5 ms·
I find it interesting that searchable history of computer activity is a problem with enough interest that independent developers have worked on solutions themse
by doright 2y ago
I find it interesting that searchable history of computer activity is a problem with enough interest that independent developers have worked on solutions themselves, some of them open source. But a company like Microsoft ought to have much more resources such that they can fix these edge cases or realize they can't fix them all and design the service accordingly.
So I guess my question is: is a company as big as Microsoft that approaches this problem space doomed to fail from the start, because of the perception issues? Would this be any different if say Apple had developed a Recall alternative and they also found it impossible to censor credit card information in an arbitrary Notes window someone whipped up as an edge case, like in the article? Or could a stricter (outward) stance on privacy make it palatable again?
Suppose if everything were assured to be kept under enough layers of encryption and the data wasn't synced online at all, would storing a credit card number surreptitiously captured on my computer be seen as much better if it's Microsoft/Apple I have to trust to engineer their AI recall feature in a secure manner?
- alt227 2y agoI never heard anything bad about https://rewind.ai https://rewind.ai which was launched exclusively on Mac before Recall was, in fact it was praised.
- deleted 2y ago[deleted]
- int_19h 2y agoAs a third party app, most people haven't even heard about Rewind. Recall, by virtue of being a core OS feature - and the one enabled by default at that - got a lot more coverage.
- luma 2y agoOne major difference would be in how it is distributed. Rewind is an app you go find, install, and deploy. Not a lot of concerns around consent there. Building it into the OS, potentially default on, is the same sort of technology. It's not the same sort of consent.
- leptons 2y agoI do not want Microsoft snooping everything I do, I don't trust that they won't do it either intentionally or not, and it's the main reason I'm leaving Windows across all of my systems after 3 decades. It's all just too much.
- jazzyjackson 2y agoRewind made a big ballyhoo about being local, not reliant on cloud services, not syncing anywhere etc Windows 11 is practically a cloud OS when paired with office365 and OneDrive, users may be forgiven for expecting their history will be exfiltrated from their machine, employers will have access to their screen recordings etc.
- btown 2y agoEDIT: I may have spoken too soon on the below; I checked myself, and the journalist's test card numbers in the OP do not, in fact, pass the Luhn algorithm! So perhaps some grace is deserved. But I'm preserving my comment below, if anything to be illustrative of how companies should approach this, and that if you want your product to be secure from criticism from journalists who don't know how to make test credit card numbers, you should possibly use even more robust approaches than what one random person on HN comes up with in real time. === But these are incredibly solvable problems! If a series of digits on screen passes the Luhn algorithm (https://en.wikipedia.org/wiki/Luhn_algorithm https://en.wikipedia.org/wiki/Luhn_algorithm), or matches AAA-BB-CCCC, prevent that screen/area from being captured! And Microsoft literally owns the code for https://docs.github.com/en/code-security/secret-scanning/introduction/about-secret-scanning https://docs.github.com/en/code-security/secret-scanning/int... for determining other high-entropy secrets. We're not nearly at the level of https://xkcd.com/1425/ https://xkcd.com/1425/ - and even that canonical example has been entirely solved by now. The problem isn't that these things are fundamentally impossible. And the problem isn't even that Microsoft decided speed to market was more important than safeguarding their users' data - I get speed to market! The problem, allegedly, is that Microsoft said these things were fixed without actually fixing them [EDIT: see above], and didn't think that their users' data was important enough to assign a red team or even an empowered SDET to do even the simple tests this journalist did before making that announcement.
- geekinchief 2y agoFYI, seeing this comment, I went back and tested again with my actual credit card number and the situation was the same.
- therein 2y agoEven if you trust Microsoft not to keep it, not to access it and index it on their cloud, and even if they were kept encrypted and local, it is still searchable and index is available on runtime. So you have yet another process that has this unencrypted in memory. Great target for malware no matter what.
- deleted 2y ago[deleted]
- sensanaty 2y agoThere's a universe of difference between an individual choosing to install this kind of software of their own volition on their own machines (or making their own version as you pointed out), and the comically evil megacorporation that is microsoft forcing it on everyone who uses windows with no way of knowing if disabling it actually disables it, and with no way to trust a single word they say because, again, it's microsoft we're talking about. The same company that already phones home with egregious amounts of data for everything you do and see and shoves ads and other bloatware right into your taskbar which requires user scripts to temporarily disable before being reinstalled anyway on a system update. How anyone can have trust that rewind won't be misused is baffling to me, I wouldn't trust a Janitor at M$ to not sell their own family out for a 1% YoY profit increase, yet alone the engineers working there and their psychotic C-suite.