Recall: Stealing everything you've ever typed or viewed on your own Windows PC
doublepulsar.com
doublepulsar.com
"Giving Windows total recall of everything a user does is a privacy minefield", 41 comments, https://news.ycombinator.com/item?id=40470806
"AI PCs are the final nail in the coffin of open computing", 60 comments, https://news.ycombinator.com/item?id=40436975
"How the new Microsoft Recall feature fundamentally undermines Windows security", 50 comments, https://news.ycombinator.com/item?id=40433884
"Windows Recall sounds like a privacy nightmare", 298 comments, https://news.ycombinator.com/item?id=40443682
By pushing this onto people in a hard way they open the door to come up with a mitigating solution that later is far beyond what we had before recall but not as bad as what they pushed onto people in the first place. So they will reach their goal, as it was never 11, it was always 9.
I gave ChromeOS a try for some machines I might otherwise have run Windows on, but I kept the Windows machines around for gaming and for the occasional oddball proprietary software package that some family member just had to have. About the time Google dropped its unofficial motto "Don't Be Evil" I started moving away from ChromeOS and back to trusty old Debian.
I've recently purchased a Framework 16 with an AMD Radeon RX 7700S GPU and installed Arch Linux and Steam on it. All the games I care about playing at the moment, including Elden Ring and Baldur's Gate 3, run phenomenally well on it. It's 100% stable driving a 2560x1600 display at 60+fps with high graphics settings. I can plug in a PS5 controller and it "just works."
With that I now feel truly free of anything Microsoft, in the sense that I don't feel like I'm making any compromises at all with how I want to use my computers by using Linux rather than Windows. I'm going to be installing Arch or Debian Linux on my remaining Windows boxen over the summer.
So this is my final adieu, my old friend Microsoft. How far our paths have diverged since we first parted ways. Hit me up again when you've extricated your OS from your cloud and stopped showing ads and integrating privacy-hostile features. I won't be holding my breath though.
I'm curious how the culture was though. I always get the vibe that Microsoft has never been "end user oriented" if that makes sense. They always seemed to be making a product for other businesses. To this day, Windows, Office, and especially stuff like MS Teams feel like they were designed from the ground up for a heavily managed business environment with heavy surveillance and tight controls.
Stuff like Telemetry and requiring MS accounts for logging into Windows 10+ seem more of a nod to employers. It's really amazing how much MS has been able to convince users to give controls of their own devices to MS/employers/others. Stuff like using Outlook on a personal phone giving the employer the ability to wipe the employee's phone.
Like I don't think they have ever, in their years, seen end users of their products as "customers". I think they see businesses, sometimes independent developers, and advertising firms as their real customers.
I started on Windows XP and left on Windows 10 (skipping Vista and Win 8.0, and part of 8.1). Windows was always a tool to get things done. Buy a software license and you can be pretty sure you can run things indefinitely on it. Everything (almost?) was accessible by clicking, so ultimately discoverable. No need to learn arcane commands, just follow and imitate. And you mostly have to do the training once. Linux was an expert tool and macOS (I used it since Mojave) always felt like it's for people who compute, but mostly as a secondary activity (shiny and pleasant, but always lacking the remaining bit).
I've never thought of myself of being a Microsoft customer, just like you don't think of being a Dell customer or HP customer when using their monitors or printers. You need to get something done and Windows was the bedrock for that. Especially if you were hiring people to do it.
But now it's like seeing your workbench animating and contorting itself in new shapes every time you come close. Insulting your intelligence all the while.
You can't even search messages more than a certain age because they're gigantic Microsoft Exchange objects. Somehow Discord can give you instantaneous results but Teams is a giant piece of crap.
That's kinda what I was getting at. And don't even get me started with Windows file permissions, or Windows' way of doing symlinks, or Windows' way of doing keyboard hotkeys that no other OS on this planet does.
Microsoft was the company that used to add bespoke code to Windows to maintain compatibility with old third party software, patch explorer.exe to stop third party customizations from crashing it, etc. While the whole Recall thing is a pretty bad idea for most users, the lack of care extended to the third party browser with overwhelming market share among their users is just sad. Are they counting on people switching to Edge because “PSA: you’ll be recorded if you watch pr0n in Chrome!”?
I dunno, and I say this as someone who works for a competitor and has no love for MS... a lot of the responses here seem really uncharitable. This isn't bad faith, it's just a rushed product with some poor planning. If Apple had rolled this same feature out with glitz and a giant slideshow about privacy and explained how everything was encrypted and never left the device, we'd all be crowing about how great it is even if it too was screenshotting incognito windows.
> nor should there be, obviously, as it would defeat the purpose
No it doesn't. Incognito mode is about leaving no trace on disk, that's all. Recall is the one defeating that purpose right now, if TFA is accurate.
[1] Not saying it's impossible. Only that I can't think of a straightforward solution in a pinch with my limited Windows experience and hacking skills.
It's not hard to support this functionality in the major browsers: it'd take me all of 15 minutes.
