Skip to content

Microsoft’s Recall feature is still threat to privacy despite recent tweaks

Technology
82 42 472
  • In what sense?

    • if you send plaintext, their email service could spy on them
    • once they decrypt, they could accidentally reply with the decryped text, or it could get backed up if they store a copy somewhere
    • screen readers could store decrypted email

    In general, if you don't trust the receiver, you shouldn't send sensitive information. Windows Recall doesn't change that, if they're competent, Windows Recall won't be enabled.

    I think this is more an issue for less technical users instead of activists, because activists will be more careful about who they trust than a secretary or something for a powerful individual.

  • Access controls is the big difference. Apps with sensitive data can choose to hide stuff to a system wid search API. It can do so on an individual level, even. And even if it previously was accessible it can be drumroll recalled. Exposure happens when a search is made.

    Microsoft Recall is all or nothing. Once it has been displayed Recall has it and you can't selectively erase stuff. Exposure is immediate. It's just purge the whole database, or leave it all in there. Apps can't retroactively flag stuff.

    ... But leaving AI summaries on by default was very stupid by Apple

  • Access controls is the big difference. Apps with sensitive data can choose to hide stuff to a system wid search API. It can do so on an individual level, even. And even if it previously was accessible it can be drumroll recalled. Exposure happens when a search is made.

    Microsoft Recall is all or nothing. Once it has been displayed Recall has it and you can't selectively erase stuff. Exposure is immediate. It's just purge the whole database, or leave it all in there. Apps can't retroactively flag stuff.

    ... But leaving AI summaries on by default was very stupid by Apple

    I'd argue that this is way more nuance than the public in general puts into the issue. In fact, the goalposts have moved quite a bit. "The big difference" used to be the local encription of the data, but it became not it once Recall implemented that. Or the opt-in, which went the same way.

    That's not to say I don't think it's a better idea to have per-app support (which is incidentally how Microsoft implemented the feature in Windows 8 the first time), but I will say that's not why people are mad at one and not the other.

    I don't actually know if you can selectively erase specific screenshots from the database because I, again, can't find any traces of Recall on my supported PCs for the life of me. Coverage had made it seem that they could, since presumably the much criticised side effect of having a local, freely accessible database with just a bunch of pictures is that you could... you know, access those. Did they obscure it further in the reimplementation?

    And also, I think people believe I'm being argumentative, but I'm not. Can somebody point me at the Recall opt-in and/or some explanation why my Copilot + device running 24H2 would not seem to have it available anywhere? I'm confused about the rollout here. I don't want it on, but I'd like to try it and see what the practical implementation is for myself (and be double sure I have it turned off once I'm done with that).

  • Funnily enough, Signal has circumvented the issue by marking their chat window as DRM content, making it invisible to Recall.

    They used the invasion of privacy to destroy the invasion of privacy?

  • This post did not contain any content.

    This is just a thinly veiled ad for AdGuard.

  • Funnily enough, Signal has circumvented the issue by marking their chat window as DRM content, making it invisible to Recall.

    They didn’t circumvent the issue - they did what Microsoft tell developers to do in regards to their programs and recall lol.

  • I'd argue that this is way more nuance than the public in general puts into the issue. In fact, the goalposts have moved quite a bit. "The big difference" used to be the local encription of the data, but it became not it once Recall implemented that. Or the opt-in, which went the same way.

    That's not to say I don't think it's a better idea to have per-app support (which is incidentally how Microsoft implemented the feature in Windows 8 the first time), but I will say that's not why people are mad at one and not the other.

    I don't actually know if you can selectively erase specific screenshots from the database because I, again, can't find any traces of Recall on my supported PCs for the life of me. Coverage had made it seem that they could, since presumably the much criticised side effect of having a local, freely accessible database with just a bunch of pictures is that you could... you know, access those. Did they obscure it further in the reimplementation?

