For those who aren’t aware, Microsoft have decided to bake essentially an infostealer into base Windows OS and enable by default.
From the Microsoft FAQ: “Note that Recall does not perform content moderation. It will not hide information such as passwords or financial account numbers."
Info is stored locally - but rather than something like Redline stealing your local browser password vault, now they can just steal the last 3 months of everything you’ve typed and viewed in one database.
teilten dies erneut
Simon B
Als Antwort auf Kevin Beaumont • • •NosirrahSec 🏴☠️
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
The Flight Attendant hat dies geteilt.
Matt Hardy 3.11 for Workgroups
Als Antwort auf NosirrahSec 🏴☠️ • • •teilten dies erneut
Glyn Moody hat dies geteilt.
Jon Greig
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Quixoticgeek und The Flight Attendant haben dies geteilt.
Fi 🏳️⚧️
Als Antwort auf Jon Greig • • •@jgreig
@hacks4pancakes
Speaking from my compliance aspect, this comprehensively fails PCI and GDPR immediately and the SOC2 controls list ain't looking so good either.
Hypolite Petovan mag das.
Lesley Carhart
Als Antwort auf Fi 🏳️⚧️ • • •Fi 🏳️⚧️
Als Antwort auf Lesley Carhart • • •This situation has me absolutely livid - infosec.exchange/@munin/112480…
Asta [AMP]
Als Antwort auf Fi 🏳️⚧️ • • •I remember having to take security training at Microsoft and this literally fails every single piece of advice they give for their own fucking employees (because duh, of course it does).
Even if a company thinks they want this on their employee's PCs, no, they don't. Really? You want a searchable movie of everything your worker has done available to anyone with physical access to their machine? Huh.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I've written up my thoughts on the Copilot Recall feature in Microsoft Copilot+ PCs
I think it will enable fraud and endanger users, and is not the sign of a company who are committed to security first.
doublepulsar.com/how-the-new-m…
How the new Microsoft Recall feature fundamentally undermines Windows security
Kevin Beaumont (DoublePulsar)teilten dies erneut
GunChleoc, The Flight Attendant, Erich M., Deadly Headshot, Nicole Parsons, Quixoticgeek, Florian Schmidt, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Lord Caramac the Clueless, KSC, Bastian Beuttel, Christian Pietsch 🍑, Linux Walt (@lnxw37j1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}, Kagami is they/them 🏳️⚧️, Ulrich Junker, DieMadColonizer und CrazyDogLadysezBreatheWithMe haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft Copilot+ Recall feature 'privacy nightmare'
Imran Rahman-Jones (BBC News)teilten dies erneut
The Flight Attendant, Deadly Headshot, Nicole Parsons, Glyn Moody, your auntifa liza 🇵🇷 🦛 🦦, Quixoticgeek, Florian Schmidt, Lord Caramac the Clueless, KSC, Christian Pietsch 🍑 und CrazyDogLadysezBreatheWithMe haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Copilot+ Recall has been enabled by default globally in Microsoft Intune managed users, for businesses.
You need to enable DisableAIDataAnalysis to switch it off. learn.microsoft.com/en-us/wind…
Manage Recall for Windows clients - Windows Client Management
learn.microsoft.comteilten dies erneut
Mallory's Musings & Mischief, Laurent Gatto, Newk, The Flight Attendant, Deadly Headshot, your auntifa liza 🇵🇷 🦛 🦦, Nicole Parsons, Claudius Link, Pieter, Florian Schmidt, Lord Caramac the Clueless, KSC, Christian Pietsch 🍑, w4tsn ~>, Wurzelmann, dbx, Autoerotic Defenestration, Frank Zimper 🕯️🐘, DieMadColonizer, Chester Wisniewski und CrazyDogLadysezBreatheWithMe haben dies geteilt.
Jay Stephens
Als Antwort auf Kevin Beaumont • • •sen
Als Antwort auf Jay Stephens • • •@jaystephens Settings: Accounts: Access work or school: here it’ll say something along the lines of “Connected to Blah Azure AD/Entra.” Beyond that, Recall is currently limited to Copilot+ ARM based devices.
@GossiTheDog
Jay Stephens
Als Antwort auf sen • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Nicole Parsons, Überlebenskünstler (er/ihm), Lord Caramac the Clueless, KSC, Christian Pietsch 🍑, Autoerotic Defenestration und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Two quick updates -
A) if you disallow recording of a website in Control Panel or GPO, in Chrome it is still recorded - disallow recording only works in Edge browser
B) Firefox and Tor Browser is recorded always, including in private mode - the exception is Hollywood DRM’d videos
teilten dies erneut
The Flight Attendant, Nicole Parsons, theOmegabit, Quixoticgeek, Frank Zimper 🕯️🐘, Florian Schmidt, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Karl Heinz Häsliprinz, Lord Caramac the Clueless, KSC, Christian Pietsch 🍑, DieMadColonizer, skibidi eichkat3r, r҉ustic cy͠be̸rpu̵nk🤠🤖 und Chester Wisniewski haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I got ahold of the Copilot+ software.
Recall uses a bunch of services themed CAP - Core AI Platform. Enabled by default.
It spits constant screenshots (the product brands then “snapshots”, but they’re hooked screenshots) into the current user’s AppData as part of image storage.
The NPU processes them and extracts text, into a database file.
The database is SQLite, and you can access it as the user including programmatically. It 100% does not need physical access and can be stolen.
teilten dies erneut
your auntifa liza 🇵🇷 🦛 🦦, CurrentBias, theOmegabit, Philip Gillißen, StreetDogg, Claudius Link, Florian Schmidt, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Valentin Pratz, Karl Heinz Häsliprinz, George Potter, Rohin Dharmakumar, Maxi 10x 💉, Natasha Nox 🇺🇦🇵🇸, Mattias de Hollander, Toph Allen, Pieter, Fenriz, Juanjo, Florian Berger (privat), Lord Caramac the Clueless, KSC, Christian Pietsch 🍑, ExcelAnalytics, Linux Walt (@lnxw37j1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864}, Nicole Parsons und DieMadColonizer haben dies geteilt.
