But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
I get your point, but Microsoft's Recall can capture anything onscreen - emails, personal info, porn, passwords and the like. And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
I think the thought is proportional to the amount of thought a non-tech customer will put into it. Nobody seems to care about or understands privacy these days. Everyone knows they're being tracked everywhere they go physically and on the web. People use their real names, address, etc for every junk service they sign up for, without seeing any reason not to. If you tell people that their TV is tracking and taking screenshots of what they watch [1], they say "yeah, Netflix knows too".
It's literally, "how it's always been" for any non tech person under 30.
[1] https://themarkup.org/privacy/2023/12/12/your-smart-tv-knows...
Part of me wonders if this is the consequence of how accessible tech has become, and the prevalence of increasingly non-technical product managers. I'm a former PM, and I'm not here to denigrate the PM role, but the fact that a product like Recall got shipped says a lot about the makeup of the product org that shipped it.
While I get that younger people tend to see privacy differently, I'd argue this isn't really a privacy issue, it's a security conversation, albeit with obvious privacy implications. Leaking what apps I use or what sites I visit is mostly a privacy issue. Leaking what I type into the boxes on those sites is a security issue. If the end result of leaking this info is the attacker can pwn all of my bank accounts, we're solidly into security territory.
The fact that this got shipped means that multiple levels of leadership either didn't think about the consequences or didn't care about the consequences. I hope it's the former, because that means they can learn from the backlash and hopefully recalibrate.
Microsoft is in a position of power that IMO requires a significant duty of care and responsibility to their customers, and lapses like this need to be judged through that lens, i.e. it is their entire business to make sure features like this are safe.
Microsoft is just tripping over themselves right now bringing AI to market because they don't want to miss the boat. Their copilot for office 365 stuff is hardly working, it's real beta quality. No normal company would have released it to market in this state. But they're just terrified that Google will eat their lunch.
I don't think security and privacy concerns are much on the radar there anymore. They just want to establish their name in this new market at all costs. And I think in their eyes it makes sense, they've always succeeded because they had the biggest installed base, not because they were the best. It makes sense they see value in being first mover at all costs.
It's just a bit frustrating as a customer. As usual with something they launch it's more promise than substance. I have to say that usually they do have the follow-through to really make it a success. But it does take time.
There was probably from lower decks, where they are closer to reality. However, people are scared for their jobs in this economy and likely didn’t take it farther.
Emphasis on "part." I'm totally guessing on this, but I think OP may have been talking about PMs where the MBA is their only notable feature rather than those where the MBA is just one part of a well balanced whole.
> You can teach a tech person to understand business, vision, strategy, finance, etc. You cannot teach very well the business person who has all that the intricacies of technology.
I'm inclined to agree with this. The thing about business degrees is that they are so minimal effort that actually understanding business isn't a prerequisite to being awarded one. I would know, I have 2 of them.
There's no guarantee a "business person" actually learned business, much less that they are capable of learning tech. Don't get me wrong, I'm not by any means implying that all business people are inept or that they are collectively unable to learn tech; it's often unrealistic, but not impossible.
When going to school for tech, such as an MS in engineering, CS, etc., typically requires enough effort that one will end up learning their respective field (I have met exceptions to this and interacting with them is infuriating) whereas going to school for an MBA is one of the easiest ways I know of to get government financing for a decade of partying.
Well this wasn't in the brochure. Best look into it!
Many here may be too young to remember when many consumer products came with a "product registration" card. This was basically a postcard that asked for all sorts of information, such as your name, address, phone number, birthdate, sex, SSN, marital status, annual income, interests, other products owned, whether you own or rent your home, etc.
People willingly filled these out and sent them in. All the info went into databases that were merged with other sources and traded around various marketing agencies on 9-track tape reels. Advertisers could get mailing lists segmented by age, sex, income level, geographical region or specific zip codes, etc. for their campaigns.
It's all much more pervasive and invisible now, but it's basically what has always been done.
Basically is doing a lot of work here, the level and degree of how much data is vacuumed, processed, and used for targeting nowadays is orders of magnitude of difference from these primitive ways.
A tent and a house are basically the same: a shelter.
I don't know, I don't think sending in product registration cards could/would often result in your bank account being drained...
> It's all much more pervasive and invisible now, but it's basically what has always been done.
So you admit it is far worse today than it was before? But the second half of your sentence seeks to disingenuously pretend that it has "always" been bad.
I can be sick with a cold or I can have stage-four brain cancer. People have "always" been sick but one is serious (terminal cancer) one is not (a non persistent cold).
Privacy is not a binary concept. There are actions and information that some people are ok being public, and there are some they prefer to remain private.
What is not OK is spying and exploitation. I should know what data you’re collecting and preferably specify which I’m ok with. I also should know what is intended for and preferably for most of it to be anonymized.
Most people expect reasonable privacy policies from companies and they believe that there’s some regulation in place.
Absolutely, but if you ask/inform these people they will say "Well, guess I have nothing to hide." because they can't comprehend going without all their devices/services.
That sounds good to some people. But if I mentioned it to most people in my family they would probably be rather weirded out by it. They probably also would have no idea of the scope of the size of it and how it is being used against them.
No, no. They thought about the privacy and security aspect. They decided that it's better for their bottom line if Windows users don't have privacy from the mother ship. Really, they already decided that way back when Windows Vista first came out and periodically asked Microsoft HQ if you should continue being allowed to use your computer.
Theyre just boiling the frog slowly. It'll be turned on by default soon enough and then theyll start looking for excuses to upload it.
This can be used to make them a shedload of money one day.
