They send any text you type in a form to their AI cloud and hold on to it for 30 days.
Any form.
On any website.
What the actual fuck?
If there are a bunch of these corrections you know something is wrong there. IMO 30 days is quite modest and if this is properly anonymized..
Edit: dear HN user who decided to silently downvote - you could do better by actually voicing your opinion
Sure, I'll bite. Let's address the obvious issue first: what you're saying is speculation. I can only provide my own speculation in return, and then you might or might not find it agreeable, or at least claim either way. And there will be nothing I can do about it. I generally don't find this valuable or productive, and I did disagree with yours, hence my silent downvote.
But since you're explicitly asking for other people's speculation, here I go. Advanced "spellchecking" necessitates the usage of AI, as natural languages cannot ever be fully processed using just hard coded logic. This is not an opinion, you learn this when taking formal languages class at university. It arises from formal logic only being able to wrangle formal logic abiding things, which natural languages aren't (else they'd be called formal languages).
What the opinion is, and the speculation is, is that this is what the feature kicks off when it sends over input data to MS's servers for advanced "spellchecking", much like what I speculate Grammarly does too. Either that, or these services have some proprietary language engine that they'd rather keep on their own premises, because why put your moat out there if you don't strictly have to.
Technologically speaking, at this point it might be possible to do this locally, on-device now. This further didn't use to be the case I believe (although I do not have sources on this), and so this would be another reason why you'd send people's inputs to the shadow realm.
Better to say what you need to say. Leave the defense for the occasion someone misunderstood what you meant to say.
I can't count the number of times on HN that I've seen responses to posts that took advantage of the poster not writing defensively to emotionally attack them in ways that absolutely break the HN guidelines, and weren't flagged or downvoted. And on other sites, like Reddit, it's just the norm.
The defensive writing will continue until morals improve.
Logs are always generated, and logs include some amount of data about the user, if only environmental.
It's quite plausible that the spellchecker does not store your actual user data, but information about the request, or error logging includes more UGC than intended.
Note: I don't have any insider knowledge about their spellcheck API, but I've worked on similar systems which have similar language for little more than basic request logging.
They had searching on the web enabled... Pretty hard to search the web using Bing without sending along a search term.
The purpose of a system is what it does, after all
But the criterion of "having access to user input" is also necessary for goofy unneeded features like showing web search results in the Start Menu though, which they shove down people's throat like they do with every other feature their product team thinks is a great idea (explaining the "being covert" bit), at which point you have a complete, non-malicious explanation for the entire thing.
The reasonable thing to do then is to apply Hanlon's razor, at which point no, it's no longer reasonable to believe or portray it to be a keylogger anymore. Not essentially, not otherwise. Not only that, but the YouTuber in question made this portrayal knowing full well that it's impossible for them to actually properly demonstrate this feature doubling as a keylogger, as they have no access to the server side. They relied on people being gullible enough to simply not grasp this, and leveraged people's preexisting privacy concerns to farm views.
Having the capability to engage in crime doesn't make a criminal. Imagine if I portrayed 107M (!) of the 340M residents of the U.S. as a criminal because they own a gun, despite knowing full well that gun ownership sensibilities are just fundamentally different over there.
It's like making up a bunch of rubbish when there's a hate train going on against something or somebody just to participate. Then having all of that backfire disproportionately when the tides turn. Why make things up when reality has plenty bad enough stuff going on already that one can report on? Rhetorical question of course.
Why are we assuming good intentions from a company who for years has increased places and amounts of data it collects and tracks, and removed more and more ways to opt-out of this?
The intention of "search web first before searching local computer even if the user never asked for it" didn't appear from the intent of "let's create a keylogger", but it never came from a good innocent intention either.
I'm talking about the FOSS community.
Users of especially the home version of the OS are kind of fucked here.
Note that this is from 2023. Their legal docs, last updated in 2024, claim a bit different: https://learn.microsoft.com/en-us/legal/microsoft-edge/priva...
> By default, Microsoft Edge provides spelling and grammar checking using Microsoft Editor. When using Microsoft Editor, Microsoft Edge sends your typed text and a service token to a Microsoft cloud service over a secure HTTPS connection. The service token doesn't contain any user-identifiable information. A Microsoft cloud service then processes the text to detect spelling and grammar errors in your text. All your typed text that's sent to Microsoft is deleted immediately after processing occurs. No data is stored for any period of time.
Does anyone know if that is true?
Some people checked it with wireshark at the time and didn’t find anything other than what was stated. [0]
0: https://gamersnexus.net/industry/2672-geforce-experience-dat...