Rob Carlson
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Dieu, your auntifa liza 🇵🇷 🦛 🦦 und Bastian Beuttel haben dies geteilt.
🆘Bill Cole 🇺🇦
Als Antwort auf Rob Carlson • • •your auntifa liza 🇵🇷 🦛 🦦
Als Antwort auf Kevin Beaumont • • •ballotproof vest
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •And if you didn’t believe me.. found this on TikTok.
There’s an MSFT employee in the background saying “I don’t know if the team is going to be very happy…”
They should probably be transparent about it, rather than telling BBC News you’d need to be physically at the PC to hack it (not true). Just a thought.
teilten dies erneut
Lord Caramac the Clueless, KSC, Nicole Parsons und DieMadColonizer haben dies geteilt.
Marcus Adams
Als Antwort auf Kevin Beaumont • • •Gavin Jones
Als Antwort auf Marcus Adams • • •Thibault D.
Als Antwort auf Gavin Jones • • •Scott Hanselman 👸🏽🐝🌮
Als Antwort auf Thibault D. • • •Scott Hanselman 👸🏽🐝🌮
Als Antwort auf Scott Hanselman 👸🏽🐝🌮 • • •Gavin Jones
Als Antwort auf Kevin Beaumont • • •Ian Betteridge
Als Antwort auf Kevin Beaumont • • •Hmmm. But that’s true for *anything* on your file system. And AFAIK no one has yet invented a way to store info locally that isn't on your file system ;)
So yes, a compromised machine where someone has set up remote access to it without you knowing would allow them to spy on your activity. But that is true today, too, on any machine, on any platform.
Plus if someone has remote access, they would be WAY better off installing akeylogger than relying on a feature I can turn off.
Quixoticgeek
Als Antwort auf Ian Betteridge • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Code Of Ethics
sqlite.orgteilten dies erneut
Lord Caramac the Clueless, KSC und Nicole Parsons haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •So the code underpinning Copilot+ Recall includes a whole bunch of Azure AI backend code, which has ended up in the Windows OS. It also has a ton of API hooks for user activity monitoring.
Apps themselves can also search and make themselves more searchable.
It opens a lot of attack surface.
The semantic search element is fun.
They really went all in with this and it will have profound negative implications for the safety of people who use Microsoft Windows.
teilten dies erneut
Lord Caramac the Clueless, KSC, Elijah Waxwing, Hahn Holio, Volt4ire, Hannah, Rohin Dharmakumar, Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •If you want to know where tech companies are with AI safety, know Microsoft Recall won’t record screenshots of DRM’d movies..
..but will record screenshots of your financial records and WhatsApp messages, as corporate interests were prioritised over user safety.
And it’s enabled by default.
teilten dies erneut
Bastian Beuttel, Simon de Boudoir, Daniel, Florian Schmidt, Rainer AI Blockchain Rehak 4.0, George Potter, Claudius Link, 0xThylacine, Peter, Marsmädchen, Jumpfruit (he/him), #DieMaskeBleibtAuf, Christian Pietsch 🍑, Frank Zimper 🕯️🐘, Nicole Parsons, DieMadColonizer, Nowhere Girl und ftl haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Nicole Parsons und DieMadColonizer haben dies geteilt.
docht
Als Antwort auf Kevin Beaumont • • •Interested layperson here:
From what you've seen so far, can you draw a conclusion that a computer with recall running sends more data than usual to Microsoft, maybe "disguised" as part of diagnostics data for example.
I wonder if recall is a fishing expedition in task mining and if so, how Microsoft, despite having promised that recall does not run in the cloud, could get the data nevertheless.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Copilot+ Recall feature pop quiz:
You deal with a sensitive matter on my Windows PC. E.g. an email you delete. Does Copilot Recall still store the deleted email?
Answer: yes. There's no feature to delete screenshots of things you delete while using your PC. You would have to remember to go and purge screenshots that Recall makes every few seconds.
If you or a friend use disappearing messages in WhatsApp, Signal etc, it is recorded regardless.
teilten dies erneut
Maxi 10x 💉, Christian Pietsch 🍑, Quixoticgeek, Lukas HvG, The Flight Attendant, Nicole Parsons, DieMadColonizer und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •It comes up a lot as people are rightly confused, but if you wonder what problem Microsoft are trying to solve with Recall:
It isn't them being evil, it's business leaders who are middle aged and can't remember what they're doing driving decision making about which problems to solve.
A huge amount of business leaders are dudes who have no idea what the fuck is happening. This leads to the Recall feature.
Microsoft exists and is driven by that bubble.
teilten dies erneut
Quixoticgeek, Arne Babenhauserheide, theOmegabit, Autoerotic Defenestration, Thomas, Flexi Bell, Nicole Parsons, DieMadColonizer, Florian Schmidt, tante, #DieMaskeBleibtAuf und Florian Berger (privat) haben dies geteilt.
Dave
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Dave • • •Misuse Case
Als Antwort auf Kevin Beaumont • • •@Laird_Dave So this is definitely geared towards not just middle-aged dudes but managers.
Like, can these people not just organize their emails into folders by topic? Microsoft could have re-worked the Outlook rules function to make this easier instead of whatever this is.
Dave
Als Antwort auf Misuse Case • • •@MisuseCase yeah, that would probably help a lot more while being a lot less creepy (and liability risk)
In turn, the liability risk will be the nicest "feature" of this shit. I'll drive a wooden stake through Recalls heart for my org before it has a chance to lay eggs.
Misuse Case
Als Antwort auf Dave • • •Kevin Beaumont
Als Antwort auf Misuse Case • • •Misuse Case
Als Antwort auf Kevin Beaumont • • •@Laird_Dave Sure, I can see that. But Microsoft has a lot of enterprise customers with CISOs, legal departments, regulatory requirements, etc. for whom Recall is worse than useless. That actually describes most of their largest enterprise customers!
Do they even pay attention to their own customers at all?
Sure enterprises can use GPO to turn it off but why make something that most of your biggest customers are going to have to turn off?
