Microsoft will switch off Recall by default after security backlash
wired.com
wired.com
And then someone goes and invents Recall. This is not the work of a lone engineer and a principal PM fishing for Impact or whatever they call success at Microsoft. This had to have gone through multiple levels of review. Microsoft PMs, CVPs, their corpo legal people, marketing approval. And yet no one stopped to say, "wait, this could blow up in our faces"?
Actions speak louder than words.
We should assume that everyone is on their worst behavior going forward. Zoom, Slack, MS, Apple, etc.
What happens is that, meanwhile, business is happening. People are making (small) decisions that adds up to big things, and leadership tends to trust those below to make the right calls and implement technology correctly. Which, time and time again, doesn't happen.
Yes, maybe it need to be more of a priority, but, it also isn't a conscious decision.
GenAI is hotter than anything else right now. As Satya publicly stated, "we made them dance" -- which shows how high-priority it is to maximize "AI innovation" at MS.
If you disagree, think about how badly "Tay" blew up in MS's face and yet they still went ahead and bundled OpenAI LLM tech into all of Office365, just so they could have bragging rights about beating Google to it.
At this point, it's a race (to where? who knows) and no Big Tech Corp wants to be seen as "not at the forefront".
That's my $0.02, anyway :)
Google kept on launching faked demos and hurriedly released an openly race biased image generator all in a bid to catch up with OpenAI.
Meanwhile Apple has been sort of lethargic. Recently annouced a deal with OpenAI to add GPT to their devices. They seem happy to continue playing catch up in this regard.
I think Meta is probably the only big tech giant that has kind of got their execution right straight from the jump. Can't point to any slip ups from their "AI announcements".
Much easier to avoid messing up, given this.
Catch up with what? Does anyone else have an AI product actually worth having?
Is it somehow bad that Apple hasn't also released an AI that doesn't do what it's supposed do half of the time?
If by lethargic you mean OCR of every single image on my computer so I can copy and paste text from anything, all running locally on the NPU on my M1 chip, then lethargic is A-OK.
That's what Apple does: they ship useful features. We'll see tomorrow if they fall in the trap and run in this race to nowhere.
This functionality is baked into Windows since 10. But for some reason you need a third party program to expose it.
https://learn.microsoft.com/en-us/uwp/api/windows.media.ocr?...
If you think the bias was due to timing constraints and not intentional then you are extremely naive.
> And then someone goes and invents Recall
Maybe you should read about the history of Microsoft, especially about its security.
But people forget easily.
But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
On the other hand, I am always freaked out by Chrome extensions that "can read and change your data on all websites". Can't they have more granular permissions? You gotta have a lot of trust for those extensions LMAO. They can read your bank passwords, probably!! And if they are ever sold...
It's "little brother" that benefits a lot here: bosses, spouses, parents, etc., who otherwise wouldn't click on 1000 links in your history.
I trust gorhill and the EFF to not fuck me over on my data, and Tampermonkey kinda needs those sorts of permissions to work. My password manager has read access to every website but I'm already trusting it with all of my passwords so...
These extensions should not store any data without a master password that you input every time.
What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate.
If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has.
>If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
My threat model doesn't include state actors targeting me specifically. Not sure much of anything works against that threat model besides maybe iOS in Lockdown Mode as your only device.
I have seen Metamask update itself randomly, and it has access to read every website
I think it's the right move to have it off by default, but I'm just not convinced by the outrage here.
In comparison browser history is nothing.
Perhaps you didn't note before, or are one yourself, but this includes e.g. abusive spouses. Sure, maybe the abusive spouse could hire a black hat, but this is very different to a drunk low-life wife-beater casually snooping through "recall".
It might not be a "new" attack vector, but its absolutely a complete degradation to any computer security.
The horse is out of the barn for many people during work hours. But in the OS and on by default is a different story!
No one retweets "Attacker gaining root access reveals all user information", but instead "Attacker gaining root access reveals all user information collected by AI program" will go viral for sure.
It's not on the individual users to take steps to preserve their basic human dignity. It's not Microsoft to not take that dignity away by default as was their plan before this fiasco predictably blew up in their faces just like the Xbox One always-online Kinect requirement before it.
Most of us know that the public Internet is based on surveillance capitalism, no matter if we hate it or are just complacent or ignorant.
OS wide is far more problematic and of low value to the user.
I get your point, but Microsoft's Recall can capture anything onscreen - emails, personal info, porn, passwords and the like. And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
In the case of the phone, one simply sees recipient of call, duration etc, regardless of how much information was exchanged. The phone I'm calling is arguably analogous to the server I request a page from, in the metadata context.
I'd argue browser history is significantly richer in some regards due to this. It's not unheard of for user identifiers to appear in URL paths either - try visiting https://news.ycombinator.com/user?id=<HN user name>... In my Chrome, that's instantly in the history file with my username.
I don’t know anything about this system, but the fact that screen shots are not ultimately stored on the user’s PC doesn’t mean anything if the content has already been classified and indexed. It will be fished.
I think the thought is proportional to the amount of thought a non-tech customer will put into it. Nobody seems to care about or understands privacy these days. Everyone knows they're being tracked everywhere they go physically and on the web. People use their real names, address, etc for every junk service they sign up for, without seeing any reason not to. If you tell people that their TV is tracking and taking screenshots of what they watch [1], they say "yeah, Netflix knows too".
It's literally, "how it's always been" for any non tech person under 30.
[1] https://themarkup.org/privacy/2023/12/12/your-smart-tv-knows...
Part of me wonders if this is the consequence of how accessible tech has become, and the prevalence of increasingly non-technical product managers. I'm a former PM, and I'm not here to denigrate the PM role, but the fact that a product like Recall got shipped says a lot about the makeup of the product org that shipped it.
While I get that younger people tend to see privacy differently, I'd argue this isn't really a privacy issue, it's a security conversation, albeit with obvious privacy implications. Leaking what apps I use or what sites I visit is mostly a privacy issue. Leaking what I type into the boxes on those sites is a security issue. If the end result of leaking this info is the attacker can pwn all of my bank accounts, we're solidly into security territory.
The fact that this got shipped means that multiple levels of leadership either didn't think about the consequences or didn't care about the consequences. I hope it's the former, because that means they can learn from the backlash and hopefully recalibrate.
Microsoft is in a position of power that IMO requires a significant duty of care and responsibility to their customers, and lapses like this need to be judged through that lens, i.e. it is their entire business to make sure features like this are safe.
There was probably from lower decks, where they are closer to reality. However, people are scared for their jobs in this economy and likely didn’t take it farther.
Emphasis on "part." I'm totally guessing on this, but I think OP may have been talking about PMs where the MBA is their only notable feature rather than those where the MBA is just one part of a well balanced whole.
> You can teach a tech person to understand business, vision, strategy, finance, etc. You cannot teach very well the business person who has all that the intricacies of technology.
I'm inclined to agree with this. The thing about business degrees is that they are so minimal effort that actually understanding business isn't a prerequisite to being awarded one. I would know, I have 2 of them.
There's no guarantee a "business person" actually learned business, much less that they are capable of learning tech. Don't get me wrong, I'm not by any means implying that all business people are inept or that they are collectively unable to learn tech; it's often unrealistic, but not impossible.
