5 ms·
Am I the only one who doesn't think that recall is a bad thing? Of course Microsoft's implementation is a buggy privacy nightmare, but the core idea of being ab
by username81 2y ago
Am I the only one who doesn't think that recall is a bad thing? Of course Microsoft's implementation is a buggy privacy nightmare, but the core idea of being able to see what happened a week/month ago and process it using LLMs looks really useful. I'm looking forward to something like this, but local, FOSS and for Linux.
- Eggpants 2y agoIt was designed for corporate management to prove the WFH employees are goofing off. It’s the only way the lack of security passed any kind of giggle test at MS. Corporate accounts are the only MS customers that matters.
- 1vuio0pswjnm7 2y agoThe issue is control, i.e., who controls whether it is installed or not and whether it is on or off. As we saw in the recent US v Google decision experts are teaching courts and the public that pre-installation and "default settings" are in effect a means of control. In theory, any software or "feature" is a "good idea" as long as no one is forced or tricked into installing or using it. In practice, so-called "tech" companies strategically pre-install and remove or obfuscate consumer choice.
- aurareturn 2y agoI want an LLM to ingest everything I do - on device.
- TiredOfLife 2y agoThats is literally what Recall is.
- aurareturn 2y agoBut I want a GPT-4 level LLM using that data.
- tarruda 2y ago> I'm looking forward to something like this, but local, FOSS and for Linux. This will probably happen soon, but I wonder what are the disk space requirements for saving screenshots of everything you do
- 4k93n2 2y agoi would imagine even a version of this idea where the screenshots are deleted after being ocr'ed and analysed would still be useful enough
- DaSHacka 2y agoI assume the screenshots are converted into a textual description quite quickly, so presumably the only disk usage would be screenshots in the buffer waiting to be processed.
- bsmartt 2y agothis isn't the case, both are stored. microsoft's website has a number of pages about the feature.
- moogly 2y agoNever once have I wanted to do this. Now that I know it's possible, I still cannot think of a valid use case for me.
- bsmartt 2y agowould you enable it when interviewing candidates for your team. so when you go to complete your assessment you can go back to something they said or some code they wrote?
- moogly 2y agoNo, we do interview assessments later in the day, or first thing the day after, plus we don't do live coding during interviews. Recall is just screenshots too; no audio. If we thought we needed to go back and scrutinize what someone said, we'd record the interview, but we don't.
- laserbeam 2y agoIf it happens on a remote server, I ain't using it. If I can control the server or it's running locally, then it's not a horrible idea.
- renegat0x0 2y agoRecall, even if run locally, is a security and privacy nightmare. Imagine all of your activities and data stored on one database. It was discussed many times by security experts.
- vachina 2y agoAs opposed to everyone’s database on a single prem/management plane?
- bsmartt 2y agoit really isnt as bad as people on twitter say it is. msft is easy to throw shade at, and a lot of bandwagoning. trust me, im an expert.
- compsciphd 2y agothe same argument applies to browser history, password managers and lots like them. Yes, they make it easier for an attacker to scoop up info (a central place with lots of juicy info), but they also make your life so much better overall. Most people use them, some heavy privacy/security oriented people don't. Even many of those of us who are conscious about the security/privacy issues, use them because we find their use outweighs the risk. I can't answer what will happen with a recall type feature, but one has to weigh the value vs risk. Personally, I'm not sure of the significant value (then again, in being really analytical, I'm now unsure of the significant value of the browser history). How often is one going to dig into recall recorded state. This same logic applies to browser history, how often does on really look at it? It provides 2 forms of value, 1) showing what you already clicked (i.e. a constant low level value) and 2) being able to find URLs you know you saw, but can't seem to find at the moment (a higher value, but much rarer, similar to recall value). Are these valuable enough? I'm wondering out loud if the first value (of showing links you already visited) could be solved in a more privacy friendly manner of a 1 way hash of url with salt. Store the hashed URLs instead of a the URL string itself. Even if an attacker vacuums up your "history database", all they get is a bunch of hashes. Even if they get the salt, they would have to hash their entire dictionary of URLs against the salt. (A counter argument is that the set of URLs in the dictionary they would want to hash against to blackmail you, might not be "so big" and hence tractable, so this doesn't gain you much).
