It’s a nightmare scenario for Microsoft. The headlining feature of its new Copilot+ PC initiative, which is supposed to drive millions of PC sales over the next couple of years, is under significant fire for being what many say is a major breach of privacy and security on Windows. That feature in question is Windows Recall, a new AI tool designed to remember everything you do on Windows. The feature that we never asked and never wanted it.

Microsoft, has done a lot to degrade the Windows user experience over the last few years. Everything from obtrusive advertisements to full-screen popups, ignoring app defaults, forcing a Microsoft Account, and more have eroded the trust relationship between Windows users and Microsoft.

It’s no surprise that users are already assuming that Microsoft will eventually end up collecting that data and using it to shape advertisements for you. That really would be a huge invasion of privacy, and people fully expect Microsoft to do it, and it’s those bad Windows practices that have led people to this conclusion.

  • dmtalon@infosec.pub
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    2 years ago

    Ya, a PR nightmare for the next 15 minutes until the next unbelievable thing comes along and the ADD nature of people forgets windows is watching everything they do.

    • assassinatedbyCIA@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      I agree with your point, but I think it’s important not to forget just how shitty tech media is a holding these companies to account. Half the shit most mainstream tech journalist publish borders on hagiography for these companies.

    • FlashMobOfOne@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 years ago

      That’s usually what I think too, but after watching how Twitter’s gone to shit since the two big user departures, I think this could legitimately affect Microsoft’s bottom line.

      • Voytrekk@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 years ago

        That will rely on businesses moving away from Windows. That is where they make a ton of their money with Enterprise licenses and Office 365 subscriptions.

          • Starkstruck@lemmy.world
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 years ago

            They do care about keeping their company secrets and proprietary info though. Recall could make corporate espionage a cake walk.

          • Taleya@aussie.zone
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 months ago

            We do however care very deeply about IP and other sensitive data - in my field (digital cinema), microsoft have literally fucked themselves out of any company that wants a TPN certification

    • gravitas_deficiency@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 years ago

      Ok fine, I’ll repeat it again:

      You’re right - many consumers will likely forget about it and just use it anyways. But enterprise customers absolutely, categorically will not. Even with their damage control, this is still going to hurt them a lot. Moreover, it’s going to hurt hardware sales from Intel, AMD, and Qualcomm, all of which have dumped MASSIVE amounts of capital into this tech. This is going to slow the rollout of NN-optimized chip tiles, and that is going to directly hit their bottom line. Microsoft hurt themselves AND the three most important hardware partners they have.

  • AWittyUsername@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Apple ensures its operating systems are clean, polished, and without bloat.

    Except for all the uninstallable Apple bloat such as Apple Music, Apple TV, etc. And the numerous bugs and issues, such as still not being able to have the touch pad and mouse scroll wheel have different settings.

    • Echo Dot@feddit.uk
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 years ago

      I remember when everyone was complaining about how terrible Safari is. The lead developer started having a go and ranting on Twitter, saying that raising bug reports is not constructive feedback.

      That was a mess.

    • ZILtoid1991@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      Don’t forget the fact they’re locked onto luxury hardware, and you can’t build your own flavor for it. Even worse is, notebook manufacturers copied them so much there’s less variations among them. I was looking for some “subnotebook” as a potential portable PC, but I had like a few options (many of which would have included AliExpress junk), but there’s an endless supply of same-looking 14-16" ones, that are thin (“real” portability according to techbros), lightweight, “desktop replacements”, and run at a constant 95°C.

      • weststadtgesicht@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 years ago

        The main takeaway of this article about Microsoft’s horrible decisions is “Apple bad”? OS flame wars really haven’t gotten less ridiculous in the past decades…

    • billwashere@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 years ago

      Apple is not blameless but they are a shit-ton better than Microsoft. I have to have M$ for a few work apps but I’m primarily MacOS for desktop and Linux for everything server-side. I avoid M$ as much as possible.

  • naeap@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    Microsoft has built a number of safety features into Windows Recall to ensure that the service can’t run secretly in the background. When Windows Recall is enabled, it places a permanent visual indicator icon on the Taskbar to let the user know that Windows Recall is capturing data. This icon cannot be hidden or moved.

