this post was submitted on 08 Jun 2024
8 points (100.0% liked)

Technology

57448 readers
4611 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

It's a nightmare scenario for Microsoft. The headlining feature of its new Copilot+ PC initiative, which is supposed to drive millions of PC sales over the next couple of years, is under significant fire for being what many say is a major breach of privacy and security on Windows. That feature in question is Windows Recall, a new AI tool designed to remember everything you do on Windows. The feature that we never asked and never wanted it.

Microsoft, has done a lot to degrade the Windows user experience over the last few years. Everything from obtrusive advertisements to full-screen popups, ignoring app defaults, forcing a Microsoft Account, and more have eroded the trust relationship between Windows users and Microsoft.

It's no surprise that users are already assuming that Microsoft will eventually end up collecting that data and using it to shape advertisements for you. That really would be a huge invasion of privacy, and people fully expect Microsoft to do it, and it's those bad Windows practices that have led people to this conclusion.

top 49 comments
sorted by: hot top controversial new old
[–] dmtalon@infosec.pub 2 points 2 months ago (2 children)

Ya, a PR nightmare for the next 15 minutes until the next unbelievable thing comes along and the ADD nature of people forgets windows is watching everything they do.

[–] gravitas_deficiency@sh.itjust.works 0 points 2 months ago* (last edited 2 months ago)

Ok fine, I’ll repeat it again:

You’re right - many consumers will likely forget about it and just use it anyways. But enterprise customers absolutely, categorically will not. Even with their damage control, this is still going to hurt them a lot. Moreover, it’s going to hurt hardware sales from Intel, AMD, and Qualcomm, all of which have dumped MASSIVE amounts of capital into this tech. This is going to slow the rollout of NN-optimized chip tiles, and that is going to directly hit their bottom line. Microsoft hurt themselves AND the three most important hardware partners they have.

[–] FlashMobOfOne@lemmy.world 0 points 2 months ago (2 children)

That's usually what I think too, but after watching how Twitter's gone to shit since the two big user departures, I think this could legitimately affect Microsoft's bottom line.

[–] Voytrekk@lemmy.world 0 points 2 months ago (1 children)

That will rely on businesses moving away from Windows. That is where they make a ton of their money with Enterprise licenses and Office 365 subscriptions.

[–] Infynis@midwest.social 0 points 2 months ago (1 children)

And businesses don't give a shit about their employees' privacy

[–] Starkstruck@lemmy.world 1 points 2 months ago

They do care about keeping their company secrets and proprietary info though. Recall could make corporate espionage a cake walk.

[–] helenslunch@feddit.nl 0 points 2 months ago (2 children)

Twitter is a great example of the exact opposite being true. Are people upset? Absolutely. Did they leave the platform? Nope. Maybe a small percentage.

[–] FlashMobOfOne@lemmy.world 0 points 2 months ago* (last edited 2 months ago) (1 children)

Respectfully, it's not.

The user departures, and response to further enshittify, have driven their stock price into the ground.

[–] helenslunch@feddit.nl 0 points 2 months ago (1 children)

What user departures? The platform has barely dipped. Stock prices are meaningless.

[–] bufalo1973@lemmy.ml 0 points 2 months ago* (last edited 2 months ago) (1 children)

X is the one telling the number of X users. Do you really trust Melon to tell the truth?

[–] helenslunch@feddit.nl -1 points 2 months ago

You're assuming my source is Musk.

[–] BroBot9000@lemmy.world -1 points 2 months ago (2 children)

It’s X.

Stop deadnaming X.

Anyone still clinging to the remnants of its former existence, please close your account. Stop kidding yourself.

[–] AlligatorBlizzard@sh.itjust.works 0 points 2 months ago (1 children)

I'll stop deadnaming Twitter when Musk stops deadnaming his trans daughter.

And for the record, I've never used Twitter. It's always kinda sucked. Now it really sucks.

[–] BroBot9000@lemmy.world -1 points 2 months ago* (last edited 2 months ago)

Musk is a complete shithead and that’s not gonna happen.

Calling it Twitter is only going to accommodate the people that refuse to get off that nazi network.

Cause you know Musk gets off on the hate of people still calling it Twitter, exactly because how he treats deadnaming.

[–] blind3rdeye@lemm.ee 0 points 2 months ago (1 children)

What's X? Is that the older version of Wayland or something?

[–] BroBot9000@lemmy.world 0 points 2 months ago (1 children)

It’s a shittier version of Mastodon but for right wing lunatics and russian bots.

[–] RobotZap10000@feddit.nl 1 points 3 weeks ago

I think that those two form a venn diagram of a blurry circle.

[–] AWittyUsername@lemmy.world 0 points 2 months ago (1 children)

Apple ensures its operating systems are clean, polished, and without bloat.

Except for all the uninstallable Apple bloat such as Apple Music, Apple TV, etc. And the numerous bugs and issues, such as still not being able to have the touch pad and mouse scroll wheel have different settings.

