Microsoft’s Copilot+ Recall: This is a bad idea!

preview_player
Показать описание
Episode 331 of the Shared Security Podcast discusses privacy and security concerns related to two major technological developments: the introduction of Windows PC's new feature 'Recall,' part of Microsoft’s Copilot+, which captures desktop screenshots for AI-powered search tools, and Slack's policy of using user data to train machine learning features with users opted in by default. Tom and Kevin express significant concerns over the implications for privacy, data security, and the potential for misuse of these features. Discussions cover the technical workings, potential vulnerabilities, and broader impacts of these technologies on privacy and security. The episode also mentions anecdotes that illustrate the practical downsides of such technologies and hints at the broader trend of companies training AI models with user data without adequate transparency or consent.

00:00 Introduction
01:21 New Shared Security Stickers
01:44 Exploring Windows PCs' New Recall Feature: A Privacy Nightmare?
02:23 The Potential Dangers of Microsoft's Recall Feature
12:20 Slack's AI Training on User Messages: A Privacy Invasion?
16:25 Concluding Thoughts
16:51 Episode Wrap-Up and Final Remarks

Show notes and links mentioned during the episode:
____________________________________________

Shared Security is your premier cybersecurity and privacy podcast where we explore the bonds shared between people and technology. Stay informed and take control of your online security and privacy in today's interconnected world. Hit that subscribe button for more great content each week!

🙏 Support and follow the podcast 🙏

🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT!

#podcast #cybersecurity #sharedsecuritypodcast #sharedsecurity #technology #privacy #cyberthreats #vulnerabilities #ai #aihype #copilot #copilot+ #recall #microsoft #windows #badidea #slack #policy #llm #aitraining #machinelearning #ml #chat
Рекомендации по теме
Комментарии
Автор

The reception of recall has been chilling. Such a concept should be universally condemned. People seriously believe a profit driven entity like Microsoft WONT take advantage of BILLIONS os users information refine their AI models just because they said they wouldnt??? People are so naive!

rdtext
Автор

We, the NSA, CIA, FSB and the MSS, want to take this occasion to solemnly thank Microsoft for its service and dedication to our organizations. It really makes our work so much easier.
Just imagine all the people we can now destroy with the help of this tool. This is a dream come true. Thank you, Microsoft, thank you so much.

andreasplosky
Автор

Hal 9000 "I'm Sorry, Dave" 2001: A Space Odyssey (1968) a classic move.

TOSStarTrek
Автор

All I see is more features that I never asked for and have no use for and are turned on by default... Which means I have more work going in and trying to turn it off and finding out the button that says turn off doesn't actually turn it off, so I open up the registry and waste a few hours. Just like Cortana and Microsoft news feeds etc. Meanwhile I just did a clean install of Windows and had to spend 2 days fixing DirectX because the installer reported an error and wouldn't complete (on a clean install!).

clouds
Автор

I switched to macbook recently and thinking of switching back to windows in a couple of years but this copilot thing pretty much killed that idea, i will probably move to linux once my macbook dies

sivavarma
Автор

Pure speculation but... is it possible that MS management did hope for this kind of security shitstorm cause they actually aim something that they dont want to be acknowledged in the public yet?
Just imagine the many CEOs in corporations who think that machine learning should be able to reduce the administration staff a lot cause they usually do a lot standard work. This is an important step to get information for systems to learn about the working processes in real environments. And when the worker protection by law is low they very fast can implement it without telling the worker.

And where the workers are protected... you could just create a new business. People will offer to work for a company for a shorter period of time but with high payment to explicitly train the system after learning the workflow in a company. The "new" colleague even doesnt have to tell the other people in office that he is actually an A.I. trainer.
I really dont think that MS didnt see the huge critique about security coming. I think they wanted the public to focus on this. So they can make the system optional and/or do other changes. But the real goal is to create a business model to put their A.I. into companies as white collar robot - and therefor the systems have to be trained within the real work environment.
And THIS is in my opinion the first huge step to offer this kind of service.

BoothTheGrey
Автор

What is there anybody paying attention to what Edward Snowden was saying?

bernl
Автор

Instead of filling up the HDD/SSD with updates, LOL, we fill up the disk with screenshots...TBH I was just previewing a PowerPoint presentation when the mouse disappeared, thank you co-pilot, I asked it to save it and gave it a name, it said sure, and did nothing, thanks co-pilot.

mtjoy
Автор

if my emails and communications can be read by the recipient, then my communication data is also on his recall database. it's just not on my computer anymore.

dougholtz
Автор

The data is stored and most likely encrypted using the TPM, and Microsoft doesn't have access to those keys. They're hard coded by Intel and AMD.
So, the best attack someone can do is pull the public key but will never decrypt it as it's RSA 2048+.
You'll need to create malware to scrape the data from memory before encryption.

honestlocksmith
Автор

11±09 nice music by City Night - Sonic Zone

shifureisaikyou
Автор

im looking forward having Recall, there is another company called Rewind that does it but only on mac and just like earing aid helps your hearing, recall helps for memory. Just have a bunch of crypto on your computer and if it goes missing know you have been hacked

tycn
Автор

Well, this feature is going to ban usage of Windows in European Union. Just look at laws, especially labour laws.

SasaJ
Автор

I have dumped Microsoft software totally. Enough is enough. Stuff you SatNad/

tonywise
Автор

I didn't even think about it from the domestic abuse angle. The more you think about this the more disgusting it gets. I wish there was an Apple like alternative without the absurd Apple tax but with the compatibility of MicroWank.

Linux unfortunately is not there yet I don't think but happy to be proven wrong.

Cleisthenes
Автор

Fake show with generative AI...one of many... but valuable information (sarcasm)

karljohnson