Windows AI feature that screenshots everything labeled a security 'disaster'
theverge.com
theverge.com
Maybe for you. Sincerely, the NSA. /s
Rather this seems like a giant security hole, I'm almost certain that my company would permanently disable anything like this on our computers and I'm sure we're not the only ones.
Oh, ha, if a company is under some kinds of investigation, could they be instructed not to disable this record-every-little-thing feature on any company Windows computer?
Finally, it's the year of Linux on the desktop! :)
Microsoft can not be trusted anymore because regulators failed in the past to properly punish companies for dirty behavior.
Obviously unforeseeable and not at all a feature implemented rashly in a clever but fragile manner.
https://www.reddit.com/r/Windows11/comments/1bh7n4d/how_do_i...
It still goes without saying that without a resounding "I understand the risks and still want to use this inherently insecure feature" things like these should not be enabled by the OS manufacturer / vendor.
Actual article: https://doublepulsar.com/recall-stealing-everything-youve-ev...
More discussion: https://news.ycombinator.com/item?id=40540703
What's the plan, encrypt the data a public key where the private key is locked most of the time? Require a passphrase any time you want to read or process it? Does anyone think that UX will fly? Maybe there's some TPM magic that makes it work without also making it trivial to steal for an attacker who already has arbitrary code execution, but no one is citing that so far. I don't see the better design that everyone seems to think is obviously there. (Besides the obvious Just Don't, which is fair as far as it goes but has nothing to do with crypto)
Then it decrypts, presents to the user, and closes the handles when you're done. In this way, the "key" isn't present -- the user has it!
That's quite a different security situation to it just sitting around in plaintext on disk. Certainly there's a number of Windows and MacOS features sitting behind authentication already, from a UX perspective.
> "That could make it trivial for an attacker" (emphasis mine)
It _is_ trivial, right? The attack _is_ trivial. It's the solution that isn't. OP isn't claiming that. Seems reasonable to me.
I went back and reread https://doublepulsar.com/recall-stealing-everything-youve-ev... which is the first link in OP. Again, it doesn't have much to say about encryption at all except to point out that hey, the protections Microsoft is claiming are underwhelming. Without those protections the cost/benefit balance is way out of whack.
This kind of "vulnerability" has been a constant topic of his blog in the past:
https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31... https://devblogs.microsoft.com/oldnewthing/20181219-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20121207-00/?p=58... https://devblogs.microsoft.com/oldnewthing/20180227-00/?p=98... https://devblogs.microsoft.com/oldnewthing/20240404-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20240102-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20070807-00/?p=25... https://devblogs.microsoft.com/oldnewthing/20230206-00/?p=10...
> the feature is enabled by default when you set up a new Copilot Plus PC, and there is no option to disable it during the setup process
I predict this thing will be big, like Scripting Host and Outlook were in their day /s