    Oh my, that one is really cute

  • CaptPretentious@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    This is status quo for every large corporation. Microsoft, Apple, Amazon, EVERY SOCIAL MEDIA PLATFORM, Roku… They all, ALL, push boundaries to see what they can get away with to not only sell you something, but also make you the thing they sell. Sometimes they’re bold enough to make it public what they’re doing, sometimes, it’s a leak that happens when people find out how little the company actually cares about it’s users (Apple, so many user data leaks).

    • Shelbyeileen@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 years ago

      My bigger concern is that almost every company now has it in their contracts/terms of services, that all users are not allowed to participate in a lawsuit, be it class action, or court case against them Most of them even have a maximum sue limit too! There’s a lot that have a rule that initial arbitration cannot have a lawyer, but that won’t be enforced.

          • Wiz@midwest.social
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            2 years ago

            Sorry, this may be unpopular, but software license click-through agreements are enforceable.

            Source: I’m not a lawyer, but worked in a software contracts office with lawyers, so some of it ruined off. Essentially your legal options are, use the software according to the license agreement, or don’t use the software.

            A third option would be, I guess, use open source software so you don’t deal with that bullshit.

            Edit: Part of it is wrapped up in the Uniform Commercial Code, which is a whole bundle of standard laws which is quite complex. Basically you pays your money, and you get a thing, but there are all sports of knobs and levers to handle every contingency. You can nope out of the transaction, but you don’t get the thing.

              • Wiz@midwest.social
                link
                fedilink
                English
                arrow-up
                0
                ·
                2 years ago

                Maybe?

                Again, I’m not a lawyer, but I’ve read a lot of EULAs.

                However, to challenge that, your have to sue Microsoft, against their team of super-lawyers, the best that Microsoft could buy. And you’d have to do it in the jurisdiction started in the license agreement, which is undoubtedly friendly to Microsoft. And you’d have to have some sort of standing, meaning you have suffered some actual damage from the thing you arguing against, and that you want remedied. So you sue for damages, but it can only be for the amount that you were actually damaged, which is problematic - especially for free Microsoft software. But for paid software, I’m sure there’s a return/refund clause which would make you whole.

                And you are paying your own lawyer to Microsoft, right? How long do you plan to sue Microsoft? I guarantee they have deeper pockets than you, and can outlast you in court. And remember if you lose the lawsuit, you will probably be countersued for the cost of their lawyers.

                Basically the EULAs are written by Microsoft’s very expensive lawyers. Other corporations cower in fear of Microsoft’s lawyers; I know the ones in my office did. And the rewards you’d get would be a Pyrrhic victory at best. “Do you feel lucky, punk?”

  • PerogiBoi@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 years ago

    I figured on my gaming and VR rig that I’d begrudgingly upgrade it to W11 when W10 stopped receiving security updates and support but at this point the recall feature (which will be used to train LLMs regardless of what Microsoft promises or guarantees) has ensured that I never install that kind of spyware as an operating system.

    I’d rather spend forever troubleshooting and getting my Valve Index to work with Ubuntu than deal with a giant backdoor.

    • areyouevenreal@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 years ago

      I wouldn’t go for Ubuntu. They are also run by a corporation that has done problematic things with the project. It also just doesn’t work that well anymore. Better off going for something Debian or Fedora based, or even an Ubuntu derivative like Pop OS.

        • rtxn@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 years ago

          It’s Debian-based, but Canonical has been really Microsofty about its development. They now have Snap as a universal packaging format, and have mandated that all official Ubuntu flavors (so X/K/Lubuntu and others, but not derivatives like Mint) must include Snap, and must not include Flatpak in the default installation. They’ve also fucked with APT where installing certain packages, like Firefox, would first install Snap and then the application’s Snap package, without even telling the user. They’ve had some controversy with Amazon ads in the search results, and advertising Ubuntu Pro in the fucking terminal. The default GNOME desktop also has a ton of issues.

          I, and many others, recommend against Ubuntu. Linux Mint is the most commonly recommended “just works” distro. That being said, switching to Ubuntu, if able, is still preferable to staying on Windows.

  • EnderMB@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    Outside of the “Microsoft bad” comments, this is a prime example of why big tech companies need to stop promoting AI leads to a position where they are able to have influence over initiatives outside of AI.

    The worst thing to happen to basically every product/service in tech right now is AI. It’s made Google unreliable in the eyes of normal people for the first time in decades, it’s destroying trust in Amazon content across reviews and Kindle, it’s adding features to Facebook that no one ever wanted, etc.

