Windows file may be storing passwords and emails
zdnet.com
zdnet.com
The WaitList.dat really does seem like a legitimate threat to security and privacy. I don't currently have a touch device to test the including Powershell script, but I'd be interested to hear what others find.
I actually understand why Microsoft is recording this information (since it helps them understand the user's sentence structure/words, to make recognition more accurate) but it is also a huge treasure trove of personal information that many wouldn't have been aware of.
I wonder if there is a way to store this information more securely?
Would text from random documents or emails on the system improve the recognition of handwritten text by a specific user?
https://privacy.microsoft.com/en-us/windows-10-speech-inking...
The argument could be made that Microsoft should do a better job to secure this file on your PC, but since if you're letting them create this file, they're sending all this data to the cloud anyways...
What about those that are ignorant? They may be ignorant about the implications of having personal data collected. They may be technically ignorant and thus unaware that they can turn off this feature. In the end it doesn't matter because the vast majority are, and arguably will remain, ignorant. Is there privacy no less important?
Features that collect personal information should always follow an explicit opt in policy to protect the ignorant. If companies are concerned that too many people will leave these features off then they need to take the steps required to educate the end user.
https://github.com/B2dfir/wlrip
There may be other files that read this, but it was found with a quick search.
> text from every document and email which is indexed by the Windows Search Indexer service is stored in WaitList.dat
> This doesn't include only metadata, but the actual document's text.
Edit: also a quick google shows that the existence and purpose of the file has been public knowledge for at least two years.
Yeah, there's a bunch of stuff on the Internet that's in the public, but actually isn't.
I use Debian, which is generally considered to be pretty stable and sane, and yet I've still spent tens and tens of hours dealing with issues that simply aren't a problem on Windows or Mac. Currently I'm fighting what I think is a DPMS issue where my external monitor wont wake up from the laptop dock after the monitors all sleep.
Ultimately, I think it's a price worth paying for the experience and flexibility I want, but it's very head-in-the-sand to pretend that it's not just as expensive as Windows, just you don't pay in cash.
I wouldn't actually disagree, except that you seem to be implying that Windows is better. Especially with their increased rate of bugs in some recent updates, I'm not convinced.
It indexes documents on the disc that are already plain text.
It only stores sensitive data if the user had sensitive documents on the disc that were then indexed.
Everything about this seems to be trying to froth up outrage. Scary clickbaity headline, check. Quotes from named 'experts in the field', check. Embedded tweets showing how to 'expose your password', check.
From the perspective of a non-technical user, the format reads the same as an article on a major data breach. And yet we wonder why we have a hard time getting users to pay attention to real security problems.