When going to school for tech, such as an MS in engineering, CS, etc., typically requires enough effort that one will end up learning their respective field (I have met exceptions to this and interacting with them is infuriating) whereas going to school for an MBA is one of the easiest ways I know of to get government financing for a decade of partying.
Well this wasn't in the brochure. Best look into it!
Microsoft is just tripping over themselves right now bringing AI to market because they don't want to miss the boat. Their copilot for office 365 stuff is hardly working, it's real beta quality. No normal company would have released it to market in this state. But they're just terrified that Google will eat their lunch.
I don't think security and privacy concerns are much on the radar there anymore. They just want to establish their name in this new market at all costs. And I think in their eyes it makes sense, they've always succeeded because they had the biggest installed base, not because they were the best. It makes sense they see value in being first mover at all costs.
It's just a bit frustrating as a customer. As usual with something they launch it's more promise than substance. I have to say that usually they do have the follow-through to really make it a success. But it does take time.
That sounds good to some people. But if I mentioned it to most people in my family they would probably be rather weirded out by it. They probably also would have no idea of the scope of the size of it and how it is being used against them.
Privacy is not a binary concept. There are actions and information that some people are ok being public, and there are some they prefer to remain private.
What is not OK is spying and exploitation. I should know what data you’re collecting and preferably specify which I’m ok with. I also should know what is intended for and preferably for most of it to be anonymized.
Most people expect reasonable privacy policies from companies and they believe that there’s some regulation in place.
Absolutely, but if you ask/inform these people they will say "Well, guess I have nothing to hide." because they can't comprehend going without all their devices/services.
Many here may be too young to remember when many consumer products came with a "product registration" card. This was basically a postcard that asked for all sorts of information, such as your name, address, phone number, birthdate, sex, SSN, marital status, annual income, interests, other products owned, whether you own or rent your home, etc.
People willingly filled these out and sent them in. All the info went into databases that were merged with other sources and traded around various marketing agencies on 9-track tape reels. Advertisers could get mailing lists segmented by age, sex, income level, geographical region or specific zip codes, etc. for their campaigns.
It's all much more pervasive and invisible now, but it's basically what has always been done.
I don't know, I don't think sending in product registration cards could/would often result in your bank account being drained...
> It's all much more pervasive and invisible now, but it's basically what has always been done.
So you admit it is far worse today than it was before? But the second half of your sentence seeks to disingenuously pretend that it has "always" been bad.
I can be sick with a cold or I can have stage-four brain cancer. People have "always" been sick but one is serious (terminal cancer) one is not (a non persistent cold).
Basically is doing a lot of work here, the level and degree of how much data is vacuumed, processed, and used for targeting nowadays is orders of magnitude of difference from these primitive ways.
A tent and a house are basically the same: a shelter.
No, no. They thought about the privacy and security aspect. They decided that it's better for their bottom line if Windows users don't have privacy from the mother ship. Really, they already decided that way back when Windows Vista first came out and periodically asked Microsoft HQ if you should continue being allowed to use your computer.
Theyre just boiling the frog slowly. It'll be turned on by default soon enough and then theyll start looking for excuses to upload it.
This can be used to make them a shedload of money one day.
I was just remembering today what they did to the security/encryption as soon as they bought over Skype… they removed it. And who would that benefit - the spies.
No-one cared about that. No-one ever cares. Except for this rare occasion - tides are turning and people are starting to care a tad more.
I don’t have any friends that care about their own security and privacy. Wanna be my friend? Lol
Of all the places on your computer that might contain porn images, that would be one of the very top candidates.
Unless, of course, you're willing to argue that a porn image stored on the local hard drive isn't contained in any folders on the same PC that soft-link it. You might have an interesting time trying to justify why it is contained in folders that hard-link it.
Sure, info about non-top-level links is extractable from e.g. request caches, but that's a different thing from the browser history SQLite DB.
Here is the URL of an image as it appears in your browser history: https://cheezburger.com/10357071872/if-i-fits-i-sits
See if you can figure out what image I was looking at.
Calling it the URL of an image seems to me like quite a bit of confusion about how web pages work.
(I really wish they followed the “standard” keyboard shortcut)
On a more relevant note, how can it know when a private browser window is open in anything other than Edge? Same question with the password manager - is there going to be some new API that apps have to "opt in" to to enable Windows to recognise them?
The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other.
Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.
Or from history you may see that you accessed a site, but not what you did on it (what comments you typed for example).
At the time, it wasn't very thinkable that someone would have the audacity to take and abuse that information.
It dates from when Internet people overall were more savvy about privacy than users overall today are, but it was also when the Internet was closer to a trustworthy environment, and before Wall Street sociopath types took over the tech and the culture.
Lots of kinds of abuse that today are routine and almost universal, for even startup tech companies, (e.g., embedding third-party trackers into Web site, and getting even worse from there), I think would've gotten them ostracized, and outraged demands for criminal charges.
During the dotcom gold rush, there was such a flood of totally new, posturing people, and so much money being thrown wildly at everything, that any remaining outrage was lost in the noise.
And now virtually no one knows any different.
But if you're trying to push some new abuse today, I think ordinary people are starting to have some awareness of what vicious sociopathic buttholes tech companies have become, and so acceptance might not be a slam-dunk.
2. Browsing history watches one app. Screenshots watch everything across the entire OS.
People might use Incognito mode to browse porn, but I imagine it's a lot less common when looking at other sensitive sites.
Does your browser history store pictures of your family?
Whereas to avoid browsing history, one only has to avoid the popular, graphical, advertising corporation browser. As I am not interesting in graphics, I do this everyday, with ease, because there are countless clients besides "Chrome/Safari/Edge" that work with the www for consuming information.
There's also always private browsing, which exists specifically because people are aware of the implications of a browsing history and a persistent cookie jar.
That awareness will be much harder to build for an always-on screen recorder.
Recall seems to be storing its info locally in an unencrypted SQLite database as well.
At least, that's according to the instructions here on how to access and view the contents:
https://www.heise.de/en/news/First-experiences-with-Recall-9...
From the submitted article, it seems like Microsoft will change/secure the access (and maybe storage) in some way, though there's no details on the specifics.
I want to be able to find things I've seen before. Recall would've been great if using it didn't require me to update to a version of Windows that contains "Copilot".
Otherwise, every creepy roommate, bad partner, bad friend, etc... will take advantage of this to do bad things.
[0] Ideally more obvious, like when Windows screen recording is running.
MS just did what every other micromanagement company did and took screenshots every second or so.
Recall will be pre-installed on Windows 11. The ubiquity is what scares me, and should make MS take a second thought about liability, as far as treating their uses right.
However regarding it being opt out… what would prevent a virus from just enabling it on a bunch of machines silently. Sure it would be caught but the damage done and most won’t be bothered to go in and disable it after.
Or Microsoft just decides they need to really market the hell out of AI and it gets turned on my default anyways.
There's no such thing as "accidental enablement" for stuff like this, as if it's a switch every employee at Microsoft has access to, and one of them one day can end up flipping by accident with their elbow and it ends up in production without anyone else noticing.
Either they decide to intentionally enable it or not. There are no accidents , when stuff like this needs to go through a committee of people for approval before it makes it into production.
> unmercenary assumptions
Absolutely. And all of them decided to screw largely defenseless non-technical consumer to make short-term profits. That's not a fantasy, that's our reality.