    And also, I think people believe I'm being argumentative, but I'm not. Can somebody point me at the Recall opt-in and/or some explanation why my Copilot + device running 24H2 would not seem to have it available anywhere? I'm confused about the rollout here. I don't want it on, but I'd like to try it and see what the practical implementation is for myself (and be double sure I have it turned off once I'm done with that).

    After the heavy criticism they changed it from default on to (opt out) to default off (opt in).

    In theory you could modify it's database, but they did mention applying stricter security (but what good does that do when the frontdoor access remains via the prompts)

  • This post did not contain any content.

    What I don't understand, is what I would need and use it for? Never in my life I thought "damn if only I had a screen recording of everything I did 1 week, 1 month or 1 year ago". Like I don't get the use case, ignoring anything else. There is no use case.

    I can view my terminal history and my recently accessed files. I have version control with git where I want and need it.

    There is no use case.

  • What I don't understand, is what I would need and use it for? Never in my life I thought "damn if only I had a screen recording of everything I did 1 week, 1 month or 1 year ago". Like I don't get the use case, ignoring anything else. There is no use case.

    I can view my terminal history and my recently accessed files. I have version control with git where I want and need it.

    There is no use case.

    So you’ve never wanted to find an article/headline that you vaguely remember seeing? Or a product that you looked at? Or a picture that you looked at?

    There absolutely is a use case for full reachability of everything you’ve done on your computer. Git commits and terminal history and “recent” files list don’t even come close to providing the same thing lol

  • Apple dropped a whole lot of vague shit that they “promised” would have some sort of holistic and on-device/private benefit to users if they pulled a full data profile of you together, kept it on-device, kept it secure, etc, etc.

    Windows stealthed an update onto PCs that suddenly started capturing and processing unsecured screenshots of everything that users were doing without ever telling anyone why or what it’s for or how it would work. People found out that it was unsecured by looking in its unsecured folder. It wasn’t the same thing.

    That said, obviously, Apple Intelligence is bullshit and doesn’t work or do anything of any use other than making Siri slightly prettier.

    Windows “stealthed” recall onto people’s machines? What? It was a hugely advertised feature, exclusive to only the new copilot+ machines, and was an opt-in test feature lol

  • One could argue that it's a feature that could be done on-client without sending to a server. Or with its server component doing nothing more than syncing with E2E encryption.

    Recall is done on-client.

  • I'll admit I've not looked into it. My computer won't even upgrade to Windows 11 if I wanted it to, thanks to MS's artificial restriction on compatibility. Maybe it is all on-device. But if so, whence all the privacy complaints? And does it not allow syncing between devices?

    So you don’t even know and didn’t bother to check if it is on-device before attacking it for not being on-device?

  • Part of why i knew so-called "digital rights management" was fucking bullshit was because very little software ever came out that empowered me to manage MY OWN rights in the digital space.

    I need there to be FOSS applications that allow me to root-level BLOCK applications from perceiving what I'm doing, to just fucking SANDBOX ABSOLUTELY EVERYTHING BY DEFAULT and let me whitelist what specific things are allowed to directly access the hardware.

    Sadly I am not as tech savvy as I used to think I was. I might've been technologically clever twenty years ago but I hadn't managed to keep up... I think what I've described might be referred to as a "hypervisor"? And I'm told it's an overbearing, clumsy, heavy-handed overkill measure that would be difficult to implement and make everything a pain in the ass to do. So ... shit, man, I dunno... i'm just so damn tired of my hardware being bossed around by people I didn't authorize.

    Write your own OS and software then. Your hardware is running someone else’s software otherwise, so no you don’t get to control every aspect of what it does.

  • OK, so... where the hell is Recall?

    I have a Copilot + device. I am typing this in one, in fact. Recall does not seem to be anywhere to be seen. They added a deployable Google Lens-style "highlight a thing for us to review" thing. It was so intrusive and easy to deploy by accident I got a pretty good notification that I should go turn it off. Maybe that was part of the Recall rollout?

