Skip to content

Microsoft’s Recall feature is still threat to privacy despite recent tweaks

Technology
82 42 474
  • The same has been true of email for years, but less bad. Activists will need to be even more careful in who they trust.

    In what sense?

  • Part of why i knew so-called "digital rights management" was fucking bullshit was because very little software ever came out that empowered me to manage MY OWN rights in the digital space.

    I need there to be FOSS applications that allow me to root-level BLOCK applications from perceiving what I'm doing, to just fucking SANDBOX ABSOLUTELY EVERYTHING BY DEFAULT and let me whitelist what specific things are allowed to directly access the hardware.

    Sadly I am not as tech savvy as I used to think I was. I might've been technologically clever twenty years ago but I hadn't managed to keep up... I think what I've described might be referred to as a "hypervisor"? And I'm told it's an overbearing, clumsy, heavy-handed overkill measure that would be difficult to implement and make everything a pain in the ass to do. So ... shit, man, I dunno... i'm just so damn tired of my hardware being bossed around by people I didn't authorize.

    Programs ran through Flatpak can only access permissions and directories that it has explicit permission for. This is perfect for a very small program that only does one thing, it can get rather awkward when you need it to access multiple storage volumes. For example, I wanted to have my Steam games stored on different hard drives, but they were never visible through Steam. I had to override the Flatpak permission to give access to my mounted disks for it to work.

  • I've disabled windows update completely so I can pick and manually dl updates. Never going to put that recall shit on my pc.

    I've disabled Windows completely so I can be safe and sound. Never going to put that shit on my PC.

    -- sorry, it seemed funnier in my head.

  • It's a centralized search that can dig through your activity cross-platform and parses it through a centralized AI. Whether the data is stored in a log or as screenshots is a difference, but not as big of a difference as people make it out to be. It just feels intuitively weirder because one is humanly readable and the other one isn't.

    To be fair, that's my takeaway from a lot of AI backlash. A whole bunch of it is people finally getting an intuitive grasp on activities that big data has been doing for years or decades and it finally clicking into shock because they can anthropomorphise the inputs and outputs better.

    No wonder the techbros have lost their intuititon for what will trigger backlash. In many cases they've been doing far worse than those things with zero awareness or pushback.

    Don't worry, Microsoft is bringing semantic search to Windows too. That way you can have the worst of both worlds.

  • In what sense?

    • if you send plaintext, their email service could spy on them
    • once they decrypt, they could accidentally reply with the decryped text, or it could get backed up if they store a copy somewhere
    • screen readers could store decrypted email

    In general, if you don't trust the receiver, you shouldn't send sensitive information. Windows Recall doesn't change that, if they're competent, Windows Recall won't be enabled.

    I think this is more an issue for less technical users instead of activists, because activists will be more careful about who they trust than a secretary or something for a powerful individual.

  • Access controls is the big difference. Apps with sensitive data can choose to hide stuff to a system wid search API. It can do so on an individual level, even. And even if it previously was accessible it can be drumroll recalled. Exposure happens when a search is made.

    Microsoft Recall is all or nothing. Once it has been displayed Recall has it and you can't selectively erase stuff. Exposure is immediate. It's just purge the whole database, or leave it all in there. Apps can't retroactively flag stuff.

    ... But leaving AI summaries on by default was very stupid by Apple

  • Access controls is the big difference. Apps with sensitive data can choose to hide stuff to a system wid search API. It can do so on an individual level, even. And even if it previously was accessible it can be drumroll recalled. Exposure happens when a search is made.

    Microsoft Recall is all or nothing. Once it has been displayed Recall has it and you can't selectively erase stuff. Exposure is immediate. It's just purge the whole database, or leave it all in there. Apps can't retroactively flag stuff.

    ... But leaving AI summaries on by default was very stupid by Apple

    I'd argue that this is way more nuance than the public in general puts into the issue. In fact, the goalposts have moved quite a bit. "The big difference" used to be the local encription of the data, but it became not it once Recall implemented that. Or the opt-in, which went the same way.

    That's not to say I don't think it's a better idea to have per-app support (which is incidentally how Microsoft implemented the feature in Windows 8 the first time), but I will say that's not why people are mad at one and not the other.