Or it could just steal your cookies which are out there in the open.
The username/password you type in next time it expires is far more valuable.
And it might not even be necessary to obtain cookies or credentials if I can just see whatever you could see when you’re logged into various sites.
https://doublepulsar.com/recall-stealing-everything-youve-ev...
Microsoft will also require Windows Hello to enable Recall, so you’ll either authenticate with your face, fingerprint, or using a PIN. “In addition, proof of presence is also required to view your timeline and search in Recall,” says Davuluri, so someone won’t be able to start searching through your timeline without authenticating first.
This authentication will also apply to the data protection around the snapshots that Recall creates. “We are adding additional layers of data protection including ‘just in time’ decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so Recall snapshots will only be decrypted and accessible when the user authenticates,” explains Davuluri. “In addition, we encrypted the search index database.”
https://www.theverge.com/2024/6/7/24173499/microsoft-windows...
But I'm glad to hear they've committed to making changes. Given the misrepresentations they made regarding the initial rollout plan (the target of most criticism, mine included), Microsoft has to prove themselves here and I'll wait until qualified security folks get their hands on this before coming to any conclusions.
What we know is that the initial version was a non-starter, and this new info validates the concerns we've all been expressing.
I truly hope Microsoft does an acceptable job of addressing this. It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
https://blogs.windows.com/windowsexperience/2024/06/07/updat...
> It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
It's possible this was the intention all along but as a early-beta feature this was just the MVP. The reason it was rolled out to early testers at all was to get feedback.
If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.
This points to structural issues at Microsoft.
Security requirements often completely change the architecture of a product. Things can be built without security that are significantly more challenging to accomplish when strict data security requirements are in place. Architectures that assume no security often completely break down when security is tacked on top.
If this is a matter of a product not yet getting "security added", that again raises major concerns about how Microsoft is building products.
I think that exploratory development is, in general, a good thing. Bogging down all development with middle-management procedures might certainly have caught this early. But that doesn't necessarily make that a better way to build products.
The scary thing about Recall isn't actually Recall itself. It's that AI makes this kind of product possible and really easy. I'm sure we're going to see implementations of this idea everywhere and not just on PCs. Imagine AIs watching security cameras.
I have never seen a crypto locker ransomware on a server except for windows servers. I haven't seen another OS with ads. So many terroble things happen only in the windows/ms ecosystem that it really makes me wonderhow it sticks around but I have ideas about that and they will just make you think I am wierd.
The virus doing the same things as recall will be much noiser and much more suspicious. Making it much more likely to be removed.
Not to mention that once recall has been running a virus only needs to extract the data. It records far more than what a password manager does and is far easier to search through. It just makes a very large attack surface.
Basically, why would anyone develop keyloggers anymore? Microsoft did it for you. And it'll never be tripped by antivirus software because it's an official and legitimately signed program. You don't see a problem with this?
If that occurs, the malware won't have access to months or years of data to sift through.
Malware that scrapes it and malware that turn it don't need to be the same.
This is what will happen. And when you turn it off again, it'll be turned back on by the next update. Enjoy.
everyone else just gets a laptop, unboxes it, turns it on, uses it, does whatever they want to it
see: any retail location in a strip mall, any mom/pop business, etc etc
When Microsoft decided to push a feature upgrade last year that automatically enabled OneDrive backups for their home directories, it technically violated HIPAA by moving electronic patient health information contained within their scanned files folder onto OneDrive servers without any prior consent or authorization. They literally called me when they were unable to find their files, Microsoft had (laughably, if it weren’t so serious) placed a text file on the desktop titled “Where Did My Files Go.txt”, and then directed them to the OneDrive folders where it had moved their desktops, documents, and pictures without their knowledge or approval.
I have since moved them to Microsoft 365 accounts where I can apply GPO, but my clients were understandably unhappy about having a new annual subscription that didn’t add any tangible benefit, rather they’re now on the hook for a couple hundred bucks a year for what’s essentially a shake down. Pay for the new service that adds nothing meaningful to their experience, or else face the consequences of Microsoft ruining your business on a whim.
Once you have the Recall capabilities, it doesn't take much to start collecting and searching the data.
Any company that has compliance requirements to keep devices supported with security updates, it's the same as Win 7 to Win 10; you either update everyone to Win 11 or you pay for the security updates for Win 10 (IIRC you have 3 years to update before you can't pay anymore). Many will likely already be on Win 11 as the upgrade path is easier/quicker than Win 7 to 10.
Also they will not have the gunk installed anyway as they will almost certainly have Windows Enterprise which has more policies that can be set, and then they will also be ordering devices from an OEM or distributor that doesn't have the junk included.
Heck, if they aren't doing Autopilot from the OEM or distributor, they will almost certainly be applying their own Windows image.
Compliance doesn't say "company can't watch employee" -- in many cases it mandates surveillance.
This just lets the employee leverage that too.
They’ll probably think twice before jumping into the fray again with the Microsoft branded Informant Wire (I mean AI wearable) ;)
At one place I worked when the company replaced my old machine with a new windows 10 system it was configured to send every single keystroke back to Microsoft. There was zero concern over privacy or compliance, just an assumption that MS would never abuse that data for any reason. I did not have their faith and disabled that "feature" then changed a massive number of other policies to try and keep as much data out of Microsoft's hands as I could.
https://www.privateinternetaccess.com/blog/microsoft-windows...
https://www.pcworld.com/article/423165/how-to-turn-off-windo...
No need to pay for being the target of surveillance. The "products" are free.
1. Unless we count the telemetry and "auto-updates". Users never asked for this stuff though, it is not initiated by them. This "product" is broken on delivery hence the alleged need to keep "fixing" it by remotely installing more software, presumably that isn't broken and will not used for surveillance, on peoples' computers. All for free. There is no money to refund if the "product" does not work as expected.
I'm glad Microsoft is making changes, but I wonder how much is out of fear for their reputation and how much is just to try and comfort people and get the news to stop talking about it so that everyone doesn't just disable it as soon as it rolls out.
A reply about tangible products that people can choose to purchase or choose not to purchase is not a response to the comment I am making. These are examples of conscious choices, coupled with payment.
With few exceptions, non-enterprise Windows users are not consciously choosing to purchase a Windows license. They are choosing to purchase a computer. The decision to purchase a Windows license was made by the OEM. If we ask these computer purchasers what they bought, they are likely to describe a tangible product, e.g., "I bought a computer", not a license to use an operating system.
If something is wrong with the computer, then the purchaser can generally contact the seller/manufacturer for redress. But when the problem is with Windows, consumers generally do not contact Microsoft. Instead they complain into the ether.
Good luck enforcing warranties or products liability laws against Microsoft with respect to a free copy of non-enterprise Windows that was pre-installed on a computer. Windows can be broken six ways to Sunday, it can be a defective "product", and Microsoft can take its time fixing the problems, or even just leave them as is.
- When a user enable Recall, it should ask to setup a "Recall password" and generate a private public key and use the password to encrypt the private key.
- Use the above public key to encrypt all the data it stores.
- When user wants to search Recall history, ask for the password, decrypt the private key and use the decrypted private key to decrypt the data and show the data to user.
- Show some sort of indicator on taskbar that Recall is running, not a tray icon (which can be hidden), but a proper big red circle kind of thing.
