Live data from Hacker News

Microsoft will switch off Recall by default after security backlash

wired.com

411–420 of 572 posts

Re: Microsoft will switch off Recall by default after security backlash

#411

Earlier quoted context omitted.

That's old information. This is how Microsoft is intending to change Recall based on these criticisms: Microsoft will also require Windows Hello to enable Recall, so you’ll either authenticate with your face, fingerprint, or using a PIN. “In addition, proof of presence is also required to view your timeline and search in Recall,” says Davuluri, so someone won’t be able to start searching through your timeline without…

"Old" is a bit of a stretch here ;) But I'm glad to hear they've committed to making changes. Given the misrepresentations they made regarding the initial rollout plan (the target of most criticism, mine included), Microsoft has to prove themselves here and I'll wait until qualified security folks get their hands on this before coming to any conclusions. What we know is that the initial version was a non-starter, and…

Well it is "old" since the article is about Microsoft's blog post where they discuss all these changes!

https://blogs.windows.com/windowsexperience/2024/06/07/updat...

> It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.

It's possible this was the intention all along but as a early-beta feature this was just the MVP. The reason it was rolled out to early testers at all was to get feedback.

Re: Microsoft will switch off Recall by default after security backlash

#412

It's sad that Microsoft (or any big company) wouldn't take a step back from such privacy intrusive or anti-user behavior unless there's a public backlash. Can't we just have a peaceful life without wasting time on constantly following and analyzing every single move from these companies?

Microsoft will go ahead with Recall, will temporarily make it opt-in. Eventually, when weather is good they’ll default it to opt-out. If new backlash ensues they’ll PR that it was a a bug and turn it off only to bundle it later with something that can’t be turned off. At this point MS is a toxic company that you’re better off, as a user, to steer away from.

I think they'll abandon it after a few years like they did with Cortana, when the reality of no one wanting to use it sets in.

Re: Microsoft will switch off Recall by default after security backlash

#413
What I think MS should do if they really believed this is a thing people want is make it an actual sold product. Not free. Not a sub.

Just like when we used to have boxed software back in the day. Of course it would be on Windows Store or whatever hogwash they use to push software.

Remember when you had to actually take market risk to publish something and not just "give it for free"? I get times are past that, but if the market is good enough for Cybertruck, surely it's good enough for Recall.

In fact, if I were the CEO I would do this just to allay FTC concerns about big-boi MS and their market power. Like how they made Office for the Mac when Jobs came back and to keep Mac afloat (or like how Google pays Firefox money).

Let the market decide, that's what these capitalists claim to love, right (yes, I know we see through their bluff from both left/right sides of the aisle - that's me calling it there).

Re: Microsoft will switch off Recall by default after security backlash

#414
post #367

I don't understand how recall even got launched. No one should have spent money developing it. Yes, the idea is cool. But even if you trust Microsoft it's obviously a privacy and security nightmare. How many people would install a keylogger on their own system? And then make that keylogger trivial to search through? It just makes windows computers extremely valuable targets for hackers and I'll ban them on my network…

> I don't understand how recall even got launched. No one should have spent money developing it. I disagree. I would feel quite comfortable using functionality like Recall on my personal computer, on which I of course run Linux, if it was opt-in. It's a great idea. The problem is that it's an idea that's just not compatible with how Microsoft is running the Windows platform, the relationship the company has with its…

> The problem is that it's an idea that's just not compatible with how Microsoft

You disagreed but ignored my entire point. No, I don't trust Microsoft, but my point was about even if we did

> I of course run Linux

I use Arch btw

Re: Microsoft will switch off Recall by default after security backlash

#416
When Recall is enabled, it should have an overlay stating that it is active so that all users are aware. Something at least as obvious as the old Windows activation overlay.[0]

Otherwise, every creepy roommate, bad partner, bad friend, etc... will take advantage of this to do bad things.

[0] Ideally more obvious, like when Windows screen recording is running.

Re: Microsoft will switch off Recall by default after security backlash

#417
FF should create a DRM that uses the bullshit webdrm standards and apply it to the entire sandboxed experience. Lock MS the fuck out. Oh you want passwords? Sorry bucko. It's DRM'd. What's good for Hollywood execs is good for End Users. (but we don't get the phat stacks of cash).

Re: Microsoft will switch off Recall by default after security backlash

#418

I am done with Windows, I really love .net, SQL Server, WSL, but I have been burnt on so many of their tools, features etc, Windows 11 was the last straw (task bar unmovable? Are you kidding me? ), and Recall will be the never look back for my personal computing.

Are you switching to Mac?

I did - I had a Macbook air on and off on the side, but Windows was home base for 30 years. I ditched Windows for good when 11 came around, it has become untenable.

Re: Microsoft will switch off Recall by default after security backlash

#420
post #370

Earlier quoted context omitted.

They're quite obviously very different, as browser history doesn't tend to include things like financial details or information subject to an NDA.

The browser history may not, the cache and other local storage may well. The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other. Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.

Only if major browsers are disregarding HTTP cache headers, which is a pretty major allegation. Do you have any evidence to support that?
Post reply on HN