10 ms·
It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database, and tracks what you do for the l
by herf 2y ago
It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database, and tracks what you do for the last 90 days. It's just a bit less visual, Incognito/Private modes work, and some users clear it more often.
But a whole lot of the surveillance attacks people imagine about Recall apply just the same to the browser. I think it's the "little brother" casual attacks that are so well enabled by Recall - it makes it faster, easier, and way more visual.
- EGreg 2y agoBrowsing history doesn't contain what's displayed on the page, and what you input into the input boxes, or POST requests. It's sorta like telephone metadata. On the other hand, I am always freaked out by Chrome extensions that "can read and change your data on all websites". Can't they have more granular permissions? You gotta have a lot of trust for those extensions LMAO. They can read your bank passwords, probably!! And if they are ever sold...
- herf 2y agoExactly - knowing the content of each webpage is pretty easy if you're "big brother" surveilling millions of people, even more so if you have a Chrome extension to help. It's "little brother" that benefits a lot here: bosses, spouses, parents, etc., who otherwise wouldn't click on 1000 links in your history.
- ls612 2y agoTo be fair for me the extensions that get that are uBO, Privacy Badger, and Tampermonkey. I trust gorhill and the EFF to not fuck me over on my data, and Tampermonkey kinda needs those sorts of permissions to work. My password manager has read access to every website but I'm already trusting it with all of my passwords so...
- EGreg 2y agoSeems like a very juicy target. These extensions should not store any data without a master password that you input every time. What if someone stole the signing key, and submitted an update to Chrome store, even for a little? Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate. If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later.
- ls612 2y ago>Oh wait that is only for Chrome Apps. For extensions, they can literally update themselves anytime. Someone would just have to steal the certificate. Mozilla reviews signed extension updates. Something tells me uBO is one of the most scrutinized given how very many users it has. >If an extension that reads all data uses a CDN (like CloudFlare) that CDN can execute a MITM attack against it and download new code, that would he catastrophic even if it was caught 1 day later. My threat model doesn't include state actors targeting me specifically. Not sure much of anything works against that threat model besides maybe iOS in Lockdown Mode as your only device.
- EGreg 2y agoExtensions can simply download and update their own code, eg by loading new stuff from localStorage. I have seen Metamask update itself randomly, and it has access to read every website
- ls612 2y agoCrypto wallets in web browser extensions seems like an absolutely terrible idea compared to any of my example.
- red_admiral 2y agoI have an extension like that called uBlock. If that ever gets compromised or sold, I will have much bigger problems ...
- immibis 2y agoYes, they can change it, that's what Manifest V2 deprecation is about. It will break a lot of ad blockers, because they rely on being able to read anything and change anything on all websites. Many people feel that Google is doing it to make more people watch more ads, not to improve security.
- Analemma_ 2y agoYeah, I think this entire debate is uninformed hysteria and manufactured outrage. "If an attacker has administrator access, they can see everything you have done on your computer!". OK? That has literally always been the case? "Attacker is root" is game over and always has been. The original writeup from DoublePulsar tried to justify that Recall is somehow different from other such scenarios, but I found it totally unconvincing. I think it's the right move to have it off by default, but I'm just not convinced by the outrage here.
- mostlysimilar 2y agoRecall FEELS like being watched. Your browser history does not.
- listenallyall 2y agoTo be clear, I am not in favor of Recall or dismissing its intrusiveness. However, the correct comparison is not just "browser history". Google is also tracking your search history, passwords (built-in password manager), location history (Google Maps), ad clicks, and more. All-in, it's a LOT of data.
- mostlysimilar 2y agoI'm with you -- I avoid Google products for the reasons you listed and am staunchly anti-surveillance capitalism. I just meant to say that even for a person with my very plugged-in perspective on these topics, Google's violations of my privacy still don't feel quite as invasive as Recall feels, even if on paper it's just as egregious and dangerous.
- Tool_of_Society 2y agoBrowser history doesn't show my passwords, everything I typed out and did on the machine. In comparison browser history is nothing.
- Analemma_ 2y ago
- andrewmutz 2y agoIf there's AI involved, everyone's panic level skyrockets. No one retweets "Attacker gaining root access reveals all user information", but instead "Attacker gaining root access reveals all user information collected by AI program" will go viral for sure.
