• Scrubbles@poptalk.scrubbles.tech
    link
    fedilink
    English
    arrow-up
    90
    ·
    7 months ago

    This is just a fucking privacy nightmare. We like to laugh and play here about Linux quite a bit, but holy shit this is the actual “If you’re using Windows and expect privacy at all, this is it, you should throw that notion out the window.”

    I don’t care how much encryption there is, or the assurance that it’s only on your hard drive, I’ve sat in too many corporate meetings in my career to trust that. There is no way Microsoft is just letting you have that data and they’re not reporting it out. Very least? They’re using ML on it to aggregate what it sees in the screenshot, and then saving that. Worst case, they’re saving it to an encrypted blob storage, calling that encrypted, and hiding deep in the ToS that you actually agreed to that (even though it said in the big letters it was local only, sorry woopsie in the small letters it said it’s also stored there.)

    Fuck, ignoring the obvious pron implications that I assume everyone here is immediately thinking of, think of HIPAA, think of the private communications with therapists that people have, think of all of the financial documents you’ve opened, think about bank accounts, chats, fucking everything.

    • Admiral Patrick@dubvee.org
      link
      fedilink
      English
      arrow-up
      42
      ·
      edit-2
      7 months ago

      Worst case, they’re saving it to an encrypted blob storage, calling that encrypted, and hiding deep in the ToS that you actually agreed to that

      And then it’s discovered that bucket was accidentally set to public for over 8 months. Oopsie daisy! But you can’t sue us because also deep in the ToS was a forced arbitration clause.

      Also, if you don’t agree to the whole ToS, you can’t use the computer you just paid for.

    • 👍Maximum Derek👍@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      19
      ·
      7 months ago

      But they specifically said in their blog post that it has “privacy you can trust.” Just imagine all the trust you have in Microsoft plus all the trust you have in the accuracy of AI and rest easy. Plus the AI runs locally so they can trust you to pay the power bill.

      Don’t think about how much money they could make with their business customers, based on telemetry alone.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      17
      ·
      7 months ago

      I am so glad I switched to Linux 7 years ago. What an absolute shitshow Windows OS has become

    • EFrances@lemmy.eco.br
      link
      fedilink
      arrow-up
      4
      ·
      7 months ago

      Meanwhile in the EU

      Europe sets benchmark for rest of the world with landmark AI laws

      "“With the AI Act, Europe emphasizes the importance of trust, transparency and accountability when dealing with new technologies while at the same time ensuring this fast-changing technology can flourish and boost European innovation,” he said.

      The AI Act imposes strict transparency obligations on high-risk AI systems while such requirements for general-purpose AI models will be lighter.

      It restricts governments’ use of real-time biometric surveillance in public spaces to cases of certain crimes, prevention of terrorist attacks and searches for people suspected of the most serious crimes."

      <snip>

      https://www.reuters.com/world/europe/eu-countries-back-landmark-artificial-intelligence-rules-2024-05-21/

    • ugo@feddit.it
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      7 months ago

      if you’re using windows and expect any privacy at all […] throw that notion out the window

      Correct. And the same is true even if you are using linux, macOS, android, or a butterfly to manipulate bits to send a message through the internet.

      Because if your message ends up on the screen of a windows user, it’s also going to be eaten by AI.

      And forget the notion of “anything you post on the internet is forever”, this is also true for private and encrypted comms now. At least as long as they can be decrypted by your recipient, if they use windows.

      You want privacy and use linux? Well, that’s no longer enough. You now also need to make sure that none of your communications include a (current or future) windows user as they get spyware by default in their system.

      Well maybe not quite by default, yet

    • ulkesh@beehaw.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 months ago

      We like to laugh and play here about Linux quite a bit

      We do? Aside from the “I use Arch, btw” memes, I must not have got that memo :) And, uhh…I use Arch, btw.

      Fuck, ignoring the obvious pron implications that I assume everyone here is immediately thinking of, think of HIPAA, think of the private communications with therapists that people have, think of all of the financial documents you’ve opened, think about bank accounts, chats, fucking everything.

      So much this. I’m glad I dumped Windows and this just guarantees that I’ll never return.