    I don't actually know if you can selectively erase specific screenshots from the database because I, again, can't find any traces of Recall on my supported PCs for the life of me. Coverage had made it seem that they could, since presumably the much criticised side effect of having a local, freely accessible database with just a bunch of pictures is that you could... you know, access those. Did they obscure it further in the reimplementation?

    And also, I think people believe I'm being argumentative, but I'm not. Can somebody point me at the Recall opt-in and/or some explanation why my Copilot + device running 24H2 would not seem to have it available anywhere? I'm confused about the rollout here. I don't want it on, but I'd like to try it and see what the practical implementation is for myself (and be double sure I have it turned off once I'm done with that).

  • Funnily enough, Signal has circumvented the issue by marking their chat window as DRM content, making it invisible to Recall.

    They used the invasion of privacy to destroy the invasion of privacy?

  • This post did not contain any content.

    This is just a thinly veiled ad for AdGuard.

  • Funnily enough, Signal has circumvented the issue by marking their chat window as DRM content, making it invisible to Recall.

    They didn’t circumvent the issue - they did what Microsoft tell developers to do in regards to their programs and recall lol.

  • I'd argue that this is way more nuance than the public in general puts into the issue. In fact, the goalposts have moved quite a bit. "The big difference" used to be the local encription of the data, but it became not it once Recall implemented that. Or the opt-in, which went the same way.

    That's not to say I don't think it's a better idea to have per-app support (which is incidentally how Microsoft implemented the feature in Windows 8 the first time), but I will say that's not why people are mad at one and not the other.

    I don't actually know if you can selectively erase specific screenshots from the database because I, again, can't find any traces of Recall on my supported PCs for the life of me. Coverage had made it seem that they could, since presumably the much criticised side effect of having a local, freely accessible database with just a bunch of pictures is that you could... you know, access those. Did they obscure it further in the reimplementation?

    And also, I think people believe I'm being argumentative, but I'm not. Can somebody point me at the Recall opt-in and/or some explanation why my Copilot + device running 24H2 would not seem to have it available anywhere? I'm confused about the rollout here. I don't want it on, but I'd like to try it and see what the practical implementation is for myself (and be double sure I have it turned off once I'm done with that).

    After the heavy criticism they changed it from default on to (opt out) to default off (opt in).

    In theory you could modify it's database, but they did mention applying stricter security (but what good does that do when the frontdoor access remains via the prompts)

  • This post did not contain any content.

    What I don't understand, is what I would need and use it for? Never in my life I thought "damn if only I had a screen recording of everything I did 1 week, 1 month or 1 year ago". Like I don't get the use case, ignoring anything else. There is no use case.

    I can view my terminal history and my recently accessed files. I have version control with git where I want and need it.

    There is no use case.

  • What I don't understand, is what I would need and use it for? Never in my life I thought "damn if only I had a screen recording of everything I did 1 week, 1 month or 1 year ago". Like I don't get the use case, ignoring anything else. There is no use case.

    I can view my terminal history and my recently accessed files. I have version control with git where I want and need it.

    There is no use case.

    So you’ve never wanted to find an article/headline that you vaguely remember seeing? Or a product that you looked at? Or a picture that you looked at?

    There absolutely is a use case for full reachability of everything you’ve done on your computer. Git commits and terminal history and “recent” files list don’t even come close to providing the same thing lol

  • Apple dropped a whole lot of vague shit that they “promised” would have some sort of holistic and on-device/private benefit to users if they pulled a full data profile of you together, kept it on-device, kept it secure, etc, etc.

    Windows stealthed an update onto PCs that suddenly started capturing and processing unsecured screenshots of everything that users were doing without ever telling anyone why or what it’s for or how it would work. People found out that it was unsecured by looking in its unsecured folder. It wasn’t the same thing.

    That said, obviously, Apple Intelligence is bullshit and doesn’t work or do anything of any use other than making Siri slightly prettier.

    Windows “stealthed” recall onto people’s machines? What? It was a hugely advertised feature, exclusive to only the new copilot+ machines, and was an opt-in test feature lol

  • One could argue that it's a feature that could be done on-client without sending to a server. Or with its server component doing nothing more than syncing with E2E encryption.

    Recall is done on-client.

  • I'll admit I've not looked into it. My computer won't even upgrade to Windows 11 if I wanted it to, thanks to MS's artificial restriction on compatibility. Maybe it is all on-device. But if so, whence all the privacy complaints? And does it not allow syncing between devices?