> Recall won’t save any content from your private browsing activity when you’re using Microsoft Edge, Firefox, Opera, Google Chrome, or other Chromium-based browsers.
Without a system-level incognito mode feature I could see apps allowing users to denote their windows as DRM content to avoid Recall.
0: https://support.microsoft.com/en-us/windows/privacy-and-cont...
That would prevent user-initiated screen captures as well. Not a good idea for browsers at least.
But it’s not the product people are criticizing, at all. Similar tools have existed for a long time and have not raised eyebrows except when it’s been forced by an employer or a school. It’s that it’s the OS putting an always on and enabled-by-default spyware on devices that are frequently shared by family members, when their average users who barely know what a web browser is and will just accept recommended defaults. Speaking of which, the whole spiel about Edge/IE is precisely their aggressive defaults. It’s the same here.
If you’re a startup building custom tools you can talk about rushed products and assume good intent. This software is built by a software company with some of the worlds best software engineers all the way up to the top. I mean, people trust them with everything from business secrets to payment details to mission critical services. This is clearly not a “rushed product oopsie”, it’s blatant disregard for privacy, and to a lesser extent, security.
I’m avoiding windows like the plague, but since seeing my mom get bombarded with “recommended Microsoft defaults” over the last decade or so, I’m convinced MS is deliberately exploiting uninformed users as much as they can get away with, while leaving hidden options for power users to disable the ads and the crapware so they don’t leave. This total recall debacle is probably a similar attempt at using their unknowing user base to train their new AI models, or similar. If it was a genuinely useful product it would not be enabled by default.
And I have to repeat: if Apple Computer had pushed the same product, but with a slide talking about how it was all locally encrypted and unextractable and tied to both the device and the user account, HN would be celebrating the attention to privacy even though macs too are "frequently shared". And the reasoning would be how strong the security engineering was around the process, because we love that stuff and we love macs.
MS doesn't get the same benefit of the doubt, and it leaks into the technical content of the argument, and that's wrong. And FWIW I'm mostly just handwaving the technical details. I mean, do we know for a fact that MS is *not* encrypting this with a TPM-managed key tied to the user account? I bet they are, honestly.
It's Microsoft. There no reason to extend any charity whatsoever when talking about this company.
Not all of us, no.
https://support.microsoft.com/en-us/windows/retrace-your-ste...
I'm saying that thankfully they are not using the threat of your guarded personal data being exposed because you want this feature but don't want to use Edge.
Personally I don't think people should actually allow this type of feature. It's too much of a risk. But my point stands on its own, that at least they aren't creating an even more perverse incentive to use Edge, which they absolutely could have done, and seems the MO of the Microsoft today who would sacrifice all else to be able to say there's 1 or 2 more Edge or Bing users.
add "Launch in private mode"
This is already basically in place with DRM since the windows screenshot utility won't screencap most DRMed content on win apps like netflix or even on firefox nowadays.
What MS is adding on top of this is an API to check which tabs/web pages are visible and selectively black out web pages that are added to a given user level blacklist.
On one level that's convenient, but on the other hand I'm not sure it's a very robust design.
A better solution would be to just pause the screen capture whenever incognito is open anywhere
Here in the UK I've literally never encountered it.
I have heard at least 10 women JOKE about my android. I'd say atleast 2 gfs in those years eventually made some snide remark.
Will you get dumped for having an android? No. Is it a small -1 mark for most women? I would say so.
And no these aren't totally brainless women. It's been doctors, MBA grads, women in tech, a writer.. I honestly think more regular woman are more sane about it actually and wouldn't care as much as 'fancier' women.
Good god how more obvious could it be?
Anyone still using this software is a lost cause.
I think the tech community is responsible for keeping companies like MS in check and pushing back against literal spyware being normalised in operating systems.
Between Recall and the mandatory account login to install Windows 10 I am progressively reverting to how I felt about them.
I think that they've been trying very hard to give out that image without really changing who they are.
It's not the first time that they try hard to look like they've changed, and it won't be the last.
Typical IT guy (not head) cannot spend money without 3 approvals from different departments.
In developers world, pushing open source, or in gaming - xbox game pass is just best value that there is.
But for every cool department, there also exists one that still behaves as a predatory corpo. And it seems to me like their main target are 'normie' users.
And the linux subsystem, well, for me a textbook example of:
https://en.m.wikipedia.org/wiki/Embrace,_extend,_and_extingu...
So sorry, they were never cool to me. I still use them, but if I must switch to win 11 soon, I might take that as an opportunity to finally cut loose my last dependencies with windows.
[1] https://azure.microsoft.com/en-us/products/virtual-machines/...
Not yet, they're still on the "embrace" step.
> Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes.
“The only good thing about Recall is that it has been the definitive decider of moving away from Microsoft permanently because for them to create such a ‘feature’ shows a complete lack of care about people’s private data - they’ll be leaving a huge jackpot prize for anyone who breaks into a system.”