To me this seems like another case of MS top executives telling every team that they have to do something with AI. Typical approach used by many executives and managers - "Here is a new tech, figure out a product to build with it".
If chat and co-pilots are all we get out of this wave of investment, then I'm not sure if it's been worth it.
Personally, data privacy/protection and compliance aside, I’d find it fairly useful on my work computer.
But just because something has utility doesn't mean it comes at high costs. I mean it's a super powerful keylogger that is searchable without technical knowledge. Not to mention that it'll probably fail to LLM type of attacks, which even many non technical people are able to figure out.
But then again, I don't understand why people so passionately store all their chat logs (not just important/memorable messages) and take millions of photos. We kinda spy on ourselves
And per my other comment [0], I think it just creates a big attack surface and makes extracting data and passwords from machines much easier. And as suggested by another user, I suspect this will be used to enforce Chat Control for those in Europe.
Giving your screen recordings to Microsoft is like giving a loaded gun to a toddler.
Now that I'm a developer, I often get into the flow and find myself knee deep in some work, but I forget to write notes about what I was doing. Coming back the next day, I often can't remember what issue I ran in to or how I fixed it. Having a quick way to review what I did the previous day is very helpful.
I can see a lot of potential uses for this technology, but I'm quite wary of any service that involves sending all of that data to some third party. Regardless of how much they might swear they won't use it for anything else, every company eventually sells your data for extra profit - it's just too tempting.
Now, the story is: Microsoft has been forced to retreat, through public pressure, from tracking everything that its users do by default.
Complete success on Microsoft's part. And the public that angrily reads headlines and angrily tweeted twice, vigourously pats themselves on the back for their "victory."
It’s a complete circus right now. Plenty of us just ignoring it and opting-out but it might reflect on our bonuses.
About a year ago my mom had said "you worked at these powerful international companies, I'd expect you to have confidence in the people working in their ranks to protect the things that you deem valuable", my response was "unfortunately that's exactly the reason why I have no hope that anyone will stand up".
What I hated the most was that the File Explorer just calls the folders in there e.g. "Documents" and "Pictures" without showing the full path. So it was hard to figure out just where in the file system you were looking -- a major annoyance if you do any work in the command-line!
Even after switching OneDrive off and doing as much as I can to try and get rid of the OneDrive folder structure, I haven't been completely successful. You can make some -- but not all -- home folders (like Downloads, Documents, etc.) point directly to their place in the local user folder, but others, particularly Pictures, don't seem to be movable. Additionally, some programs still seem to want to use the OneDrive folder by default, like I think Office programs still do their best to use them.
In the grand scheme of things it's a small annoyance but god it annoys the shit out of me! I didn't ask for cloud backup and it drives me nuts they tried to force it on me!
You will still get it reinstalled during a major OS update, but at least it can easily be removed. Before it was a chore to clean up.
I would speculate there is even some way to prevent it from reinstalling during those major updates. That seems like the kind of capability they would build in because a huge Windows customer complained (i.e. realistically, the major check against dark patterns in Windows).
It id what SRP's are for (but yes, I would not put it past them to disable anything targeting OneDrive).
The one positive about Windows is their need to cater to their enterprise IT fleet management base. So, as long as you have a Pro version of Windows, there is usually a way to lock down most things like this via Computer Policy settings. It's just not easy to discover nor time-efficient if you're managing a personal "fleet" of three PCs.
Internet access is not always guaranteed or reliable. Please do not assume that the cloud is a viable solution for every user.
I ran into this on my phone awhile back. I knew I would be out of service for some time but had some PDFs I needed to reference. So I downloaded them to "files". Que surprise when I later go to look up a value and there's a little cloud with a down arrow button next to the PDF in the files app, which of course fails because I'm nowhere near any internet access. Even more fun: turning off the cloud integration in files just causes the files to disappear, even if you are currently connected. It's allergic to local storage.
Also every <35 years old person is a js/web dev, so that’s what they do on cloud
In the UK, every time I got on a train, I'd experience that. And it was worse than not having internet; you had internet, but with extreme packet loss and instability, meaning that every app out there would simply stall, even if it already had the data to do whatever it is I wanted it to do, because it was waiting on some background request to complete. And because I had internet, the request didn't just fail, but it also wouldn't complete in any reasonable amount of time.
Very frustrating.
So fun to spring for the paid duolingo only to realize you can only download the next lesson up, not like the entire course.
The lessons are like 5m long wtf am I supposed to do with that? I just want to spend my idle time on the plane or camping disconnected from distractions so I can learn, but app developers have made that effectively impossible
And this is why I don't pay for, or even use duolingo even though I'm actively learning a language
1. Create new office document (Word/PowerPoint/etc) and hit save.
2. No, the default location in OneDrive isn’t right so you click the down arrow to see more.
3. No, none of the other recent locations in the (short) list are right either, so you click “More locations”
4. Now you have to click Browse to see an actual Save As dialog that finally lets you navigate through folders. Even then the actual folders are right down at the bottom of the left hand “tree” pane, below a bunch of virtual folders, below OneDrive (aside: if you navigate “up” from here you get to “Desktop”, but it’s not the same “Desktop” that appears lower down in the list; that one is inside your OneDrive), below Music, Videos (you get no hint as to where these actually are), finally near the bottom there is This PC and Network which you can navigate sanely through. Oh, and right at the bottom there is “Microsoft PowerPoint”, as a save location. You can click on it and try to save a document in there, wherever “Microsoft PowerPoint” is. Just kidding, you are stopped by a dialog box telling you this isn’t a valid location.
JFC. No wonder people prefer the “everything is an app icon” approach. Windows is diabolical for managing files.
Saving files in Office has turned into a nightmare.
I don't understand what Microsoft is thinking with this behavior.
I'm fine with that being the default flow. But it can't even be turned off.
I imagine this design is better for non power users.
They no longer forget where they saved their files.
But for power users, this is terrible.
Literally my only option was to use the local account bypass. How long before they fully remove that, though, remains to be seen.
I've gotten burned by that "isn't really downloaded" thing a few times before too, to the point where I don't trust apps to download anymore. I just adb push files from my laptop to my phone before I go. Can't always do that though, but I try to.
Not trying to make this sound like a value judgment, more an observation. But it makes you wonder, what do we lose by excessive abstraction.
Or like complaining people forgot how to use teletypes. We didn't have to keep using teletypes, and we didn't keep using them. Our Linux terminals are still modeled after teletypes, but not in a way that has anything to do with using a real teletype. You don't learn teletypes, you learn terminals (which to a medium extent are like teletypes).
It isn't like when people don't learn to add numbers or how Quicksort works or assembly code. Those are still fundamental truths that help people understand things. It's more like not learning to write Roman numerals, or not learning ALGOL 60. Nothing is really lost except the ability to read old things. You don't learn Roman numerals, you learn western Arabic numerals, and they're better, not worse. You don't learn ALGOL 60, you learn C11, and some people would argue whether it's better, but it's not worse.
Files are currently used to implement apps, but that can be seen as a transitional measure, like an OS that supports both files and raw disk access. A fully app-based OS without files, though not existing currently, would be possible.
Another idea the industry discarded was to make the disk a big SQL database, again without files.
