>events generated by the operating system, and your "inking and typing data."
Sounds like a key logger virus, but then built-in the OS? Is this for real?
>events generated by the operating system, and your "inking and typing data."
Sounds like a key logger virus, but then built-in the OS? Is this for real?
In reality you can bet there will be NSL's and other legal tools used to co-opt this stuff for more noble aims, like defending against terrorism and protecting our children via fishing expeditions and secret gag orders.
If you already have access to the things I type and my metadata includes the websites I visit, you don't really need to phish me to get my credentials.
If a service also happens to not support 2FA and doesn't have some sort of account activity section, you can effectively have control of me over that service, without me ever doing anything wrong and me not even suspecting a thing.
It's a consequence of the old security thinking where programs were installed by a "trusted administrator". Everything run by a user is assumed to be sound. The only way to prevent this is either aggressive limiting of features and sandboxing, like in the web browser.
(Any windows application running as the user can also remote-control and surveil any other windows application through windows messages.)
The only company that tries at all to respect your privacy is Apple. Google has a photo album with facial recognition and automatic tagging and the ability to search based on what the subject of the picture is, but it requires that you upload all your pictures to their servers so they can search through them. Apple does the same thing but the pictures never leave your device.
You'd never expect to see Microsoft or Google get up on stage and say "we're intentionally giving up an entire revenue stream because we respect your privacy". Instead they subsidize the cost of their software with privacy invasion and then brag about how much better value for the money their products are.