And only 4 days later, it is shown.
Just my 2p
The #1 merit of Nadella is pushing for increased accessibility.
23 years later and here we are.
From todays's perspective, considering for example the Snowden and Wikileaks revelations that caused exactly these barely-nil reactions in the public, I know that I was right regarding this feeling.
In my observation it really was as I described:
- those who already deeply distrusted the government continued to do so
- the others (the huge majority) simply did barely care or even attempted to justify the crimes
Concerning your point about tech and security sectors: those who form the inner core of the people working in these sectors basically already knew what was happening since at least the 90s.
Every time someone points at this and acts like it was a revlation I shake my head.
https://en.wikipedia.org/wiki/Room_641A
https://en.wikipedia.org/wiki/Joseph_Nacchio (Every one screams about conspiracy's but the only people who told the Bush II government no went to prison).
https://www.politico.com/blogs/politico-now/2008/02/senate-p...
They did it, out in public people wrote about it, everyone shrugged and went on with their lives. All Snowden did was give it a face, some (program) names, but any one with any sense stayed away already.
The American public has been warned twice, and did not care. It's gonna take something major leaking for them to do anything about it.
"When he first came out, I was delighted. It was, first of all, vindication for what I was saying," Klein said. "He also revealed the programs they were doing were vastly bigger than I ever understood at the time."
https://www.nbcbayarea.com/news/local/bay-area-whistleblower...
Perhaps Trump's support could be a far reaction to it, with no clear direction but just a strong wish to screw it all. We see the same in other countries where people go to the extremes as discomfort rises with no actionable way.
Even today, a non-CIA-grade camera head is probably 2-3mm across and the optics on a fibre optic can be far narrower.
You can only have a pinhole spy cam if you have a void directly behind the pinhole.
The only way to make that happen is to store that information somewhere. The best way to do anything, that I just want the benefits of, is automatically.
And now we are here. It feels monstrous but, to me, the above still stands. How to connect the dots to get to a place that feels good, I do not know. I would not be shocked if it turned out to be mostly about adjusting ourselves to it over time.
But I am almost 100% positive we will all* want this super power, in some much better and much more complete form, in our future lives. And not being able to have it will feel absolutely silly, from there on out forever.
People already have traded privacy and a comprehensive personality profile for silly streams of video, photos and text on social media for the past 20 years. Imagine what happens, when you get something immensely useful out of it.
Today, nobody will work with you, if you are unable to manage E-Mail. In the future, nobody will work with you, if you can't properly use the time information dimension that this technology enables. You will simply look demented by comparison.
A good delineation is your work PC will be spied on (assume anyone in the org can see what you are doing, even before this tech).
Opting out of it on personal devices is fine. You wont look like an idiot or be refused work I am sure.
With an eraser, entirely not interested.
I'm willing to make the bet on this FOMO that while people risk this, I'll still be just as employable by living like it's 1999
I provide the value, not what I did before
However. This is the holy grail of computer usage. A good version of this could be the killer app for modern AI. Because of that, ripple are going to keep trying to make this feature happen. There’s already a popular implementation on macOS. I’m excited for the end-state, but apprehensive about getting there.
i’ve seen this often and i’m trying to understand the issue. i have never wanted to go back in history or have a comprehensive history of all my actions. the only exception is the terminal and for that ctrl+r/history is more than enough. i learn, apply and move on.
what’s the use case for this recall thing?
Being able to search everything I've seen on my screen would address all of these. I think it would fundamentally change how we interface with computers, if we could do it reliably. Silos between applications can start to break down when you have sufficient intelligence about what's on the screen too, and that's a huge opportunity.
Surveillance, very obviously.
It'd be reasonable to see this as a waymark on a roadmap.
Which is why it makes little sense to users. Why it is counterintuitive in that it will drive people away instead of draw them to the product. And why it is being rammed out into the market regardless.
What's the waymark after this?
What the hell is the "wrong" way to use a computer? Emails, social media and doing your banking?
And why attack "moms and dads"? Speaking as a grandfather, I find it insulting, having used and programmed computers since the 1970s.
Don't take so much joy out of the fact that youre currently the only member of your thousands of years old generic lineage that hasn't procreated.
One of the most common questions every computer user has at any given moment is some variant of "What/Where was it?".
I agree it's a holy grail, but it's also a road paved with good intentions.
Computers are the holy Grail of computers. Stop playing with fire. The tool is already here.
And with 'no time', with a delay of less than 5-10 seconds on creating/restoring a snapshot.
On search, as they stated, Recoll did it fine over 20 years.
Malware can probably read most of the user’s data in RAM, but if OS components keep getting more isolated from each other, maybe that can be secure enough.
Sure, memory isolation techniques may serve as a deterrent with extreme care. But if Microsoft increases the attack surface by sloppily integrating that feature everywhere in Windows, the yet-to-be-implemented-if-at-all encryption is going to be ineffective. And that’s going to happen more likely than not.
