Live data from Hacker News

Microsoft to delay release of Recall AI feature on security concerns

reuters.com

431–440 of 485 posts

Re: Microsoft to delay release of Recall AI feature on security concerns

#431
post #90

Earlier quoted context omitted.

This is a very cynical take. I've not seen anything to make me think this feature is intended for surveillance as opposed to personal utility. The personal utility benefits are very clear to me - the problem is the ease with which malicious attackers might steal the data (if they can breach the system).

and your take is quite naive. Surveillance is absolutely the purpose, overt or not. The huge push for bossware/spyware for windows in 2020+ demonstrates that the less ethical portions of industry desperately want to spy on users workstations! Eventually there will be retention laws in certain regulated industries that mandate such technologies! Why enable this potential abuse? Microsoft is trying to Sherlock the surv…

I would suspect its much more ambitious than just peeking over your shoulder.

If you are going to try to make some new product to automate white color jobs a good way would be to sample what all the people are actually doing on windows every 5 seconds and see what you really have.

Peeking over your shoulder will be a side effect you get for free.

It is amusing to me because I was actually considering getting a windows laptop then they pull this shit. So standard for this evil company, I had just been lulled to sleep.

Re: Microsoft to delay release of Recall AI feature on security concerns

#432

Earlier quoted context omitted.

Which is fine because the browser has a private browsing mode, and the shell has the space trick (for example if a tool requires an SSH key as a command-line argument) as well as various "pinentry" things. You'd need some API for applications to signal to Recall "the user has requested not to save this", and then every single program with a password input box would have to update to call this.

> "the user has requested not to save this" Yea it has stuff for these use cases. https://support.microsoft.com/en-us/windows/privacy-and-cont...

All the important controls here have to be done by the user. You really think the average user is going to blacklist things in the awful settings app?

Re: Microsoft to delay release of Recall AI feature on security concerns

#433
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

My recollection is that the CEO stated no security problem with the product, security was their utmost and first the toppest priority all the time and into eternity, they wouldn't dare trying to release anything with security concerns.

Apparently there are security concerns afterall. Did they lie before or now or just completely clueless about what is a security concern or what? I am confused.

Re: Microsoft to delay release of Recall AI feature on security concerns

#434
post #55

This is confusing and vague to me, which I believe is exactly the intent. It focuses on security, reiterates that security is their top priority (and we know that this is untrue). What were the security problems? They don't even allude to the existence or detection of any specific security problems. It sounds to me like they're figuring out a new marketing approach, or they're softening the blow by "listening to user…

Per one of the ars Technica articles, All the information collected was stored locally completely unencrypted, and would be accessible by anyone with local administrator rights.

What if it was encrypted but the key need to be present locally anyway. Key under the mat situation? PIN on the back of the card case?

Re: Microsoft to delay release of Recall AI feature on security concerns

#435
post #273

Earlier quoted context omitted.

The delay of Recall has absolutely nothing to do with technical limitations.

The marketing was 100% trying to sell AI built into a new version of Windows. They completely jumped the shark because of technology. That they weren’t thinking it through is endemic of everything going on relating to LLMs.

[deleted]

Re: Microsoft to delay release of Recall AI feature on security concerns

#436

Satya Nadella's Microsoft is such a weird company. It's like there's one side of it that is running with Zuckerberg's "move fast and break things" and the other side is saying "wait, we're the most important software company in the world! Things can't break!"

This is a pretty insightful comment. That's exactly how it feels. The core of their technologies have never been more solid, including Windows. But then on top of that solid core is a bunch of "move fast and break things" and short-term profit choices that make the whole thing seem awful.

Don't forget the ones that can't get a simple chat app to work right (Microsoft Teams) or the ones redesigning outlook which introduced a shit ton of bugs.

It's amazing that humans as a collective have decided that private corporations are the best way to progress as a civilization.

Re: Microsoft to delay release of Recall AI feature on security concerns

#437
post #187

Recall suffered from a classic Microsoft mistake they've made time and again, but never learned from - how to correctly market and package your feature. Microsoft always tends to "go big" with their integrations, often to their detriment, in order to increase adoption of new features. One notable time was with Windows 8. They really, REALLY wanted people to try out the new Metro UI, so they deeply integrated it into…

> Microsoft pushed what objectively is a great tool

... excuse me!? Complete surveillance being a great tool?! Objectively great tool?! Maybe in China, yes.

Re: Microsoft to delay release of Recall AI feature on security concerns

#438
post #171
post #95

Earlier quoted context omitted.

Has TPM been a net positive or negative for users / enterprises / the industry?

TPM protects against two main threat models: 1. You don't trust people with physical access to the computer. For the average home user, this means you consider the hardware owner a threat. 2. You want to protect against malware that has already taken complete control over the OS at runtime, and that wants to write itself to disk or the BIOS so that it survives a reboot. At this point, the attacker has already won, so…

I think you are missing some parts in the industrial use.

The TPM is also used for device authentication. It prevents the leakage of certificates that are used to ensure that you are using the device you claim to be using. This is highly relevant when having remote access from users and one would like to enforce tiering rules together with privileged access workstations.

Furthermore, the second example in which "the attacker already won" is missing the context. The attacker does not want to access the computer (in the industrial example), it wants to use to escalate access within its organization. The TPM can be used for remote attestation, that is, a remote server can verify the integrity of the boot process of the device before giving access to remote resources. In other words, it can be used to check for device compliance.

It is definitely a positive for enterprise security.

Re: Microsoft to delay release of Recall AI feature on security concerns

#439
post #187

Recall suffered from a classic Microsoft mistake they've made time and again, but never learned from - how to correctly market and package your feature. Microsoft always tends to "go big" with their integrations, often to their detriment, in order to increase adoption of new features. One notable time was with Windows 8. They really, REALLY wanted people to try out the new Metro UI, so they deeply integrated it into…

> The same thing is happening here - Microsoft pushed what objectively is a great tool, but they did so in a way that never gave users a choice of whether or not they wanted it.

Citation needed. I highly doubt this is true.

Re: Microsoft to delay release of Recall AI feature on security concerns

#440
post #432

Earlier quoted context omitted.

> "the user has requested not to save this" Yea it has stuff for these use cases. https://support.microsoft.com/en-us/windows/privacy-and-cont...

All the important controls here have to be done by the user. You really think the average user is going to blacklist things in the awful settings app?

what could the OS do to "blacklist" things on its own?

How would the OS have any chance of knowing I don't want my programming session recorded if I don't' tell it?

How would google chrome know to go to incognito mode if I don't tell it?

Of course the burden for this is on the user, what other way could possibly work?

Post reply on HN