UX prognosticators have been preaching for decades that anything that computer users find confusing should simply be hidden. Not made more clear, or easier to use, but just papered over so users can no longer identify a specific thing to complain about. It’s just like the weirdos who try to get rid of the address bar on web browsers every few years, but the filesystem haters have been a lot more successful, and computers are more confusing as a result. You don’t solve confusion by hiding it behind a thin layer of paint. All the same problems still exist, but there’s no longer a way for experts to even try to help. There are so many better ways to simplify computing than pretending it’s magic.
They figure that the less users know about how their device/software works the more dependent they are on developers who can then act as gatekeepers of what the user can and can't do even when the system is capable of much more. They don't want users doing things differently, or disabling things, or seeing what's going on under the hood. Keeping users ignorant, controlled, and dependent gives them a very secure feeling.
Phones aren't secretly using Roman numerals or tiny embedded abacuses though. If they were for whatever reason, there would be plenty of value in learning those systems.
If you're hard coding paths you're doing it wrong.
A user doesn't want to do this though.
I tried casually using a windows 11 machine for something the other day (I think I was fixing game folders for my girlfriend), using just explorer, and it was pretty obscenely bad how overly confusing it had gotten. I say this, and I fairly routinely debug old build systems with complex nesting file structures, I know my way around a file system.
This wasn't a case of "oh you're just a power user", this was a case of the system had broken, and the simple advice of "backing up your files" and "copy your files over here" wasn't working.
Telling everyone they need to use API calls is just ridiculous, the filesystem is just broken for the average user.
The fact that I needed to log in, wait 24 hours for my account to unlock due to inactivity (!!!), and enable sync in order to disable it was enough for me to finally decide that Windows 10 will be my last Microsoft product. It may be a small annoyance, but to me it was the straw that broke the camel's back.
The process is quite tedious and takes a few hours, but in the end you end up with a personalized version of Windows, without any of the garbage. You still need to be vigilant of Windows Update undoing some of this, but you can also disable it altogether and manually cherry pick the updates you want to install.
It's insane that Microsoft is building such a user hostile OS that forces users to resort to this, but if you absolutely must use it, the experience after doing the above is not so bad. I've been running a custom install of Windows 11 for about a year now without any issues.
[1]: https://www.tomshardware.com/how-to/create-custom-windows-11...
After a certain point anyone paying attention can see it's not accidental. Oops sorry! No. Their goal is your technological enslavement. Mis-features like that don't accidentally just always end up being evil and oops sorry when there is a real backlash. They wanted to see if they could get away with it, like they do.
I abandoned MS products in 1998 for good. Win98se pushed me over the edge.
I have disposed of my last PC now and have nothing to do with the infernal things, or onedrive, or any of that crap ever again!
I like this video of Jonathan Blow ranting about the file explorer: https://www.youtube.com/watch?v=le6dvr95Z2Q
I did later connect my Microsoft account. In my installation the OneDrive folder is empty and the entries in Explorer map to the normal places (C:\Users\X\Pictures etc). If I open one of the default folders, it does show a "Start backup" entry in the address bar that is referring to OneDrive, though. If I open the OneDrive folder, it asks me to sign in (entering password) and set it up-- which is funny, because the Windows user is signed in using a Microsoft account already- so seems like they haven't connected those dots properly yet. In theory this might be their way of implementing a security check for uploading all your files, but if so it's an awkward way to do it.
> Additionally, some programs still seem to want to use the OneDrive folder by default, like I think Office programs still do their best to use them.
If I remember correctly, there is an API that programs can use to locate common folder locations for users (such as Documents, Pictures, etc). My guess is that your account still points to the C:\Users\X\OneDrive\Pictures instead of C:\Users\X\Pictures. If you could adjust those directly (maybe in the registry?), I would imagine that it will work correctly in these programs, especially since I doubt those programs would break on my setup, where there is no OneDrive subfolders (though I don't use Office so I can't check). And in case you wonder if there really are no subfolders in OneDrive since I can't open it in Explorer without signing into it- it shows nothing when viewed via PowerShell.
The former because my desktop is... where I want things just a certain way for THIS computer, not across the cloud. And because it's a PITA to undo and set it the correct way.
The latter because of course I use Remote Desktop on multiple computers, but it keeps saving a "default" file in the same place across computers, and throwing errors left and right because they conflict. So stupid.
And for that matter, make Apple do the same for iCloud; I'd love to keep all my iPhone stuff in my own self hosted "cloud" and get 1st party integration.
For Windows 11: https://www.tomshardware.com/how-to/install-windows-11-witho...
Apple also uses dark patterns to try and get a monthly income from customers. Apple has upsells and nag nag nag advertisements for iCloud.
The irony with Microsoft is that I would consider paying a monthly fee for a modern version of Windows 2000 without extra features. No adverts, no telemetry, no OneDrive, no cloud signin, no store, no games installed as part of the OS, no MS junkware, no bullshit. Aside: why is there no "Windows for developers" - even Balmer knew "developers developers developers" was worthwhile but Microsoft has deleted that from its DNA: even though Apple's competition is a mixed bag.
Meanwhile Recall takes a stream of high-quality images, from which a full reconstruction of your entire computer-use activity over the last 90 days can be reconstructed in high fidelity and searched through.
From a security point of view, the threat models are a world apart.
I think most, if not all, of the overwhelmingly negative feedback is tied to this being enabled by default, and shipped by default
I assume they would push it for the same reason they would push any other mildly-useful feature improvement.
I'm not sure who at the org is pushing for this as it would essentially hand the PC games market to SteamOS. I suppose they saw how well it's worked for enterprise customers that essentially already use a Windows VM through Citrix or some other provider, and think this would solve the virus/malware problem once and for all.
... or they will just stop developing windows games and do only xbox/playstation games ...
PC games can already be played on a remote server, using services like Stadia, so it would not necessarily hand the PC games market to local Linux-based devices running SteamOS (like the Steam Deck).
To be frank, I would not mind having this feature on linux provided it was entirely local, and encrypted.
Here's the thing. When no-one asks for it, hard push is the only way to sell it.
:)
Microsoft was last to the party.
It's easy to say if you aren't one to benefit from this, but that doesn't mean no one will or that no one asked for it.
Most recently I used it to refresh my memory on a particularly convoluted way to authenticate with a third-party oauth system (it involved using an online oauth debugger and curl commands). I had gone through the process once successfully weeks ago, but by the time I had to do it again I'd forgotten every detail. Rather than have to go through the process of figuring it out again, I went back to my successful attempt, watched it, and basically retraced my steps. Rewind probably saved me an hour or two.
My take on Recall is that, like with almost everything, it's a trade-off of security for convenience. I find it valuable enough that I'm willing to make the trade-off, but others might not.
There were definitely some comments in a previous HN post about it that attempted defend it and to paint everyone else as overreacting. Several of them even said that they thought it would be useful for something they might hypothetically like to remember or search for... I don't really remember, because the whole thing is crazy to me and I think it's crazy for any tech-savvy person to be running Windows in 2024.
> Why is MS pushing something so hard when nobody asked for it?
I assume this is a rhetorical question, but just in case it isn't: this is not a feature/product for Windows USERS. This is a feature to help train/test MS's AI stuff- YOU are the product, not the customer.
The natural next step is to have a local model trained on everything I’ve ever done, and for all of my computing tasks to be contextual to that history.