When there is a will, there is eventually a way, for anyone with enough resources.
Please explain to me how anything achieved infallible nature. Consider the natural vacuum is space.
> A lot of Windows users just want their PCs so they can play games, watch porn, and live their lives as human beings who make mistakes
The vast, VAST majority of Windows users don't care about a feature like this. You might say "if we'd ask people what they'd wanted they'd have said a faster horse", but we've seen this play out time and time again since ~2014 where the tech industry believes some thing is going to be Next Big Huge, it doesn't stick, and Microsoft Office continues to make fifty billion dollars a year because, it turns out, we kinda solved PCs in the 90s and 78% of what We The Tech Industry has invented since then has a market 5% the size the hype would lead you to believe. Metaverse, VR, AR, Crypto, Decentralized Finance, AI, Voice assistants, tablets (what's a computer?), quantum computing, IoT (all consumers love our toasters connected to the internet, this is undeniable and people pay extra for this /s).
Sometimes people just want a faster horse; which in this case means "filesystem search that actually works". The techbro response to that is "well, you can have both" but there's fucking actually zero evidence of this, period, neither Microsoft nor Apple have demonstrated the capability to get the basics of their operating systems right anymore, We Their Customers should have zero faith in their ability to even get this right, as articles like this demonstrate.
> I used Microsoft Defender for Endpoint — which detected the off the shelve infostealer — but by the time the automated remediation kicked in (which took over ten minutes) my Recall data was already long gone.
This isn't a Microsoft problem; well, obviously it is, but its really an industry problem. Sorry for waxing abstractly here, but we've literally actually forgotten how to build software [1]. The smart & dedicated people have either left the industry or have been marginalized by MBAs, and the kids are rewriting the Windows Start menu in javascript [2].
Still this is the worst spyware ever made. Have a telehealth appointment, lawyer conference, loan application, now Recall will store all that like it or not.
This made me decide to go with a non Snapdragon Laptop since I want nothing to do with this. Gonna dual boot with Fedora ( sorry Debain, but it looks like Stable is a bit behind what I need hardware support wise).
Microsoft is making a serious argument for going full Linux + maybe a PS5 for competitive gaming ( since anti cheat is Windows only by design).
I really really don't want to switch to OSX here since a 4TB drive is literally a 1200$ upgrade for Macs. Compared to 200$ when you can upgrade it yourself.
Music production isn't great on Linux.
bookworm-backports has kernel 6.6, which is the very latest LTS series. Is this not new enough?
I'm generally not a hardcore Linux person. Fedora seems to be more up to date out of the box.
echo deb http://deb.debian.org/debian bookworm-backports main | sudo tee -a /etc/apt/sources.list.d/backports.list
sudo apt-get update
sudo apt-get install -t bookworm-backports linux-image-amd64
Season to taste, of course.(and backports currently has kernel 6.7, not 6.6)
2024: People are willingly activating a key logger.
2024: People are forced to swallow keyloggers in order to continue to use their desktop PCs.
Most don't know what they're agreeing to, because most people don't have the time to be experts in tech despite it affecting every factor of their lives, much in the same way that tech people don't have the time to be be farming and agriculture experts in their free time despite it affecting every factor of their lives.
I used to think this maybe 20 years ago, but I think it's about time we shift gears to the realization that the reality is people don't care about tech privacy and security.
We have to remember: The internet as most people know it (the World Wide Web) is 33 years old, personal computing is even older. The 30- and 40-years olds literally grew up with all this. The 10- and 20-years olds are living all this from the moment they were born. Even legislation like GDPR came into force. The result is still nobody cares.
Lack of awareness isn't a problem anymore. Everyone knows, nobody cares.
<Insert "Am I out of touch? No, it's the people who are wrong." The Simpsons meme here.>
Example: tap water quality (assuming you live where tap water is safe to drink). Do you know how it works? What steps are being taken? Could you fix that yourself for your house if things break down? And yet, you probably care.
Another example: car safety features. Could you add a crumple zone to an 80s car? A cage construction? Yet you probably care that any car you're in has those properly engineered and no part of your body will be crumpled in case of a collision.
I strongly doubt that based on what I've seen. People install random apps on their phone just because they wanted to crop a picture and frame it or trim a video and compress it is because they ultimately think that nothing will happen to them. Like you don't expect your fridge to blow just because you open the door.
Another issue is that people are trustful. They trust their government to have laws for that. And even if a few accidents happen, they shrug because for them, the system generally works. And they don't care, just like you don't care a business having security cameras while you're shopping. Because you trust they will be sensible with the recording.
Tech privacy and security is nebulous for people and we have hordes of companies marketing that it does not really matter and the government not doing anything. And most people don't feel the impact. Getting them to understand is hard. Because they think that when they click delete, it's gone. Or if they've not posted, only they have the only copy.
The people of Troy didn't "willingly" bring in a huge wooden horse full of enemy soldiers. They "unknowingly" brought in a horse full of enemy soldiers.
