Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

381–390 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#381
post #4

Meanwhile Apple Intelligence recalls across all apps with no backlash. I personally like this idea, should be done in a thoughtful and safe way, but recalling your logs is more useful than searching anew. I see the same double standard with Google's generative search vs OpenAI's chatGPT with search - when Google gets it wrong, it's a big issue, but not for the other.

MS recall captures screenshot, analyze them, extract data from them and create a database index of these things so you can search them. Apple AI essentially provides API hooks that apps can use to expose actions and data to the model. Currently it seems Apple own apps does that but any app owner can decide to support this or not. Two completely different approach.

To me it sounds that anyone could implement Microsoft’s approach as an app, there is no reason for it to be bundled with the OS. The only difference would be it would cost users token costs directly as opposed to be paid by other means.

Re: Microsoft to delay release of Recall AI feature on security concerns

#382
post #357

Earlier quoted context omitted.

I imagine MS did a lot of user studies, and found that the average user could gain a lot from being able to ask the computer questions like "where's the word document for the summer anniversary party that I worked on a couple of weeks ago" or "the photo with the waterfall from our holiday in Greece in 2015 that I sent to Mary recently". Whether Recall in 2024 will be good enough to answer queries like that remains to…

> the photo with the waterfall from our holiday in Greece in 2015 that I sent to Mary recently Google Photos' search bar would be able to complete this search, since like 2015. Recall is completely overkill for this, like building a Death Star to swat a fly.

Only if your photos are in Google Photos. And weren't we expressing the concern of sharing our personal data with giant massive tech companies? Google Photos work entirely locally these days?

Re: Microsoft to delay release of Recall AI feature on security concerns

#384
Nevermind the security and ethical issues.

The implementation will be a slog, annoying, and distract from something that Microsoft ought to care about: creating a delightful, snappy experience.

Why isn’t recall a piece of software instead of an operating system integration?

Can apps spawn apps? Like, if you want chrome session recalled- open recall, then open chrome from there?

Why does every new feature need to enshitificate the operating system? Isn’t that an indication that the operating system doesn’t give app developers enough expressive power to create tools that they must go up the hierarchy and reach for OS modification?

Re: Microsoft to delay release of Recall AI feature on security concerns

#385
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

I can't believe that no one there didn't anticipate the blowback. It could just have been a way for Satya to put the feature in front of their business customers. They'd likely want that feature even if consumers reject it.

Re: Microsoft to delay release of Recall AI feature on security concerns

#386
post #187

Recall suffered from a classic Microsoft mistake they've made time and again, but never learned from - how to correctly market and package your feature. Microsoft always tends to "go big" with their integrations, often to their detriment, in order to increase adoption of new features. One notable time was with Windows 8. They really, REALLY wanted people to try out the new Metro UI, so they deeply integrated it into…

The problem is not marketing. The problem is the tool is fundamentally not secure, and in my opinion, fundamentally not securable without major changes.

The core issue is that everyone has things on their computer that they want to be transient. I don't ever want my computer taking screenshots when I'm entering, say, my credit card number. More importantly, though, I oftentimes have text editors containing "scratch pads" that may contain sensitive data that I never want to persist.

Microsoft just never thought through the security implications of this feature.

Re: Microsoft to delay release of Recall AI feature on security concerns

#387

Earlier quoted context omitted.

You are very lucky if you have a choice of OS at work. In any case, something like this wouldn't be hard to implement on Linux. And if Windows normalizes it in corporate environments, rest assured that other parties will offer it for Linux as well.

I don’t really care in corporate settings. I don’t like to bring personal stuff on my work machine anyway. Most of the time the only thing I keep is a picture for setting up my profiles. I have my personal computer or my phone nearby when I want to do these stuff.

I don't want to be spied on at work or at home. These companies are so painfully American in what they think is acceptable.

