Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

21–30 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#21
post #19

> The lack of a formal market for land has not made land any cheaper, it has simply shifted the price from being denominated in money-dollars, to time-dollars and pain-in-the-butt-dollars. Vitalik writes about this too: https://vitalik.eth.limo/general/2021/08/22/prices.html

Off topic??

Re: Microsoft to delay release of Recall AI feature on security concerns

#22
post #19

> The lack of a formal market for land has not made land any cheaper, it has simply shifted the price from being denominated in money-dollars, to time-dollars and pain-in-the-butt-dollars. Vitalik writes about this too: https://vitalik.eth.limo/general/2021/08/22/prices.html

Off topic??

Definitely off topic. Should have been posted somewhere here: https://news.ycombinator.com/item?id=40676408

Re: Microsoft to delay release of Recall AI feature on security concerns

#23
post #12
post #4

Meanwhile Apple Intelligence recalls across all apps with no backlash. I personally like this idea, should be done in a thoughtful and safe way, but recalling your logs is more useful than searching anew. I see the same double standard with Google's generative search vs OpenAI's chatGPT with search - when Google gets it wrong, it's a big issue, but not for the other.

Are we really comparing a userland, unencrypted-at-rest SQLite database with Apple's app sandbox + secure enclave?

To be evenhanded, encrypting SQLite at rest is a well-solved problem. Dr. Richard Hipp and his merry men even sell an official extension to do so. Plenty of third party FOSS solutions also exist for this.

I feel if that were the case I'd suddenly feel a lot more comfortable with the MS approach than the Apple approach.

Re: Microsoft to delay release of Recall AI feature on security concerns

#24
post #9
post #4

Meanwhile Apple Intelligence recalls across all apps with no backlash. I personally like this idea, should be done in a thoughtful and safe way, but recalling your logs is more useful than searching anew. I see the same double standard with Google's generative search vs OpenAI's chatGPT with search - when Google gets it wrong, it's a big issue, but not for the other.

Their implementation is entirely different. This is like comparing Telegram to Signal.

More like comparing Instagram to Signal

Re: Microsoft to delay release of Recall AI feature on security concerns

#25
I don’t understand how the gap was so large between them saying this data was encrypted/protected and people easily being able to get the raw data. I know once you’re on someone’s machine in a way all bets are off, but it feels like this should have had far greater security attached to it. It doesn’t seem to even match their promises. Couldn’t this have been seen a mile away?

Re: Microsoft to delay release of Recall AI feature on security concerns

#26
post #4

Meanwhile Apple Intelligence recalls across all apps with no backlash. I personally like this idea, should be done in a thoughtful and safe way, but recalling your logs is more useful than searching anew. I see the same double standard with Google's generative search vs OpenAI's chatGPT with search - when Google gets it wrong, it's a big issue, but not for the other.

MS recall captures screenshot, analyze them, extract data from them and create a database index of these things so you can search them. Apple AI essentially provides API hooks that apps can use to expose actions and data to the model. Currently it seems Apple own apps does that but any app owner can decide to support this or not. Two completely different approach.

Not only that but the data is what is exposed to spotlight - an api that’s existed forever. iOS 18 just has much better search over the same data.

Re: Microsoft to delay release of Recall AI feature on security concerns

#27
post #12

Earlier quoted context omitted.

Are we really comparing a userland, unencrypted-at-rest SQLite database with Apple's app sandbox + secure enclave?

To be evenhanded, encrypting SQLite at rest is a well-solved problem. Dr. Richard Hipp and his merry men even sell an official extension to do so. Plenty of third party FOSS solutions also exist for this. I feel if that were the case I'd suddenly feel a lot more comfortable with the MS approach than the Apple approach.

Under what circumstances would someone have access to the database but not the key?

Re: Microsoft to delay release of Recall AI feature on security concerns

#28
post #16

Earlier quoted context omitted.

> Browsing history, Undo in any number of productivity software, search histories both local (eg: Windows) and remote (eg: Google, Bing), password managers and Post-Its on monitors(tm), chat logs, vidja gaem save files, and more. None of these are taking screenshots of your entire desktop, using OCR and AI to summarize all text/secrets displayed and storing them in a single centralized, location, (currently) easily e…

Is there a difference between that and the others? I'm not seeing one fundamentally and brutally speaking. Also, if a hostile has access to your computer then all bets are off. Nothing matters at that point besides how quickly you can remove that access if it's even possible and whether you can deal with the fallout.

I probably would have agreed once that someone physically having access to your computer was as bad as things could get.

Given the choice now though between someone having access to my computer, _or_ someone having physical access to my computer as well as a database with a detailed and lengthy history of every secret i've ever seen in my terminal or web browser, as well every bit of employer or customer data that I've seen whilst working, as well as well ... everything else personal, all in one nice tidy package they could download and search as they pleased - I think the former would end up not being quite as bad things could get.

Post reply on HN