Crass - Where Next Columbus? (1981)
The idea behind Recall, universal, machine-assisted search, is a good one but it's embarrassingly clear that in terms of implementation, this ain't it, chief. Microsoft should do what Google has done with Sky -- withdraw the product, take the hit, and hope that something can be salvaged from this debacle, both in terms of an improved product, and better company-wide testing and rollout practices.
Also a clickbait: nobody is stealing anything.
If you get malware or you have other admins on your computer, they can already record anything you do at their will.
The data is NOT uploaded to M$.
The whole fuss is stupid and I am impressed 90% comments here seem to think otherwise.
It seems like you live in the same kind of detached echo chambers as the people at Microsoft who approved this feature. No wonder you find this nonsensical. I bet the product managers responsible for this also find this article nonsensical.
Of course it is critical that it does not also know what porn you watched in incognito, or what you had in snapchat messages.
Wait, scratch the snapchat. I don't think they have desktop client.
> I think it’s an interesting entirely, really optional feature with a niche initial user base that would require incredibly careful communication, cybersecurity, engineering and implementation. Copilot+ Recall doesn’t have these. The work hasn’t been done properly to package it together, clearly.
Definitely needed some copy editing however.
>A. No, that’s insanely reductive. They’re super smart people, and sometimes super smart people make mistakes. What matters is what they do with knowledge of mistakes.
Never attribute to malice that which can be adequately explained by neglect, ignorance or incompetence.
But
>Q. Did Microsoft mislead the BBC about the security of Copilot
>A. Yes.
>Q. Have Microsoft mislead customers about the security of Copilot?
>A. Yes. For example, they describe it as an optional experience — but it is enabled by default and people can optionally disable it. That’s wordsmithing.
Maybe at some point we should reconsider.
Every internet connected windows computer is insecure by design and cannot be trusted to protect your privacy or security.
Having this power is inherent in making the OS. Whoever is the vendor of your particular Linux distribution has the same powers, it is just that you trust them not to use them (or, in a very small theoretical minority of cases, you’ve audited the code and binaries yourself).
So yes, you shouldn’t use an OS from a vendor you don’t trust, I agree completely.
I don’t understand why people are acting like this is earth shattering news though, this has always been the case since people started using software they didn’t write themselves.
No, it really isn't. For decades I owned computers with operating systems which didn't have that capability. Once installed and configured, the OS was consistent and (reasonably) stable. Someone would literally have to break into my house or office to modify my settings or install software against my wishes.
Even after I started connecting my devices to the internet the OS itself had no ability to do these things and couldn't gain that ability unless I explicitly chose to install updates that enabled that behavior. That's entirely different from the situation today where MS forces updates and restarts, installs unwanted software on our computers, and has files and folders that we (even using administrator accounts) don't have access to.
Linux too is very different. Linux is transparent about what it does, adds, or changes. You have the power to choose which updates to apply or not. You have the power to modify any part of your OS so that it does what you want. I can't speak to all distros out there, but I've never seen a linux system force a restart in the middle of the day, or reinstall applications users removed without notice. Can't say the same for Windows. Unlike Windows, linux typically respects its users and their wishes.
You really don't have to write your own software in order to have software that respects you and leaves you in control of your own devices. It's kind of crazy that you'd think there could be no other way.
In one case, someone discovering sketchy secret backdoor code causes a huge flap and damage to the company's brand and stock price etc.
In the other, some corporate drone bafflegabs about it enabling superior customer satisfaction synergies, while pointing to a tiny clause in an enormous contract of adhesion to claim everybody knowingly agreed to it.
if you're paranoid about the distribution of your pre-built distro you can compile everything by hand and some do that for fun.
so putting them on the same pedestal is weird mind gymnastics.
Your partner always has the capability to screw you over, cheat on you, embezzle from the shared account, whatever.
Linux is like a nerdy guy who stays at home, plays with Warhammer figures and cooks you dinner.
Windows is an OnlyFans model who goes on vacations for weeks at a time and ignores your calls.
It's finally here. It's been fun, I love windows but this is the end IMO.
Doubt. Jobs was a deadbeat dad for many years, refused to acknowledge his daughter or even admit that he named a computer after her, treated employees and cofounders like crap, etc. I think Jobs had a very low EQ, perhaps even a sociopath. He was just lucky, shrewd, and ruthless. Accounts of his last days indicate that even he regretted his behavior.
> A lot of great artists were borderline or full on terrible people. We still appreciate their art.
Speak for yourself. Whenever I learn that an artist is a monster, I think appreciate their work much less. Thankfully much of Apple's success is due to the work of hundreds and thousands of others, not solely this "great man" whose worshipped among the faithful.
Wondering you can imagine a scenario you'd be ok with.
I for one know of a guy that was told by his gf she was on birth control. Turns out she purposely wasn't so that that she could have a baby with him. This isn't someone's guess. This was told to my sister by her best friend.
I sometimes (always) wonder which planet Microsoft leadership live on - it's certainly not the real world that you and I live on.