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
rugk, DieMadColonizer und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Autoerotic Defenestration, Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Some screenshots of Recall's SQLite database here: mastodon.social/@detective/112…
Just to clarify, I can access it without SYSTEM too. Microsoft are about to set cybersecurity back a decade by empowering cyber criminals via poor AI safety. Feature ships in a few weeks.
Albacore
2024-05-27 14:30:16
teilten dies erneut
Nicole Parsons, DieMadColonizer und Peter haben dies geteilt.
docht
Als Antwort auf Kevin Beaumont • • •This ist also worth noticing:
According to Axios Microsoft is "exploring if there are ways that make sense to allow the feature to work across devices."
axios.com/2024/05/21/microsoft…
Bou
Als Antwort auf docht • • •docht
Als Antwort auf Bou • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •The latest Risky Business episode on Recall is good, but one small correction - it doesn’t need SYSTEM rights.
Here’s a video of two MSFT employees gaining access to the Recall database folder - with SQLite database right there. Watch their hacking skills. (You don’t need to go this length as an attacker, either). Cc @riskybusiness
I’m not being hyperbolic when I say this is the dumbest cybersecurity move in a decade. Good luck to my parents safely using their PC.
teilten dies erneut
0xThylacine, Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.
My look at the feature, FAQs from the community etc
doublepulsar.com/recall-steali…
Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.
Kevin Beaumont (DoublePulsar)teilten dies erneut
Simon B, BrianKrebs, Daniel AJ Sokolov, Alex@rtnVFRmedia Suffolk UK, Matthias Eberl, nehrka - RIP Natenom, Bianca Kastl, #DieMaskeBleibtAuf, Laurent Gatto, @pineywoozle ‘s #3WordNote, Mint Spies has gone Beige, GunChleoc, Florian Schmidt, Nicole Parsons, DieMadColonizer und Daniel haben dies geteilt.
Simon B
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •this is the out of box experience for Windows 11's new Recall feature on Copilot+ PCs. It's enabled by default during setup and you can't disable it directly here. There is an option to tick "open Settings after setup completes so I can manage my Recall preferences" instead.
HT @tomwarren
teilten dies erneut
Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •You allow BYOD so people can pick up webmail and such. It’s okay, because when they leave you revoke their access, and your MDM removes all business data from the machine ✅
What the employee does: opens Recall, searches their email, files etc and pastes the data elsewhere.
Nothing is removed from Recall, as it is a photographic memory of everything the former employee did.
teilten dies erneut
Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
The Flight Attendant, Nicole Parsons, DieMadColonizer und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Security and privacy researchers - You can now install Copilot+ Recall on any ARM hardware (doesn’t need an NPU) or in Azure VMs.
Guide from @detective
The devices launch THIS MONTH to customers so I suggest people look at this.
github.com/thebookisclosed/Amp…
GitHub - thebookisclosed/AmperageKit: One stop shop for enabling Recall in Windows 11 version 24H2 on unsupported devices
GitHubteilten dies erneut
Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Nvidia and AMD are bringing Microsoft’s Copilot Plus AI features to gaming laptops
Tom Warren (The Verge)teilten dies erneut
Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Newk, Florian Schmidt, Fink, Lord Caramac the Clueless, KSC, Michael Simons, The Flight Attendant, Nicole Parsons, Toni C. 🎗🍉🔻 und DieMadColonizer haben dies geteilt.
Uwe Küchler
Als Antwort auf Kevin Beaumont • • •Screenshot of the output of the script "totalrecall.py" that shows a detected "Windows Recall", and an extraction folder created for extracted Recall contents.
Two lists of captured content follow, one containing the captured windows (one with an open Gmail account) and the other one shows all extracted screenshots.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Recent DHS published report handed to the US President which said it had "identified a series of Microsoft operational and strategic decisions that collectively pointed to a corporate culture that deprioritized enterprise security investments and rigorous risk management"
Microsoft: let’s use AI to screenshot everything users do every 5 seconds, OCR the screenshots, make it searchable and store it in AppData!
teilten dies erneut
StreetDogg, Peter, Nicole Parsons, DieMadColonizer, Florian Schmidt und Maxi 10x 💉 haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
The Flight Attendant, Nicole Parsons und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Nicole Parsons, DieMadColonizer, Florian Schmidt und Alex@rtnVFRmedia Suffolk UK haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •If anybody is wondering if you can enable Recall on a machine remotely without Copilot+ hardware support - yep.
I’ve also found a way to disable the tray icon.
teilten dies erneut
Daniel AJ Sokolov, George Potter, The Flight Attendant, CaptainMalu, Nicole Parsons, DieMadColonizer, Hahn Holio, your auntifa liza 🇵🇷 🦛 🦦, Bastian Beuttel, Claudius Link, skibidi eichkat3r, Florian Schmidt, Anna Christina und António Domingues haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I went and looked at YouTube for Recall to get out of the echo chamber and I can only find one positive video. Even the people at the event are slating it, including people with media provided Copilot+ PCs.
There’s some content creators who’ve realised it records their credit cards, so they’re making videos of their cards going walkies.
teilten dies erneut
Nicole Parsons, The Flight Attendant, DieMadColonizer und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •It’s going to be interesting to see how Microsoft get out of this one. They may have contractual commitments to ship Recall with external parties.
I thought they were risking crashing the Copilot brand with this one, but I was wrong looking at the videos and comments on them - I think they’re crashing the Windows consumer brand.
The reaction to photographic memory of what people do at home has - you’ll be surprised to know - not been seen as a reason to buy a device, but a reason why not to.
teilten dies erneut
Nicole Parsons, The Flight Attendant, Quixoticgeek, DieMadColonizer und Florian Schmidt haben dies geteilt.
Simon Zerafa
Als Antwort auf Kevin Beaumont • • •This whole feature is beinf used to market AI co-processors and so force hardware upgrades.
Let's hope that sinking the Windows brand further is worth it.
Nicole Parsons
Als Antwort auf Kevin Beaumont • • •Investments by oil despots yields products that despots want.
businessinsider.com/microsoft-…
arabnews.com/node/2507356/busi…
consultancy-me.com/news/8148/p…
cio.com/article/2079045/pwc-mi…
arabnews.com/node/2518936/amp
bloomberg.com/news/articles/20…
PwC Middle East and Microsoft launch an AI excellence center in Saudi Arabia
Andrea Benito (CIO)Forgi
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Forgi • • •@forgifuzzbutt yep. And there’s loads of tangible security benefits from the rest of the work going on in Windows 11 in terms of security.
