Live data from Hacker News

Microsoft will switch off Recall by default after security backlash

wired.com

431–440 of 572 posts

Re: Microsoft will switch off Recall by default after security backlash

#431
post #58

It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database, and tracks what you do for the last 90 days. It's just a bit less visual, Incognito/Private modes work, and some users clear it more often. But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual att…

This is a horrible comparison. Browsing history doesnt show the contents of the page. It doesnt show you what you were doing on that page. It doesn't reveal anything other than you went there and maybe how long.

It's like the difference between sniff https and http traffic

Re: Microsoft will switch off Recall by default after security backlash

#432

Earlier quoted context omitted.

Well it is "old" since the article is about Microsoft's blog post where they discuss all these changes! https://blogs.windows.com/windowsexperience/2024/06/07/updat... > It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection. It's possible this was the intention all along but as a early-beta feature this was just the MVP. The rea…

> It's possible this was the intention all along ... to get feedback If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.

Microsoft is a big organization with different teams. It wouldn't surprise me if this front-end AI team didn't consider the larger security implications -- having it stored in your profile probably seemed sufficient. It's the same security all your documents have, your browser cache, etc.

Re: Microsoft will switch off Recall by default after security backlash

#433

Earlier quoted context omitted.

"Total Recall", aka "We Can Remember It For You Wholesale"

"Total Recall" in quotes makes me think you're trying to get your ass back to Mars and that you're trying to remember something because you had your memories wiped. It makes me think of nothing about a friendly service being offered forcefully upon you from your friendly and malevolent OS provider.

Get your ass back to libre software!

Re: Microsoft will switch off Recall by default after security backlash

#434
post #360

Earlier quoted context omitted.

I recently tried to fully rid myself of OneDrive and it took me over 48 hours to accomplish. The only working method I found involved fully enabling OneDrive, signing in, and waiting for a full sync. Only then was I able to tell it to stop syncing and finally remap Documents, Downloads, Pictures, etc. The fact that I needed to log in, wait 24 hours for my account to unlock due to inactivity (!!!), and enable sync in…

That is truly insidious, but FWIW, you don't need to abandon Windows entirely because of this. There are ways of creating a custom Windows installation disk that removes OneDrive, along with other bloatware, spyware, and pretty much anything else you don't like. Look into tools such as Tiny11 Builder, MSMG Toolkit, NTLite, etc. This is a decent guide[1] for setting all of this up. The process is quite tedious and tak…

Thanks, I'll take a look into this! I'm still probably going to move to a linux distro for my desktop, but I'm always down to try breaking things on another system.

Re: Microsoft will switch off Recall by default after security backlash

#435

Earlier quoted context omitted.

> It's possible this was the intention all along ... to get feedback If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.

Microsoft is a big organization with different teams. It wouldn't surprise me if this front-end AI team didn't consider the larger security implications -- having it stored in your profile probably seemed sufficient. It's the same security all your documents have, your browser cache, etc.

They clearly did not consider the larger security implications. That is both the point and the problem.

This points to structural issues at Microsoft.

Re: Microsoft will switch off Recall by default after security backlash

#436

Earlier quoted context omitted.

I recently tried to fully rid myself of OneDrive and it took me over 48 hours to accomplish. The only working method I found involved fully enabling OneDrive, signing in, and waiting for a full sync. Only then was I able to tell it to stop syncing and finally remap Documents, Downloads, Pictures, etc. The fact that I needed to log in, wait 24 hours for my account to unlock due to inactivity (!!!), and enable sync in…

And I can almost guarentee you it will magically all turn itself back on/reinstall itself eventually after the OS force updates/reboots itself in the not too distant future.

It's already re-created the OneDrive folder, but it hasn't moved any of my libraries back yet. Knock on wood.

Re: Microsoft will switch off Recall by default after security backlash

#437
post #427

When Recall is enabled, it should have an overlay stating that it is active so that all users are aware. Something at least as obvious as the old Windows activation overlay.[0] Otherwise, every creepy roommate, bad partner, bad friend, etc... will take advantage of this to do bad things. [0] Ideally more obvious, like when Windows screen recording is running.

How is this different from having screen recording on?

If you had screen recording on by default you’d run out of disk space pretty quick.

MS just did what every other micromanagement company did and took screenshots every second or so.

Re: Microsoft will switch off Recall by default after security backlash

#438
post #421
post #338

Earlier quoted context omitted.

>Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate. Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has. >If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that…

Extensions can simply download and update their own code, eg by loading new stuff from localStorage. I have seen Metamask update itself randomly, and it has access to read every website

Crypto wallets in web browser extensions seems like an absolutely terrible idea compared to any of my example.

Re: Microsoft will switch off Recall by default after security backlash

#440

Earlier quoted context omitted.

Microsoft is a big organization with different teams. It wouldn't surprise me if this front-end AI team didn't consider the larger security implications -- having it stored in your profile probably seemed sufficient. It's the same security all your documents have, your browser cache, etc.

They clearly did not consider the larger security implications. That is both the point and the problem. This points to structural issues at Microsoft.

Maybe security oversight happens later in the process. No need to bother with that if the feature doesn't even work.
Post reply on HN