[–] billwashere@lemmy.world 0 points 2 months ago (1 children)

Apple is not blameless but they are a shit-ton better than Microsoft. I have to have M$ for a few work apps but I’m primarily MacOS for desktop and Linux for everything server-side. I avoid M$ as much as possible.

[–] AWittyUsername@lemmy.world 1 points 2 months ago

I agree. But everyone acts like Apple's shit doesn't stink.

[–] gravitas_deficiency@sh.itjust.works 0 points 2 months ago* (last edited 2 months ago)

A lot of people here seem to be missing the nuance.

Sure, it’s problematic for their consumer market share, but you’re right that that’ll probably be forgotten by the mostly tech-illiterate populace over time. But that’s not the problem.

Step 0 of MS’s plan for this should have been “make sure there is an absolutely bulletproof and ironclad way to disable that stuff completely for enterprise customers”. And they didn’t do that. So now, enterprise IT writ large is going to… you know… just not buy any of these devices. Which is absolutely their right.

But the really frustrating bit is that MS may have significantly harmed the rollout of ARM-based laptops (as well as x86 chips with beefy NN-optimized tiles) with this, and additionally done real, massive harm to Intel, AMD, and Qualcomm by doing so. All three of those manufacturers have gone to ENORMOUS lengths to roll this tech out, largely at MS’s behest. They’re all going to take this on the chin if the rollout goes poorly. And the rollout is already going poorly.

But MS thought they could Apple-handwave away the details. And they can’t, because a lot of people who understand the absurd security implications of continuous capture and OCR and plaintext storage of the OCR output. It’s not something you can handwave away. It’s entirely a non-starter in the context of maintaining organizational security (as well as personal data security, but we’ve already talked about why that’s a bit of a moot point with the general public). But enterprise IT largely does try to take their job seriously, and they are collectively calling MS’s bluff.

The problem for the long term is that MS has pretty much proven to the IT industry with this stunt that they can’t be trusted to make software that conforms to their needs. That’s a stain that isn’t going to go away any time soon. It might even be the spark that finally triggers enterprise to move away from MS as a primary client OS. After all, Linux is WAY easier to manage from a security perspective.

TL;DR: the issue is that MS has significantly damaged their reputation with this stunt. And you can’t buy reputation.

Edit:

The article has an update:

Update noon ET June 7, 2024: Microsoft has released a statement noting it is making three significant changes to how Recal works including making it opt-in during setup, requiring Windows Hello to enable Recall, proof of presence is now required to view your timeline, and search in Recall, and adding additional layers of data protection including “just in time” decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so that snapshots will only be decrypted and accessible when the user authenticates.

It’s definitely a move in the right direction… but it also begs the question of why didn’t they do that in the first fucking place? Seriously, some heads are gonna roll over how badly this whole release was planned, and the very clear lack of due diligence.

[–] ultratiem@lemmy.ca 0 points 2 months ago (1 children)

You guys trusted MS before this???

[–] TwilightVulpine@lemmy.world 0 points 2 months ago (1 children)

A couple years ago it wasn't thoroughly and transparently sucking off every bit of personal data it could get, and gearing up to put adds on the desktop on top of that.

[–] helenslunch@feddit.nl 0 points 2 months ago* (last edited 2 months ago) (1 children)

As expected, there is no evidence that this is "the straw that broke the camel's back". Don't waste your time reading this article.

MS has been doing this kind of shit for decades and their market share has never changed significantly.

Was it stupid? Yeah. Are people upset? Sure. Is anyone going to do anything about it? No, because the vast majority don't care or they would have stopped using it a long time ago.

[–] Weslee@lemmy.world 1 points 2 months ago (1 children)

I'm using windows 11 and after hearing about recall and all the other shit they've done, I've finally decided to make the jump to Linux

So for atleast me, this was the final straw

[–] fluckx@lemmy.world 1 points 2 months ago* (last edited 2 months ago)

I had dabbled in gaming on Linux but never made the jump. After reading about recall I spent a week making my choice on OS of choice ( and then I switched a week after :') ).

I'm fully on Linux now. Even if they fully back down from windows recall I dont need an OS that's trying to sell me something based on whatever I do in it.

It was my final straw as well.

Edit: and it hasn't really been bad either. The shader compilation after every gfx driver update is a bit annoying. That's about it.

I'll probably run into something at one point. Like some anti cheat that doesn't work and is preventing me from playing the game.

[–] moon@lemmy.cafe 0 points 2 months ago (1 children)

Gamers will literally install root kits on their PCs just because an update pop up tells them to. They really don't care lol.

[–] hikaru755@feddit.de 0 points 2 months ago

Companies and their legal departments do care though, and that's where the big money lies for Microsoft when it comes to Windows

[–] jet@hackertalks.com 0 points 2 months ago (1 children)

Not really

For the retail market, most people just have phones not computers anymore. Microsoft has already lost The Battle of Windows phone.

For the Enterprise market none of this recent b******* is going to enterprise customers anyway, they would have group policies and volume licensing deals to avoid all the b*******.