They just shit their own bed on this one by not understanding their customers, Apple must be so happy.
Forgi
Als Antwort auf Kevin Beaumont • • •Actual clown show announcing it immediately after this blog post:
blogs.microsoft.com/blog/2024/…
But yeah, the direction 11 was going in has been great, then they abruptly veered right off the cliff.
Prioritizing security above all else - The Official Microsoft Blog
Microsoft Corporate Blogs (The Official Microsoft Blog)Simon B
Als Antwort auf Forgi • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •"Microsoft should recall Windows Recall" — Security researcher discovers Microsoft's new AI tool is woefully insecure
Zac Bowden (Windows Central)teilten dies erneut
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft has been declining to comment on criticism of Recall for a week - but they have apparently told a journalist off the record at Future that changes will be made before Copilot+ devices drop in the coming days.
This may include an attempt to invalidate researcher criticism, we’ll see.
teilten dies erneut
DieMadColonizer, The Flight Attendant und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •WIRED has a piece about Total Recall, a now released tool which dumps keypresses, text and screenshots (they’re JPEGs) from Microsoft Recall
wired.com/story/total-recall-w…
Total Recall software by @xaitax github.com/xaitax/TotalRecall
Example search for ‘password’:
🪟 Captured Windows: 133
📸 Images Taken: 36
🔍 Search results for 'password': 22
📄 Summary of the extraction is available in the file:
C:\Users\alex\Downloads\TotalRecall\2024-06-04-13-49_Recall_Extraction\TotalRecall.txt
GitHub - xaitax/TotalRecall: This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots.
GitHubteilten dies erneut
Florian Schmidt und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I hadn’t been aware until today of the external reaction to Recall. Holy shit. Tim Apple must be pleased.
Everything from media coverage to YouTube to TikTok is largely negative. All the comments are negative.
These videos have tens of millions of views and hundreds of thousands of comments.
I knew it would be bad but.. it’s worse. I’ve spent hours looking at the sentiment and.. well, they probably would have got better coverage from launching an NFT of pregnant Clippy.
teilten dies erneut
Quixoticgeek, Florian Berger (privat), leyrer, Marcus "MajorLinux" Summers, The Flight Attendant, Bastian Beuttel, Florian Schmidt, Claudius Link und DieMadColonizer haben dies geteilt.
Killa Koala
Als Antwort auf Kevin Beaumont • • •Becca Cotton-Weinhold
Als Antwort auf Killa Koala • • •Charlie Stross
Als Antwort auf Becca Cotton-Weinhold • • •Becca Cotton-Weinhold
Als Antwort auf Charlie Stross • • •John Breen
Als Antwort auf Kevin Beaumont • • •Brad Lazaruk
Als Antwort auf Kevin Beaumont • • •Matthias Eberl
Als Antwort auf Kevin Beaumont • • •immibis
Als Antwort auf Kevin Beaumont • • •Arnim Sommer 🇪🇺
Als Antwort auf Kevin Beaumont • • •@christian
theOmegabit
Als Antwort auf Kevin Beaumont • • •have you or others looked at say, Rewind for macOS in a similar fashion as you have been with recall in terms of a deeper dive on what’s really going on under the hood?
rewind.ai/
Rewind
www.rewind.aiBen Ramsey
Als Antwort auf Kevin Beaumont • • •@jalcine The same rule that says this?
So, I doubt Microsoft engineers care.
Ben Ramsey
Als Antwort auf Ben Ramsey • • •@jalcine What’s more damning is that many engineers are dues-paying members of the ACM or IEEE, which do have codes of ethics they encourage computing professionals to follow (even if not members).
ACM Code of Ethics, 4.2: “Each ACM member should encourage and support adherence by all computing professionals regardless of ACM membership.“
We should hold our profession accountable to these codes.
acm.org/code-of-ethics
computer.org/education/code-of…
Code of Ethics for Software Engineers
DX Editor (IEEE Computer Society)koehntopp ~ :
Als Antwort auf Kevin Beaumont • • •Microsoft does do Threat Modeling, right @adamshostack ...?
There are so many ways this WILL go wrong... 🤭
Adam Shostack
Als Antwort auf koehntopp ~ : • • •Andrew
Als Antwort auf Kevin Beaumont • • •yikes yikes yikes fucking yikes.
I'm done with Microsoft. This is insanity. Windows is not going on any of my PCs ever again. I'd sooner buy a Mac, and I hate macOS.
trusty falxter 🧠
Als Antwort auf Kevin Beaumont • • •OCR Bot
Als Antwort auf trusty falxter 🧠 • • •Sensitiver Inhalt
@flxtr
Image 1:
@ learn.microsoft.com
Lockdown Enabled
Configure policies for Recall
By default, Recall assists users by considering their
historical behaviors and data. Organizations that
aren't ready to use Al for historical analysis can
disable it until they're ready with the Turn off saving
snapshots for Windows policy. The following policy
allows you to disable user data analysis:
/ Expand table
Setting
CSP ./User/Vendor/MSFT/Policy/Config/WindowsAl/Dis
Group User Configuration > Administrative Templates > W
policy Components > Windows Copilot > Turn off saving
Windows
Image 2:
12:13 9 ef 4 5
AA @ learn.microsoft.com @
Lockdown Enabled
DisableAlDataAnalysis
/ Expand table
Scope _ Editions Applicable OS
x Pro Windows
Device Enterprise Insider Preview
Education
User Windows SE
loT Enterprise / loT
Enterprise LTSC
User = Copy
. /User/Vendor/MSFT/Policy/Config/WindowsAI/
This policy setting allows you to control whether
Windows saves snapshots of the screen and
analyzes the user's activity on their device.
e lf you enable this policy setting, Windows won't
be able to save snapshots and users won't be
able to search for or browse through their
historical device activity using Recall.
e lf you disable or don't configure this policy
setting, Windows will save snapshots of the
screen and users will be able to search for or
browse through a timeline of their past activities
using Recall.