- ydnaclementine 2y agoDoes Recall run entirely locally? I don't think your browser history gets sent out
- toyg 2y agoI expect it does, if you're using Chrome outside of Incognito Mode. Iirc, there is an opt-out about "web history" on the google account - which then disables some other things so that it annoys enough people into keeping it on.
- juancn 2y agoIt does, that's why it needs an NPU to run.
- al_borland 2y agoIt does, but who's to say insights in gains won't ever be sent back and used/sold?
- layer8 2y agoThe vulnerability is that the first thing any malware that happens to run on the PC will do is upload the Recall database, giving the attacker your entire usage history since installation (and of any other user account on the same PC). This can then be analyzed for worthwhile targets for scams and blackmailing.
- navjack27 2y agoMy browser history does. It's synchronized with every edge instance that I have running. I can open up the tabs from my mobile browser on my desktop and I could see the browser history from everything on everything.
- russdpale 2y agono it isnt the same, you may know I went to my health care provider's website, maybe even to make an appointment depending on the url, but with recall, everything that is on the page will be stored, not just the url. It's totally different. So the message I sent my healthcare provider that is discussing some of my most sensitive medical issues will be available to read and a record is kept of it... not just the url. Do you not see the difference?
- herf 2y agoYes, but one product cycle and there's metadata (like a background texture) that tells the OCR to skip this page. Or ask your local LLM if the user is talking about medical conditions? If you like the feature at all you can make these things work.
- entropicdrifter 2y ago"If you like the feature at all you can make these things work." It's not on the individual users to take steps to preserve their basic human dignity. It's not Microsoft to not take that dignity away by default as was their plan before this fiasco predictably blew up in their faces just like the Xbox One always-online Kinect requirement before it.
- deleted 2y ago[deleted]
- tracerbulletx 2y agoDon't worry it's ok if you don't want to use Recall, someone will just get that information by hacking your provider anyways.
- biftek 2y agoYour browser history doesn't contain screen recordings of what you do on websites
- nyrikki 2y agoTheir is a very different scope at the OS level. Most of us know that the public Internet is based on surveillance capitalism, no matter if we hate it or are just complacent or ignorant. OS wide is far more problematic and of low value to the user.
- GordonS 2y agoYour browsing history is unlikely to contain personal information, secrets, porn images etc. And if you use Chrome, they get your full browsing history by default. I get your point, but Microsoft's Recall can capture anything onscreen - emails, personal info, porn, passwords and the like. And it feels, bizarrely for 2024, that little thought has gone into privacy or security.
- axus 2y agoIt's analogous to phone call metadata vs. the contents of the phone calls.
- GordonS 2y agoYes, it's a good way to put it. Though it's worse in some respects, since AI will add "context" to the "contents" too.
- giobox 2y agoPerhaps. A key difference though - history files can include the individual pages I requested from the same host. Right now I have like 50 entries for the various posts I read just from HackerNews, all as separate line items etc etc. In the case of the phone, one simply sees recipient of call, duration etc, regardless of how much information was exchanged. The phone I'm calling is arguably analogous to the server I request a page from, in the metadata context. I'd argue browser history is significantly richer in some regards due to this. It's not unheard of for user identifiers to appear in URL paths either - try visiting https://news.ycombinator.com/user?id=<HN https://news.ycombinator.com/user?id=<HN user name>... In my Chrome, that's instantly in the history file with my username.
- BoredPositron 2y agoIt won't save your passwords in clear text though.
- deafpolygon 2y ago
- torstenvl 2y agoThey're quite obviously very different, as browser history doesn't tend to include things like financial details or information subject to an NDA.
- sho_hn 2y agoThe browser history may not, the cache and other local storage may well. The take-away is simple though: Modern desktop operating systems need a security model where individual applications are sand-boxed and protected from each other. Legacy systems have security models that protect users from each other, but this isn't the personal computing world we live in anymore.
- torstenvl 2y agoOnly if major browsers are disregarding HTTP cache headers, which is a pretty major allegation. Do you have any evidence to support that?
