Or it could just steal your cookies which are out there in the open.
The username/password you type in next time it expires is far more valuable.
And it might not even be necessary to obtain cookies or credentials if I can just see whatever you could see when you’re logged into various sites.
https://doublepulsar.com/recall-stealing-everything-youve-ev...
Microsoft will also require Windows Hello to enable Recall, so you’ll either authenticate with your face, fingerprint, or using a PIN. “In addition, proof of presence is also required to view your timeline and search in Recall,” says Davuluri, so someone won’t be able to start searching through your timeline without authenticating first.
This authentication will also apply to the data protection around the snapshots that Recall creates. “We are adding additional layers of data protection including ‘just in time’ decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so Recall snapshots will only be decrypted and accessible when the user authenticates,” explains Davuluri. “In addition, we encrypted the search index database.”
https://www.theverge.com/2024/6/7/24173499/microsoft-windows...
But I'm glad to hear they've committed to making changes. Given the misrepresentations they made regarding the initial rollout plan (the target of most criticism, mine included), Microsoft has to prove themselves here and I'll wait until qualified security folks get their hands on this before coming to any conclusions.
What we know is that the initial version was a non-starter, and this new info validates the concerns we've all been expressing.
I truly hope Microsoft does an acceptable job of addressing this. It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
https://blogs.windows.com/windowsexperience/2024/06/07/updat...
> It remains baffling and worrisome that it took a public outcry for them to implement what sounds like a baseline level of acceptable protection.
It's possible this was the intention all along but as a early-beta feature this was just the MVP. The reason it was rolled out to early testers at all was to get feedback.
If they're relying on public feedback to realize how completely unacceptable the initial rollout was, that again points to deep problems at Microsoft and is why I'm saying this is baffling.
This points to structural issues at Microsoft.
Security requirements often completely change the architecture of a product. Things can be built without security that are significantly more challenging to accomplish when strict data security requirements are in place. Architectures that assume no security often completely break down when security is tacked on top.
If this is a matter of a product not yet getting "security added", that again raises major concerns about how Microsoft is building products.
I think that exploratory development is, in general, a good thing. Bogging down all development with middle-management procedures might certainly have caught this early. But that doesn't necessarily make that a better way to build products.
The scary thing about Recall isn't actually Recall itself. It's that AI makes this kind of product possible and really easy. I'm sure we're going to see implementations of this idea everywhere and not just on PCs. Imagine AIs watching security cameras.
I have never seen a crypto locker ransomware on a server except for windows servers. I haven't seen another OS with ads. So many terroble things happen only in the windows/ms ecosystem that it really makes me wonderhow it sticks around but I have ideas about that and they will just make you think I am wierd.
The virus doing the same things as recall will be much noiser and much more suspicious. Making it much more likely to be removed.
Not to mention that once recall has been running a virus only needs to extract the data. It records far more than what a password manager does and is far easier to search through. It just makes a very large attack surface.
Basically, why would anyone develop keyloggers anymore? Microsoft did it for you. And it'll never be tripped by antivirus software because it's an official and legitimately signed program. You don't see a problem with this?