  • MangoKangaroo@beehaw.org
    link
    fedilink
    arrow-up
    43
    ·
    edit-2
    7 months ago

    I’m curious whether the increasingly invasive telemetry of modern Windows will have legal implications surrounding patient privacy here in the US. I work IT in the healthcare field, and one of our key missions is HIPAA compliance. What, then, will be the impact if Microsoft starts storing more and more in-depth data offsite? Will keyboard entries into our EHR be tracked and stored in Microsoft’s servers? Will we subsequently be held liable if a breach at Microsoft causes this information to leak, or if Microsoft just straight-up starts selling it to advertisers? Windows is our one-and-only option for endpoint devices, so it’s not like we can just switch.

    I genuinely don’t have the answers to these questions right now, but it may start to become a serious conversation for our department in the future if things continue at the trajectory they’re going at. Or, maybe I’m just old and paranoid and everything will be okie dokie.

    • B0rax@feddit.de
      link
      fedilink
      arrow-up
      18
      ·
      7 months ago

      I guess it will be like it was before, that there is a different version of windows for these use cases. Like Windows LTSC.

    • SapientLasagna@lemmy.ca
      link
      fedilink
      arrow-up
      6
      ·
      7 months ago

      Like most of Microsoft’s more odious features, this one can be turned off through GPO/Intune policy across an organization. As such, the liability will mostly fall on the organization to make sure it’s off. The privacy and security impacts will be felt by individuals and small businesses.

      They claim that the data is only stored locally, so far. We’ll see, I guess.

      • MangoKangaroo@beehaw.org
        link
        fedilink
        arrow-up
        4
        ·
        7 months ago

        Sadly a lot of the privacy switches are exclusive to enterprise and education users, but our endpoints are running Pro (we have our previous supervisor to thank for that). I guess I’ll hope this is one of the ones we can just toggle off without any fuss.

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    36
    ·
    7 months ago

    That closing quote is ominous:

    “Recall is currently in preview status,” Microsoft says on its website. “During this phase, we will collect customer feedback, develop more controls for enterprise customers to manage and govern Recall data, and improve the overall experience for users.”

    I read “so, yeah, we built in all the telemetry connections we swear we’ll never use … just for testing, ya know?”

    • smallpatatas@lemm.ee
      link
      fedilink
      arrow-up
      29
      ·
      7 months ago

      more controls for enterprise customers to manage and govern Recall data

      ahh ok so this is employee monitoring software

      • klangcola@reddthat.com
        link
        fedilink
        arrow-up
        13
        ·
        7 months ago

        Probably more what MangoKangoroo and B0rax talked about, that enterprises can opt out of this telemetry, due to compliance or Intellectual Property protection.

        So only the commoners get mandatory full-scale surveillance, Ehm I mean “ai enhancement”

  • BmeBenji@lemm.ee
    link
    fedilink
    arrow-up
    32
    ·
    7 months ago

    Despite the privacy concerns, Microsoft says that the Recall index remains local and private on-device, encrypted in a way that is linked to a particular user’s account.

    Just like how Microsoft domain-bound emails were stored locally on machines running Outlook, right? Or how purchasing and downloading music, movies, and video games meant that we owned them, right?

    I don’t believe for a fucking second that this “feature” will remain locally encrypted forever. Fuck Microsoft, fuck the AI bubble.

    “Don’t be evil!

    wait, you say you’ll pay me to be evil? Well fuck that changes everything!”

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    29
    ·
    7 months ago

    I have to believe at this point that a serious generation gap exists if there is an audience for this sort of constant monitoring. Because that’s what it is.

    Where it goes and whether Microsoft can be trusted are of course very valid concerns, but Jesus tap-dancing Christ, this is surveillance before the data go anywhere. Add that to your AI assistant that works best with the camera on, et voila!

    No doubt Google is going to say “hold my beer,” and there’s no pure Linux offramp on the overwhelming majority of Android hardware, so even if you’ve told Microsoft to fuck off …

    • DaPorkchop_@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      7 months ago

      I would say the vast majority of people (across all generations) either don’t know, or don’t really understand how extensive it (the monitoring) is and what the consequences of that are.

