Honestly speechless
Honestly speechless
TFA says it's encrypted at rest, with Bitlocker. When running, the data is accessible only to the SYSTEM user. That's exactly how I'd expect to implement this on Windows, I'm not sure what else you could do while offering the features it does.
The insecurity stems from the concept of Recall, not its implementation.
The main threat is from malware that compromises SYSTEM, or whatever user interface is offered onto Recall.
There's a second-order threat too - Microsoft changing their privacy policy in 1,2,3 years and feeding it to their AI models & 2317 advertising partners. Sure there'll be an opt-out - a paper form in a basement filing cabinet, with a sign saying "beware of the leopard" etc.
There's just no secure way of implementing a feature that collects and stores an enormous amount of new personal data.
It's a keylogger -- the system IS the malware.
Given that the benefits are few, there's no better time to shout it down.
But long term, Recall is platform that MS will build on, offer more access to, synchronise, offer to 3rd parties. Imagine your insurance company demanding access, or potential employer?
It'll be a scary "new normal" when your computer OS records everything you do, as standard, and everyone else expects that to be the case.
Oh, I agree. It's the rational observation and conclusion. But this feature isn't for us.
It's for the average non-technical computer user, and ostensibly they do want this feature, the downsides be damned.
> It'll be a scary "new normal" when your computer OS records everything you do, as standard, and everyone else expects that to be the case.
That is scary and not even something I had considered, since trying to criminalize E@EE gets all the press these days.
It's possible one day that all these computers from the last few decades may end up being very valuable given they are all unlocked and future ones may not be.
Based on the article, it is encrypted, but you can access it without manually decrypting it on every access.