Live data from Hacker News

Microsoft Research chief scientist has no issue with Recall

theregister.com

61–70 of 91 posts

Re: Microsoft Research chief scientist has no issue with Recall

#61

Earlier quoted context omitted.

It would be good for security but horrible for usability. I recently got an iPhone and had to migrate to it from my Android phone which turned out to be really unpleasant because I could not carry over WhatsApp data. Turns out that the SQLite database is encrypted and I can’t easily carry it over, nor even get the encryption key in a non-rooted device. Furthermore, there is also the issue that Android only backs up t…

FWIW I did manage to decrypt the sqlite database with the encryption key that you create for google drive backups (and should have noted down somewhere). It's been a while, but I think I used this github repo [0], that was the first search result, and it also mentions the 64 character long key. [0] https://github.com/ElDavoo/wa-crypt-tools

Quickly tried it out again, and it still works

If you still have the key and encrypted database, you "only" need to:

1. Have python

2. Install the project like described in the README

3. Execute

  wacreatekey --hex 
4. Execute

  wadecrypt encrypted_backup.key msgstore.db.crypt15 msgstore.db

Re: Microsoft Research chief scientist has no issue with Recall

#62
post #54
post #46

Earlier quoted context omitted.

well good news, this feature can be 100% disabled by your IT team, and you dont need these snapdragon high end consumer laptops in your hospital anyway. why am i having to defend microsoft? have we all lost our minds? or do we just shoot first, ask questions later for the lulz

Please point to a documentation reference that shows an officially supported way, to completely disable all telemetry on Windows OS...

https://learn.microsoft.com/en-us/compliance/regulatory/offe...

Re: Microsoft Research chief scientist has no issue with Recall

#63
post #3

We've launched a FOSS alternative with OpenRecall https://github.com/openrecall/openrecall to (hopefully) work towards addressing some of the concerns people have with Windows Recall. We think it could be a useful feature but it must be (1) fully auditable/open source (2) using open source local models (3) focused on privacy/security and (4) hardware/OS independent. We're working out the roadmap currently so any feed…

Why would I want this?

https://en.wikipedia.org/wiki/Memex

https://en.wikipedia.org/wiki/Lifelog

https://en.wikipedia.org/wiki/MyLifeBits

Re: Microsoft Research chief scientist has no issue with Recall

#64
post #54

Earlier quoted context omitted.

Please point to a documentation reference that shows an officially supported way, to completely disable all telemetry on Windows OS...

https://learn.microsoft.com/en-us/compliance/regulatory/offe...

This is about Azure Cloud and Office 365. No mention of Windows OS.

Also by the way...although unrelated to the question, does not by itself guarantee compliance, as addressed in the FAQ:

"Does having a Business Associate Agreement with Microsoft ensure my organization's compliance with HIPAA and the HITECH Act?"

"No. By offering a Business Associate Agreement, Microsoft helps support your HIPAA compliance. However, using Microsoft services does not on its own achieve HIPAA compliance..."

Not to mention that HIPAA compliance specifically protects health information (ePHI). It does not cover other types of data, so companies like Microsoft can collect and use telemetry data without violating HIPAA, even if this raises privacy issues.

Re: Microsoft Research chief scientist has no issue with Recall

#65
post #50

Earlier quoted context omitted.

To think it’s purely money is utterly naive. It’s surveillance tech for the NSA which ALSO makes Microsoft a packet.

The nsa doesn’t need recall to gather signals. They can gather higher fidelity data directly as text, network traffic. If the historical data is what concerns you, that assumes the nsa wants to sneak in and then sneak out, but they will just stay there forever. Why only 3 months when you could stay forever.

Again. Utterly bonkers naive. Stupendously naive.

It’d be so much easier to have recall store the data and then have the processor power do the AI analytics on the data.

You also fail to remember the past. Microsoft has a history of changing security settings with updates. Just because the data is stored locally just now does NOT mean that in a few updates time that they won’t change it.

