by Microsoft

Re: Microsoft to delay release of Recall AI feature on security concerns

#93
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

TPM was met with resistance due to privacy concerns and Microsoft quietly re-introduced it anyway. The same will happen to Recall.

Re: Microsoft to delay release of Recall AI feature on security concerns

#94
post #85
post #63

In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk. Anyone who is still using windows in 2024 and isnt a multinational business or llc gets what they deserve.

Not quite true: The other huge group of customers is simply gamers.

And more generally, consumers of Windows-only software, of which there is still a ton.

Re: Microsoft to delay release of Recall AI feature on security concerns

#95
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

TPM was met with resistance due to privacy concerns and Microsoft quietly re-introduced it anyway. The same will happen to Recall.

Has TPM been a net positive or negative for users / enterprises / the industry?

Re: Microsoft to delay release of Recall AI feature on security concerns

#96
post #63

In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk. Anyone who is still using windows in 2024 and isnt a multinational business or llc gets what they deserve.

And what should we choose instead? $$$$ set of adapters or Kubuntu that can’t calm down with updates and sudo password?

Before putting me in crazy fanboy fandom, I’ve used all three systems each for at least a decade now (and counting), and windows wins workstation pc award by simply being alone in the league of what works out of box with no additional expenses or headaches.

Edit: don’t get me wrong I hate ms, but I hate stupid bugs and restrictions much more.

Re: Microsoft to delay release of Recall AI feature on security concerns

#97
post #78

What is recall ai?

It's a system microsoft designed that took regular screenshots of what was happening on the desktop, stored them in a sqlite database, and then allowed people to ask their "AI" questions that would take into account literally everything they user has ever done on their computer. People pointed out that this would record things like people watching porn, typing in banking credentials, viewing bills, filing taxes, etc…

I didn't think Recall was about answering questions - there was no LLM component - so much as it was about being able to search your history, based on a combination of SQLite FTS against OCRd text plus CLIP-style embeddings-based semantic search against the content of those images.

Re: Microsoft to delay release of Recall AI feature on security concerns

#98

This is only the beginning of AI-centric offerings that were oversold and will be delayed or quietly abandoned. LLMs are nice for simple things, but they’ve already reached their limits. No amount of data will solve the iteration and complexity problems.

Every month I am in meetings where LLMs are being considered for applications they are absolutely not the right fit, but the answer to my concerns is "we need more AI advocates". These conversations are led by people who never actually read a single paper on LLMs or tried them in real life. They have no idea about risks, but plough on because their clueless bosses told them to come up with a plan to use AI.

Re: Microsoft to delay release of Recall AI feature on security concerns

#99
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

There's a much more mundane read: They invested a bunch of effort into a product the market loudly rejected. They're now withdrawing the product while they figure out what they can salvage from the effort. Key stakeholders may have a few ideas about how to proceed (ranging from "try again later" through "repurpose it" to "forget it"), but enterprises of Microsoft size make decisions very slowly so of course it's vagu…

In addition to direct market reaction, they must be a bit red in the face considering that Apple just laid out a complex and well thought out implementation of "AI", which focused on privacy.

As someone who grew up near Redmond, who still has an emotional soft-spot for Microsoft for some reason, I feel truly embarrassed for their implementation.

Re: Microsoft to delay release of Recall AI feature on security concerns

#100
post #50

Earlier quoted context omitted.

MS recall captures screenshot, analyze them, extract data from them and create a database index of these things so you can search them. Apple AI essentially provides API hooks that apps can use to expose actions and data to the model. Currently it seems Apple own apps does that but any app owner can decide to support this or not. Two completely different approach.

> Two completely different approach. Just semantics. In the end Apple has access to everything, like MS.

I suspect Apple doesn’t have access to everything typed into a web form, or in a notes app, even if those values are erased/backspaces, not saved, not submitted. But Recall does. All usernames in all apps/websites. The content of every single web page you visit, not just the URL. The content of every email you read, every document you open of any kind in any app. Apple _might_ spy on some of this. Recall WOULD record ALL of that. Very different in my opinion.
Post reply on HN