Microsoft

Controversial Windows Recall AI Search Tool Returns – Slashdot

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

typodupeerror
  • This is essentially the Panopticon. Sad times when the OS supplier has to be regarded as an enemy of all users.

    Sure, they _pretend_ this is secure, but do you really think the usual authoritarian assholes in law enforcement and the TLAs can really restrain themselves? They have to think the Holy Grail of surveillance has been found!

    • Most users don’t care. And we can’t make them care. So, for the most part, Microsoft is right in their beliefs.

      They have the means, motive, and opportunity to spy on their users for their own profit. So, they will.

      I only use windows for work. And I don’t do anything relating to my personal life on my work computer. So, this is my employer’s problem, not mine.

    • Sad times when the OS supplier has to be regarded as an enemy of all users.

      People have had decades to accept that they run software which is intended to serve other parties’ interests above their own. And still to this day, we argue over the definition of “malware.”

    • “… authoritarian assholes in law enforcement and the TLAs…” that’s the problem with our elected officials, they hear the ” authoritarian assholes in law enforcement and the TLAs” say that ‘they can’t do their job’ without this level of surveillance, and some variant of ‘think of the children’ then the all vote to give ‘ authoritarian assholes in law enforcement and the TLAs’ the powers they ask for.

      The thing is, that no matter how much power you give the ‘ authoritarian assholes in law enforcement and

    • Are they an enemy of the user though, or do you just think so due to lack of information? One of the key things from the announcement not mentioned in this article, but covered in others is that Recall is fully optional and Microsoft will allow the user to completely uninstall it.

      https://www.theverge.com/2024/… [theverge.com]

      Sure, they _pretend_ this is secure

      Literally every attack on the preview has required elevated system privileges. When an attacker has that already you are no longer using your own machine, you’re using theirs. Windows recall isn’t

  • I’ll reduce the surface area by shutting it off and disabling the feature, thank you very much.

    • Next update enables it again without your approval

  • and using that to train your AI without my consent. Mr. Weston, YOU are the attacker.

    • Exactly. This is a blatant attack on the users, nothing else.

  • Now it provides cryptographically secure proof of whatever your abusive spouse thinks it says. Sorry women, a whole lot of you are going to die horrible deaths because of Microsoft.

    • I’m sorry, I don’t follow.

    • I’m happy you raised this. Having to make a leap of faith to the “think of the abused women” destination means that all other problems with Recall have been addressed right?

  • I don need no steenkin’ CoPilot, I don need no steenkin’ Recall, I don need your untested buggy security.
    Period.

  • A consultant may be granted temporary access to proprietary data and PII that they are required by contract and possibly by law to be deleted when the contract ends. How do they do this? Its not clear that physically destroying the computer is sufficient because a lot of Microsoft data is shared between computers on the same account.

    That is separate from the insane security risk that now all passwords that are used on the computer will be visible in the screen shots.

    I don’t know if this is pushed by

    • I think it is desperation. MS has sunk tons of money into AI and applications or profits are not materializing. Hence crap like this. Obviously, it is going to be abused and obviously, attackers are going to get in.

      My one hope at the moment is that this is likely turning out to be completely illegal in the EU and even the possibility may be illegal already.

  • Who need the govt to spy on you when the corporations can do it for fun, profit? The profit, of course, being when they sell the spying data to the govt.

  • Assuming security works like described, why was there a rush to get this feature out the door way before it was secured. Remember Recall was advertised as “encrypted” previously but that meant if the drive had Bit-Locker turned on, then the files were encrypted.

    • MS has poured billions into AI and applications or profits are not materializing. They are desperate.

    • because AI, blockchain, cloud

  • You don’t get a second chance to make a first impression. They put so very very little thought into the first iteration, that the second one is DOA. Its like trying to sell a fire safe made out of FlashPaper. Yes thats a bad idea, and no I won’t be interested in their follow up now that they admit they have no brains.

    • You don’t get a second chance to make a first impression.

      You would think MS learned that after the Xbox One launch, but no.

  • Microsoft says it has completely overhauled the security architecture with proof-of-presence encryption, anti-tampering and DLP checks, and screenshot data managed in secure enclaves outside the main operating system

    That’s nice, but have they bothered to overhaul their answer the following question: why the hell would anybody want or need this?

    • That’s easy. Their customers asked for it.

      Their customers. You know, advertisers. They’re all asking “How do I choose which users’ eyes are worth paying for?”

  • From TFA:

    Recall will now be an “opt-in experience” during setup. “If a user doesn’t proactively choose to turn it on, it will be off, and snapshots will not be taken or saved,” he explained, noting that Windows users can remove the feature entirely.

    “You can remove it completely, never be turned on in future,” Weston said.

    Also:

    Under the hood, the Microsoft VP said snapshots and any associated information in the vector database are always encrypted with keys that are protected by the TPM (Trusted Platform Module), tied to a user’s Windows Hello Enhanced-Sign-in Security identity.

    “You have to have proof-of-presence to turn it on,” Weston said.

  • Normally I’d like to avoid cursing and put well thought out words into the world but are you fucking kidding me? No one fucking wants it, no one, no one fucking wants it.

    Ohhhh we made it more secure to add…you missed the part where no one fucking asked for it, and no one fucking wants it. The only person who wants it, is fucking microsoft to collect more data.

    I don’t care how secure and proof of security for a feature NO ONE FUCKING WANTS is. It shows your clear deception to gather data WE DO NOT WANT TO FUCKING GIVE YOU.

    Maybe it’ll be mega quantum forever secure! Great NO ONE FUCKING WANTS IT STILL. The miscommunication, is we don’t fucking want it.
    Address that concern by fucking off.

    • Time will tell. Microsoft is giving the users the ability to uninstall it, completely. https://www.theverge.com/2024/… [theverge.com] let’s see after release if you’re right, or if (as I suspect) only a few vocal minority of people don’t want it / give a shit enough to care about it.

      By the way I remember the iPhone announcement here like it was yesterday. I’m sure someone said NO ONE FUCKING WANTS IT in all caps when they were shown a phone without a keypad as well. More power to you as an individual but I suspect you a

  • The risks of screenshot data being targeted is ZERO if there is no screenshot data. Anything above that is not an example of minimized risk.

    They mean they THINK they made the risk smaller but if the customer doesn’t even want the feature, the risk/reward ratio is still infinity.

Slashdot Top Deals

After any salary raise, you will have less money at the end of the month than you did before.

Working…

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Check Also
Close
Back to top button

Adblock Detected

Block the adblockers from browsing the site, till they turn off the Ad Blocker.