    Incidentally, this piece is... a bit weird. Not only is it an ad, but the concerns they seem to flag as still existing (presumably to sell you their security subscription) seem to be that there is no biometric unlock and just the system PIN and that they don't trust Microsoft on principle. The second is up to you, but the first doesn't really work for me. Not only is the PIN a valid override to biometrics across the board in general (Windows defaults to that when biometrics fails), but it's more secure on principle, since it can't be entered by accident or by force.

    I just don't think the featue is particularly useful for how much potential it has for accidental misuse (even if they never see the data and they keep it entirely secure). It's not the only one of this class, or even Microsoft's first attempt at this (a similar feature shipped with Windows 8). It's certainly become more of a meme than anything else at this point.

    Yeh the entire article is just an ad for AdGuard, using FUD to sell their product.

  • Well:

    1. MacOS is not malware
    2. Apple doesn't make a habit of blatantly lying about their security
    3. As you said, it doesn't actually exist
  • Well:

    1. MacOS is not malware
    2. Apple doesn't make a habit of blatantly lying about their security
    3. As you said, it doesn't actually exist

    Ah, so Apple just happens to be one of the good massive megacorps routinely deploying anti-consumer practices. Gotcha.

    See, it's that gap in perception I'm interested in. Microsoft wants nothing more than having the closed ecosystem Apple has. From their Surface line to their much maligned store to their subscription-forward, always signed-in account environment.

    Why they suck so much at selling that where Apple can get away with murder is much more interesting to me than the perceived differences between the implementations, which I would argue in a number of cases are worked backwards from the brand perception anyway. Part of it is the implementation and the execution rakes Apple chooses not to step on, but certainly not all of it, and that's fascinating.

  • Ah, so Apple just happens to be one of the good massive megacorps routinely deploying anti-consumer practices. Gotcha.

    See, it's that gap in perception I'm interested in. Microsoft wants nothing more than having the closed ecosystem Apple has. From their Surface line to their much maligned store to their subscription-forward, always signed-in account environment.

    Why they suck so much at selling that where Apple can get away with murder is much more interesting to me than the perceived differences between the implementations, which I would argue in a number of cases are worked backwards from the brand perception anyway. Part of it is the implementation and the execution rakes Apple chooses not to step on, but certainly not all of it, and that's fascinating.

    M$ is trying to take an open system and forcibly close it - after driving their user base by force into an unstable OS

    Apple were smart enough to start locking their shit down before home computers became an absolute necessity ...and do it with a functional OS

  • so Apple just happens to be one of the good massive megacorps

    No they're just a different type of shitty.

  • Programs ran through Flatpak can only access permissions and directories that it has explicit permission for. This is perfect for a very small program that only does one thing, it can get rather awkward when you need it to access multiple storage volumes. For example, I wanted to have my Steam games stored on different hard drives, but they were never visible through Steam. I had to override the Flatpak permission to give access to my mounted disks for it to work.

    The fact that we can choose to enhance the permissions beyond their default scope on a case by case basis is powerful.

  • M$ is trying to take an open system and forcibly close it - after driving their user base by force into an unstable OS

    Apple were smart enough to start locking their shit down before home computers became an absolute necessity ...and do it with a functional OS

    Apple locked down their shit way after home computers were a necessity. I'd argue it was the rollout of handheld devices that needed a home computer to fully work that made their walled garden viable.

    And Windows is the main player in home computer OSs. You can take issue with their choices, but it's certainly functional. I'd argue Win11 is annoying, but not even in the top 3 least functional versions of Windows. I mean, I was there for Me, 8.0 and Vista.

    But yes, Apple successfully deployed a locked-down, closed space, and I'm curious about why people are ok with it. That they did it early is... a solid hypothesis, I suppose.

