• Scrubbles@poptalk.scrubbles.tech
    link
    fedilink
    English
    arrow-up
    91
    ·
    6 months ago

    This is just a fucking privacy nightmare. We like to laugh and play here about Linux quite a bit, but holy shit this is the actual “If you’re using Windows and expect privacy at all, this is it, you should throw that notion out the window.”

    I don’t care how much encryption there is, or the assurance that it’s only on your hard drive, I’ve sat in too many corporate meetings in my career to trust that. There is no way Microsoft is just letting you have that data and they’re not reporting it out. Very least? They’re using ML on it to aggregate what it sees in the screenshot, and then saving that. Worst case, they’re saving it to an encrypted blob storage, calling that encrypted, and hiding deep in the ToS that you actually agreed to that (even though it said in the big letters it was local only, sorry woopsie in the small letters it said it’s also stored there.)

    Fuck, ignoring the obvious pron implications that I assume everyone here is immediately thinking of, think of HIPAA, think of the private communications with therapists that people have, think of all of the financial documents you’ve opened, think about bank accounts, chats, fucking everything.

    • Admiral Patrick@dubvee.org
      link
      fedilink
      English
      arrow-up
      43
      ·
      edit-2
      6 months ago

      Worst case, they’re saving it to an encrypted blob storage, calling that encrypted, and hiding deep in the ToS that you actually agreed to that

      And then it’s discovered that bucket was accidentally set to public for over 8 months. Oopsie daisy! But you can’t sue us because also deep in the ToS was a forced arbitration clause.

      Also, if you don’t agree to the whole ToS, you can’t use the computer you just paid for.

    • 👍Maximum Derek👍@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      20
      ·
      6 months ago

      But they specifically said in their blog post that it has “privacy you can trust.” Just imagine all the trust you have in Microsoft plus all the trust you have in the accuracy of AI and rest easy. Plus the AI runs locally so they can trust you to pay the power bill.

      Don’t think about how much money they could make with their business customers, based on telemetry alone.

      • applepie@kbin.social
        link
        fedilink
        arrow-up
        8
        ·
        6 months ago

        Yeah at this point you must assume that they are mining that data one way or another. Paying for windows license has no meaning practically speaking. And yet we pay and they mine…

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      18
      ·
      6 months ago

      I am so glad I switched to Linux 7 years ago. What an absolute shitshow Windows OS has become

      • applepie@kbin.social
        link
        fedilink
        arrow-up
        9
        ·
        6 months ago

        Yeah having made the switch a while back and really happy about it. Mega corps are deff tightening the screws and this is just the start.

        At this rate any self respecting adult will need to learn Linux lol

        Every other month microshit creates a batch of Linux enjoyers.

    • ulkesh@beehaw.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 months ago

      We like to laugh and play here about Linux quite a bit

      We do? Aside from the “I use Arch, btw” memes, I must not have got that memo :) And, uhh…I use Arch, btw.

      Fuck, ignoring the obvious pron implications that I assume everyone here is immediately thinking of, think of HIPAA, think of the private communications with therapists that people have, think of all of the financial documents you’ve opened, think about bank accounts, chats, fucking everything.

      So much this. I’m glad I dumped Windows and this just guarantees that I’ll never return.

    • EFrances@lemmy.eco.br
      link
      fedilink
      arrow-up
      4
      ·
      6 months ago

      Meanwhile in the EU

      Europe sets benchmark for rest of the world with landmark AI laws

      "“With the AI Act, Europe emphasizes the importance of trust, transparency and accountability when dealing with new technologies while at the same time ensuring this fast-changing technology can flourish and boost European innovation,” he said.

      The AI Act imposes strict transparency obligations on high-risk AI systems while such requirements for general-purpose AI models will be lighter.

      It restricts governments’ use of real-time biometric surveillance in public spaces to cases of certain crimes, prevention of terrorist attacks and searches for people suspected of the most serious crimes."

      <snip>

      https://www.reuters.com/world/europe/eu-countries-back-landmark-artificial-intelligence-rules-2024-05-21/

    • ugo@feddit.it
      link
      fedilink
      arrow-up
      4
      ·
      edit-2
      6 months ago

      if you’re using windows and expect any privacy at all […] throw that notion out the window

      Correct. And the same is true even if you are using linux, macOS, android, or a butterfly to manipulate bits to send a message through the internet.

      Because if your message ends up on the screen of a windows user, it’s also going to be eaten by AI.

      And forget the notion of “anything you post on the internet is forever”, this is also true for private and encrypted comms now. At least as long as they can be decrypted by your recipient, if they use windows.

      You want privacy and use linux? Well, that’s no longer enough. You now also need to make sure that none of your communications include a (current or future) windows user as they get spyware by default in their system.

      Well maybe not quite by default, yet

    • Ilandar@aussie.zone
      link
      fedilink
      arrow-up
      14
      ·
      6 months ago

      If you are new to Linux I would recommend buying a second drive or dual-booting for a bit just to ease into it. It has helped me persist with the transition because I always have the option of booting into Windows for a few hours if there’s something that I’m just too tired/frustrated to deal with at that given moment. Over time I’ve found myself booting into Windows less and less, to the extent that I’ll be able to drop it completely later this year without the big learning curve/wave of troubleshooting that I encountered the first time I tried to switch cold turkey.

