Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

311–320 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#311
post #90

Earlier quoted context omitted.

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

I don't think that mistrust of tech companies is cynicism, especially not after we have seen them repeatedly prioritize profits over our privacy, including literally selling our privacy on the open market.

It's hard for me to imagine that Microsoft would implement a "watches everything you do" program if they didn't want to look at what it sees.

The entire internet, all of your personal information, every written text, and every photo uploaded to social media have been absorbed into these companies AI models, and they are all clamoring to one-up each other. They are going to acquire as much data as they can get their hands on, and this software is a clear way to do it.

Even the AI features in MS Paint will send your data to Microsoft for "content safety", even though the model runs locally. They're already setting the scene for what they plan to do with Recall.

Re: Microsoft to delay release of Recall AI feature on security concerns

#312
post #178

Earlier quoted context omitted.

You're taking about this company: https://learn.microsoft.com/en-us/purview/purview-compliance https://learn.microsoft.com/en-us/purview/communication-comp...

This is disgusting. I did not know that Microsoft offers these tools to organizations. I'm honestly shocked that this exists. They'll 100% abuse preview to offer similar features in the future. Over the last years/decade, they worked hard to improve their image in the tech community, and I have to admit, it worked, at least for me. They've just lost all the respect I had for them.

Every enterprise communication platform provides something similar.

It’s important to realize you don’t own any of the communication on a corporate owned device.

Re: Microsoft to delay release of Recall AI feature on security concerns

#313

Earlier quoted context omitted.

I do not think it is cynical to assume that Microsoft would sell this to companies as a way to do constant surveillance of their employees with OCR and LLMs used to make it easier for a manager to sift through massive amounts of data. That's just an actual use case that their true customers would pay for, I think it's awful and should be illegal under any reasonable worker protections but why would they not advertise…

It's exactly this. Development of a feature like this surely started during the WFH craze, where managers could no longer casually walk behind people who had to have their monitors facing outwards. A market opened up, and this is not the only tool for this sort of corporate surveillance. Certain Software Engineers will probably get some time without it by claiming they need Admin rights and that the system messes up…

It's not even only about surveillance. Microsoft also makes Github Copilot. Getting Recall onto developer machines gives them the opportunity to train their AI on how programmers actually program, rather than just using an LLM trained on code.

Eventually we'll have programmers with Recall activated by company policy on their PCs, actively training the AI models that will replace their labor.

That has to be part of the goal here. The full automation of software development. Think about how much money Microsoft would make if they did it, and how much they would save if they implemented it.

We need a new Luddite movement to protect the workers from all of this.

Re: Microsoft to delay release of Recall AI feature on security concerns

#314

Unless I'm understanding this wrong, 99% of computers out there wouldn't even be able to run this anyway, since it requires a special neural processing chip that supports 40 trillion operations per second (and this can't be the GPU). So basically only Microsoft's own brand new Surface models could even use it in the first place.

Acer Asus Dell HP Lenovo Samsung

https://blogs.microsoft.com/blog/2024/05/20/introducing-copi...

Re: Microsoft to delay release of Recall AI feature on security concerns

#315
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

and your take is quite naive. Surveillance is absolutely the purpose, overt or not. The huge push for bossware/spyware for windows in 2020+ demonstrates that the less ethical portions of industry desperately want to spy on users workstations! Eventually there will be retention laws in certain regulated industries that mandate such technologies! Why enable this potential abuse? Microsoft is trying to Sherlock the surv…

[dead]

Re: Microsoft to delay release of Recall AI feature on security concerns

#316

Earlier quoted context omitted.

[flagged]

You are very lucky if you have a choice of OS at work. In any case, something like this wouldn't be hard to implement on Linux. And if Windows normalizes it in corporate environments, rest assured that other parties will offer it for Linux as well.

I could see this implemented as a hypervisor that doesn't care what OS you're running.

Re: Microsoft to delay release of Recall AI feature on security concerns

#317
post #178

Earlier quoted context omitted.

