Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

121–130 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#121

This is not a must have feature for me, but I am interested to see how it unfolds and I can definitely see it being useful in the future. I do think they bungled the launch by not thinking through the security implications, and particularly how many sensitive threads this crosses. That being said, they took a risk, it did not go over well, and they’re adjusting. I am sure I will get flamed, but I appreciate the appro…

What’s damning is that they didn’t foresee the obvious reaction. It’s characteristic of the bubble that informs their product design decisions.

Re: Microsoft to delay release of Recall AI feature on security concerns

#122

Earlier quoted context omitted.

There's a much more mundane read: They invested a bunch of effort into a product the market loudly rejected. They're now withdrawing the product while they figure out what they can salvage from the effort. Key stakeholders may have a few ideas about how to proceed (ranging from "try again later" through "repurpose it" to "forget it"), but enterprises of Microsoft size make decisions very slowly so of course it's vagu…

In addition to direct market reaction, they must be a bit red in the face considering that Apple just laid out a complex and well thought out implementation of "AI", which focused on privacy. As someone who grew up near Redmond, who still has an emotional soft-spot for Microsoft for some reason, I feel truly embarrassed for their implementation.

From all three major OS vendors on the consumer market, Microsoft is still the one that pushes more C and C++ into production on their OS, in detriment of .NET, despite all the security discussions.

All the efforts from other teams to have .NET reach Swift, Java, Kotlin levels of adoption on Windows, have always hit a wall against WinDev culture.

Also the 90's spirit from features over security hasn't yet gone away from WinDev, so it isn't really surprising this turned out this way.

Re: Microsoft to delay release of Recall AI feature on security concerns

#123
You know what would be catastrophically bad? A Recall AI feature being baked into Android.

Like most people don't actually use personal computers anymore, even laptops aren't common among demos younger than millennials. I can tolerate switching to Linux or buying a steam deck.

But if this became a hard coded feature of android or iOS I'd have to give up smartphones entirely.

Re: Microsoft to delay release of Recall AI feature on security concerns

#124
post #115
post #88

Recall uses local AI models built into Windows 11 to screenshot mostly everything you see or do on your computer and then give you the ability to search and retrieve items you’ve seen. An explorable timeline lets you scroll through these snapshots to look back on what you did on a particular day on your PC. Everything in Recall is designed to remain local and private on-device, so no data is used to train Microsoft’s…

Newer Apple Intelligence features will require 16gb ram and new M-series chips to run on-device. How is Microsoft able to release wide-spread features on device when there is a much diverse ecosystem of lower-powered, low-cost, windows devices??

This feature is exclusive to PCs designated as CoPilot+, which requires 16 gigs of ram and a NPU of a certain speed.

Re: Microsoft to delay release of Recall AI feature on security concerns

#125
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

It's a system that constantly surveils you, of course it's meant for surveillance. The only question is who gets access, is it just you, or is it you and the cops, or is it you and the cops and anyone with a checkbook.

I think the issue is more that nobody asked for it.

These tools are useful, and on a Mac if you want Rewind, you have to know you want it, go out download it, pay for it, install it yourself .. and you knew what you were getting into the whole time.

Having a tool like this planted in your device without your consent is pushing your userbase over the edge.

If they made it a separate feature you had to manually install, like Windows Sandbox or WSL .. they could have avoided shooting themselves in the foot.

Re: Microsoft to delay release of Recall AI feature on security concerns

#126
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

You're assuming Microsoft acts as a singular, cohesive entity, which like any company it is not.

Re: Microsoft to delay release of Recall AI feature on security concerns

#127
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

> I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility.

In the future companies can have this enabled and just ask chatgpt to fire bottom 10% of staff.

Or they can ask microsoft to 'train' their own company AI based on worker interactions then fire them once the AI can mimic the work good enough. (this is likely the goal)

Re: Microsoft to delay release of Recall AI feature on security concerns

#128
post #92
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

> I've not seen anything to make me think this feature is intended for surveillance It's published by Microsoft

tbh that's a knockdown argument. All the conversation second guessing the intent and motives of bosses, users and third parties is moot when it runs on an OS that is controlled remotely and insecure by design. Apple are following, (and I exlect you'll have even less choice about that - because its clientsode scanning in disguise) and Google have always been proud of their surveillance based business model, so I think the whole landscape of big provider computing is changing. People are actually starting to question what they want computer devices for

Re: Microsoft to delay release of Recall AI feature on security concerns

#129
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

As far as I know, a long while ago, the Islamic Republic of Iran asked Cisco to develop a filtering solution to stop their citizens from accessing undesirable content. Cisco said no. Then US companies started asking for filters to stop their employees watching porn at work, Cisco invented a centralised domain/packet filtering solution for their routers, and Iran went "can we buy one of those, please?".

My take is that MS did intend the feature purely for utility (and to be fair to them I can think of a lot of scenarios where it is useful). But they did this by not seriously thinking about security at all, and the wider internet has now done that thinking for them.

It reminds me of why SSL version numbers effectively start at 3. Netscape wrote version 1, their internal security team broke it, so they wrote version 2 and I believe shipped it without letting their internal security team do a full review. That got broken quickly too, so they want back and did the job properly (by the standards of the day) and shipped SSL v3, which lasted a while. (It's also been broken now, of course.)

I think Microsoft realised recall needed more work, and is now looking at that more seriously.

Re: Microsoft to delay release of Recall AI feature on security concerns

#130
post #122

Earlier quoted context omitted.

In addition to direct market reaction, they must be a bit red in the face considering that Apple just laid out a complex and well thought out implementation of "AI", which focused on privacy. As someone who grew up near Redmond, who still has an emotional soft-spot for Microsoft for some reason, I feel truly embarrassed for their implementation.

From all three major OS vendors on the consumer market, Microsoft is still the one that pushes more C and C++ into production on their OS, in detriment of .NET, despite all the security discussions. All the efforts from other teams to have .NET reach Swift, Java, Kotlin levels of adoption on Windows, have always hit a wall against WinDev culture. Also the 90's spirit from features over security hasn't yet gone away f…

My personal feelings aside, Microsoft is Too Big to Suck like this, regarding security and privacy. At this point, their culture is a national security liability.

We have seen some recent efforts, but how does one right such a large ship?

https://www.theregister.com/2024/06/14/brad_smith_microsoft_...

https://www.theverge.com/2024/4/3/24119787/microsoft-cloud-e...

Post reply on HN