Article: "This database file has a record of everything you’ve ever viewed on your PC in plain text"
Microsoft: "Snapshots are encrypted by Device Encryption or BitLocker, which are enabled by default on Windows 11."
https://support.microsoft.com/en-us/windows/privacy-and-cont...
The article is a little bit hand-wavy about how exactly the database comes to be decrypted and remotely exfiltrated. The headline says it takes "two lines of code" but unless I'm missing it, I don't see those lines discussed in the article.
The databases are plain-text sqlite files within the current user's %appdata% folder.
So, literally anything that can grab those files and put them somewhere else can qualify as exfiltration. Any backup product worth its salt would be covering these databases.
Q. Have you exfiltrated your own Recall database?
A. Yes. I have automated exfiltration, and made a website where you can upload a database and instantly search it.
I am deliberately holding back technical details until Microsoft ship the feature as I want to give them time to do something. I actually have a whole bunch of things to show and think the wider cyber community will have so much fun with this when generally available.. but I also think that’s really sad, as real world harm will ensue.2. The article says that they are not releasing PoC (my words not theirs) because this feature isn't out, and they want to give M$ a chance to fix it:
> I am deliberately holding back technical details until Microsoft ship the feature as I want to give them time to do something.
"Show HN: Rem: Remember Everything (open source)", 196 comments, https://news.ycombinator.com/item?id=38787892
"I made an open source Windows app to rewind and search everything on screen", 166 comments, https://news.ycombinator.com/item?id=40105371
"Rewind: The Search Engine for Your Life", 92 comments, https://news.ycombinator.com/item?id=33421751
I guess people trust Microsoft a lot less.
And for me it's not so much that I trust Microsoft less than any other company. It's that using their services require so much trust, yet they give so little trust in return.
https://x.com/AlexBlechman/status/1457842724128833538?lang=e...
Still, sqlite ... tempting. Sometimes, if I am missing something I read months or even years ago, the right query to the sqlite files Firefox keeps can give good results.
I also wonder how "knowledge transfer" will happen when you get a new machine in the future? What about backups, do they sit in the cloud already? These all sounds like ways that this "local" AI PC will share data with the MS cloud in one form or another. With Apple doing similar things already on iPhones (I know there are differences, but its still analyzing your data etc), I wonder if Linux might actually become a more mainstream OS in the future.
Could also be that people stop using computers as much and just use tablets with docking stations + keyboard & monitors (again, there is work to be done, but its a possibility from a HW level). That would leave us with MacOS & Windows for business desktops (with some Chromebook & Linux sprinkled in there). Education would probably be more Tablet & Chromebook style compute, and gaming is already moving to the cloud (I guess the positive here is that we might finally be able to get rid of AntiCheat software:) ).
> I also wonder how "knowledge transfer" will happen when you get a new machine in the future? What about backups, do they sit in the cloud already?
Honestly, I guess this will become very expensive for Microsoft, and they won't find a good business case what to do with the collected data. So Microsoft is wasting a huge load of money, and additionally their AI spyware causes a huge reputation damage for Microsoft: a lose-lose situation. :-(
Considering the global market share of Windows, there would be a need to roll out such a grandiose service slowly, too.
The Qualcomm Oryon SoC is about half the price of an Intel CPU.
The other issue, the vendors tend not to leave glaring security holes in their software, both because of IT desire to maintain control of the operating environment, but also because there is intense awareness that corporate espionage is a constant, real, and ongoing threat.
It sounds like the MS folks rushed out a "feature" and wanted to pretend we all live in some utopia where nobody does anything bad, ever. Possibly all snorting coke or something...
In most sectors the installed corporate spyware is from a different company than Microsoft.
Once Recall is out the story will go from laughable to worrying - all they'll have to do is change their text to include instructions to open Recall (the same way old websites would open 'file:///' to show they 'knew' what's on your PC) and regular people will lose their minds (and money).
And then there's the age-old adage "if you can see it you can exfiltrate it" - it didn't work for DRM and it won't work here. Malware will steal this data.
Perfect recall, no need for memory, available at your fingertips - with T&C that completely disregards your need for personal privacy.
The challenge though is the "better" alternatives where a mix of privacy and convenience is there is not always convenient. We have and continue to be marketed convenience at the cost of privacy.
What we need is consumer data privacy to really become a societal and government concern and for devices which infringe on this to really go through the same scruity as say a drug going thru FDA approval.
Actually, people in the US are worried about privacy in the age of AI. [1]
[1] https://www.pewresearch.org/internet/2023/10/18/how-american...
Law enforcement, attorneys, and three letter agencies must be extremely excited about Recall. Now they won't have to hope that MS has records of everything you've typed while using your device, because with Recall all of that evidence will be stored on the device itself.
"If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged." imagine could be found using everything a person ever types on their computer.
They just put a little AI lipstick on that old pig in the form of OCR and some image classification.