    So you don’t even know and didn’t bother to check if it is on-device before attacking it for not being on-device?

  • Part of why i knew so-called "digital rights management" was fucking bullshit was because very little software ever came out that empowered me to manage MY OWN rights in the digital space.

    I need there to be FOSS applications that allow me to root-level BLOCK applications from perceiving what I'm doing, to just fucking SANDBOX ABSOLUTELY EVERYTHING BY DEFAULT and let me whitelist what specific things are allowed to directly access the hardware.

    Sadly I am not as tech savvy as I used to think I was. I might've been technologically clever twenty years ago but I hadn't managed to keep up... I think what I've described might be referred to as a "hypervisor"? And I'm told it's an overbearing, clumsy, heavy-handed overkill measure that would be difficult to implement and make everything a pain in the ass to do. So ... shit, man, I dunno... i'm just so damn tired of my hardware being bossed around by people I didn't authorize.

    Write your own OS and software then. Your hardware is running someone else’s software otherwise, so no you don’t get to control every aspect of what it does.

  • OK, so... where the hell is Recall?

    I have a Copilot + device. I am typing this in one, in fact. Recall does not seem to be anywhere to be seen. They added a deployable Google Lens-style "highlight a thing for us to review" thing. It was so intrusive and easy to deploy by accident I got a pretty good notification that I should go turn it off. Maybe that was part of the Recall rollout?

    Incidentally, this piece is... a bit weird. Not only is it an ad, but the concerns they seem to flag as still existing (presumably to sell you their security subscription) seem to be that there is no biometric unlock and just the system PIN and that they don't trust Microsoft on principle. The second is up to you, but the first doesn't really work for me. Not only is the PIN a valid override to biometrics across the board in general (Windows defaults to that when biometrics fails), but it's more secure on principle, since it can't be entered by accident or by force.

    I just don't think the featue is particularly useful for how much potential it has for accidental misuse (even if they never see the data and they keep it entirely secure). It's not the only one of this class, or even Microsoft's first attempt at this (a similar feature shipped with Windows 8). It's certainly become more of a meme than anything else at this point.

    Yeh the entire article is just an ad for AdGuard, using FUD to sell their product.

  • Well:

    1. MacOS is not malware
    2. Apple doesn't make a habit of blatantly lying about their security
    3. As you said, it doesn't actually exist
  • Well:

    1. MacOS is not malware
    2. Apple doesn't make a habit of blatantly lying about their security
    3. As you said, it doesn't actually exist

    Ah, so Apple just happens to be one of the good massive megacorps routinely deploying anti-consumer practices. Gotcha.

    See, it's that gap in perception I'm interested in. Microsoft wants nothing more than having the closed ecosystem Apple has. From their Surface line to their much maligned store to their subscription-forward, always signed-in account environment.

    Why they suck so much at selling that where Apple can get away with murder is much more interesting to me than the perceived differences between the implementations, which I would argue in a number of cases are worked backwards from the brand perception anyway. Part of it is the implementation and the execution rakes Apple chooses not to step on, but certainly not all of it, and that's fascinating.

  • Vibe coding service Replit deleted production database

    Technology technology
    118
    1
    578 Stimmen
    118 Beiträge
    773 Aufrufe
    iavicenna@lemmy.worldI
    And you are talking about obvious bugs. It likely will make erroneous judgements (because somewhere in its training data someone coded it that way) which will down the line lead to subtle problems that will wreck your system and cost you much more. Sure humans can also make the same mistakes but in the current state of affairs, an experienced software engineer/programmer has a much higher chance of catching such an error. With LLMs it is more hit and miss especially if it is a more niche topic. Currently, it is an assistant tool (sometimes quite helpful, sometimes frustrating at best) not an autonomous coder. Any company that claims so is either a crook or also does not know much about coding.
  • 3 Stimmen
    1 Beiträge
    11 Aufrufe
    Niemand hat geantwortet
  • 31 Stimmen
    6 Beiträge
    54 Aufrufe
    moseschrute@piefed.socialM
    While I agree, everyone constantly restating this is not helpful. We should instead ask ourselves what’s about BlueSky is working and what can we learn? For example, I think the threadiverse could benefit from block lists, which auto update with new filter keywords. I’ve seen Lemmy users talk about how much time they spend crafting their filters to get the feed of content they want. It would be much nicer if you could choose and even combine block lists (e.g. US politics).
  • The Death of the Student Essay—and the Future of Cognition