  • mypasswordis1234@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    TL;DR:

    • Windows Recall, part of Microsoft’s new Copilot+ PC initiative, has sparked major privacy and security concerns.
    • The feature uses AI to capture and store screen data locally, allowing users to search for past activities using natural language.
    • Despite assurances that data is not uploaded to the cloud or used by Microsoft, user trust is lacking.
    • Microsoft has a history of practices that have eroded user trust, including obtrusive ads, ignoring user preferences, and requiring Microsoft Accounts.
    • Users are skeptical, fearing future misuse of the collected data for advertising or AI training.
    • Windows Recall reportedly stores data unencrypted, making it vulnerable to access by third-party apps and potential malware.
    • The open nature of Windows amplifies these risks, unlike more secure systems like iOS and Android.
    • Users have compared Windows Recall to spyware, with many threatening to switch to other operating systems like Linux or Mac.
    • Microsoft’s attempts to keep the development of Windows Recall secret did not help build trust.
    • Windows Recall will only be available on new Copilot+ PCs, requiring specific hardware not present in existing PCs.
    • Users will have the option to disable the feature, but there are concerns about it being enabled by default.
    • Despite security issues, the feature is effective in helping users find lost or forgotten data.
    • It could improve productivity if trust and security concerns are resolved.
  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    Not really

    For the retail market, most people just have phones not computers anymore. Microsoft has already lost The Battle of Windows phone.

    For the Enterprise market none of this recent b******* is going to enterprise customers anyway, they would have group policies and volume licensing deals to avoid all the b*******.

    For those poor retail customers who still run Windows, they suffer, but they’re minor, not significant

    • Weslee@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 years ago

      I’m using windows 11 and after hearing about recall and all the other shit they’ve done, I’ve finally decided to make the jump to Linux

      So for atleast me, this was the final straw

      • nelson@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 years ago

        I had dabbled in gaming on Linux but never made the jump. After reading about recall I spent a week making my choice on OS of choice ( and then I switched a week after :') ).

        I’m fully on Linux now. Even if they fully back down from windows recall I dont need an OS that’s trying to sell me something based on whatever I do in it.

        It was my final straw as well.

        Edit: and it hasn’t really been bad either. The shader compilation after every gfx driver update is a bit annoying. That’s about it.

        I’ll probably run into something at one point. Like some anti cheat that doesn’t work and is preventing me from playing the game.

          • sgtgig@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            A couple people recommended Fedora spins but I’d recommend just sticking with the big distros (that have up-to-date graphics drivers readily available - so not Debian.) A lot of the gaming-focused distros are only saving you a few terminal commands and increase your risk of running into issues; they’re good, but they may not be as 100% stable as you’ll find in major long-running distros like Fedora or Mint.

            I have settled on Fedora with KDE Plasma. Here’s basically everything I copy pasted for gaming:

            # install steam, discord, nvidia drivers
            sudo dnf install https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-$(rpm -E %fedora).noarch.rpm https://mirrors.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-$(rpm -E %fedora).noarch.rpm -y
            sudo dnf config-manager --enable fedora-cisco-openh264 -y
            sudo dnf update -y
            sudo dnf install steam discord akmod-nvidia xorg-x11-drv-nvidia-cuda
            
            # install bluetooth Xbox driver
            sudo dnf install git dkms
            cd /tmp
            git clone https://github.com/atar-axis/xpadneo.git && cd xpadneo
            sudo ./install.sh
            

            I also had to enable Legacy X11 App Support through the settings gui so that Discord could receive push to talk presses without having focus.

    • lazynooblet@lazysoci.al
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      2 years ago

      Yeah this. Fed up with sensationalist headlines that are far from reality. Us Lemmy users have a better understanding of what’s going on but we shouldn’t be falling for this journalism as it’s nonsense.

  • egeres@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 years ago

    I do think that the concept of recall is very interesting, I want to explore a FOSS version where you have complete ownership of your data in a secure manner

    • JasSmith@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      Yeah the concept is pretty damn cool. It’s just horrifying to have a company own and control that data. I suspect this is like Xbox One launch disaster in 2013, in which Microsoft initially required all consoles to have an always-online connection. People rebelled, but today and certainly on our current trajectory, it now looks like Microsoft was just a little ahead of the curve. I think people will eventually become a lot more comfortable with companies owning their data because the benefits will be so enormous. I’m not happy about that future, but I think I understand it.

