Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

201–210 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#201
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

> What were the security problems?

> They don't even allude to the existence or detection of any specific security problems

Arguably the product itself. Which is another reason they might be vague about it. Because to talk about those security problems would taint the entire product and they can't do that if they aren't willing to completely scrap it.

People have been talking about how the data in here is similar to what may be already existing but that's far from the truth. Yes, these companies have a lot of data on us, but this is a significant step forwards in the granularity of that data. It's also worth noting that hackers could not get into your computer and assume that your computer not only has a keylogger that they can access to further compromise your system (and other systems/accounts) but that they can also obtain screenshots. These increase user risk significantly and greatly reduce the requisite technical skill needed for those infiltrating machines.

Similarly, many have pointed out the potential connections to Chat Control[0] and how such systems can likely be used by many companies to be exploitative of workers. While you may trust your company/partner/significant others/government and so on, it is important to remember that not everyone has such luxuries. It is also important to remember that such things can change. Even in the US there are high risks of potential abuse: such as police obtaining a warrant to get this data to see if someone is trying to obtain abortion medication. Regardless on where you fall on that specific issue, you can replace it with any other concerning issue and I'm sure you wouldn't like that (guns, religion, gender identity, political affiliations, and so on). So even if you trust Microsoft to not give away this type of information nor to provide authorities access (which often includes authorities not in your home country), then you must ask if the benefits are worth the costs. And not just for you, but for others.[1]

> It sounds to me like they're figuring out a new marketing approach

I suspect this is correct and as segasaturn suggested, turned up the heat too fast. I also suspect that this type of data invasion can be much more easily understood by the general public, who often struggle with understanding what metadata is and how it is/can be used. It does require technical knowledge for this and is often non-obvious, even for people who are well above average in technical literacy (as is the average HN user).

[0] Specifically we should note here that Chat Control would force Microsoft to use this system in a much more invasive way. We lambasted Apple over their proposal for CSAM detection, including the potential risks of abuse even if it were theoretically impossible to avoid hash collisions. Having Relay would require Microsoft to implement such a system and that's why there are many conspiracies arising that Relay is specifically intended for Chat Control, because true or not it would likely have similar outcomes. We'll see if Apple revisits the idea, and the recent WWDC doesn't rule out such a possibility https://www.patrick-breyer.de/en/posts/chat-control/

[1] https://www.youtube.com/watch?v=goQ4ii-zBMw

Re: Microsoft to delay release of Recall AI feature on security concerns

#202
post #198

Earlier quoted context omitted.

If I understand the modern security issues correctly, this is all happening on Azure, correct? Windows is relatively secure, but their cloud has too much legacy compatibility/tech debt? For example, Kerberos support in Azure AD led to the some of the latest issues?

On the contrary, Azure has a much better security culture than Windows business unit. Most stuff is built with .NET, Go, Java and Rust, while the hypervisors are based on Windows (Azure Host OS[0]) it isn't the same as regular Windows, and most workloads are Linux based, officially > 60% [1]. Finally, starting this year, Azure has new security guidelines, all new software is to be written in managed languages, if a G…

Thank you, I really appreciate this response. I need to read all of this. However, the most recent compromises did happen on Azure, and not Windows, correct?

edit: and of course that's where the threat actors put their focus, because that's where the data lived.

Re: Microsoft to delay release of Recall AI feature on security concerns

#203
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

Per one of the ars Technica articles, All the information collected was stored locally completely unencrypted, and would be accessible by anyone with local administrator rights.

Re: Microsoft to delay release of Recall AI feature on security concerns

#204
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

https://answers.microsoft.com/en-us/msteams/forum/all/tracki...

Re: Microsoft to delay release of Recall AI feature on security concerns

#205
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

They're totally waiting for the negative press to die down, then they'll try again.

Re: Microsoft to delay release of Recall AI feature on security concerns

#206
post #63

In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk. Anyone who is still using windows in 2024 and isnt a multinational business or llc gets what they deserve.

What if you can't afford a Mac, and you're not technically literate enough to install Ubuntu ? Speaking for myself, I dual boot mint and windows because I really like playing games and making music. Both of those are absolutely subpar on Linux. Outside of our nerd bubble, most normal people don't really want to run desktop Linux. Macs are great, but I can't really game on them.

Then you install one of those slimmed down builds of Windows that removes almost everything that isn't required to run win32 software.

Re: Microsoft to delay release of Recall AI feature on security concerns

#207
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

> I've not seen anything to make me think this feature is intended for surveillance What it's intended for and what it can actually be used for are two different things.

> According to the cybernetician, the purpose of a system is what it does. This is a basic dictum. It stands for bald fact, which makes a better starting point in seeking understanding than the familiar attributions of good intention, prejudices about expectations, moral judgment, or sheer ignorance of circumstances.

— Stafford Beer, 2001 (via Wikipedia: https://en.wikipedia.org/w/index.php?title=The_purpose_of_a_...)

Re: Microsoft to delay release of Recall AI feature on security concerns

#208
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

> This is a very cynical take.

I think it fits reality.

Re: Microsoft to delay release of Recall AI feature on security concerns

#209
post #63

In summary: the only customers that matter --corporations paying site licenses-- declared this to be an unacceptable business risk. Anyone who is still using windows in 2024 and isnt a multinational business or llc gets what they deserve.

I work for an S-Corp with ~500 office employees and high nine-figure revenue (in dollars). All of our industry specific software is only available on Windows.

What’s your industry?

Re: Microsoft to delay release of Recall AI feature on security concerns

#210

This is not a must have feature for me, but I am interested to see how it unfolds and I can definitely see it being useful in the future. I do think they bungled the launch by not thinking through the security implications, and particularly how many sensitive threads this crosses. That being said, they took a risk, it did not go over well, and they’re adjusting. I am sure I will get flamed, but I appreciate the appro…

I think there's more to it than that. After a while, they say "We're going to send some of your information into the cloud to give you a better experience." Then a while after that, you have to click the button giving permission to send all your information to the cloud or you can't use Windows. In spite of claims often made on this site that nobody understands or cares about privacy, people do care and understand wh…

Or at the very least, every other week when your computer forcibly updates itself as Windows likes to do, and you go through your 127th iteration of the onboarding process to your own computer that you've owned for 4 years, one of the new steps will be "Enable Copilot for an improved experience!" with a big "Enable" button and a tiny little piece of text that you wouldn't know was clickable for "More options" which spawns a button labeled "Leave off for now (not recommended)"
Post reply on HN