< C an
Jeramee
Als Antwort auf Kevin Beaumont • • •So, Microsoft wants to take screenshots by default? How many people will be completely unaware of this?
Switching to #Linux is now a matter of digital self-defense. Fwiw, my switch to @linuxmint was easy.
Martijn Vos
Als Antwort auf Kevin Beaumont • •@Kevin Beaumont
This sounds like an unbelievably bad idea by Microsoft, following a long string of increasingly poor ideas.
I think it's more than time for Microsoft to get out of the desktop OS market. And governments should crack down hard on installing and enabling this sort of spyware without very explicit consent from the user.
Jared White — Free Garcia Now!
Als Antwort auf Kevin Beaumont • • •“This is my computer”
Is it though?
"This is my Recall"
Is it though?
"This is all being done locally"
For now.
See, the problem is we can't trust these companies. So when they make claims that they've voluntarily decided to implement something in a manner which appears to be ethically-driven, we have zero recourse if they suddenly change their minds. (And most of the time, they do.)
your auntifa liza 🇵🇷 🦛 🦦
Unbekannter Ursprungsbeitrag • • •eerlijkdigitaalonderwijs.nl
Als Antwort auf Kevin Beaumont • • •#Windows and #Microsoft products are thus not suitable for use in #school. Our #education system should be free of #surveillance tech.
We should not be normalising this kind of dangerous #spyware by teaching kids that this is normal.
#SpywareByDesign #Recall
Dave Lane 🇳🇿
Als Antwort auf eerlijkdigitaalonderwijs.nl • • •Explainer: Digitech risks for School Boards
Dave LaneStefan
Als Antwort auf eerlijkdigitaalonderwijs.nl • • •@CEDO
You forgot MacOS and iOS from Apple to mention too. 😉
Oh there is also ChromeOS from the biggest surveillance Company known as Google as part of Alphabet.
FireOS from Amazon is also worth mentioning.
#Surveillance #Capitalism
@GossiTheDog @citizenk4te
Martin Schröder
Unbekannter Ursprungsbeitrag • • •theOmegabit
Unbekannter Ursprungsbeitrag • • •mkj
Unbekannter Ursprungsbeitrag • • •@theomegabit Indeed, software that does this has been available for a good while.
That doesn't make it a good idea to embed into the OS a default-on function to do it.
Nicole Parsons
Unbekannter Ursprungsbeitrag • • •Saudi Arabia had been flooding American tech companies with cash since 2018.
Twitter was just one example of anti-democracy oil oligarchs hijacking tech.
Kushner's $2 billion in Saudi sovereign funds isn't buying beach-front condos in Gaza, it's being spent on torpedoing tech brands like Microsoft.
Google, Apple, Oracle, Amazon, Microsoft, all had MBS visit in 2018. The investments continued after the Khassoghi murder & its accelerated in recent months.
vox.com/technology/2023/5/1/23…
How Saudi money returned to Silicon Valley
Jonathan Guyer (Vox)Nicole Parsons hat dies geteilt.
Nicole Parsons
Unbekannter Ursprungsbeitrag • • •Microsoft made a sudden shift towards AI development in 2018 under pressure from investors. As did the Big Five.
Recall was one of the products developed with those investments.
Nicole Parsons hat dies geteilt.
Nicole Parsons
Als Antwort auf Nicole Parsons • • •The funding isn't restricted to tech companies. In 2018, anti-democracy donors suddenly decided AI was the next big thing. Recall's snapshots are a data-gathering tool for CoPilot AI.
Noted GOP megadonor to Trump, Stephen Schwarzman funded MIT's new AI faculty in 2018.
shass.mit.edu/news/news-2018-a…
qz.com/annual-corporate-invest…
statista.com/statistics/941137…
forbes.com/sites/jeanbaptiste/…
pymnts.com/news/artificial-int…
The flood of money is inducing the premature product launches of flakey AI.
AI Startups Culled $9.3B In 2018
PYMNTS (PYMNTS.com)Nicole Parsons hat dies geteilt.
Nicole Parsons
Unbekannter Ursprungsbeitrag • • •@das_menschy @OvertonDoors
I've been reading a lot about the anti-democracy movement being funded by the fossil fuel industry.
It's not restricted to politics & religion. It's economic, cultural and technology also being molded and manipulated as well.
Nicole Parsons hat dies geteilt.
das_menschy
Unbekannter Ursprungsbeitrag • • •OvertonDoors
Unbekannter Ursprungsbeitrag • • •@Npars01
Sure, and it's an coincidence that the WaPo ousted it's editor in favor of someone who wants TuckerKarlson op-eds.
I suppose you believe it was pure incompetence that drove Musk's management of Twitter into the shitter.
Rupert Murdoch marries his ruZZian handler, nothing to see here.
But co-pilot's creation has nothing to do with the billions of autocratic petro-dollars being pumped into Microsoft. Your not trying nearly hard enough to stick your head in the sand.
Kevin Beaumont
Als Antwort auf OvertonDoors • • •Nicole Parsons
Als Antwort auf das_menschy • • •@das_menschy @OvertonDoors
A simple Google search for "Microsoft +Saudi" lists several hundred articles describing the scale of Saudi investment in AI.
Don't believe me? Check any reputable business news website.
The scale of the investment by the fossil fuel industry in such a short time is astonishing.
Nicole Parsons hat dies geteilt.
Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •Recall and Copilot+ is also coming to ASUS systems, including AMD, in a deal with Microsoft.
ASUS Announces Complete Portfolio of AI-Powered Copilot+ PCs asus.com/us/news/pnm9tg6qccql6…
Nvidia announced they are bringing Copilot+ and Recall to PCs, in a deal with Microsoft: theverge.com/2024/6/2/24169568…
Nvidia and AMD are bringing Microsoft’s Copilot Plus AI features to gaming laptops
Tom Warren (The Verge)teilten dies erneut
DieMadColonizer hat dies geteilt.