- sho_hn 2y agoYou're assuming that all sensitive information is served with sensible cache policies. There's a lot more websites than browsers.
- XlA5vEKsMISoIln 2y agoThis doesn't make Recall any better.
- juancn 2y agoThe ickier parts are on the unintended capture side, like enabling "show password" on a site doesn't affect browser history but Recall may capture it in the clear. Or from history you may see that you accessed a site, but not what you did on it (what comments you typed for example).
- byteknight 2y agoThis is a horrible comparison. Browsing history doesnt show the contents of the page. It doesnt show you what you were doing on that page. It doesn't reveal anything other than you went there and maybe how long.
- nottorp 2y agoWell, on old school sites where there are static pages each pointed to by an unique url, yes it does show the contents of the page :)
- powersnail 2y agoPublicly available content, yes. But not the content entered by the user themselves (security question answers, for example), and not contents behind a login, which is usually the case for sensitive information. Screenshots capture them all.
- deleted 2y ago[deleted]
- jasonfarnon 2y agoIt's like the difference between sniff https and http traffic
- neilv 2y agoOne difference is that Web browser history has been there 30 years, since before most people at the time had even touched a Web browser. At the time, it wasn't very thinkable that someone would have the audacity to take and abuse that information. It dates from when Internet people overall were more savvy about privacy than users overall today are, but it was also when the Internet was closer to a trustworthy environment, and before Wall Street sociopath types took over the tech and the culture. Lots of kinds of abuse that today are routine and almost universal, for even startup tech companies, (e.g., embedding third-party trackers into Web site, and getting even worse from there), I think would've gotten them ostracized, and outraged demands for criminal charges. During the dotcom gold rush, there was such a flood of totally new, posturing people, and so much money being thrown wildly at everything, that any remaining outrage was lost in the noise. And now virtually no one knows any different. But if you're trying to push some new abuse today, I think ordinary people are starting to have some awareness of what vicious sociopathic buttholes tech companies have become, and so acceptance might not be a slam-dunk.
- usrbinbash 2y ago1. Browsing history doesn't show what the user is doing on the page. There is a big difference between logging "user visited his e-banking app", and logging his actual credentials as they are entered. 2. Browsing history watches one app. Screenshots watch everything across the entire OS.
- kenny11 2y agoNot just credentials - account balances, account numbers, etc. There's a big difference between your browser history recording that you opened your bank or healthcare provider's web site and Recall recording everything that appeared on the screen while you did. People might use Incognito mode to browse porn, but I imagine it's a lot less common when looking at other sensitive sites.
- epanchin 2y agoTalk on zoom to the wife while bathing the kid, stored on recall. VC the girlfriend, stored on recall. Does your browser history store pictures of your family?
- deleted 2y ago[deleted]
- 1vuio0pswjnm7 2y agoContinuing with the comparsion, Recall applies to the entire operating system not just one application. To avoid it, one has to avoid Windows. Whereas to avoid browsing history, one only has to avoid the popular, graphical, advertising corporation browser. As I am not interesting in graphics, I do this everyday, with ease, because there are countless clients besides "Chrome/Safari/Edge" that work with the www for consuming information.
- lxgr 2y agoAt least on macOS, I can't navigate to the directory holding Safari's data with other apps (without special full-disk read permissions). There's also always private browsing, which exists specifically because people are aware of the implications of a browsing history and a persistent cookie jar. That awareness will be much harder to build for an always-on screen recorder.
- justinclift 2y ago> It's interesting to compare this to the Chrome/Safari/Edge browsing history, which is stored in an unencrypted SQLite database ... Recall seems to be storing its info locally in an unencrypted SQLite database as well. At least, that's according to the instructions here on how to access and view the contents: https://www.heise.de/en/news/First-experiences-with-Recall-9750408.html https://www.heise.de/en/news/First-experiences-with-Recall-9... From the submitted article, it seems like Microsoft will change/secure the access (and maybe storage) in some way, though there's no details on the specifics.
- LoganDark 2y agoI hate that most browsers do not let you set them to keep history for longer than 90 days. I want to be able to find things I've seen before. Recall would've been great if using it didn't require me to update to a version of Windows that contains "Copilot".