Most people use them, some heavy privacy/security oriented people don't. Even many of those of us who are conscious about the security/privacy issues, use them because we find their use outweighs the risk.
I can't answer what will happen with a recall type feature, but one has to weigh the value vs risk.
Personally, I'm not sure of the significant value (then again, in being really analytical, I'm now unsure of the significant value of the browser history). How often is one going to dig into recall recorded state.
This same logic applies to browser history, how often does on really look at it? It provides 2 forms of value, 1) showing what you already clicked (i.e. a constant low level value) and 2) being able to find URLs you know you saw, but can't seem to find at the moment (a higher value, but much rarer, similar to recall value). Are these valuable enough?
I'm wondering out loud if the first value (of showing links you already visited) could be solved in a more privacy friendly manner of a 1 way hash of url with salt. Store the hashed URLs instead of a the URL string itself. Even if an attacker vacuums up your "history database", all they get is a bunch of hashes. Even if they get the salt, they would have to hash their entire dictionary of URLs against the salt. (A counter argument is that the set of URLs in the dictionary they would want to hash against to blackmail you, might not be "so big" and hence tractable, so this doesn't gain you much).
ex: they exploit the browser to get to your userspace, which while they can access / modify your files, they can't elevate it to root to make the exploit more persistent. Therefore, they just vacuum up what they can at that moment (not even analyzing it, that's for later, this is just the collection phase) and move onto someone else.
But yes, I agree with you, if one's more concerned about the possibility of offline attacks, there are other ways to mitigate it / you have bigger problems if those mitigations fail.
Does that mean we should not care about our data, and expose every bit and piece to the system? Should we max out data exposure, or still fight against it?
1) I said that users care about the benfits provided to them more than the security/privacy they give up and can see that from practical history.
2) I questioned the value of recall and asked is what one gives up worth that value
3) I compared to browser history and even provided a mechanism to get some of the value without giving up privacy.
Right?
Are all of those things you said, and do, readily available in one easy to siphon up database? Easily searchable and reportable to nation state entities? Can I or LEOs read your Hacker News posts and comments, and easily determine exactly who you are and that your previously open tabs where porn and anarchy related websites?
No. RECALL is a damn privacy and security nightmare. Don't act like it's saving the world, it's intent is to close the walls in around you.
Not directly but in combination to other information it could.
The fact is, these kind of recording tools are not meant to publish your information to everyone.
> Don't act like it's saving the world,
I am not acting like that. I have no plan to use RECALL (I don't even use a single windows computer) nor any similar software.
However I find it funny that in any news about RECALL you see so many "privacy nightmare, will someone think of the children" comments while similar open source or proprietary projects for MacOs and Linux, or browser extensions predating RECALL were unanimously praised for their usefulness.
As any tool, you have to balance the risk of a leak in case your systems (or those that host your data) are compromised but it isn't in any way different than any other data you have online or locally on your computer.
You have as much if not much more to lose if your primary email account is compromised and you kept received email in the mailbox.
its an attempt by microsoft to flex about their new "AI PC" which just means it comes with this npu that is optimized for the processing workloads associated with various ai usecases. an attempt to profit on the AI hype by pitching their users reason to buy a new computer.
Nobody is using the AI components on these devices yet, but I've heard plenty of stories from developers with MacBooks about how nice it is to have NPU acceleration for whatever models they're running. I've got Jetbrains' offline AI code suggestions enabled and I imagine widespread availability of NPUs would save a lot of random CPU usage spikes for that kind of workload.
General consumers probably don't get much out of AI (the models if any value are too big to run on these small client machines) but I can't say I'd hate a world where NPUs are cheap and abundant.