  • 799 Stimmen
    220 Beiträge
    904 Aufrufe
    uriel238@lemmy.blahaj.zoneU
    algos / AI has already been used to justify racial discrimination in some counties who use predictive policing software to adjust the sentences of convicts (the software takes in a range of facts about the suspect and the incident and compares it to how prior incidents and suspects were similar features were adjudicated) and wouldn't you know it, it simply highlighted and exaggerated the prejudices of police and the courts to absurdity, giving whites absurdly lighter sentences than nonwhites, for example. This is essentially mind control or coercion technology based on the KGB technology of компромат (Kompromat, or compromising information, or as CIA calls it biographical leverage, ) essentially, information about a person that can be used either to jeopardize their life, blackmail material or means to lure and bribe them. Take this from tradecraft and apply it to marketing or civil control, and you get things like the Social Credit System in China to keep people from misbehaving, engaging in discontent and coming out of the closet (LGBTQ+ but there are plenty of other applicable closets). From a futurist perspective, we homo-sapiens appear just incapable of noping out of a technology or process, no matter how morally black or heinous that technology is, we'll use it, especially those with wealth and power to evade legal prosecution (or civil persecution). It breaks down into three categories: Technologies we use anyway, and suffer, e.g. usury, bonded servitude, mass-media propaganda distribution Technologies we collectively decide are just not worth the consequences, e.g. the hydrogen bomb, biochemical warfare Technologies for which we create countermeasures, usually turning into a tech race between states or between the public and the state, e.g. secure communication, secure data encryption, forbidden data distribution / censorship We're clearly on the cusp of mind control and weaponizing data harvesting into a coercion mechanism. Currently we're already seeing it used to establish and defend specific power structures that are antithetical to the public good. It's currently in the first category, and hopefully it'll fall into the third, because we have to make a mess (e.g. Castle Bravo / Bikini Atol) and clean it up before deciding not to do that again. Also, with the rise of the internet, we've run out of myths that justify capitalism, which is bonded servitude with extra steps. So we may soon (within centuries) see that go into one of the latter two categories, since the US is currently experiencing the endgame consequences of forcing labor, and the rest of the industrialized world is having to bulwark from the blast.
  • This AI System Helped Me Work Less and Post More

    Technology technology
    1
    2
    0 Stimmen
    1 Beiträge
    14 Aufrufe
    Niemand hat geantwortet
  • 51 Stimmen
    8 Beiträge
    52 Aufrufe
    B
    But do you also sometimes leave out AI for steps the AI often does for you, like the conceptualisation or the implementation? Would it be possible for you to do these steps as efficiently as before the use of AI? Would you be able to spot the mistakes the AI makes in these steps, even months or years along those lines? The main issue I have with AI being used in tasks is that it deprives you from using logic by applying it to real life scenarios, the thing we excel at. It would be better to use AI in the opposite direction you are currently use it as: develop methods to view the works critically. After all, if there is one thing a lot of people are bad at, it's thorough critical thinking. We just suck at knowing of all edge cases and how we test for them. Let the AI come up with unit tests, let it be the one that questions your work, in order to get a better perspective on it.
  • Linus Torvalds and Bill Gates Meet for the First Time Ever

    Technology technology
    226
    786 Stimmen
    226 Beiträge
    1k Aufrufe
    N
    Sorry, wasn't my intention
  • Twitch is getting vertical livestreams

    Technology technology
    20
    1
    11 Stimmen
    20 Beiträge
    76 Aufrufe
    zombiemantis@lemmy.worldZ
    Oh, yeah, that makes sense. I kinda assumed they already supported it, like YouTube Shorts adopting the vertical format for shorts after Ticktock blew up.
  • The Internet of Consent

    Technology technology
    1
    1
    11 Stimmen
    1 Beiträge
    11 Aufrufe
    Niemand hat geantwortet
  • 17 Stimmen
    1 Beiträge
    13 Aufrufe
    Niemand hat geantwortet
  • 56 Stimmen
    4 Beiträge
    32 Aufrufe
    cupcakezealot@lemmy.blahaj.zoneC
    !upliftingnews@lemmy.world