Security researcher discovers Microsoft's Recall tool is woefully insecure
windowscentral.com
windowscentral.com
> If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems. This is key to advancing both our platform quality and capability such that we can protect the digital estates of our customers and build a safer world for all.
https://www.theverge.com/24148033/satya-nadella-microsoft-se...
That could be orthogonal for a company as large and diverse as Microsoft for both to be true at the same time. Like certain more enterprise facing products like the windows kernel or Azure could be very secure, while others like these user facing Windows features, very un-secure.
In general I noticed that most new tools and consumer facing features dropping on Windows 11 are of terrible quality, as if they were written by some web-dev interns rather than engineers experienced in Windows programming.
Maybe if there's parts of the org that need to get all their mandates through MS Teams, I could see how that introduces unreasonable delays.
Hence why the Windows development experience has went downhill since he took over.
We might have a Microsoft <3 Linux, with a ton of FOSS products being on Microsoft's accounting list, however Windows is a shade of itself versus "Developers, Developers, Developers" days.
Recent example, Microsoft Photos team proudly presents their UWP to Windows APP SDK migration,
https://blogs.windows.com/windowsdeveloper/2024/06/03/micros...
Turns out they are now using WebView2 for the UI part.
https://doublepulsar.com/recall-stealing-everything-youve-ev...
A random selection of serious security incidents from Azure:
just from Wiz from the past 2-3 years, and of course they aren't the only ones:
https://www.wiz.io/blog/secret-agent-exposes-azure-customers...
https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...
https://www.wiz.io/blog/azure-active-directory-bing-misconfi...
https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-o...
https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...
of course Microsoft AI researchers sucking at security: https://www.wiz.io/blog/38-terabytes-of-private-data-acciden...
Nice overview from Corey Quinn that predates some of those but things were already horrifically bad: https://www.lastweekinaws.com/blog/azures-terrible-security-...
Oh and there's also this, them selling your usage patterns to partners (hopefully they've stopped): https://twitter.com/QuinnyPig/status/1359769481539506180
Oh and another one where they bungled the response: https://twitter.com/QuinnyPig/status/1536868170815795200
I find it impossible to believe that Azure as a whole organisation takes security seriously. There might be individuals that do, but definitely nobody with decision making power. Half of the above described exploits are trivial and should have never passed any sort of competent review process.
So this is funny in a way, because MS had such a terrible and mostly deserved security reputation with Windows...and then they really cleaned and tightened it up. Windows had and continues to have one of the best OS security architectures, and is certainly the best out of all consumer operating systems.
But with the cloud stuff and embarrassing gaffs like this, what the hell happened? New managers and a lot of employee turnover, I guess?
I, for one, very much agree with Belinda.
I really ask myself who cooked up that shit and who allowed it into the product.
It's super invasive. Nobody ever asked for it and just because they can is a rotten reason to impose this on your (presumably) customers.
> Let's call it what it really is, Gates power control issues because he wants to rule the entire world!
Actual article: https://doublepulsar.com/recall-stealing-everything-youve-ev...
More discussion: https://news.ycombinator.com/item?id=40540703
This is the most disgusting consent violation I've ever seen out of Microsoft.
"my computer" > "this pc" meme is real
On the other hand, they just laid off a couple hundred from Azure, so maybe the above isn't quite right or there just isn't enough room in the Windows group for those who fail to perform at the expected level doing Azure, so they were laid off directly.
Honestly speechless
Based on the article, it is encrypted, but you can access it without manually decrypting it on every access.
TFA says it's encrypted at rest, with Bitlocker. When running, the data is accessible only to the SYSTEM user. That's exactly how I'd expect to implement this on Windows, I'm not sure what else you could do while offering the features it does.
The insecurity stems from the concept of Recall, not its implementation.
The main threat is from malware that compromises SYSTEM, or whatever user interface is offered onto Recall.
There's a second-order threat too - Microsoft changing their privacy policy in 1,2,3 years and feeding it to their AI models & 2317 advertising partners. Sure there'll be an opt-out - a paper form in a basement filing cabinet, with a sign saying "beware of the leopard" etc.
There's just no secure way of implementing a feature that collects and stores an enormous amount of new personal data.
It's a keylogger -- the system IS the malware.
Given that the benefits are few, there's no better time to shout it down.
But long term, Recall is platform that MS will build on, offer more access to, synchronise, offer to 3rd parties. Imagine your insurance company demanding access, or potential employer?
It'll be a scary "new normal" when your computer OS records everything you do, as standard, and everyone else expects that to be the case.
Oh, I agree. It's the rational observation and conclusion. But this feature isn't for us.
It's for the average non-technical computer user, and ostensibly they do want this feature, the downsides be damned.
> It'll be a scary "new normal" when your computer OS records everything you do, as standard, and everyone else expects that to be the case.
That is scary and not even something I had considered, since trying to criminalize E@EE gets all the press these days.
It's possible one day that all these computers from the last few decades may end up being very valuable given they are all unlocked and future ones may not be.