- bsmartt 2y agoI got downvoted and patronized pretty hard in a thread a while back for pushing back (as much as I dont ever want to defend microsoft). https://news.ycombinator.com/item?id=40595344 https://news.ycombinator.com/item?id=40595344 I think it got shipped a bit hastily, but also dont think hackers will find it more attractive than dropping keyloggers, banking trojans, or ransomware. And screenshots can be photoshopped, so I don't know, I really doubt anyone will care to flip through 25 gb of screenshots. Also, I'd be interested in a feature like this enabled while interviewing candidates as well as interviewing with potential employers, or while taking courses online, probably a lot of stuff ive not yet thought about too.
- dgellow 2y agoI really want to try out before dismissing the concept. If implemented correctly that could be fantastic. But I can also see how employers could abuse it by forcing the feature on employees devices.
- bsmartt 2y agoi really don't see this being used in the enterprise environment. first off, employees without a need for an NPU probably wont be given one. its like who right now is giving out hardware to employees with sick graphics cards? i don't think anyone. There are much easier ways to spy on your workforce already, like deep traffic inspection.
- hnlmorg 2y agoEmployers can already track every activity on an employees device if they wanted to. If anything, I think employers are more likely to opt out of Recall because of security fears and cost of hardware rather than replace existing device management tools with this
- luismedel 2y agoIdea (ok) vs execution (crap)
- mschuster91 2y ago> but the core idea of being able to see what happened a week/month ago and process it using LLMs looks really useful By definition, it's not only you who can recall what happened a month ago, it's also the cops, burglars, your partners, your children... everyone with access to your machine now has access to everything you did.
- ethbr1 2y agoDo I trust Microsoft, in its current/recent form, to implement this feature, including the ways it is likely to evolve? No. Even if it's built in a fully-local, privacy-first manner, I have no confidence it will stay that way. Microsoft has shown itself again and again to prioritize turning Windows into an ad platform, over sound technical decisions. Why would this be any different?
- mrinfinitiesx 2y agoIt won't be any different. My guess is they'll pull some stunt like Mozilla is with the Anonym with the PII removed to send data over to further turn Windows and Office 365 in to more of an ad platform. I could be ignorant. I could be paranoid. I could be wrong. I want to be wrong. But I don't think I am. And you aren't either. That's what's scary.
- bsmartt 2y agoi think you are wrong. they are trying to convince the average consumer that they need this new laptop with special hardware because they have exclusive magical features (read: OCR) like windows recall. theyre making it intentionally exclusive and locally computed specifically to brag about new capabilities.
- ethbr1 2y agoToday. And when this feature exists on all machines, and Microsoft has access to the codebase, you don't think other portions of the company will pitch a "+X revenue if we just used it for Y" re-use of the existing data? Most of Google and Apple's recent user-hostile decisions can be traced directly back to too much potential revenue to refuse (ad tracking data, app store lock-in). Microsoft isn't immune to those same strategic marketing pressures. Some data is too tempting to use for evil, that the only sane approach is to ensure there's no centralized manner to access it at scale.
- bsmartt 2y agoi mean... no one is going to convince you of anything if youre speaking of some hypothetical future possibility. But at least acknowledge theyve improved on security. Defender is included with windows, theyve been steady shipping significant and effective protections like device guard and smartscreen. and maybe you hate edge, but it unquestionably better than IE. i can't defend the heavy marketing and ads in windows 11 other than to say power users can disable that shit entirely. If that isn't good enough, then i think youre right and probably won't ever be one of their customers. thankfully there are other choices though :)
- torginus 2y agoYou are the only one. It's mass surveillance and it's used to train their neural networks to be able to automate people out of their jobs. No matter what 'guarantees' they offer, they're just an update and group policy setting away from removing them. Maybe they'll offer 'Recall Enterprise' for company owners, and normalize employers spying on their users while selling them the sales pitch of automating away their employees. If it was a genuine value add, it would be a boxed product, possibly made by a third party, that people would pay money for.