You're taking about this company: https://learn.microsoft.com/en-us/purview/purview-compliance https://learn.microsoft.com/en-us/purview/communication-comp...

This is disgusting. I did not know that Microsoft offers these tools to organizations. I'm honestly shocked that this exists. They'll 100% abuse preview to offer similar features in the future. Over the last years/decade, they worked hard to improve their image in the tech community, and I have to admit, it worked, at least for me. They've just lost all the respect I had for them.

I can't believe I'm saying this, but in Microsoft's defense, those controls are aimed at companies working in regulated industries. They're meant to help those companies prove they they're meeting their legal and/or contractual compliance obligations.

For example, if your company works with healthcare information and is a HIPAA "covered entity", your customers will demand to see proof that you're using data loss prevention (DLP) software. Such software does things like:

- MITMing output email to make sure you're not sending a spreadsheet full of social security numbers.

- The same but for posts to web forms.

- The same but for instant messengers.

...etc. Netskope is a big player in that space. Go read up on what all their stuff can do sometime. As an individual, a donor to the EFF, and a vocal advocate for user privacy, those things make me shudder. As someone responsible for making sure our employees didn't accidentally upload PHI to Facebook from a work computer, I gritted my teeth and accepted that they're a necessary evil.

There's no reminder that "your work laptop belongs to your employer" quite like working in healthtech. I'm willing to cut Microsoft some slack for offering those products to customers.

Re: Microsoft to delay release of Recall AI feature on security concerns

#318

Earlier quoted context omitted.

Genuinely asking: is that huge in terms of their install base or revenue, or is that huge in terms of PR ramifications (like, "vocal minority" type of deal)? In my younger days I'd've had a heavily skewed pro-gamer and pro-authority-of-the-gamer-rabble viewpoint, but now at this phase of my life I can't help but feel the majority of the places I see Windows are all in business and education contexts (so just business…

Was "gamer-rabble" the word of the day?

Perhaps not the hyphenated form, but I'd had a chat with a friend a couple days ago where we meandered around some surface level philosophy and I paraphrased a section or two from Thus Spoke Zarathustra about the rabble ([1]), so I'm sure that's why it was front of mind. I only used it twice just to be clear that it was referring to the same thing, I didn't intend for any semantic satiation or emphasis through repetition. My apologies!

[1] http://www.literaturepage.com/read/thusspakezarathustra-107....

Re: Microsoft to delay release of Recall AI feature on security concerns

#319
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

Explain the personal utility here... Ohh I cannot find that one website I visited but I know I had found it a couple weeks back? Really. The personal utility use case looks pretty weak IMO.

I disagree. I think having an easy to search database of everything I've looked at would be very useful.

And if I ever want such a thing, I'll be happy to go and find one and install it myself. I don't want it anywhere near my computer unless I deliberately select and acquire it myself.

Re: Microsoft to delay release of Recall AI feature on security concerns

#320

Earlier quoted context omitted.

Your post could've been written in 2004, when Microsoft was pinky swearing it was gonna refocus on security-first development, starting with XP SP2

To be a bit fair, Windows security has gone from a laughing stock in 2004, to having Windows Defender in the 2020s. I ain't no city slickin' infosec guy, but Defender appears to be state of the art end point protection today. They can figure this stuff out sometimes, right? How did they get from Windows/AVG/ESET to Windows Defender, and how can they make that happen on Azure?

To me this seems like a different aspect of security. The push with the winxp service packs onwards was to make it secure by default against the network (trying to be vague because I'll probably be wrong on the details), I'm fairly sure it was xp where you could be infected before setup was complete if the network was plugged in, or that acquiring third party AV was something you must do for anything that touches the internet or media from a source you can't 100% trust. Now with defender this is far in the background for most users that they don't need to think about it at all.

The difference with recall is about blast radius of any unauthorized/unintended access, which still happens even if it's less common or via something like clicking a bad link in an email. That's in addition to mistrust of MS or large corporations sucking up data, and how secure they are (what would a Ashley Madison type breach look like with recall data?)

Post reply on HN