  • secretlyaddictedtolinux@lemmy.worldBanned
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 years ago

    Most male computer uses watch porn and would not want an AI to log that. Many women find porn sickening and don’t understand it and will never understand male urges that result in watching it. The fact that this got into a finished product tells you a lot about Microsoft’s corporate culture.

    No one working there really cares about the company enough to bring up uncomfortable issues, they are all there just to get their paycheck and actual outcomes be damned. The culture their must be toxic for this product to have been put into a product enabled by default.

    If this was a top-down decision and there was no input by others into it, it leads to questions over whether this feature was forced to be included by the government, which can easily require corporations to do anything and then issue gag orders and whether it was some sort of test to see how much intrusive spying bullshit that regular consumers will tolerate now. If this was a feature that was forced into the product, the plan may have been to turn it off by default after negative feedback, but then just keep it in the program for when governments want to turn it on. Governments may have realized it in any capacity such a terrible feature would result in outrage and may have thought this was the path of least resistance, like saying “Would you like to eat a bowl of shit? No, okay, we’ll just give you these brussel sprouts”

    • JasSmith@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 years ago

      Most male computer uses watch porn and would not want an AI to log that. Many women find porn sickening and don’t understand it and will never understand male urges that result in watching it. The fact that this got into a finished product tells you a lot about Microsoft’s corporate culture.

      Excellent point. We saw exactly the same phenomenon play out with Google and Gemini. The tool created racially diverse Nazis. Even a few minutes with the tool revealed major issues. There must have been hundreds of people who witnessed the slow moving train crash in realtime, but were either unwilling or unable to speak out. I think these companies have clearly cultivated a hierarchical culture of fear and intimidation. I recently left a job in which my manager was ex-Google. The stories she would tell were appalling. Her command-and-control style was, frankly, disgusting. She permitted zero critical feedback or discussion. It was her way or “fuck off.” I found that very instructive as to how these companies have morphed into shells of their formers selves. I’m not bullish on the future of these companies. They’re coasting very well on the fumes of their historical successes, and I think their demise is all but assured.

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    2 years ago

    A lot of people here seem to be missing the nuance.

    Sure, it’s problematic for their consumer market share, but you’re right that that’ll probably be forgotten by the mostly tech-illiterate populace over time. But that’s not the problem.

    Step 0 of MS’s plan for this should have been “make sure there is an absolutely bulletproof and ironclad way to disable that stuff completely for enterprise customers”. And they didn’t do that. So now, enterprise IT writ large is going to… you know… just not buy any of these devices. Which is absolutely their right.

    But the really frustrating bit is that MS may have significantly harmed the rollout of ARM-based laptops (as well as x86 chips with beefy NN-optimized tiles) with this, and additionally done real, massive harm to Intel, AMD, and Qualcomm by doing so. All three of those manufacturers have gone to ENORMOUS lengths to roll this tech out, largely at MS’s behest. They’re all going to take this on the chin if the rollout goes poorly. And the rollout is already going poorly.

    But MS thought they could Apple-handwave away the details. And they can’t, because a lot of people who understand the absurd security implications of continuous capture and OCR and plaintext storage of the OCR output. It’s not something you can handwave away. It’s entirely a non-starter in the context of maintaining organizational security (as well as personal data security, but we’ve already talked about why that’s a bit of a moot point with the general public). But enterprise IT largely does try to take their job seriously, and they are collectively calling MS’s bluff.

    The problem for the long term is that MS has pretty much proven to the IT industry with this stunt that they can’t be trusted to make software that conforms to their needs. That’s a stain that isn’t going to go away any time soon. It might even be the spark that finally triggers enterprise to move away from MS as a primary client OS. After all, Linux is WAY easier to manage from a security perspective.

    TL;DR: the issue is that MS has significantly damaged their reputation with this stunt. And you can’t buy reputation.

    Edit:

    The article has an update:

    Update noon ET June 7, 2024: Microsoft has released a statement noting it is making three significant changes to how Recal works including making it opt-in during setup, requiring Windows Hello to enable Recall, proof of presence is now required to view your timeline, and search in Recall, and adding additional layers of data protection including “just in time” decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so that snapshots will only be decrypted and accessible when the user authenticates.

    It’s definitely a move in the right direction… but it also begs the question of why didn’t they do that in the first fucking place? Seriously, some heads are gonna roll over how badly this whole release was planned, and the very clear lack of due diligence.