I could see this transforming how we use computers.
But I wouldn’t go anywhere near Recall.
I suspect Microsoft is pushing this so hard because they want to do what I just described, and they want to start collecting the data necessary to enable it ASAP.
I can easily see a future capability that people might love that they wouldn’t have even known to ask for. But the way they’re rolling out Recall is certainly not a good foundation.
But for non-technical people, of course, computers are already unpredictable. They routinely (appear to) misplace files and overwrite them with previous versions, and if the URL falls out of autocomplete the site might as well not exist. For people who google to find the Facebook login page, this would simply be how computers should work. You tell it to give you the thing and it gives you the thing. How that happens is immaterial.
The difference between that and Recall: I decide what goes into the wiki.
Most of those features are garbage and make the product worse, either because they don't address an actual problem or because they are implemented poorly. But of course improving the product is at best a secondary concern, chasing the hype is far more important, both for the company itself and the individuals building this stuff.
Because they bet big on AI, and hardware suppliers bet big on AI-enabled hardware, and so they are trying to find use cases for it.
Yes, the idea is cool. But even if you trust Microsoft it's obviously a privacy and security nightmare. How many people would install a keylogger on their own system? And then make that keylogger trivial to search through? It just makes windows computers extremely valuable targets for hackers and I'll ban them on my networks even if relay isn't enabled.
Edit: I imagine there's going to be fewer keyloggers developed. Microsoft provides one for you, that's officially signed, legitimate, and won't trip antivirus systems. Attackers now just need to make programs that turn on replay. They can then wait. User sees replay running? They blame Microsoft. Legitimate software is so buggy that it's not going to set off alarm bells. That virus just needs to lay dormant for a week or so. And if the user already had replay running, well then the attacker can extract information prior to their infiltration. Stuff that wouldn't normally be logged even if the user had a keylogger.
I disagree. I would feel quite comfortable using functionality like Recall on my personal computer, on which I of course run Linux, if it was opt-in. It's a great idea.
The problem is that it's an idea that's just not compatible with how Microsoft is running the Windows platform, the relationship the company has with its customers, and that it was originally announced as impossible to disable.
Recall as default-on for managed corporate devices is preposterous, for example.
You disagreed but ignored my entire point. No, I don't trust Microsoft, but my point was about even if we did
> I of course run Linux
I use Arch btw
Truth is they will have it off at first then an update will only do the windows folder and slowly creep from there. Another update will “accidentally “ turn it on then more options will be available and more will be defaulted on.
There will not be a single option but multiple toggles at some point.
Also, wasn't their history of closed source drivers and their short support timeline was the reason Android devices only ever got 2 years of updates only a few years back?
They claim they're all in on making Linux work seamlessly on the Snapdragon X. I'll leave it up to you on whether or not to believe them.
Can't we just have a peaceful life without wasting time on constantly following and analyzing every single move from these companies?
I have, and I am still happy to be on Linux as my daily driver for over 20 years now.
At this point MS is a toxic company that you’re better off, as a user, to steer away from.
Not if you're using Microsoft products, no.
People continue to get irritated when "we" do this, but here I go: you should be running Linux exclusively on your personal computers. You should also stop buying "smart" shit.
All I can say is:
Linux does just about everything more efficiently than Windows, but Windows does just about everything better than Linux. What makes Linux so great is also what keeps it perpetually at ~5% adoption.
I'm probably going to go back to Windows again soon. I'm just not interested in needing to learn a bespoke computer language to get the most of of my PC.
I'm not like so many who seem to have to rationalize their choice of Linux or other free software by pretending it's actually technically better than the proprietary for-profit stuff. It's not about that.
Linux could get 10% of the battery life of Windows, have zero games, no Netflix/whatever support, and be slow as hell--I'd still choose it over proprietary options out of principle.
I want to own my computer. I don't want my computer to spy on me. Microsoft is literally adversarial to its users (Apple and Google are, too, but Apple at least has slightly different incentives that might make them less bad). Why would I invite that negativity into my life? Life is hard enough without trying to fight against a trillion dollar company for my privacy when I don't have to. It's that simple for me: I'm not inviting a Trojan horse in. But, people act like I'm some tinfoil hat nutjob. I think everyone else is crazy for sacrificing their privacy for "but Windows has a game I like".
Apologies for the preaching, but I don't know how to explain my point of view without it sounding like that!
No, we can't. Peaceful, content, satisfied, private, conscious makes less rent than disturbed, displeased, unsatisfied, surveilled. So while some people desire the first set, some others desire the second, and so, the cat-and-mouse game continues.
Will be interesting to hear what he has to say when he's inevitably asked to comment in his next public appearance.
Mind bogglingly tone-deaf and out of touch with what users want
That's all.
Just like when we used to have boxed software back in the day. Of course it would be on Windows Store or whatever hogwash they use to push software.
Remember when you had to actually take market risk to publish something and not just "give it for free"? I get times are past that, but if the market is good enough for Cybertruck, surely it's good enough for Recall.
In fact, if I were the CEO I would do this just to allay FTC concerns about big-boi MS and their market power. Like how they made Office for the Mac when Jobs came back and to keep Mac afloat (or like how Google pays Firefox money).
Let the market decide, that's what these capitalists claim to love, right (yes, I know we see through their bluff from both left/right sides of the aisle - that's me calling it there).
If they're that essential for our existence, then go ahead and sell it to consumers.
As the Rabbit (and Humane) before it demonstrated, none of these things are (a) essential, or (b) polished and ready for daily use.
The major difference is that it's a 3rd party software, not bundled with the OS, and you would have to intentionally go out and buy it and install it.
Microsoft has just taken it for granted that everyone would want this and then forced it on everyone.
After their success with installing Teams, Microsoft has seen that the regulators will not proactively stop this kind of thing anymore
Go M$, go faster. I have one more Win11 installation to wipe, probably two Win10 too.
An abusive spouse will easily switch it to on. It's very likely Windows will downright push you to do so anyways.
How does Microsoft intend to mitigate that harm?
Because AirTags worked out just fine:
> AirTags have been a tool for stalkers and domestic abusers since Apple launched them in 2021. Police records show that this is a problem, and the legal system has failed women who were targeted by stalkers using AirTags. There have been several instances where AirTag stalking has turned violent, and in at least two cases, resulted in the tracker murdering their target.
https://www.404media.co/email/ce4cec4d-51c3-4101-b2b4-2c9a64...
How many women will beaten and murdered because of Recall? Why is it that Microsoft reacts to software security concerns but not to the concerns of women?
Techbros never admit their myopic view.
Similarly with airtags, you have been able to buy cheaper cellular based GPS trackers for years prior to airtags existing.
In the airtag case, those GPS tags also do not alert the individual that there is a beacon following their person, and as such most likely go unnoticed and under reported.
Strange that you were able to discover this. Has anyone asked you for your research? Does knowing how to grab a freeware keylogger imply that you know how to code up a keylogger for yourself, or did your study not go that far?
It is much the same with airtag.
Instead you should hurt their business. Ditch Windows, switch to open source solutions, do not but their product and services. This is the only language they understand.
The irony here is thick enough to cut with a knife.
But good on Microsoft for changing their minds and deciding to make this opt-in. That's progress for sure.