- chii 2y ago> Maybe they'll offer 'Recall Enterprise' for company owners, and normalize employers spying on their users while selling them the sales pitch of automating away their employees. That would be fine, as long as the employees are told ahead of time and is part of their employment contract (which i assume would be, because software such as crowdstrike already would be just as nominally intrusive). As for non-enterprise windows users, this should be at best an opt-in feature. Otherwise, it would be a huge breach of privacy.
- bsmartt 2y agoi get the impression you aren't much aware of the existing ways employers monitor activity of their workforce at scale for both windows and mac users without needing to browse through GBs of screenshots on a regular basis.
- username81 2y agoAs I said, I think the idea is good, not the implementation that relies on Microsoft's servers.
- Ukv 2y ago> it's used to train their neural networks Is it? I thought the screenshots were stored and analyzed locally. This seems like something that can be verified with Wireshark. If you mean they could sneaikily update Windows in the future to start sending screenshots to their server - I feel they could do that regardless of whether or not this local search tool exists, and it'd still get caught almost immediately. If anything, it'd seem counter-intuitive to draw lots of attention/scrutiny through marketing this feature.
- cybrexalpha 2y agoThe whole concept is so fundamentally flawed that no amount of tweaking or improvement can save it. Of course the implementation is terrible, but even if the implementation was perfect it would be awful. Even if it ran locally-only, even if the implementation were pure free software, even if the LLM used was guaranteed to operate in your best interest. Even then, we're still talking about a perfect surveillance engine that allows any future person to observe your behaviour across your past. Imagine what it would mean for the police to retroactively search your entire life for the past 30 days when they arrest someone. Or how this might affect people living with abusive partners, or LGBTQ+ kids in non-supportive households. This technology, no matter the implementation, puts vulnerable people at risk.
- talhah 2y agoEveryone has different threat models, vulnerable people don't need to use such a feature, assuming that it's all local and implemented perfectly. It should also be opt out by default for Microsoft. I personally see a lot of use for this if it was running entirely local. I always find myself in a position where there's things which I've browsed or come across but it's difficult retrieving it from my history.
- superb_dev 2y ago> assuming that it's all … implemented perfectly. As long as this impossibility is achieved, we’re good!
- garblegarble 2y ago>vulnerable people don't need to use such a feature Vulnerable people often do not have a choice in the matter. Pre-installed, widely-advertised features are significantly more dangerous because somebody who is controlling isn't necessarily thinking of new ways to monitor, but they'll sure take advantage of any they know about. It's the same problem as Apple's AirTags: GPS trackers existed long before them (and are harder to detect), but you can get a 4-pack of AirTags at the store and they're super easy to use.
- username81 2y ago
- kkfx 2y agoThe old memex https://en.wikipedia.org/wiki/Memex https://en.wikipedia.org/wiki/Memex concept is a different thing and most important a thing is owning the system, another is having a limited usage license with a black box de facto at the vendor mercy. Personally I have no memex alike, but I use versioned org-mode notes for anything, meaning my NixOS boot into EXWM with the daily note opened and that note is partially auto-generated to summarize things I might want to see in a single place, NixOS config itself as Emacs config are org-mode notes as well, so it's a kind of full-text-searcheable base with history as well. I've not automated things like Firefox places.sqlite and other data source simply because it's too long to being worth the effort and way to specific and might change "suddenly" following upstream decisions, but essentially that's enough for my needs and I've chosen daily notes model for a reason: I still generate too much "noise" to keep an useful and clean note-base. Chronological division allow to keep the noise "might be useful in future" without polluting too much, collecting screnshots like Recall it's definitively way too much for personal usage, while might be a nice mine of behavioral data for deep analysis on someone else CPU and storage...