• MangoKangaroo@beehaw.org
    link
    fedilink
    arrow-up
    28
    ·
    edit-2
    4 months ago

    I’m curious whether the increasingly invasive telemetry of modern Windows will have legal implications surrounding patient privacy here in the US. I work IT in the healthcare field, and one of our key missions is HIPAA compliance. What, then, will be the impact if Microsoft starts storing more and more in-depth data offsite? Will keyboard entries into our EHR be tracked and stored in Microsoft’s servers? Will we subsequently be held liable if a breach at Microsoft causes this information to leak, or if Microsoft just straight-up starts selling it to advertisers? Windows is our one-and-only option for endpoint devices, so it’s not like we can just switch.

    I genuinely don’t have the answers to these questions right now, but it may start to become a serious conversation for our department in the future if things continue at the trajectory they’re going at. Or, maybe I’m just old and paranoid and everything will be okie dokie.

    • SapientLasagna@lemmy.ca
      link
      fedilink
      arrow-up
      5
      ·
      4 months ago

      Like most of Microsoft’s more odious features, this one can be turned off through GPO/Intune policy across an organization. As such, the liability will mostly fall on the organization to make sure it’s off. The privacy and security impacts will be felt by individuals and small businesses.

      They claim that the data is only stored locally, so far. We’ll see, I guess.

      • MangoKangaroo@beehaw.org
        link
        fedilink
        arrow-up
        2
        ·
        4 months ago

        Sadly a lot of the privacy switches are exclusive to enterprise and education users, but our endpoints are running Pro (we have our previous supervisor to thank for that). I guess I’ll hope this is one of the ones we can just toggle off without any fuss.

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    26
    ·
    4 months ago

    That closing quote is ominous:

    “Recall is currently in preview status,” Microsoft says on its website. “During this phase, we will collect customer feedback, develop more controls for enterprise customers to manage and govern Recall data, and improve the overall experience for users.”

    I read “so, yeah, we built in all the telemetry connections we swear we’ll never use … just for testing, ya know?”

    • smallpatatas@lemm.ee
      link
      fedilink
      arrow-up
      19
      ·
      4 months ago

      more controls for enterprise customers to manage and govern Recall data

      ahh ok so this is employee monitoring software

      • klangcola@reddthat.com
        link
        fedilink
        arrow-up
        8
        ·
        4 months ago

        Probably more what MangoKangoroo and B0rax talked about, that enterprises can opt out of this telemetry, due to compliance or Intellectual Property protection.

        So only the commoners get mandatory full-scale surveillance, Ehm I mean “ai enhancement”

  • BmeBenji@lemm.ee
    link
    fedilink
    arrow-up
    21
    ·
    4 months ago

    Despite the privacy concerns, Microsoft says that the Recall index remains local and private on-device, encrypted in a way that is linked to a particular user’s account.

    Just like how Microsoft domain-bound emails were stored locally on machines running Outlook, right? Or how purchasing and downloading music, movies, and video games meant that we owned them, right?

    I don’t believe for a fucking second that this “feature” will remain locally encrypted forever. Fuck Microsoft, fuck the AI bubble.

    “Don’t be evil!

    wait, you say you’ll pay me to be evil? Well fuck that changes everything!”

  • Gork@lemm.ee
    link
    fedilink
    arrow-up
    19
    ·
    4 months ago

    As you might imagine, all this snapshot recording comes at a hardware penalty. To use Recall, users will need to purchase one of the new “Copilot Plus PCs” powered by Qualcomm’s Snapdragon X Elite chips, which include the necessary neural processing unit (NPU). There are also minimum storage requirements for running Recall, with a minimum of 256GB of hard drive space and 50GB of available space. The default allocation for Recall on a 256GB device is 25GB, which can store approximately three months of snapshots. Users can adjust the allocation in their PC settings, with old snapshots being deleted once the allocated storage is full.