It can't really do anything.
Can someone smarter than I chime in on this?
It's not really about looking back at your own activity in case you forgot. But the AI will use it to learn about your habits, wants and hates, interests, people you deal with, usual schedule etc.
An assistant is after all much more effective if it knows you through and through. The one problem is: I don't want Microsoft to be that assistant and know all that about me. Even if "it's all local". They still control what gets done with that info and can change it at any time.
Some games require a little fiddling, sure, but I've never had an issue that couldn't be resolved using some copy-pasting from ProtonDB. As you may have surmised from the way I set up my machines, I may have a higher tolerance for fiddling than most folks. YMMV.
I have always assumed that distros layer on so many extensions, customizations, etc that Gnome or KDE would be alien if naively installed.
Fully de-GNOME'ing desktop Ubuntu is Sisyphean. It's easier to build up Ubuntu Server from a plain terminal.
> Any especially thorny bits?
Nvidia drivers. Just check that all apt packages with the word "nvidia" in them have the same version number. Otherwise Xorg and/or torch will go boom.
> Gnome or KDE
I'm using neither! I have no login manager. I type my username and password into a login shell, run "startx" and that starts i3.
And yes, it is somewhat alien. GTK and Qt based applications will have no theme, so they all default to that black-on-gray circa Windows 95 look.
> Do you see improved performance or fewer background processes?
Yes and yes. With i3wm loaded, my desktop idles at about 100MB of RAM used. My desktop compares favorably to similarly-specced entries on openbenchmarking, especially in IPC-related tests.
I note that my Ubuntu derived system idles at multiple gigs of ram
But now I'm moving all my computers, including work computers, to Linux. Will miss out on some hardware/software I use for music production (biggest loss will be TotalMix FX for my RME audio interface), but MSFT leadership has shown they don't get it.
Also, Fusion360 for Linux when?
So now I need MS permission to read my own data stored on my own machine? Insane.
Maybe they should have done some research to determine if this "feature" actually had significant marketplace appeal.
Just insane that this wasn’t already the rule.
(I’m being a bit provocative and assume today it stores locally only but a future TOS change will secretly and “anonymously” upload your data ‘for training purposes’ —- that’s what everyone else is doing these days)
Throw in the towel, it has been besmirched to the point of no return.
if so, i would not keep it on a system drive, when you can store it externally, to be plugged in when the owner feels they actually need recall data, and left physically out of band when its wise to do so
Will you be warned when sending information to someone who has Recall on?
Kinda defeats the purpose of all those confidential communication apps when everything is automatically screenshotted.
theres a lot of people who have a lot of data they wont want to put into this and run other people's closed source code and you dont really know what its doing.
is there an open source linux friendly equivalent?
One more reason to resist their extend embrace extinguish strategy and not use their tools (vs code etc), this won’t end well and Microsoft will always be Microsoft.
Should be security concerns
we'll find a way to turn it on, and share it with our corporate partners
Let's not pretend several decades of unscrupulous behavior is going to change now. Unless regulatory structures get implemented to brutally, exactingly, unflinchingly and relentlessly punish firms, they won't stop trying.
Punitively maul them into submission.
I'd give a setup option to provide a non-OneDrive Documents folder, that feature would be turned on automatically if OneDrive senses that there is a database residing in the Documents folder (ACT!, I'm looking at you!)
That was the last straw for me when it comes to Windows BS---designs that only serve Microsoft, and disrespects all the other times I've said no to their crap. I switched everything over to Linux the next day.
> on by default in Windows 11 25H1, impossible to disable in Windows 11 25H2
If Recall continues to inspire grumbling and receives very little praise, I could see it unceremoniously removed in a Windows 12 26H2 Feature Update.
I'm aware that other OSes exist, but I happen to hate Windows least on the whole :/
Have you given Linux a try? Unless you have an Nvidia card or an Adobe workflow; it is usually good. The Nvidia issue may go away in a year.
Have they? What GPU? Are you using the new open source kernel driver? Wayland or X?
I'm an OpenCL guy, not even using CUDA, and have had a decent enough experience with AMD's drivers, but that wasn't enough. I still think MSVC, again with all its flaws, is the best C++ IDE (I've similarly tried them all, repeatedly over decades).
Please do not use Slackware. With respect to Slackware, almost no one uses it because it is very old school. If I remember correctly you have to use a 3rd party tool to even download updates or packages. It took years for the maintainer to actually have a release. Please use a modern developer distro that has a regular release cycle and modern tools. Fedora or Ubuntu. If you need to use Nvidia, go with Ubuntu.
Also when did you use it? Linux distros haven't used floppy disks in so long.
> I'm an OpenCL guy, not even using CUDA, and have had a decent enough experience with AMD's drivers
That is not my field, but Fedora added the ROCm packages in 40. You can install those and give it a try.
> I still think MSVC, again with all its flaws, is the best C++ IDE (I've similarly tried them all, repeatedly over decades).
I still remember during my time in college (where they required us to use Visual C++) a friend and I were playing with the latest C++ features. We had this very difficult runtime bug. I later found notes in the news that Microsoft's implementation of C++ at the time was incomplete. Tried it in GCC-worked out of the box.
If you still hate Windows least, that's almost certainly because it's what you know best. I work with Windows, Linux, and OSX on a daily basis and Windows is easily the most user-hostile of the three.
Edit: All you know -> What you know best
It's true that I'm most familiar with Windows; given free choice, why would someone use an OS they dislike more? I personally think Mac OS is more user-hostile (it's a whole lifestyle and worldview they really want to sell you!) but it's comparable.
What I actually want isn't Linux or Mac OS, but a Windows-like OS that isn't so goddamn user hostile and doing stupid shit like always-listening Cortana or this Recall feature or whatever they feel trumps what the user actually wants. If there were a "Windows but actually a user-first product and not a data collection vehicle" I bet it would utterly crush in the marketplace (inasmuch as there is a viable market for OSes).
Would you like to share what you like about windows that you don't have on other operating systems, or what puts you off about other OSes? Not trying to be passive aggressive, just curious
Around the time of Windows 7 for example, to me there was just no contest whatsoever in terms of ease of use, no shaming / cargo culting (Apple can piss right off telling me that my scroll direction is "unnatural" and pushing me to use Apple-everything, users putting stickers on their cars etc), ... Windows is just the default for people coming from a gamedev and graphics background from the 90s, for better or worse. I'm painfully aware of its shortcomings, and I don't want to champion Windows, it's just what made me hate my life least on average :)
Softwar never changes.
Windows is soo low quality. It feels cheap. It feels like you are at a car dealership.
Fedora, feels like you are at some futuristic office that has buttons that do multiple steps. I was literally angry last year that it took me so long to learn about up-to-date linux. Canonical's marketing of debian-family linux gave Desktop Linux a bad name.
I've been dual booting for a while and last weekend I went full Linux at home. My day job revolves around being truly good at solving Windows issues, and I will happily continue doing that, but at home I'm still just liking for something that "just works" I hope I'm part of a trend, and that 2024 is the year of the....
You can install Steam on whatever distribution you want, I use the Flatpak, and just enable Proton in the compatibility settings.
I got set on SteamOS as i was contemplating buying an SBC with similar hardware and giving it a custom case.
But this looks better!