      • Go-On-A-Steam-Train@lemmy.ml
        link
        fedilink
        arrow-up
        4
        ·
        6 months ago

        I can second this! For me it meant that I could finish my game of modded fallout new vegas, and connect to my work’s microsoft vpn nonsense (IT support didn’t fancy trying it on Mint but that’s another story!)

        I now have a personal OS that I like, and a windows partition for those few things that I can’t be bothered to troubleshoot.

        So far the list is just those things and the Unity Engine as Visual Studio debugs better than code in my experience. :)

        Having the option to flick back is great :) In the XP days, I loved the WUBI(?) tool that let you install ubuntu dual boot as an exe, but I think that’s not a thing these days., :)

        • Kaity@leminal.space
          link
          fedilink
          English
          arrow-up
          3
          ·
          6 months ago

          Currently playing fallout New Vegas modded on Linux! Of course if you already did it, remodding and transferring the saves would be frustrating, but it is actually pretty simple once you learn how to use Steam Tinker Launch.

          • Go-On-A-Steam-Train@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            6 months ago

            Oh fantastic! :) Thank you, next playthrough I will get things going on Linux in that case, as that’s new to me! :) Like a fool I tried nexus mods vortex in Wine initially because I didn’t know better!

      • petrescatraian@libranet.de
        link
        fedilink
        arrow-up
        2
        ·
        6 months ago

        @Ilandar this is a good solution . Another would be to just not jump ship head first, but rather replace everything wth FOSS alternatives instead if they’re not available on Linux (e.g.: replace MS Office with LibreOffice, Photoshop with GIMP or something else, etc.) and use them for a while. Most of the programs should also be available for Windows, and if not you could also use WSL to run them.

        Once you get used to these programs, the actual Linux transition should be easier.

        @Onii-Chan

        • Ilandar@aussie.zone
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          6 months ago

          Yes, that’s a great strategy and one I began before even transitioning across. I guess the only reason I didn’t initially mention it is because I’ve found many Windows users immediately switch off the moment you tell them they might need to consider non-proprietary apps and services. There are a lot of really solid and reliable workarounds these days that mean you can keep some of that Windows workflow if you really want to, so I feel like maybe it’s best to just let them try the operating system first and see how much they can get away with.

          • petrescatraian@libranet.de
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            6 months ago

            @Ilandar you’re right, I didn’t think about this. However I might add that there are still programs that do not function well even under Wine. For example, the latest version of Office is always problematic to set up.

    • maxprime@lemmy.ml
      link
      fedilink
      arrow-up
      9
      ·
      6 months ago

      Awesome! There are so many good communities on Lemmy for Linux noobs and enthusiasts! Be patient, and take snapshots!

    • Scrubbles@poptalk.scrubbles.tech
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 months ago

      As others said, trial and error, and patience. My two cents, as a Windows convert who likes to game, I did PopOS. If you have an nvidia card they have a version with the drivers baked in. Steam was relatively easy, there were only a few things I had to go to the terminal for. Now it’s my daily driver and I actually just uninstalled Windows a few months ago.

    • Blisterexe@lemmy.zip
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      Congrats, I’d recommend Linux mint. Feel free to DM me/reply to this comment if you have any questions

  • MangoKangaroo@beehaw.org
    link
    fedilink
    arrow-up
    45
    ·
    edit-2
    6 months ago

    I’m curious whether the increasingly invasive telemetry of modern Windows will have legal implications surrounding patient privacy here in the US. I work IT in the healthcare field, and one of our key missions is HIPAA compliance. What, then, will be the impact if Microsoft starts storing more and more in-depth data offsite? Will keyboard entries into our EHR be tracked and stored in Microsoft’s servers? Will we subsequently be held liable if a breach at Microsoft causes this information to leak, or if Microsoft just straight-up starts selling it to advertisers? Windows is our one-and-only option for endpoint devices, so it’s not like we can just switch.

    I genuinely don’t have the answers to these questions right now, but it may start to become a serious conversation for our department in the future if things continue at the trajectory they’re going at. Or, maybe I’m just old and paranoid and everything will be okie dokie.

    • B0rax@feddit.de
      link
      fedilink
      arrow-up
      18
      ·
      6 months ago

      I guess it will be like it was before, that there is a different version of windows for these use cases. Like Windows LTSC.

    • SapientLasagna@lemmy.ca
      link
      fedilink
      arrow-up
      6
      ·
      6 months ago

      Like most of Microsoft’s more odious features, this one can be turned off through GPO/Intune policy across an organization. As such, the liability will mostly fall on the organization to make sure it’s off. The privacy and security impacts will be felt by individuals and small businesses.

      They claim that the data is only stored locally, so far. We’ll see, I guess.

      • MangoKangaroo@beehaw.org
        link
        fedilink
        arrow-up
        4
        ·
        6 months ago

        Sadly a lot of the privacy switches are exclusive to enterprise and education users, but our endpoints are running Pro (we have our previous supervisor to thank for that). I guess I’ll hope this is one of the ones we can just toggle off without any fuss.

