Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

211–220 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#211
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

Given they have performed the strategy of user-hostile rollouts time and time again, why would you think they would behave any differently?

Relatedly, do you like ads in the OS?

Re: Microsoft to delay release of Recall AI feature on security concerns

#212
post #73

What a dumb feature. They had to get all that backlash to understand why everyone wouldn't want it. Is someone at Microsoft taking crazy pills to think consumers would be into that? They pulled the exact same shit 11 years ago when they launched the Xbox One as a "home media center" instead of a gaming console and it came with mandatory always-on internet connection, disc games DRM tied to a single console unable to…

It's not as stupid as you're making it out to be. For almost all tech companies - hell, almost all companies in the modern world - customer abuse is a first-class strategy. Some push it further than others, some are more blatant than others. It's probably not about them being insanely out-of-touch with what people want, but about them miscalculating what people will tolerate. Microsoft seems to be willing to push thi…

Yeah, and if you do that long enough, eventually there will be generation of consumers which think that it is totally normal.

I remember a time, when I set specific firewall rules for each application. A time where I would never allow to share my location. A time where I would never link my google account to other services. But as I grew older I stopped caring because I have other stuff to do.

The problem is, that those companies have time on their side. They can do whatever they want, back out, constantly rebrand stuff and confuse their users until we eventually give up. And at some point a large part of the population stops caring, because it's a fight, which is very hard to win. I hate it, but I have not the strength, time and will to push back.

Re: Microsoft to delay release of Recall AI feature on security concerns

#213

Earlier quoted context omitted.

I do not think it is cynical to assume that Microsoft would sell this to companies as a way to do constant surveillance of their employees with OCR and LLMs used to make it easier for a manager to sift through massive amounts of data. That's just an actual use case that their true customers would pay for, I think it's awful and should be illegal under any reasonable worker protections but why would they not advertise…

It's exactly this. Development of a feature like this surely started during the WFH craze, where managers could no longer casually walk behind people who had to have their monitors facing outwards. A market opened up, and this is not the only tool for this sort of corporate surveillance. Certain Software Engineers will probably get some time without it by claiming they need Admin rights and that the system messes up…

[flagged]

Re: Microsoft to delay release of Recall AI feature on security concerns

#214
post #171
post #95

Earlier quoted context omitted.

Has TPM been a net positive or negative for users / enterprises / the industry?

TPM protects against two main threat models: 1. You don't trust people with physical access to the computer. For the average home user, this means you consider the hardware owner a threat. 2. You want to protect against malware that has already taken complete control over the OS at runtime, and that wants to write itself to disk or the BIOS so that it survives a reboot. At this point, the attacker has already won, so…

For a mobile device, such as a laptop, lots of people other than the device owner will have physical access.

The useful use-case of a TPM to me is the ability to encrypt my disk without having to type a decryption password each time I use it.

Re: Microsoft to delay release of Recall AI feature on security concerns

#215
post #157

Earlier quoted context omitted.

> Every major power broker wants something like Recall to become the norm - bosses to spy on their employees... Isn't that already the norm, or at least very very common? It's just a 3rd party package totally focused on surveillance, not built into the OS and used for some user-accessible features. > ...governments to spy on their citizens/enemies, and tech CEO's to collect training data for AI and target more ads at…

>These applications would be novel, at least on a widespread basis in Western liberal democracies. How? We already know Google trains its AI on people's private emails and Five Eyes conducts mass surveillance on Western citizens (see: Snowden). You can be sure that the people behind the PRISM program are salivating at the thought of access to the unencrypted Recall databases, and that they'll be twisting Microsoft's…

>> These applications would be novel, at least on a widespread basis in Western liberal democracies.

> How? We already know...

I think you're making the mistake of interpreting this as a binary thing, which obscures the difference between, for instance, tapping phone calls and installing bugs in every room of everyone's home (a la 1984's telescreens). Or in this case, Google scanning the emails you sent/stored on their servers vs. Microsoft storing and scanning every action you take on your PC.

It would be novel because most people outside a corporate environment don't have a keylogger/screen-recorder running on their system.

Re: Microsoft to delay release of Recall AI feature on security concerns

#216

Earlier quoted context omitted.

What if you can't afford a Mac, and you're not technically literate enough to install Ubuntu ? Speaking for myself, I dual boot mint and windows because I really like playing games and making music. Both of those are absolutely subpar on Linux. Outside of our nerd bubble, most normal people don't really want to run desktop Linux. Macs are great, but I can't really game on them.

What is this laptop that costs less than a Mac but is good for gaming?

Steam Deck + bluetooth mouse and keyboard + external monitor if you want

Re: Microsoft to delay release of Recall AI feature on security concerns

#217
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

> It focuses on security, reiterates that security is their top priority (and we know that this is untrue).

I think that messaging is a direct response to their hearing in from of the House yesterday. They were being grilled on their numerous security lapses and Brad Smith (president of Microsoft) constantly reiterated that they are refocusing their priorities to be security. They were also questioned about Recall specifically so it's not surprising to see this as one of the first places where they are putting out that messaging.

Re: Microsoft to delay release of Recall AI feature on security concerns

#218

This is only the beginning of AI-centric offerings that were oversold and will be delayed or quietly abandoned. LLMs are nice for simple things, but they’ve already reached their limits. No amount of data will solve the iteration and complexity problems.

Every month I am in meetings where LLMs are being considered for applications they are absolutely not the right fit, but the answer to my concerns is "we need more AI advocates". These conversations are led by people who never actually read a single paper on LLMs or tried them in real life. They have no idea about risks, but plough on because their clueless bosses told them to come up with a plan to use AI.

Honestly, people just need to touch a hot pan every now and then. Let them slap their LLM onto something low-stakes and experience the results for themselves.

Everyone does, it's just that some of us have the decency to do it in a homelab or on a cheap proof of concept first.

Re: Microsoft to delay release of Recall AI feature on security concerns

#219
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

With large corporations and governments the general rule is: assume a cynical take until proved as not.

I actually think this is a pretty healthy mindset for anything that is political.

Re: Microsoft to delay release of Recall AI feature on security concerns

#220
post #63

In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk. Anyone who is still using windows in 2024 and isnt a multinational business or llc gets what they deserve.

> In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk.

I think it's more narrow than that. Yesterday, Brad Smith (president of Microsoft) went in front of the House committee for Homeland security and they were making the case that Microsoft is a national security risk.

Corporate customers may react based off of that testimony, but given the timing, it feels like the US government is the motivating factor for this announcement today.

Post reply on HN