      • mctoasterson@reddthat.com
        link
        fedilink
        arrow-up
        3
        ·
        7 months ago

        Just look at the number of normies who use Apple, Samsung, or vanilla Pixels as their daily driver. Unless you have a degoogled Android, all the major flagship devices are essentially surveillance and advertising powerhouses. People have embraced the willful ignorance part of this bargain. They think they need whatever proprietary garbage is offered by Apple, to the point that even their own privacy is too ethereal a concept to regret mortgaging it away in the tradeoff.

  • Gork@lemm.ee
    link
    fedilink
    arrow-up
    24
    ·
    7 months ago

    As you might imagine, all this snapshot recording comes at a hardware penalty. To use Recall, users will need to purchase one of the new “Copilot Plus PCs” powered by Qualcomm’s Snapdragon X Elite chips, which include the necessary neural processing unit (NPU). There are also minimum storage requirements for running Recall, with a minimum of 256GB of hard drive space and 50GB of available space. The default allocation for Recall on a 256GB device is 25GB, which can store approximately three months of snapshots. Users can adjust the allocation in their PC settings, with old snapshots being deleted once the allocated storage is full.

    Oh no my computer doesn’t meet the hardware requirements whatever shall I do

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    23
    ·
    7 months ago

    “Recall screenshots are only linked to a specific user profile and Recall does not share them with other users, make them available for Microsoft to view, or use them for targeting advertisements. Screenshots are only available to the person whose profile was used to sign in to the device,” Microsoft says.

    It’s conspicuous that this statement talks only about the raw screenshots, not any data derived from them (such as aggregated data, inferred data, or even just slightly reprocessed data). So Microsoft could do any minor reworking of the data and send it off to the cloud for their own purposes, while technically complying with the above.

  • cobra89@beehaw.org
    link
    fedilink
    arrow-up
    21
    ·
    7 months ago

    How does this work with local laws regarding 2 party recording? If you’re on a video call and this records the other party without their permission, that is AFAIU illegal in many states in the US. I’m sure in parts of Europe as well.

  • Fluid@aussie.zone
    link
    fedilink
    English
    arrow-up
    17
    ·
    7 months ago

    A lawsuit waiting to happen… someone needs to class action MS for systemic breaches of privacy. Think of all the critical infrastructure, government, medical, policing, etc. systems processing sensitive, private, and in some cases classified, information.

    • jcarax@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      7 months ago

      Wish I had a choice, at work. Technically I can run Linux or MacOS, but I’d need to run a Windows VM for a few things anyway.

  • Vodulas [they/them]@beehaw.org
    link
    fedilink
    arrow-up
    11
    ·
    7 months ago

    Good news , it is just on their Copilot+ computers for now. For now is likely doing some heavy lifting there, though.

    I threw Mint on a partition to test moving away from Windows, and sadly does not play well with my 2080ti. This makes me want to put more effort into getting it to work…

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 months ago

      I honestly switched to PopOS, which has an NVidia version with the driver baked in, and it was stable as a rock. ended up just being easier for me. (Much better as a gaming OS all around tbh)

      • Vodulas [they/them]@beehaw.org
        link
        fedilink
        arrow-up
        2
        ·
        7 months ago

        That was the next thing i was going to try. Already have the bootable preview on a drive even. Maybe I’ll try that first before diving in to the wild west that is getting nvidia to work.

    • Blisterexe@lemmy.zip
      link
      fedilink
      arrow-up
      2
      ·
      7 months ago

      There’s a lot of work going into nvidia on linux ATM, so its improving pretty fast, but Also you can get a faster amd GPU with the money you can get from selling your 2080 ti

    • salarua
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 months ago

      try $ sudo apt install akmod-nvidia. it’s gonna pull in some dependencies and a proprietary driver, and probably break Secure Boot if you have it set up, but that’s how i got it to work on Fedora (except i used dnf, of course)

  • dumbass@leminal.space
    link
    fedilink
    arrow-up
    10
    ·
    edit-2
    7 months ago

    I open windows and it starts recording: opens Plex, plays Mash for 13 hours straight, PC closed down.