If you genuinely cannot see that it is the slow introduction of powerful NSA surveillance tech, it just means you don’t know Microsoft enough. NSAKey and Prism - Windows has always been about NSA.

This particular surveillance software is leaps better than anything which has become before it, because now they can make the users computers do all the processing and storage. It is vastly superior than their other techniques in so many ways than the methods you mentioned.

Another thing you seem to mix up is that why would NSA have to do all the hard work to surveil system like you mentioned? They can simply hop on to the connections Windows makes to it’s own Microsoft servers. In the same way that AT&T historically had a NSA room in their premises which the entire network went through.

Re: Microsoft Research chief scientist has no issue with Recall

#66
post #2

Sycophantic research chief scientist has no issues with Recall. He cant recall what he really thinks of recall due to the serious business of getting his "sandwiches wrapped in a road map" and sent on his way.

It is a she

[flagged]

Re: Microsoft Research chief scientist has no issue with Recall

#67
post #46

Working at a company in the healthcare space, this raises so many HIPPA compliance questions for our customers it's hilarious. And by hilarious, I mean bad. Screenshots of PHI? Sweet as, just chuck them in an SQLite DB, no worries there.

well good news, this feature can be 100% disabled by your IT team, and you dont need these snapdragon high end consumer laptops in your hospital anyway. why am i having to defend microsoft? have we all lost our minds? or do we just shoot first, ask questions later for the lulz

You shouldn’t be and Microsoft deserves this kind of behavior.

This falls well into the category of a feature that nobody asked for and which shouldn’t exist. Microsoft will make this opt out (if we’re lucky enough) and if even then it will be difficult and hidden to do so, so they’ll trap all the normal users and harvest insane amounts of data.

I have no problems shooting first when the receiving end is Microsoft, because it’s pretty much always deserved.

Re: Microsoft Research chief scientist has no issue with Recall

#68
post #54
post #46

Earlier quoted context omitted.

well good news, this feature can be 100% disabled by your IT team, and you dont need these snapdragon high end consumer laptops in your hospital anyway. why am i having to defend microsoft? have we all lost our minds? or do we just shoot first, ask questions later for the lulz

Please point to a documentation reference that shows an officially supported way, to completely disable all telemetry on Windows OS...

https://learn.microsoft.com/en-us/windows/privacy/manage-con...

is about as close as we get.

Re: Microsoft Research chief scientist has no issue with Recall

#69
post #37

Earlier quoted context omitted.

I don't want to run an operating system where I need to get the vendor's permission to run my own applications under my authority.

This is not correlated. Android has sandboxing and you can run your own applications.

I can't run with full authority on Android, however. My own apps can't access my own data from other apps that I run. This is not something I can forego on my main computing device. I'm willing to tolerate it in a phone because it's just a tool; I wouldn't use a phone to store data I wouldn't mind losing.

Re: Microsoft Research chief scientist has no issue with Recall

#70
post #35

Earlier quoted context omitted.

Some excerpts from https://doublepulsar.com/recall-stealing-everything-youve-ev... : ---------- Q. So how does it work? A. Every few seconds, screenshots are taken. These are automatically OCR’d by Azure AI, running on your device, and written into an SQLite database in the user’s folder. This database file has a record of everything you’ve ever viewed on your PC in plain text. OCR is a process of looking an image, a…

so official microsoft documentation vs infosec twitter. that's not how you back up an argument with proof. there are no microsoft engineers in that video. i see a laptop. is that from tiktok? how are you taking this guy's word for shit without even thinking? its like 13 seconds taken out of context showing a folder click and authorization (what's even happening here, is this an admin account?)

> how are you taking this guy's word for shit without even thinking?

For starters:

* Because it's been confirmed and demonstrated by other people too?

* Because Total Recall (https://github.com/xaitax/TotalRecall) is a thing that you can try yourself?

* Because Microsoft's entire response to concerns has basically been "oh it's fine, _trust us_"

Post reply on HN