The Windows 10 Timeline feature has been around for 6 years. It is a bit surprising there is so much pushback this time around for effectively the same thing. I wonder if it's because Microsoft has been burning away people's trust through ads and dark patterns and all that bullshit, and this is the direct result of that.
As far as I know, nothing used it except for MS' own apps. This new solution bypasses that problem by having no requirement for apps to use the Graph API-- it will just use an AI to deduce what the tasks were, and provide a search-like conversational experience on top of the collected images.
Same as
> The Tesla will never crash in FSD
Same as
>out platform is hacker proof
But good grief wtf. I was mostly joking when I said before MS was intentionally trying to kill windows, but is there actually any other explanation for implementing this "feature"?
But this sort of tone-deaf move from Microsoft is irritating me. I already dislike Windows 11's UI and UX flow because it is so reminiscent of macOS; this is why I haven't updated to it on my personal main computer yet (which is running Windows 10 Education, courtesy of my alma mater's Azure subscription). I've seen rumours that Microsoft hired a bunch of UI designers who used nothing but macOS and decided it was a good idea to port macOS UI designs to Windows. What a terrible terrible thing. UI responses that are instant even on Windows 10 now have a jelly-like lag to them on Windows 11, for no good reason. Also consider the regression of the right-click context menu, the ads and Copilot everywhere, a preference for unlabelled icons over text, amongst many others.
As another comment says, Windows Recall appears to be an AI evolution of the already-present Windows Timeline feature. The privacy outcomes of this are concerning and I really really wish we didn't have 'AI' and 'Copilot' stuffed down our throats all the time. I would like to opt-in to features I want, rather than have them all pre-enabled. Some of them are very useful, like clipboard history with Windows-Ctrl-V; some less so and are flagrant privacy violations.
I have already disabled almost every tracking, phone-home and auto-update feature possible using group policies; this is just another thing to add to my list of disabled 'help' features.
That being said, if Recall doesn't phone home—which appears to be the case here—I don't buy the argument that 'it's stealing everything you do and hackers can access it if they have physical access'. I believe that the moment a computer's physical access record is compromised, the entire computer is compromised, regardless of security theatre like disk encryption in the form of BitLocker/LUKS, Secure Boot etc. It doesn't matter whether Recall is present or not.
The risk is not physical access, the risk is malware installed on the machine, or a security hole in some browser feature enabling malicious actors to covertly uploading the recall database to a remote server.
Yes it does. Consider getting some malware that is detected a few minutes later and removed. For most people there would be no harm. With recall, you would be instantly screwed.
If you're capturing screen shots, then how is something like using Signal or some other encrypted service still possible?
The idea other people with access to the device could see a photographic memory is.. very scary to a great many people on a deeply personal level. Windows is a personal experience. This shatters that belief.
How did we get here? A 20-year lifelog.2003, https://en.wikipedia.org/wiki/DARPA_LifeLog
>The objective of the LifeLog concept was "to be able to trace the 'threads' of an individual's life in terms of events, states, and relationships", and it has the ability to "take in all of a subject's experience, from phone numbers dialed and e-mail messages viewed to every breath taken, step made and place gone".
2007 Microsoft Research, https://www.microsoft.com/en-us/research/video/the-microsoft...
> The SenseCam is a personal, wearable camera developed by Microsoft Research in Cambridge, UK, and used as a lifelogging device in projects like MyLifeBits.. is based on wearing the SenseCam for lifelogging of ‘events’ during your day, and generating a fast-forward movie of the event as the memory recall interface.
2010 Microsoft Research, https://www.microsoft.com/en-us/research/publication/now-let...
> Lifelogging technologies can capture both mundane and important experiences in our daily lives, resulting in a rich record of the places we visit and the things we see.. Previous work has demonstrated that Lifelogs can aid recall, but that they do many other things too. They can help us look back at the past in new ways, or to reconstruct what we did in our lives, even if we don’t recall exact details.
https://www.microsoft.com/en-us/research/project/mylifebits/ & https://en.wikipedia.org/wiki/MyLifeBits
> MyLifeBits is a life-logging experiment begun in 2001. It is a Microsoft Research project inspired by Vannevar Bush's hypothetical Memex computer system.. The "experimental subject" of the project is computer scientist Gordon Bell.. For this, Bell has digitized all documents he has read or produced, CDs, emails, and so on. He continues to do so, gathering web pages browsed, phone and instant messaging conversations and the like more or less automatically. The book Total Recall describes the vision and implications for a personal, lifetime e-memory for recall, work, health, education, and immortality.
Lifelogging was referenced by 10,000 academic papers over two decades, https://scholar.google.com/scholar?q=lifelogging
The source article is a QA with himself. There’s 1 tweet references, that shows a screenshot of a truncated SQLite db that shows a log of the applications opened via the user UI shell: https://x.com/gossithedog/status/1796218726808748367?s=46&t=...
Whoopty doo. There are many, many sources throughout Windows that can give you a list of recently opened applications (that have existed for 10-25 years)
If a corporation was a man, it would be a tyrant that demands to know everything its subjects do and think, and wants to control what they do and think.