    Technology technology
    26
    1
    134 Stimmen
    26 Beiträge
    157 Aufrufe
    artisian@lemmy.worldA
    I would love to see the source on this one. It sounds fascinating.
  • How LLMs could be insider threats

    Technology technology
    12
    1
    105 Stimmen
    12 Beiträge
    72 Aufrufe
    patatahooligan@lemmy.worldP
    Of course they're not "three laws safe". They're black boxes that spit out text. We don't have enough understanding and control over how they work to force them to comply with the three laws of robotics, and the LLMs themselves do not have the reasoning capability or the consistency to enforce them even if we prompt them to.
  • Why doesn't Nvidia have more competition?

    Technology technology
    22
    1
    33 Stimmen
    22 Beiträge
    88 Aufrufe
    B
    It’s funny how the article asks the question, but completely fails to answer it. About 15 years ago, Nvidia discovered there was a demand for compute in datacenters that could be met with powerful GPU’s, and they were quick to respond to it, and they had the resources to focus on it strongly, because of their huge success and high profitability in the GPU market. AMD also saw the market, and wanted to pursue it, but just over a decade ago where it began to clearly show the high potential for profitability, AMD was near bankrupt, and was very hard pressed to finance developments on GPU and compute in datacenters. AMD really tried the best they could, and was moderately successful from a technology perspective, but Nvidia already had a head start, and the proprietary development system CUDA was already an established standard that was very hard to penetrate. Intel simply fumbled the ball from start to finish. After a decade of trying to push ARM down from having the mobile crown by far, investing billions or actually the equivalent of ARM’s total revenue. They never managed to catch up to ARM despite they had the better production process at the time. This was the main focus of Intel, and Intel believed that GPU would never be more than a niche product. So when intel tried to compete on compute for datacenters, they tried to do it with X86 chips, One of their most bold efforts was to build a monstrosity of a cluster of Celeron chips, which of course performed laughably bad compared to Nvidia! Because as it turns out, the way forward at least for now, is indeed the massively parralel compute capability of a GPU, which Nvidia has refined for decades, only with (inferior) competition from AMD. But despite the lack of competition, Nvidia did not slow down, in fact with increased profits, they only grew bolder in their efforts. Making it even harder to catch up. Now AMD has had more money to compete for a while, and they do have some decent compute units, but Nvidia remains ahead and the CUDA problem is still there, so for AMD to really compete with Nvidia, they have to be better to attract customers. That’s a very tall order against Nvidia that simply seems to never stop progressing. So the only other option for AMD is to sell a bit cheaper. Which I suppose they have to. AMD and Intel were the obvious competitors, everybody else is coming from even further behind. But if I had to make a bet, it would be on Huawei. Huawei has some crazy good developers, and Trump is basically forcing them to figure it out themselves, because he is blocking Huawei and China in general from using both AMD and Nvidia AI chips. And the chips will probably be made by Chinese SMIC, because they are also prevented from using advanced production in the west, most notably TSMC. China will prevail, because it’s become a national project, of both prestige and necessity, and they have a massive talent mass and resources, so nothing can stop it now. IMO USA would clearly have been better off allowing China to use American chips. Now China will soon compete directly on both production and design too.
  • Telegram partners with xAI to bring Grok to over a billion users

    Technology technology
    36
    1
    38 Stimmen
    36 Beiträge
    167 Aufrufe
    R
    So you pay taxes to Putin. Good to know who actually helps funding the regime. I suggest you go someplace else. I won't take this from a jerk from likely one of the countries buying fossil fuels from said regime, that have also supported it after a few falsified elections starting in 1996, which is also the year I was born. And of course "paying taxes to Putin" can't be even compared to what TG is doing, so just shut up and go do something you know how to do, like I dunno what.
  • The Document Foundation is proud to release LibreOffice 25.2.3

    Technology technology
    7
    1
    265 Stimmen
    7 Beiträge
    53 Aufrufe
    somethingburger@jlai.luS
    View -> User Interface -> Tabs It already exists but is nowhere near as good as MS Office (like everything with LO).