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    37
    ·
    6 months ago

    That closing quote is ominous:

    “Recall is currently in preview status,” Microsoft says on its website. “During this phase, we will collect customer feedback, develop more controls for enterprise customers to manage and govern Recall data, and improve the overall experience for users.”

    I read “so, yeah, we built in all the telemetry connections we swear we’ll never use … just for testing, ya know?”

    • smallpatatas@lemm.ee
      link
      fedilink
      arrow-up
      29
      ·
      6 months ago

      more controls for enterprise customers to manage and govern Recall data

      ahh ok so this is employee monitoring software

      • klangcola@reddthat.com
        link
        fedilink
        arrow-up
        13
        ·
        6 months ago

        Probably more what MangoKangoroo and B0rax talked about, that enterprises can opt out of this telemetry, due to compliance or Intellectual Property protection.

        So only the commoners get mandatory full-scale surveillance, Ehm I mean “ai enhancement”

  • BmeBenji@lemm.ee
    link
    fedilink
    arrow-up
    33
    ·
    6 months ago

    Despite the privacy concerns, Microsoft says that the Recall index remains local and private on-device, encrypted in a way that is linked to a particular user’s account.

    Just like how Microsoft domain-bound emails were stored locally on machines running Outlook, right? Or how purchasing and downloading music, movies, and video games meant that we owned them, right?

    I don’t believe for a fucking second that this “feature” will remain locally encrypted forever. Fuck Microsoft, fuck the AI bubble.

    “Don’t be evil!

    wait, you say you’ll pay me to be evil? Well fuck that changes everything!”

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    30
    ·
    6 months ago

    I have to believe at this point that a serious generation gap exists if there is an audience for this sort of constant monitoring. Because that’s what it is.

    Where it goes and whether Microsoft can be trusted are of course very valid concerns, but Jesus tap-dancing Christ, this is surveillance before the data go anywhere. Add that to your AI assistant that works best with the camera on, et voila!

    No doubt Google is going to say “hold my beer,” and there’s no pure Linux offramp on the overwhelming majority of Android hardware, so even if you’ve told Microsoft to fuck off …

    • DaPorkchop_@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      I would say the vast majority of people (across all generations) either don’t know, or don’t really understand how extensive it (the monitoring) is and what the consequences of that are.

      • mctoasterson@reddthat.com
        link
        fedilink
        arrow-up
        3
        ·
        6 months ago

        Just look at the number of normies who use Apple, Samsung, or vanilla Pixels as their daily driver. Unless you have a degoogled Android, all the major flagship devices are essentially surveillance and advertising powerhouses. People have embraced the willful ignorance part of this bargain. They think they need whatever proprietary garbage is offered by Apple, to the point that even their own privacy is too ethereal a concept to regret mortgaging it away in the tradeoff.

  • Gork@lemm.ee
    link
    fedilink
    arrow-up
    25
    ·
    6 months ago

    As you might imagine, all this snapshot recording comes at a hardware penalty. To use Recall, users will need to purchase one of the new “Copilot Plus PCs” powered by Qualcomm’s Snapdragon X Elite chips, which include the necessary neural processing unit (NPU). There are also minimum storage requirements for running Recall, with a minimum of 256GB of hard drive space and 50GB of available space. The default allocation for Recall on a 256GB device is 25GB, which can store approximately three months of snapshots. Users can adjust the allocation in their PC settings, with old snapshots being deleted once the allocated storage is full.

    Oh no my computer doesn’t meet the hardware requirements whatever shall I do

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    23
    ·
    6 months ago

    “Recall screenshots are only linked to a specific user profile and Recall does not share them with other users, make them available for Microsoft to view, or use them for targeting advertisements. Screenshots are only available to the person whose profile was used to sign in to the device,” Microsoft says.

    It’s conspicuous that this statement talks only about the raw screenshots, not any data derived from them (such as aggregated data, inferred data, or even just slightly reprocessed data). So Microsoft could do any minor reworking of the data and send it off to the cloud for their own purposes, while technically complying with the above.

  • cobra89@beehaw.org
    link
    fedilink
    arrow-up
    21
    ·
    6 months ago

    How does this work with local laws regarding 2 party recording? If you’re on a video call and this records the other party without their permission, that is AFAIU illegal in many states in the US. I’m sure in parts of Europe as well.

  • Fluid@aussie.zone
    link
    fedilink
    English
    arrow-up
    17
    ·
    6 months ago

    A lawsuit waiting to happen… someone needs to class action MS for systemic breaches of privacy. Think of all the critical infrastructure, government, medical, policing, etc. systems processing sensitive, private, and in some cases classified, information.

    • jcarax@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      Wish I had a choice, at work. Technically I can run Linux or MacOS, but I’d need to run a Windows VM for a few things anyway.

  • dumbass@leminal.space
    link
    fedilink
    arrow-up
    11
    ·
    edit-2
    6 months ago

    I open windows and it starts recording: opens Plex, plays Mash for 13 hours straight, PC closed down.