Microsoft's Recall is already exploited
github.com
github.com
Microsoft deserves all the opprobrium it's getting over this galactically stupid idea.
But they'll try again
- - -
A User can access their own data. That isn't an exploit.
Recall is a malware.
- - -
Most browsers beg to store credit cards by default, e2e encrypted messages are already accessible by the user (because they are one of the "ends"), reset codes are probably in most people's download folders, in the stuff-sent-to-the-printer cache, or forgotten completely (which IMO is worse)
If you are security-aware enough to avoid those issues, then you aren't using a closed-source operating system in the first place.
So what about everyone else?
Now thousands of tech-impaired organizations have to proactively go out and find alternatives that don't alienate their users. How many of do you think will get it right as opposed to ever more inconvenient security theater to satisfy compliance checklists?
It seems obvious that MS should put Recall data behind more of an access control than “any process that can read files”.
I type totp code that will be valid for 2 minutes, and they are clear.
I have emails, account numbers and emails.
I have contacts of my network, sites I visits regularly and nick names I use. Sometimes I paste sensitive content in encrypted chats, but hey, now they are in the screenshot.
Then there are nude pics of partners, intimate journaling notes, porn activity, how much I have in the bank, contracts with clients under nda, legal and illegal drugs I order, political alliances, and all the stupid stuff I may do...
All that conveniently centralized and searchable.
In turn, I do not see people complaining about Firefox storing all your browsing history in plain text, your chat history in cache files, so on and so forth.
Probably because Firefox doesn't do this. Firefox's cache is very predictable, and does as it's told: most chat services do not result in information being stored in the cache, once you end the session.
This kind of poorly controlled local access makes it significantly more dangerous to use a Windows PC, because it significantly increases the harm/value of info stealing malware and will increase the degree of interest in penetrating windows systems. The fact that it's enabled by default is horrific, especially when you consider that the people most vulnerable are also the least likely to understand or disable the feature.
Before, info stealers would look for specific words/phrases in documents because anything more would be bandwidth/compute prohibitive. Now, such stealers just need to pull the Recall DB, and all of the juiciest information is served up on a platter.
To prove his point, Kevin deployed a piece of common info stealing malware and it was able to exfiltrate the Recall data before Windows Defender could remediate the issue.
This would still be a dangerous architecture even if Windows had a reputation for being impenetrable. Given the reality, this architecture is incomprehensibly bad.
- [0] https://doublepulsar.com/recall-stealing-everything-youve-ev...
You seem to be looking at this from the standpoint of a user doing dumb stuff things with their windows configuration (also common) vs. the very active ongoing malware campaigns against windows and how this changes the playing field for such malware and the makers of malware.
In a world where privilege escalation is common and expected, it makes no sense to deploy a database of highly sensitive data without robust security.
It’s a bit like storing money in your car in a city known for high rates of car theft.
If there was Priv Esc, then it doesn't matter how robust the security is because you make your way to root and you win regardless.
I agree with your last paragraph, and that is exactly what makes Recall such a big problem, and why the security community is reacting strongly against this feature.
Assuming the attacker wins, which they currently do on a regular basis, they get to know everything about everyone who has used the computer to a degree of detail that is unprecedented both in scope and in detail. The harm of losing this information to an attacker is potentially extreme, with obvious consequences.
Since this is an opt-out feature, Microsoft has essentially guaranteed that a sizable portion of their user base will overnight start feeding attackers more details than they could have ever hoped for.
It’s incompetent, irresponsible, and should be categorically rejected by the tech community.
I say this while also seeing the value of such a feature if it could be implemented safely. I hope someone figures out a safe architecture because I could see a local model trained on everything I’ve ever done on my PC being a transformational capability.
But I wouldn’t go near Recall at this point.
- - -
"Implemented safely" doesn't include security through obscurity. Past having an encrypted home directory, the only practical way to make it more secure than it currently is would be a separate device that records from tapping your monitor's cables.