Linux so easy your mamas can use it. No seriously, works out of the box. Microsoft aint gonna be screenshottin' NOBODIES SCREEN. Shady ass company. After that Crowdstrike stuff, this is some monopolistic act of terrorism.
6 CVEs, two notably: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38193 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
One being where North Korea can take over ring0 entirely? Don't see this AI snapshot stuff ending badly at all, no sir-e!
Linux for days.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-20... - the mitre.org link in my original comment.
I pay attention to all the CVEs daily (or as much as I can). the other one is something found in IPv6 by a research group that allows root level remote code execution by exploiting IPv6 packets, but what I'm getting at is, Windows I'll be trusting, absolutely not if it's going to be playing with this 'Recall' thing.
I'm pro-privacy and I highly feel this Recall system opens up a new attack/exploit vector in new unprecedented ways that I don't even want to begin to imagine. I mean, it reads your screen and recalls everything you've ever done..
Torrent files, pretty much anything. It's not that scary at the moment.
Browsers can do it now. It's an age old 'feature' -> https://github.com/garywill/LAN-port-scan-forbidder
uBlock apparently blocks your browser from reaching out to your LAN though, but; no 'sandbox escapes' needed, just javascript being loaded.
Our browsers could have been exploiting things behind NAT this entire time. Smart TVs, Smart watches, phones, anything pingable on your LAN.
Go here and see it in action: http://samy.pl/webscan/
Maybe if they’re running an HTTP server (which isn’t too uncommon for IoT devices) while allowing the attacker website via CORS (less likely). An IoT device listening for WebSocket or WebRTC connections won’t benefit from CORS, but those are relatively rare and ought to have other mitigations in place.
All your links show is the ability to scan ports, not even read the responses to the fetch() requests made to local IP addresses. That could be useful to an attacker, but a far cry from exploiting any smart device or having the ability to send “outgoing crafted packets” from the browser. You cannot even open arbitrary sockets or craft arbitrary HTTP requests.
Meanwhile, in reality, it's easier than ever to be MS-free, thanks to the rise of web-based applications. There's lots of alternatives to MS Office, including MS's own Office365 online, as well as Google docs, LibreOffice, and others. Most users just use their computers for web browsing anyway, and that can be done on any computer. 20+ years ago, people had much better excuses, because most software was run locally, so if they used some proprietary Windows-only application, they were basically stuck unless they could get it running in WINE, but those days are mostly gone.
But people want to stick with what they know (even though it's actually constantly changing with every new Windows version), so they'll put up with whatever crap MS wants to put in Windows: spyware, ads, etc.
Of course, some people are rebelling and leaving Windows, as we saw in the recent article about Linux desktop usage being at an all-time high, but it's still only about 5%, though that's a lot better than 20 years ago.
But Linux isn’t a greener pasture for the only thing I use windows for. For the things in which it is, I already use Linux or other non windows based operating systems.
I assume you’re talking about “non IT” people though I suppose who may only be able to facilitate the usage of one operating system at a time.
I call it the "GMail Searchification Effect", that heavily focuses on "The Experience", is driven more by the UX and marketing teams rather than the technical team.
They implement the features with no real configuration, no interoperability, no local options, no way to point to another server implementation, etc. Probably no way to script it, either.
and already developer apis for interop.. https://learn.microsoft.com/en-us/windows/ai/apis/recall
Thanks for the links and the info, but I still believe it'll pan out in a very specific way. Time will tell I guess.