I'm considering Linux with a Windows VM for Visual Studio. I've had my Linux detours in the past and it honestly works pretty well for me. I personally enjoy Fedora with Gnome which I think strikes a good balance between stability, security, and freshness. But if being stable and worryfree is of top importance (like where you are "unpaid tech support", haha), why not just go Debian. :)
He ended up switching to Apple around 15 years ago after a series of bad experiences. He was very nervous about it, and really hedged his bets early on. It took him some time to get used to how the OS worked, to find new apps to replace some that he had used since the Windows 3.1 days, and sort out his workflows. He eventually gave up his Windows VM when he realized the only thing he ever used it for was to run Windows Update.
I grew up on Windows, with the views from my dad instilled in me. In college I tried Linux and ultimately moved to the Mac about 21 years ago. I still used Linux on and off for the past 22 years (and currently have a music server running it). I do find Linux to still be much more finicky than macOS. No system is perfect, but macOS is more of a "just works" operating system than Linux (imo), likely due to the focus on polishing that last 10% of the user experience, that never seems to get the attention it needs in Linux. While I am excited to see what Cosmic has to offer later this year on Pop OS, I'm always ending up having to deal with some level of nonsense, even my most recent install of Mint just last week had a few annoying things where things didn't work, and they should have worked.
Alternative cynical take: they needed to have a compelling story for press/launching the laptops they've been working with software/hardware partners on for years. They got to announce "Copilot+ PCs with Total^H^H^H^H^H Recall"! And now they get to walk it back enough controversy will die down and they can still do the first bit I mentioned. Hm.
But this is a pretty cut and dry announcement. There isn’t any ambiguity they could stand behind if they are lying.
I would fully expect it will be disabled by default (for now)
It will prompt you (and select by default) to disable the need for an online account. I installed the Pro version and then just said I was setting it up for work or school, chose domain and then I set it up just fine as a local account.
I don't know for sure how much of this is rufas or the pro version. But I just installed Windows 11 within the last hour.
> use Rufus to create your installation usb
Pick one. "Normal" users don't use specialized software to create installation media. They boot the laptop with the OS already installed and go on from there.
It is also not uncommon for 'normal' gamers to use a custom built PC which would require installing Windows.
Maybe normal is the wrong word, but it would be a pretty quick and easy to understand guide to do this.
You've already scared away all the normal users
"microsoft office features y and j require Recall! please click here to enable it"
etc etc
Maybe it shouldn’t be on by default, but this looks amazing.
>My workplace
It wont affect me personally, because I dont use crappy operating systems on my personal time. Microsoft products are just an efficiency loss, I still bill the same.
I literally get everything done faster on Fedora, no linux prayer needed anymore. Its just better.
Of course the security of the implementation is important and I agree with some of the criticism there. But I see a lot of people arguing that the feature is worthless, or that it doesn't make sense at the OS level, or that Microsoft specifically should not be allowed to add it to Windows, and I have to strongly disagree.
Microsoft, Google, Apple - everyone is scared shitless of some AI startup kicking their nutsacks, and is launching products that should have gone through extensive ethics discussions beforehand in a matter of weeks.
[1] https://www.npr.org/2022/07/11/1110391316/google-data-aborti...
I have been a windows user basically my whole life. 3 years ago I got an ipad pro (2018, 12.9") for drawing and I hate the operating system. 7 months ago I got a steam deck and its fine for games but doing anything in the OS is confusing and annoying.
Microsoft announced recall and suddenly I'm using a spare computer to test linux distros, and I suck at everything to do with linux and I'm doing it anyways.
It's too dangerous, to much an invasion of privacy, and too easily enabled completely outside of my control.
No one is really saying this feature has no value. For a user, there is value to being able to get to a previous point in time. That feature, however, is clearly not very well designed and implemented if it took days for it to be cracked on the internet for everyone to see. If I could trust that it STAYS local, maybe I would be less paranoid. But this is MS we are talking about.
Personally, I am glad this thing was created. It may be finally make people hesitate over the evolution of PCs.
I really don't understand this line of thinking. What was cracked? That the database is readable, unencrypted? How could it be encrypted and usable at the same time?
> If I could trust that it STAYS local
This I agree with. While it's local now, not trusting MS is a valid belief, given their past behavior. If they feel sending some of the info to the cloud could get them $$$, then they will do it. Although I feel regulators might be pretty quick on this one...
I am admittedly mildly confused by this response. Do online portals typically use unencrypted passwords? Do they let data flow unecrypted? Are those portals somehow unusable?
Could you elaborate a little bit? It is possible I am misunderstanding your point.
There is plenty to criticize about Microsoft, but that one seems manufactured.
As far as I know, the database is local, and Recall does not use the cloud at all. That also means that you can't view the history from one computer on another. But I agree that trust that it will stay that way is not particularly wise.
I think you have a point there. Would you accept reverse engineering[1] as a more accurate term instead of cracking?
<< I have only been somewhat paying attention
We are in the same boat. I saw the thing pop in my feeds in the past weeks. I skimmed it, thought it was a bad idea, but since I don't have a PC that would be affected, mostly ignored it. I think I only pay more attention today, because it is the weekend and somehow my testing is not ready for me..
[1]https://en.wikipedia.org/wiki/Reverse_engineering [2]https://www.wired.com/story/microsoft-windows-recall-privile...
Either way, I'm holding off on buying one of these PCs until some real-world info comes out (no one really has this capability yet, so it's all largely speculative).
1) Recall takes snapshots of user’s activity and then copilot analyses it and keep the info in a plain text database.
2) The database is accessible to other accounts in the same computer.
3) The database is kept very small in order to save storage space. The trouble is that it is so small that it takes no time at all to upload it. One researcher infected his machine with a know piece of malware. By the time the AV software recognized it the database had already been sent.
4) Oncenthe database is in hand it is trivial to see whatever the person was working on and what information was involved. Apparently you can literally see some things.
So yeah, collecting large amounts of sensitive data makes for a very juicy target.
Oh yeah?
> I have a really hard time understanding the use case for something like this. Stuff that I want to remember I just write down https://news.ycombinator.com/item?id=40612277
> the only people that really want this feature are the ones trying to push it down everyones collective throat. Why is MS pushing something so hard when nobody asked for it? https://news.ycombinator.com/item?id=40611263
> It really doesn't [sound like a cool feature]. Not a single person I've spoken to likes the idea of this, at all https://news.ycombinator.com/item?id=40445335
> i have never wanted to go back in history [...] what’s the use case https://news.ycombinator.com/item?id=40544521
etc.
The issue is not that the concept has no value. The issue is that the risks and drawbacks are so severe, that they override any value the concept would have.
It's like asbestos, or leaded fuel; these have several useful properties, but their drawbacks are bad enough that they have been banned in many places.
> I have a really hard time understanding the use case for something like this. Stuff that I want to remember I just write down https://news.ycombinator.com/item?id=40612277
> the only people that really want this feature are the ones trying to push it down everyones collective throat. Why is MS pushing something so hard when nobody asked for it? https://news.ycombinator.com/item?id=40611263
> It really doesn't [sound like a cool feature]. Not a single person I've spoken to likes the idea of this, at all https://news.ycombinator.com/item?id=40445335
> i have never wanted to go back in history [...] what’s the use case https://news.ycombinator.com/item?id=40544521
etc.