Microsoft ordered me to buy a new computer for Win 11, so I took said kids to Microcenter, asked for a machine whose specs could play a particular steam game on Linux, returned to my mortgage, installed Ubuntu and haven't given Windows a second thought in months.
https://www.omgubuntu.co.uk/2016/01/ubuntu-online-search-fea...
and importantly it seems that Canonical/Ubuntu is not doing something like that right now, whereas MSFT is all in on online only mode.
By default, when you implement a form that takes a password, you (the developer) are going to be using the "input" HTML element with the type "password". This element is exempt from spellchecking, so no issues there.
However, many websites also implement a temporary password reveal feature. To achieve this, one would typically change the type of the "input" element to "text" when clicking the reveal button, thereby unintentionally allowing spellchecking.
You (the developer) can explicitly mark an element to be ineligible for spellchecking by setting the "spellchecking" attribute to "false", remediating this quirk: https://developer.mozilla.org/en-US/docs/Web/HTML/Reference/...
You (the developer) can of course also just use a different approach for implementing a password reveal feature.
As the MDN docs remark, this infoleak vector is known as "spelljacking".
- Don't show ads (saves power)
- Don't call home (saves power)If, as tested, this setting makes a double-digit percentage difference, I'm glad Microsoft exposes it in the UI. I'd also be glad if they didn't do as much weird stuff on their user's devices as they do.
I'd rather them write more performant code. This feels like your car having the option to burn motor oil to show a more precise clock on the dash; you don't get kudos for adding an off-switch for that.
In keeping with the theme of the comment you're replying to, writing better-performing code and providing performance options are not mutually exclusive. Both are good ideas.
> This feels like your car having the option to burn motor oil to show a more precise clock on the dash; you don't get kudos for adding an off-switch for that.
(Sounds more like you're arguing that it should be forced off instead of being an option? Reasonable take in this case, but not the same argument.)
I think we all agree there needs to be some additional power draw for the seconds feature, but it’s unclear how much power is truly necessary vs this just being a poor implementation.
There's an ungodly amount of CPU and GPU spikes throughout the OS which make the "omg seconds" invisible in comparison
Energy isn’t free.
Even if they wrote more performant code, it would just mean less relative loss of energy to show seconds but still loss compared to not showing seconds.
I actively don't want to see seconds; the constant updating is distracting. It should be an option even if there were no energy impact. (Ditto for terminal cursor blinking).
My expectations of Microsoft software aren't terribly high. I'd say Windows is performant (ie it works about as well as I expect).
The feature is off by default in Windows 11 and was not offered in any previous non-beta Windows version.
(Have I mentioned how much I loathe Windows 11?)
The recommendations suggest, among other things, switching to power-saving mode, turning on dark mode, setting screen brightness for energy efficiency, and auto-suspending and turning the screen off after 3 minutes.
Power-saving mode saves little at least on most laptops but has a significant performance impact, dark mode only saves power on LED displays (LCDs have a slight inverse effect), and both dark/light mode and screen brightness should be set based on ergonomics, not based on saving three watts.
When these kinds of recommendations are given to the consumer for "lowering your carbon footprint", with a green leaf symbol for impact, while Microsoft's data centres keep spending enormous amounts of power on data analysis, I find it hard to see that as anything more than greenwashing.
Also airlines asking for extra money to offset emissions, just absolute insanity
This used to be done entirely in hardware (VGA text modes), and I believe some early GPUs had a feature to do that in graphics modes too.
It is not. This "feature" is disabled by default.
Google "manufactured outrage".
(For the record, I abhor Windows 11)
It doesn't because that feature only just release, only works on specific new laptops and most ipmortant: YOU HAVE TO MANUALLY ENABLE IT
That reminds me of Chrom[e|ium]'s insanely bad form suggest/autofill logic: The browser creates some sort of fuzzy hash/fingerprint of the forms you visit, and uses that with some Google black box to "crowdsource" what kinds of field-data to suggest... even when both the user and the web-designer try to stop it.
For example, imagine you're editing a list of Customers, and Chrome keeps trying to trick you into entering your own "first name" and "last name" whenever you add or edit an entry. For a while developers could stop that with autocomplete="off" and then Chromium deliberately put in code to ignore it.
I'm not sure how much of a privacy leak those form-fingerprints are, but they are presumptively shady when the developers ignore countless detailed complaints over many years in order to keep the behavior.
To be fair, websites with a horrible misunderstanding of security kept on using that for "this password is important, better make sure the user is forced to enter it by hand!"
and building multiple gigawatt consuming data centres to produce AI slop no-one asked for and no-one wants
powered by fossil fuels