I was just remembering today what they did to the security/encryption as soon as they bought over Skype… they removed it. And who would that benefit - the spies.
No-one cared about that. No-one ever cares. Except for this rare occasion - tides are turning and people are starting to care a tad more.
I don’t have any friends that care about their own security and privacy. Wanna be my friend? Lol
In the case of the phone, one simply sees recipient of call, duration etc, regardless of how much information was exchanged. The phone I'm calling is arguably analogous to the server I request a page from, in the metadata context.
I'd argue browser history is significantly richer in some regards due to this. It's not unheard of for user identifiers to appear in URL paths either - try visiting https://news.ycombinator.com/user?id=<HN user name>... In my Chrome, that's instantly in the history file with my username.
I don’t know anything about this system, but the fact that screen shots are not ultimately stored on the user’s PC doesn’t mean anything if the content has already been classified and indexed. It will be fished.
Of all the places on your computer that might contain porn images, that would be one of the very top candidates.
(I really wish they followed the “standard” keyboard shortcut)
Unless, of course, you're willing to argue that a porn image stored on the local hard drive isn't contained in any folders on the same PC that soft-link it. You might have an interesting time trying to justify why it is contained in folders that hard-link it.
Sure, info about non-top-level links is extractable from e.g. request caches, but that's a different thing from the browser history SQLite DB.
Here is the URL of an image as it appears in your browser history: https://cheezburger.com/10357071872/if-i-fits-i-sits
See if you can figure out what image I was looking at.
Calling it the URL of an image seems to me like quite a bit of confusion about how web pages work.
On a more relevant note, how can it know when a private browser window is open in anything other than Edge? Same question with the password manager - is there going to be some new API that apps have to "opt in" to to enable Windows to recognise them?
2. Browsing history watches one app. Screenshots watch everything across the entire OS.
People might use Incognito mode to browse porn, but I imagine it's a lot less common when looking at other sensitive sites.
Or from history you may see that you accessed a site, but not what you did on it (what comments you typed for example).
Does your browser history store pictures of your family?
The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other.
Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.
It's not on the individual users to take steps to preserve their basic human dignity. It's not Microsoft to not take that dignity away by default as was their plan before this fiasco predictably blew up in their faces just like the Xbox One always-online Kinect requirement before it.
Whereas to avoid browsing history, one only has to avoid the popular, graphical, advertising corporation browser. As I am not interesting in graphics, I do this everyday, with ease, because there are countless clients besides "Chrome/Safari/Edge" that work with the www for consuming information.
Recall seems to be storing its info locally in an unencrypted SQLite database as well.
At least, that's according to the instructions here on how to access and view the contents:
https://www.heise.de/en/news/First-experiences-with-Recall-9...
From the submitted article, it seems like Microsoft will change/secure the access (and maybe storage) in some way, though there's no details on the specifics.
There's also always private browsing, which exists specifically because people are aware of the implications of a browsing history and a persistent cookie jar.
That awareness will be much harder to build for an always-on screen recorder.
I want to be able to find things I've seen before. Recall would've been great if using it didn't require me to update to a version of Windows that contains "Copilot".
At the time, it wasn't very thinkable that someone would have the audacity to take and abuse that information.
It dates from when Internet people overall were more savvy about privacy than users overall today are, but it was also when the Internet was closer to a trustworthy environment, and before Wall Street sociopath types took over the tech and the culture.
Lots of kinds of abuse that today are routine and almost universal, for even startup tech companies, (e.g., embedding third-party trackers into Web site, and getting even worse from there), I think would've gotten them ostracized, and outraged demands for criminal charges.
During the dotcom gold rush, there was such a flood of totally new, posturing people, and so much money being thrown wildly at everything, that any remaining outrage was lost in the noise.
And now virtually no one knows any different.
But if you're trying to push some new abuse today, I think ordinary people are starting to have some awareness of what vicious sociopathic buttholes tech companies have become, and so acceptance might not be a slam-dunk.
On the other hand, I am always freaked out by Chrome extensions that "can read and change your data on all websites". Can't they have more granular permissions? You gotta have a lot of trust for those extensions LMAO. They can read your bank passwords, probably!! And if they are ever sold...
It's "little brother" that benefits a lot here: bosses, spouses, parents, etc., who otherwise wouldn't click on 1000 links in your history.
I trust gorhill and the EFF to not fuck me over on my data, and Tampermonkey kinda needs those sorts of permissions to work. My password manager has read access to every website but I'm already trusting it with all of my passwords so...
These extensions should not store any data without a master password that you input every time.
What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate.
If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has.
>If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
My threat model doesn't include state actors targeting me specifically. Not sure much of anything works against that threat model besides maybe iOS in Lockdown Mode as your only device.
I have seen Metamask update itself randomly, and it has access to read every website
Most of us know that the public Internet is based on surveillance capitalism, no matter if we hate it or are just complacent or ignorant.
OS wide is far more problematic and of low value to the user.
I think it's the right move to have it off by default, but I'm just not convinced by the outrage here.
In comparison browser history is nothing.
Perhaps you didn't note before, or are one yourself, but this includes e.g. abusive spouses. Sure, maybe the abusive spouse could hire a black hat, but this is very different to a drunk low-life wife-beater casually snooping through "recall".
It might not be a "new" attack vector, but its absolutely a complete degradation to any computer security.
The horse is out of the barn for many people during work hours. But in the OS and on by default is a different story!
No one retweets "Attacker gaining root access reveals all user information", but instead "Attacker gaining root access reveals all user information collected by AI program" will go viral for sure.