Becca Cotton-Weinhold
Unbekannter Ursprungsbeitrag • • •@weirdwriter will it? ecoevo.social/@rlcw/1125630235…
Becca Cotton-Weinhold
2024-06-05 08:17:12
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Three Copilot+ Recall questions that keep coming up.
Q. Can you alter the Recall history?
A. Yes. You can change the OCR database and change the screenshots as the logged in user or as software running as the local user. There is no audit log of changes.
Q. Are they snapshots, as Microsoft says, or screenshots?
A. They are just screenshots, jpegs.
Q. What is to stop apps on your machine accessing your Recall covertly?
A. Nothing. There is no audit log of access.
teilten dies erneut
Daniel AJ Sokolov, Alex@rtnVFRmedia Suffolk UK, GunChleoc, Quixoticgeek, Waldtochter, Charles ☭ says trans rights, The Flight Attendant, wolfstettler, Jens Bannmann, Laura Lis Scott, Winchell Chung ⚛🚀, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, #DieMaskeBleibtAuf, Robert Weißgraeber🇪🇺, DieMadColonizer und Mx. Luna Corbden haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Maxi 10x 💉 und DieMadColonizer haben dies geteilt.
Lesley Carhart
Als Antwort auf Kevin Beaumont • • •The Flight Attendant hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •If anybody is wondering what Microsoft's reaction to any of the Copilot+ Recall concerns are, they're continuing to decline comment to every media outlet.
I've seen comments MS staff have been given for enterprise customers, which are nonsense handwaving.
Product ships live on devices from Dell, Lenovo etc this month. x.com/zacbowden/status/1798221…
teilten dies erneut
leyrer, The Flight Attendant, Bastian Beuttel und DieMadColonizer haben dies geteilt.
For I am CJ
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Quixoticgeek, The Flight Attendant und DieMadColonizer haben dies geteilt.
Mina
Als Antwort auf Kevin Beaumont • • •Well, your supervisor at work will appreciate the possibility to easily look into what you did all day.
@tiraniddo
Moritz Bartl
Als Antwort auf Kevin Beaumont • • •Passenger
Als Antwort auf Mina • • •@mina @tiraniddo
Since I can rewrite the database myself with this, it means that I can tell my supervisor exactly what she wants to hear.
Diego Roversi
Als Antwort auf Moritz Bartl • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •GitHub - xaitax/TotalRecall: This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots.
GitHubteilten dies erneut
w4tsn ~>, Mx. Luna Corbden, Bastian Beuttel, Quincy, Wurzelmann, Jürgen 🌗🪐🌌, Paul J Wege, Steffen Voß, BrianKrebs, The Flight Attendant und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •You can now remotely dump Recall data and screenshots over the internet from Linux etc. Changes in flight for parsing data too.
github.com/Pennyw0rth/NetExec/…
Add Recall module for dumping all users Microsoft Recall DBs & screenshots by Marshall-Hallenbeck · Pull Request #335 · Pennyw0rth/NetExec
GitHubteilten dies erneut
w4tsn ~>, Fink und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
The Flight Attendant hat dies geteilt.
DieMadColonizer
Als Antwort auf Kevin Beaumont • • •hey thanks for continuing to post on this.
I saw on bighard's website that they're rolling this Copilot out to Win10 as well but it's not clear if Recall will be on there? Have you been able to find anything on that aspects of this? Thanks again!
support.microsoft.com/en-us/wi…
Welcome to Copilot in Windows - Microsoft Support
support.microsoft.comKevin Beaumont
Als Antwort auf Kevin Beaumont • • •Turns out speaking out works.
Microsoft are making significant changes to Recall, including making it specifically opt in, requiring Windows Hello face scanning to activate and use it, and actually encrypting the database.
There is obviously going to be devils in the details - potentially big ones.
Microsoft needs to commit to not trying to sneak users to enable it in the future, and it needs turning off by default in Group Policy and Intune for enterprise orgs.
theverge.com/2024/6/7/24173499…
Windows won’t take screenshots of everything you do after all — unless you opt in
Tom Warren (The Verge)teilten dies erneut
tante, Stefan Bohacek, Ralf Bendrath, DieMadColonizer, Zack Whittaker, radioactivestardust, Hafensophie, The Flight Attendant, your auntifa liza 🇵🇷 🦛 🦦, CurrentBias, Alex@rtnVFRmedia Suffolk UK, h4sh und technicat haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Obviously, I recommend you do not enable Recall, and you tell your family not to enable it too.
It’s still labelled Preview, and I’ll believe it is encrypted when I see it.
There are obviously serious governance and security failures at Microsoft around how this played out that need to be investigated, and suggests they are not serious about AI safety.
teilten dies erneut
0xThylacine hat dies geteilt.
Lulu · לולו
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft reverses course, makes Recall feature opt-in only after security backlash
therecord.mediateilten dies erneut
Florian Berger (privat), h4sh und DieMadColonizer haben dies geteilt.
Adam Shostack
Unbekannter Ursprungsbeitrag • • •@suzannealdrich
"Why not both"?
Suzanne Aldrich (she/her)
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Suzanne Aldrich (she/her) • • •evacide
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
your auntifa liza 🇵🇷 🦛 🦦 hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I should be transparent btw that I took Satya and Charlie’s commitment to security at face value too - I even published a blog on it backing that up - and I have concerns (it isn’t just me).
They’re now going to have to win trust back about winning trust back.
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I know somebody at a retailer in Europe that is selling Copilot+ PCs. They’ve had fewer than a thousand preorders through to customers.
In relative terms, for them it’s about as successful as Suicide Squad Kill The Justice League.
teilten dies erneut
Maxi 10x 💉, Bastian Beuttel und DieMadColonizer haben dies geteilt.
sebastian büttrich
Als Antwort auf Kevin Beaumont • • •While that might be a nice partial interim success, #MicroSoft
will certainly not stop sneaking on users - it s their business concept, and you dont need graphical snapshots to track a user. There s telemetry you cant turn off. Try run a #Windows PC without net connection (or blocking connections to the overlords), and you will know.
There is one way to turn it off: install Linux.
#Total #Recall
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •A reminder that a few weeks ago at RSA, Microsoft signed CISA's Secure By Design pledge... and then shipped an enabled by design keylogger that OCRs your screen constantly into AppData.