    Oh no my computer doesn’t meet the hardware requirements whatever shall I do

  • Pete Hahnloser@beehaw.org
    link
    fedilink
    arrow-up
    18
    ·
    4 months ago

    I have to believe at this point that a serious generation gap exists if there is an audience for this sort of constant monitoring. Because that’s what it is.

    Where it goes and whether Microsoft can be trusted are of course very valid concerns, but Jesus tap-dancing Christ, this is surveillance before the data go anywhere. Add that to your AI assistant that works best with the camera on, et voila!

    No doubt Google is going to say “hold my beer,” and there’s no pure Linux offramp on the overwhelming majority of Android hardware, so even if you’ve told Microsoft to fuck off …

    • DaPorkchop_@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      4 months ago

      I would say the vast majority of people (across all generations) either don’t know, or don’t really understand how extensive it (the monitoring) is and what the consequences of that are.

      • mctoasterson@reddthat.com
        link
        fedilink
        arrow-up
        3
        ·
        4 months ago

        Just look at the number of normies who use Apple, Samsung, or vanilla Pixels as their daily driver. Unless you have a degoogled Android, all the major flagship devices are essentially surveillance and advertising powerhouses. People have embraced the willful ignorance part of this bargain. They think they need whatever proprietary garbage is offered by Apple, to the point that even their own privacy is too ethereal a concept to regret mortgaging it away in the tradeoff.

  • cobra89@beehaw.org
    link
    fedilink
    arrow-up
    17
    ·
    4 months ago

    How does this work with local laws regarding 2 party recording? If you’re on a video call and this records the other party without their permission, that is AFAIU illegal in many states in the US. I’m sure in parts of Europe as well.

  • floofloof@lemmy.ca
    link
    fedilink
    English
    arrow-up
    14
    ·
    4 months ago

    “Recall screenshots are only linked to a specific user profile and Recall does not share them with other users, make them available for Microsoft to view, or use them for targeting advertisements. Screenshots are only available to the person whose profile was used to sign in to the device,” Microsoft says.

    It’s conspicuous that this statement talks only about the raw screenshots, not any data derived from them (such as aggregated data, inferred data, or even just slightly reprocessed data). So Microsoft could do any minor reworking of the data and send it off to the cloud for their own purposes, while technically complying with the above.

  • Vodulas [they/them]@beehaw.org
    link
    fedilink
    arrow-up
    9
    ·
    4 months ago

    Good news , it is just on their Copilot+ computers for now. For now is likely doing some heavy lifting there, though.

    I threw Mint on a partition to test moving away from Windows, and sadly does not play well with my 2080ti. This makes me want to put more effort into getting it to work…

    • salarua@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      try $ sudo apt install akmod-nvidia. it’s gonna pull in some dependencies and a proprietary driver, and probably break Secure Boot if you have it set up, but that’s how i got it to work on Fedora (except i used dnf, of course)

    • Blisterexe@lemmy.zip
      link
      fedilink
      arrow-up
      2
      ·
      4 months ago

      There’s a lot of work going into nvidia on linux ATM, so its improving pretty fast, but Also you can get a faster amd GPU with the money you can get from selling your 2080 ti

  • MudMan@fedia.io
    link
    fedilink
    arrow-up
    8
    ·
    4 months ago

    I mean, no thanks.

    But they did this already, right? Their “Timeline” feature in Windows 10 recorded a log of your activities to display it in your Win+Tab menu screen. I switched it off immediately, but the point is this is a new approach to an old feature they have done in the past.

    Everybody must have turned it off, though, because it hadn’t been present in Win 11 until now. It’s still a dumb idea.

    • jcarax@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      4 months ago

      Wish I had a choice, at work. Technically I can run Linux or MacOS, but I’d need to run a Windows VM for a few things anyway.

  • eveninghere@beehaw.org
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    4 months ago

    Well, so, you use password generator, the password screenshot is saved.

    This makes most password generators useless because they show the password for user feedback. You can turn this MS AI off, but I will have no idea if there was a bug.