Giving Windows total recall of everything a user does is a privacy minefield
theregister.com
theregister.com
The second problem I have is that they tell me that neither the snapshots are send to Microsoft nor are they analyzed on Microsoft's servers, but I do NOT know what happens with the data once stuff got analyzed on an operating system that is phoning home all kinds of information all the time w/o me being able to tell what it is. Not even the enterprise version can disable all the "phone home features" there are and Microsoft doesn't make everything public that they transfer.
The third issue is that stuff is stored on my local drive with bitlocker encryption that can be easily circumvented even if they store the keys in a TPM. There is this universal, not well known, only documented in a single file, backdoor to Windows [1] that allows you to gain full control over the system even with secure boot enabled.
The possibilities of your boss spying on you will become endless. Not that they aren't already, but this opens a whole new can of worms.
[1] - https://download.microsoft.com/download/8/a/2/8a2fb72d-9b96-...
[1] - https://www.rijksoverheid.nl/documenten/rapporten/2019/06/11...
The sheer existance of the feature came to light when people began to wonder why Lenovo is able to install their install service every time after they did a clean installation. They went as far as changing the hard drive and the service still reappeared.
Asking Lenovo what was going on, Lenovo replied with the information about this and Microsoft had to come up with some documentation. Its existance was neither communicated to the public nor documented anywhere in Microsoft's documentation.
Just google the name and be surprised how you cannot find anything about it on Microsoft's pages besides this one document.
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager" /f /t REG_DWORD /v DisableWpbtExecution /d 1The whole feature shouldn't be there in the first place and while WBPT has been documented since Windows 8, similar features have existed way before that and where never documented.
While I'm no fan of WPBT, I don't see it as much of a security threat.
Providing all the power of this recording to watch employees.
If anyone thinks that it is too extreme to be serious, you have to know that Microsoft offered (and is maybe still offering) to company creepy spy stats other employee activities through Office 365, like how long is spent on emails, active on the computer, chatting with other employees,...
"AI PCs are the final nail in the coffin of open computing", 52 comments, https://news.ycombinator.com/item?id=40436975
"How the new Microsoft Recall feature fundamentally undermines Windows security", 48 comments, https://news.ycombinator.com/item?id=40433884
"Windows Recall sounds like a privacy nightmare", 293 comments, https://news.ycombinator.com/item?id=40443682
a) I doubt they'd do that
b) I'm not very interesting
c) It'd be a massive lawsuit if they were
d) privacy hackers have motivation to find out if they are - see c
It doesn't add to the conversation, and further, people you know could be interesting. And interesting in ways, that you don't know about.
Apple lets you turn off many things privacy wise on their system. You can turn them all offf. And your system till phones home continuously (try little snitch).
Microsoft is objectively worse wrt privacy. Do you think a microsoft-programmed off button would work?
Do you always disparage strangers online and is it unconscious or do you take pleasure in it?
I was naive long ago when I worked with an ex-microsoft employee (90's). I was telling him about how some version of windows broke third-party software, and I said that engineers often don't know who is using their software etc.
He told me that I was naive. That microsoft had meetings about things like this, and they discussed their strategies and "how can we own this?"
As far as microsoft and privacy, they have shown again and again that they are not on the side of the individual. They collect amazing quantities of data, they keep on mixing things up to obfuscate things, and they show no signs of slowing down (just the opposite). As far as privacy is concerned, microsoft sets a very bad example, and others follow.
"senior citizen, searching dementia symptoms, wants to invest life savings"
"verizon employee, money trouble, access to sim reprogramming application"
"young woman, height proportional to weight, poor decision making skills"
That said, it makes going to random websites from comment chains or user submitted stories much more dangerous. If they lead to illegal content, it's now stored ready to be used against you if law enforcement ever wants to take a close look at you.
About 1x/year I get frustrated with the depth of my lock-in to the Apple Ecosystem and start looking for an alternative (thats not a science project).
After I go through the Windows offerings and do some reading I'm generally happy to go back to dealing with whatever bullshit Apple want's to cram down my throat this release. Now sure iCloud knows the depths of my soul but at least I voluntarily put things there. Thats a far cry from some AI screen capping me in the background and running some AI over it (to show me more relevant ads in the Start Menu).
I have a Windows desktop PC, that I use almost exclusively for playing PC games with friends. I already had to use some obscure method to bypass signing in with my Microsoft account during installation. I boot it anywhere between once a month and a few times a week, and about 50% of the time some random configuration changes and I can’t do the one thing that I set out to do (play a game) without updating or downgrading some arbitrary driver.
Oh, and it nags me almost every boot to sign in with my Microsoft account for one reason or another. And this is an operating system with an MSRP of $200!
There are loads of things to critique about my Mac, but I can use it daily just fine, without the OS trying to trick me into signing into some service or other. The daily experience of using it feels much more consensual, as you describe.
But the fact is, I don't. If something like this (with negligible enough compute/storage impacts) could be implemented locally, I would probably buy into it. I'm sure it would be "better" with a larger model, but as a jumping-off point for finding something I saw or read about prior, I think a locally available model would suffice.
Trusting Microsoft (or Apple, OpenAI, etc.) with this information for a "better" AI model is not a trade-off I'd personally find acceptable.
It is implemented locally
I am afraid nothing Microsoft works on is local anymore.
https://www.theverge.com/23935029/microsoft-edge-forced-wind...
If it was open source software that I could fully administer that only changed when I wanted it to change, things would be very different.