For those poor retail customers who still run Windows, they suffer, but they're minor, not significant

[–] brb@sh.itjust.works -1 points 2 months ago

Why are you censoring yourself? Are you stupid?

[–] PerogiBoi@lemmy.ca 0 points 2 months ago* (last edited 2 months ago) (2 children)

I figured on my gaming and VR rig that I’d begrudgingly upgrade it to W11 when W10 stopped receiving security updates and support but at this point the recall feature (which will be used to train LLMs regardless of what Microsoft promises or guarantees) has ensured that I never install that kind of spyware as an operating system.

I’d rather spend forever troubleshooting and getting my Valve Index to work with Ubuntu than deal with a giant backdoor.

[–] skillissuer@discuss.tchncs.de 0 points 2 months ago (1 children)

better get W10 LTSC in VM and use it until EOL and beyond, it'll be more privacy friendly this way

[–] pearsaltchocolatebar@discuss.online 0 points 2 months ago (1 children)

Using an internet connected OS past EOL is definitely not privacy friendly.

[–] KrapKake@lemmy.world 0 points 2 months ago (1 children)

He said until EOL. Windows LTSC, the IoT version in particular is supported until 2032.

[–] RobotZap10000@feddit.nl 1 points 3 weeks ago

2032 will be the year of the Linux desktop!

[–] areyouevenreal@lemm.ee -1 points 2 months ago

I wouldn't go for Ubuntu. They are also run by a corporation that has done problematic things with the project. It also just doesn't work that well anymore. Better off going for something Debian or Fedora based, or even an Ubuntu derivative like Pop OS.

[–] rtxn@lemmy.world 0 points 2 months ago* (last edited 2 months ago)

My dad is now pissed at both Microsoft and Adobe, and curious about Linux. If I can find a Lightroom alternative, he might actually switch.

[–] JasonDJ@lemmy.zip 0 points 2 months ago (1 children)

You know what would be a nice thing to put into windows?

A fucking decent way to search for files.

Also, grep and tail, as implemented in Linux. It's 2024 and there's no native equivalent to tail -f *.log. How embarrassing.

[–] retrospectology@lemmy.world 0 points 2 months ago* (last edited 2 months ago) (1 children)

You can do a commandline "dir /s *.log" to search an entire directory it works better than the normal file search generally. Unless I misunderstand what you're asking.

[–] grrgyle@slrpnk.net 0 points 2 months ago (1 children)

-f follows the file so you can see updates as they come in to the bottom of the file. I wasn't aware this worked with globs, but that's neat.

Is that what /s does? I haven't used Windows in years.

[–] retrospectology@lemmy.world 0 points 2 months ago

Oh, perhaps not. I may've just understood how you're using the search. /s is just a straight search if the directory, I don't know that it can be used to generate dynamic results like that. Go figure.

[–] spaghettiwestern@sh.itjust.works 0 points 2 months ago* (last edited 2 months ago) (1 children)

It's also important to remember that Microsoft has no monetary incentive to force people to use Windows Recall.

With that in mind, there would be no reason for Microsoft to automatically enable Windows Recall in an update down the line. If it does happen, the user will be able to instantly tell thanks to that that visual indicator and turn it off again.

This article is nothing but propaganda. There is huge monetary incentive to force people to use Windows Recall and collect their data, and Microsoft routinely uses Windows Update to enable data collection. They began that practice years ago on Windows 7. It's a ridiculously simple matter for MS to disable the visual indicator and force This Week's Plan on their users to monetize their data.

Windows Central pretends to be critical of plans to enable a feature that can be made into malware by Microsoft in a couple of minutes, but then back peddles and says it can't be done (utter BS) and if it could be, it wouldn't be that bad.

[–] barsquid@lemmy.world 0 points 2 months ago (1 children)

Even if the database remains local only forever, which I don't believe for a second, the computer will eventually make hyperspecific requests for ads based on the spying.

[–] Luccus@feddit.de 0 points 2 months ago

Only data that is not stored cannot fall victim to attackers. It does not matter whether it is a 'nigerian prince', Microsoft or some agency. Even if you completly trust whatever entity with your data right now, they may become problematic in the future.

This is why a low profile is a crucial component of OPsec.

Recall is objectively stupid, even if Microsoft only had their users best interest in mind. And they don't.

[–] NoiseColor@startrek.website -1 points 2 months ago (1 children)

Lol! How incredibly detached from reality!

Nobody cares! Well a few people care that make a big fuss, but most people don't ever think about their os. I bet a pretty big percentage don't know what os they use and I bet more than half don't know what version of the os they are using.

Nobody cares!

[–] TrickDacy@lemmy.world 0 points 2 months ago (1 children)

Haha I thought I recognized that username. The same person arguing with me that recall was a brilliant move which will solidify Microsoft as the industry leader they've always been 😂

[–] NoiseColor@startrek.website -1 points 2 months ago

Ah, the asshole! I thought I blocked you already. Bye!

[–] 58008@lemmy.world -1 points 2 months ago

I wish Linux weren't completely fucking impenetrable for casual users.