Edit: I should say that's less a reflection on Microsoft and more a reflection on CISA's Secure By Design pledge.. it's a good idea, but the scope is extremely limited.
teilten dies erneut
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I think MS are a way off extracting themselves from Recall situation they've got themselves into.
This is just one YouTube comments section on a video since the not-enabled-by-default change - 500k views - but there's loads more, similar on TikTok.
I imagine it's going to continue through week and into next week when the laptops ship.
I have heard rumblings MS are discussing trying to take action against me over the whole thing, which a) good luck and b) would be pouring petrol on the flames.
teilten dies erneut
The Flight Attendant hat dies geteilt.
Simon Zerafa
Als Antwort auf Kevin Beaumont • • •It's wasn't just you calling attention to the whole Recall Debacle.
I was castigated by one person actually investing for "tin-foil hat conspiracies".
If anything I was underselling the actual privacy and security issues.
I still wonder if the Recall data is destined for a local LLM "assistant" to satisfy the craving for yet more AI bollocks.
Simon Zerafa
Unbekannter Ursprungsbeitrag • • •@JessTheUnstill
I've not seen any specific mentions of a local LLM anywhere by MS or anyone discovering functionality but it seems like a "logical" use for the Recall data.
I posted ramblings on it earlier this week as to the possible ramifications 🫤
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Some backstory - it's being reported Microsoft developed Recall in secret to try to avoid scrutiny. windowscentral.com/software-ap…
I'm hearing that various MSFT people are furious about how this played out over the past few weeks, which IMHO represents a serious lack of introspection.
A PR disaster: Microsoft has lost trust with its users, and Windows Recall is the straw that broke the camel's back
Zac Bowden (Windows Central)teilten dies erneut
Peter, 0xThylacine, The Flight Attendant und Volt4ire haben dies geteilt.
Ikon Hannunen
Als Antwort auf Kevin Beaumont • • •yeah, well all major customers of Microsoft should factor this along with MSOFT's milquetoast decision to have it as default off into their decision-making models.
Microsoft clearly want this to blow over and move forward and eventually perniciously be enacted spyware/surveillance ware.
All major customers should be moving away from Microsoft until resignations occur and Recall is completely scuttled. Full stop.
DieMadColonizer
Als Antwort auf Ikon Hannunen • • •@hannu_ikonen fwiw I won't be bacc permanently, just like I stopped using apple products more than a decade ago, when they didn't honor a warranty on my last iPod.
And I'll never shut up about how bad they are, and will convince people to use other shit and teach em how. I won't end msft but I'll do my part to dissuade bad actors in tech (just like im doing with google). They've fked their brand for a generation I think.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft have paused the rollout of Windows 11 24H2 in preview channel, it was the version containing Recall. Microsoft have not explained why.
x.com/brandonleblanc/status/17…
I don't know if it was publicly known but it was possible to use Recall on more hardware via Mach2, before this was pulled.
teilten dies erneut
theOmegabit und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •I have an image where when viewed on a Copilot+ Recall PC, a Windows process crashes as it tries to process the screenshot.
New email signature?
teilten dies erneut
DieMadColonizer und Bastian Beuttel haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •To put this one into perspective, there's one broadcast TV network looking at Recall still, and an investigative journalist.
Plus I imagine @evacide, @wdormann etc would have something to say if MS tried holding anybody but themselves accountable for their own actions.
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Volt4ire und DieMadColonizer haben dies geteilt.
lizard appreciator
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft’s President Brad Smith appears before US House Committee on Homeland Security tomorrow.
His testimony: homeland.house.gov/wp-content/…
In this bit he talks about Recall (not named), where he pats himself and Microsoft on the back for “a feature change” and job well done.
Given it has been a complete cybersecurity and privacy car crash - and as of today the changes (plural) they’re referring to haven’t even been implemented - it seems like Microsoft fails to grasp customer needs: safety.
teilten dies erneut
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •One other thing - Microsoft's written testimony to the US House says, quoting, bolded by MS:
"Before I say anything else, I think it’s especially important for me to say that Microsoft accepts responsibility for each and every one of the issues cited in the CSRB’s report. Without equivocation or
hesitation. And without any sense of defensiveness."
Counterpoint: they publicly disputed the report in the media. theverge.com/2024/4/25/2413991…
Microsoft needs to win back trust
Tom Warren (The Verge)teilten dies erneut
DieMadColonizer hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I should say that if Brad is asked about Recall tomorrow, the answers may raise some.. uh... eyebrows here.
I don't know what MS SLT have been told, but expect fun when the feature drops on consumer laptops in a few days.
As I mentioned in my blog, there is some more security hardening there on Copilot+ PCs (this was before MS put out their blog)... but it's still easily bypassable.
DieMadColonizer hat dies geteilt.
Adam Shostack
Unbekannter Ursprungsbeitrag • • •Michael Weiss
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •Microsoft’s Recall puts the Biden administration’s cyber credibility on the line
cyberscoop.com/microsoft-recal…
Interesting article. All through this, CISA and the DHS have declined to comment.
Microsoft’s Recall puts the Biden administration’s cyber credibility on the line
eliasgroll (CyberScoop)teilten dies erneut
DieMadColonizer, Florian Schmidt und Tuckers Nuts Resist! 🇺🇦 haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Hahn Holio, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Florian Berger (privat), The Flight Attendant und DieMadColonizer haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •The Verge reports today that "Windows engineers are scrambling to get additional changes tested and ready for the release of Copilot+ PCs next week."
It also says "Recall was developed in secret at Microsoft, and it wasn’t even tested publicly with Windows Insiders."
I've also been told Microsoft security and privacy staff weren't provided Recall, as the feature wasn't made available broadly internally either.
theverge.com/2024/6/13/2417770…
Xbox delivered and Windows scrambles to secure Recall
Tom Warren (The Verge)teilten dies erneut
Lord Caramac the Clueless, KSC, DieMadColonizer, Florian Schmidt und Tuckers Nuts Resist! 🇺🇦 haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Felix, Maxi 10x 💉, 0xThylacine und Bastian Beuttel haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Florian Schmidt hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Brad Smith just said Recall was designed to be disabled by default. That is not true. Microsoft’s own documentation said it would be enabled by default - they only backtracked after outcry.