It literally does not: https://news.ycombinator.com/item?id=40543584
So I guess at least marketing that as a feature now makes it obvious that it is possible, I guess.
But now they will claim you have a way to turn it off. Who knows ! There is so much telemetry being recorded anyway.
This is like people preferring Macbooks from 2016 because it was pre-touchbar. I honestly consider good tech from previous years to be far more secure than what’s around now. Who knows what’s in your products now?
(* I am intentionally not stating the name because they don't deserve the attention or free advertising)
Can we PLEASE have proper per-process file access restrictions on Windows already - like MacOS has had for a decade now ????? Why is win32 app isolation still not done?
It's a bit opaque though, not as simple as *nix owner/group/everyone permissions.
I may "trust" a video editing app, for example, so I can access my raw content folders. It should still be completely impossible for that process (or any spawned from it) to access my browser session information in case of an RCE from loading a malicious video.
Yeah... This is a BIG issue with the modern generation of antimalware solutions.
The old signature-based detection is great and immediate. But it has drawbacks. It only detects already-known malware. Not tailored stuff used only on one specific target. Also, malware can change its own signature adaptively. and hook into known-safe binaries.
So, a modern antimalware uses AI learning and behavioural analysis. Why is notepad.exe suddenly logging all your keywords? Ban it. The problem is: This takes a while. The tool can be configured to block it before someone looks at it, but it still takes a while. At the point that this happens, the damage is often already done.
At an enterprise level this is not a huge problem because it does mean the problem is detected, and by the time it is investigated it's possible to stop the source of the malware and ban it from all the other 100.000 PCs by using signature detection or other mitigations. On personal PCs this is more of an issue because they don't have a dedicated SOC (Security Operations Centre) jumping on to these things.
Also, the noise level is an issue in the enterprise, set the detection threshold too high and your SOC gets overwhelmed by all the detections and becomes ineffective.
Anyhow, this is indeed a good argument against Recall. When it was first introduced last week, people stated that it wasn't a big deal because malware can install its own key/screen logging. However a repository of the last 6 months of activity is indeed a very juicy target to exfiltrate quickly before detection.
Disabled by feature flag? Sure.
Disabled by default? Sure.
Once Windows stops having administrator accounts, they'll enable it by default.
As Smith would say, "it's inevitable".
To which I reply:
sudo rm -rf /agents && echo "the only windows here are made of glass""Once Windows stops having administrator accounts"?
An abuser being able to access their partners/kids computers and go and see every thing they have done is terrifying
Can we just not do this at all?
Keep pushing chaps...
Malware?
Keyloggers?
Adware?
Rootkit DRM?
Turns out they changed what "it" is, and I'm not even halfway to my pension yet...
This is societal cancer. Total information monitoring is the death of any semblance of human independence and should be violently resisted.
I have never been more disgusted by a management team. How clueless can you be? Combined with digital intelligence, this technology is profoundly dangerous to anyone who works with a computer or technology (which is almost everyone).
You might want to consider an alternative plan, as doing that to an employer's / government's computer could get you in a lot of trouble.
2. Turn data into AI that replaces users
a. A way to capture more personal data and sell it to advertisers, or
b. A way to make Windows even more attractive to enterprise customers so that managers can snoop on employees, or
c. A handy feature that most users will want.
What Microsoft is saying publicly is c, which in itself is a red flag that suggests it's probably not true. The other red flag is that even as tone-deaf as Microsoft is about user wants and desires, even they can't be stupid enough to believe most users want this. So it's gotta be a or b or both.
I mean, I have no idea how to stop laughing inappropriately at the moment but I know the product exists, that it can be delivered to my doorstep and that I can afford it.
I’m sick of brain dead execs and product managers. What world do these people live in?
https://kacos2000.github.io/WindowsTimeline/WindowsTimeline....
The default progression of this sort of "feature" and business practice.
lol, lmao even. Some might even be so inclined to say rofl.
It is actually kind of depressing the state in which Windows is and is going. For me personally the only actual "advantage" Windows has over my homegrown Archlinux install is app/game support. And basically all of the ones that don't work, don't work by design because they don't want the user to own their hardware/software.
Getting promoted by other execs based on the visibility of delivered features.
I might seriously quit my job and start a discovery consulting / tech company just for targeting these databases.
Given that you can exempt particular website (in addition to private browsing modes in "supported browsers" already being exempted [1]), that implies some integration between a browsing context and Recall.
[1] https://support.microsoft.com/en-us/windows/retrace-your-ste...
Obviously that 90kb doesn't include the separate folder with all the jpegs.
By that logic password managers are also no-no.
I do not remotely whatsoever trust Microsoft or Windows to keep their Recall database secure and offline. Attackers will know exactly where the file is, unlike with my password manager. There's no shortage of Windows privilege escalation exploits to gain TrustedInstaller status to read any file on the system.