Re: Microsoft to delay release of Recall AI feature on security concerns

#388
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

My takeaway is that Microsoft has been trying to boil the frog, but slipped and turned the temperature up too quickly. They're retreating for now, but make no mistake that Recall will slowly trickle back into Windows under another name. Every major power broker wants something like Recall to become the norm - bosses to spy on their employees, governments to spy on their citizens/enemies, and tech CEO's to collect tra…

Employers can collect task/business process staps by recording the screens.

This will help train RPA bots and reduce the need for human workforce for repetitive tasks.

Microsoft can collect this data across industries with or without informed consent and sell RPA/AI bots back to the same enterprise customers as a managed service.

Lot of commercial potential there for the taking. Just needs a innocuous enough cover story ro make it a default offering to server you the individual customer alone and help you gain an edge over your peers.

Re: Microsoft to delay release of Recall AI feature on security concerns

#389

Earlier quoted context omitted.

Easy answer. It's a built in history. I use bash history all the time, I use my browser history all the time. To be able to use an OS history would be amazing. What was the name of the esoteric software i was using to program my lego robot, What was I working on last Thursday so I can fill out the government required SHRED report to get the Canadian RnD tax rebate. What was the song i was listening to that Spotify pl…

Which is fine because the browser has a private browsing mode, and the shell has the space trick (for example if a tool requires an SSH key as a command-line argument) as well as various "pinentry" things. You'd need some API for applications to signal to Recall "the user has requested not to save this", and then every single program with a password input box would have to update to call this.

> "the user has requested not to save this"

Yea it has stuff for these use cases.

https://support.microsoft.com/en-us/windows/privacy-and-cont...

Re: Microsoft to delay release of Recall AI feature on security concerns

#390

Earlier quoted context omitted.

Explain "hypocrisy". As far as "overblown" goes, there's no other realm of social balance wherein concession to something means an obligation to an extreme. Last, your statement falsely presupposes that most are happy with any tracking / intrusion.

>Explain "hypocrisy". Recall is neither the first nor the last thing to record and store your actions and data. Why is it such a big problem? >Last, your statement falsely presupposes that most are happy with any tracking / intrusion. Most people are in fact fine with tracking, it has been demonstrated time and time again ad nauseum that the commons do not fucking care about digital privacy and especially if they are…

>Recall is neither the first nor the last thing to record and store your actions and data. Why is it such a big problem?

Not agreeing to something that one does not want, in spite of tolerating qualitatively similar yet different objects that one also does want not want, is not "hypocrisy". It's a boundary.

Are you unfamiliar with the concept of boundaries?

I feel like I'm in an argument with a psychologically abusive SO.

You imply a defect in rationality via your misuse or misunderstanding of vocabulary.

As what? A means of browbeating people into acceptance?

Your need to resort to such a non-agreeable tactic, alone, should inform you that your logic is the problem if not your motive or Recall itself.

It is within everyone's right, and within the bounds of rationality, to reject Recall on its qualitative differences, on the sole fact that they don't want one more tracker when they really don't want the first, or because others seem strangely over-interested in making poor yet insistent arguments in favor of it.

I mean, if it's just one more tracker than why does anyone need it? Right?

Or is the singular nature of Recall that makes it uniquely desirable to some the reason that it is rationally undesirable to others?

Denial of that nature of Recall is what is hypocritical.

>Most people are in fact fine with tracking,

Do "most" people have the option of easily turning tracking completely off? Most are "fine" with it?

Except the ones that aren't, who are tend to also be against having second to second activity recorded. Right?

And who are significant enough that you feel compelled to argue with them here.

>the commons do not fucking care about digital privacy

ooph, the spicy language. I'm persuaded.

>As for intrusions (presumably you mean attacks, whether digital or physical?)

No, as the attack vs tracking difference of user data being sent to an off-site server, and then sold or otherwise, is immaterial when the user isn't aware of the nature of the data being sent if they are aware of it being sent at all. With Recall and for most users, the possibility that screenshot data would be remotely accessed certainly falls under the category of "intrusion". In spite of legalese.

>it's not so much most people are fine with it so much as... it's all far above their paygrades.

Boom

Post reply on HN