The article, without the paranoia, appears to be accurate. Recall will give a user the same ability to look back at his online activity as his ISP and/or employer has had for years. It will have the added advantage of searching offline work as well.
ISPs, telecoms, and employers, etc. have always had the ability to observe our activity. My former company’s firewall logs recorded every page a user visited or tried to visit. And I received a report when a computer made repeated attempts to visit a blocked site or some other suspicious activity was observed. Today it appears common for employers to use on device software to monitor employees.
IMO the only solution is strong privacy laws, and for us to not use AI personal assistants.
That is not the issue I do have with “Recall”. First and foremost, Recall will take any control about any data away that is being stored on or entered in PCs that have this feature. And no matter what other security measures one has in place (Password Managers, disk images and what not), all of that it potentially compromised at some point. I as a user have totally will have lost control about my data after “Recall”.
The article, without the paranoia, appears to be accurate.
The paranoia actually is no paranoia if I have a look at the bigger picture. Even if Microsoft will leave everything on device, this local data source is something that that will be attacked by malware and what not. There are areas where “AI” must not have access, no matter what. Not having information stored digitally sometimes is the only way to protect it.
I felt that it might be a good idea to include this opinion piece over here because I think that Microsoft’s spin on its new features was quite successful without being questioned to its true core (even if without any bad intent on Microsoft’s part).
It is absolutely true that a personal assistant needs to know “almost” everything. The thing with Recall is that this function is far more than a personal assistant in real life. Because the word “almost” is being eliminated with “Recall”. There is no almost - and that is no paranoia seeing it that way. You do not take your personal assistant with you when using the bathroom, when talking deeply personal stuff with your better half or children, when being on vacation doing whatever you are doing, when … There are boundaries and we need to have those.
The article loses some of its precision being translated to English. What the author is trying to make clear is that a feature like “Recall” and whatever follows in this direction could mean that a computer can no longer be truly personal to the owner after something like this has been introduced. There are areas where it must be technically impossible for them to be captured by “Recall”. Of course, a human personal assistant needs to know a lot - and yes, it is tempting to equate that with a digital assistant. But as with a human assistant, it must be ensured that there are limits to the digital assistant. And these are exceeded with “Recall”. And it is a dangerous attack vector for third parties.
And this will happen. What makes me sad is that players like Microsoft that apparently do not want to understand what the issues are will lead to such drastic regulation that otherwise may not have been necessary in the first place. And too much regulation often leads to unwanted results.
“Recall” in its current form never should have been announced in the first place. It is irresponsible from my point of view.
Normally I’m the guy who jumps at “new” ideas/technology because I like to give things a chance before saying if they are a mistake or not.
But…………with Recall I can appreciate the goal, but I can’t seem to get past all the downsides. A one-stop-shop (even on device) of my entire computing life? I don’t know about that. I’m not even talking websites people may not want in their history. I’m thinking banking data, investment information, pay stubs, medical communications, etc. There’s a lot of personal information that goes across our screen that seem benign until you combine it all in one place. What a treasure trove for a bad actor.
I think it is reasonable to expect every purchase we have every made with a credit card has been sold to a data broker as well as any purchase made with an app or store loyality card. My financial data has been leaked by two or the three major credit bureaus and I was recently notified my hospital records have been hacked.
We don’t even know all information about us that is stored digitally. Just the info in public records is staggering. IMO, the data on our personal computers isn’t a drop in the bucket compared to what is available in the world.
As I understand the feature, if I chose to turn it on, I would be able to select what was and was not “remembered” and how long it would be retained. I could, for example, tell it to not record any data from the Firefox browser. If that is correct, I would probably at least try Recall if I were a Windows user.
Each of us will need to decide how we will use the AI tools that will be offered to us. I think you and I may only disagree over how much control of our data we have today.
My first thought when I first saw the news about Recall was that Microsoft is sherlocking apps like this.
My reaction to all of these apps and features is overwhelmingly negative. It doesn’t help that Microsoft has a terrible record in infosec.
TBF, iPhones by default store an on-device record of everywhere you go while your phone is with you. You aren’t asked if you want this, and you have to know 1) that it’s doing this and 2) where to dig into the settings to turn it off.
I hope for the sake of Windows users that Recall can be turned off easily, and that users will be asked if they want it when they set up the OS.
Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers. That data may be in snapshots that are stored on your device, especially when sites do not follow standard internet protocols like cloaking password entry.
So it means if you need to use the show password thing that’s literally built into Edge and most other browsers then Recall has a searchable record.
Not to mention people need to be able to use their devices for purposes they just don’t want recorded for posterity. There is so little gain for users with this feature but so much risk.
And this might be on ARM windows today, but Intel will include NSUs in future chips and now Windows has a Rosetta 2 equivalent ARM PCs are going to get way more common.
They haven’t been hiding this, it was discussed in multiple places on day one. Pretty much every tech site has pointed this out.
You can roll your eyes all you want, but if it comes to Intel based Macs, I would just turn it off. Yes MS has it’s questionable history in this area, but as a regular Windows user, I am not even slightly concerned about this.
It is ok if you want this feature, and some people do. There is a Mac app that does this, and people like it.
I don’t want it, and I am curious as where they go with this because all their corporate/government users will not want it. So is this a thing that is only in the retail version? Do they offer a paid version that doesn’t include this? It’s a bit early to be too concerned, but I am very interested in how they handle this. As I said though, just like Kinetic, I think this will fail miserably.
AI PCs are predominantly targeted at enterprise customers. It’s a standard Windows feature in Windows 11. It will be installed automatically on every single Windows 11 PC that can run it via Windows update this year.
My work computers, federal gov and large corps, are never feature equivalent to my home computers. Corporations would never stand for this. Although, I can’t see them all jumping ship to Linux/Mac either.
Recall and its predecessors seem like they were developed by programmers in love with git, who thought, “What if we did something like git, but for everything your computer does and everything you do on your computer,” without realizing what an infosec and privacy nightmare that was and how many downsides there would be.
Yep. By default Safari on Mac can keep our “browsing history for as long as a year, while some iPhone, iPad, and iPod touch models keep browsing history for a month.”
All computers store more data than most people realize.
And they call home with a lot of that data. When I upgraded to a Unifi system, my dashboard shows me where most of my data goes, Apple, Microsoft, and Google are always near the top of the list.
It’s probably silly, but I am considering dual booting a PC to Linux because of it.
Linux has its own problems. One of the strengths of open source software is the ability for anyone to examine the code. But log4j is an example of what can happen when no one does, a mistake is made, and millions of computers are compromised.
I’ve used several flavors of Linux/UNIX, a couple of midrange computers, and every Microsoft OS since DOS. But I’m most familiar with macOS and Windows and that, IMO, gives me more of an advantage than a more secure, but unknown, OS.
So I know some folks had hot takes about Microsoft’s Recall feature and today a security researcher published the first malware to extract it’s data remotely (before it’s even been released).
It was bad enough as a niche app, but sherlocking it into the world’s most widely used laptop and desktop OS was guaranteed to turn it into a massive, data-rich target screaming “HACK ME! HACK ME!”