He has somehow got almost every detail about Recall wrong while testifying.
teilten dies erneut
Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Florian Schmidt und Ulrich Junker haben dies geteilt.
DieMadColonizer
Als Antwort auf Kevin Beaumont • • •DieMadColonizer
Unbekannter Ursprungsbeitrag • • •🌱 Ligniform
Als Antwort auf Kevin Beaumont • • •Nullstring 🏴☠️
Als Antwort auf 🌱 Ligniform • • •DieMadColonizer
Unbekannter Ursprungsbeitrag • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Mx. Luna Corbden und Florian Schmidt haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Timo Hetzel, Adam Shostack, Florian Schmidt, Dieu, Ulrich Junker und Lord Caramac the Clueless, KSC haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Obviously, I’ll wait to see the announcement but it sounds like they’ve finally realised they need to take the time and get the feature right (and frankly consider the target audience - most home users, it ain’t).
They should have announced this before or during the US House hearing.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Announcement is out. Good on Microsoft for finally reaching a sane conclusion.
- Recall won’t ship as a feature at launch on Copilot+ PCs any more.
- Won’t be available in Insider preview channel at launch, as it was pulled.
When it does appear in preview channels, privacy and security researchers need to keep a close eye on what Microsoft are doing with the feature.
Microsoft tried developing this feature in secret in a way which tried to avoid scrutiny. Thank you to everyone who stood up.
teilten dies erneut
Fink, BioSchweiz und Lord Caramac the Clueless, KSC haben dies geteilt.
0xThylacine
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •If anybody is wondering, Microsoft moved the announcement up as I scooped them 🤣
Thank you to everyone who helped out with this one, there was no way something that constantly OCR’d the screen being implemented so poorly was acceptable but Microsoft really, really dug their heels in.
Photographic memory of everything you’ve ever done on a computer has to be entirely optional, with risks explained and be done right.. or not at all. Accountability matters.
Microsoft, be better.
0xThylacine
Als Antwort auf Kevin Beaumont • • •Of course they did. They need to distract attention away from the blatant lies that were just told to the house. It's SOP for companies to stamp out bad publicity before it gets traction in mainstream media, by luring them with another baitline.
Thanks for your efforts btw.
Adam Shostack
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •If anybody wonders if Recall classifies what porn you watch, yes. Aside from OCRing text it also classifies images in videos.
9 minute 50 second mark in this, screen is blurred for obvious reasons.
youtu.be/2GTI00pFcLc?si=EiBEaJ…
Wir haben Windows Recall ausprobiert, damit ihr es nicht müsst
YouTubeteilten dies erneut
Sirana hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Here’s the clip translated around adult content with Microsoft Recall.
They filter search terms in English like naked - but don’t filter it in other languages.
Everything you view - including in videos - is classified and stored in the database.
teilten dies erneut
Newk und The Flight Attendant haben dies geteilt.
Maxi 10x 💉
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •This is pretty good - detecting Microsoft Recall misuse for data exfil. youtu.be/SV9-dn-5uEY?si=jVz9sC…
I tested this against the latest release of Recall and both TotalRecall and these detections still work.
Obviously Recall may well alter before it hits Insider preview channel, nobody needs to rush out detections yet.
Btw all through this saga, Microsoft Defender never triggered Recall specific alerts for me. Sophos did.
Microsoft Recall: Detecting Abuse | Threat SnapShot
YouTubeFlorian Schmidt hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Maxi 10x 💉
Unbekannter Ursprungsbeitrag • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Windows 11 24H2 preview release has been rereleased (but only for Copilot+ devices). It doesn’t include Recall any more.
pcworld.com/article/2370043/wi…
Additionally the Copilot+ PCs now have an update which enables the other AI features. This wasn’t available until a few hours ago, hence the lack of unsupervised reviews of the devices. It means you will see those reviews drop after the devices launch tomorrow.
Windows 11's latest update is kind of insane, in a bad way
Mark Hachman (PCWorld)Maxi 10x 💉
Unbekannter Ursprungsbeitrag • • •Maxi 10x 💉
Unbekannter Ursprungsbeitrag • • •Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •.@JohnHammond’s video on Recall is great, and a lot of fun - should also stop history being rewritten on this one later.
youtu.be/JujkOmvbgGw
Windows Recall (was) a Security Nightmare
YouTubeKevin Beaumont
Als Antwort auf Kevin Beaumont • • •There’s a website which gives some insight into how the UI and marketing push for Copilot+ Recall came together. The actual video appears to have gone MIA.
iamp.at/work/introducing-recal…
Introducing Recall - Patrick Flaherty
Patrick FlahertyKevin Beaumont
Als Antwort auf Kevin Beaumont • • •I got ahold of what I think is the latest Microsoft Recall (Copilot+ Recall? Nobody knows the branding) build and.. well.. Total Recall still works with the smallest of tweaks to export the database, it's still accessible as a plaintext database with marketing as the security layer.
Another observation, the Recall backlog must be very large as it's just becoming a truck load of features being dumped on.
teilten dies erneut
theOmegabit hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •One thing MS needs to fix in Recall, before the Insider canary build hits again, is the MSRC bug bounty.
As far as I can see, if you find a critical or high in Recall it qualifies for *drumroll* $1k bounty, unless I'm misinformed.
That probably needs clarifying as nobody is going to sell photographic memory access to Windows devices to MS for that value - it's way more valuable elsewhere.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •The Truth about Snapdragon X Laptops…
YouTubeKevin Beaumont
Als Antwort auf Kevin Beaumont • • •New Microsoft ads tout unavailable Recall feature, don't mention it was indefinitely delayed due to privacy concerns
Dallin Grimm (Tom's Hardware)Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Nicole Parsons hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Should Microsoft Recall ever reappear I plan to keep checking how secure it is, because the next evolution of security cannot be Microsoft pouring petrol onto the infostealer fire.
Infostealer malware is swiping millions of passwords, cookies, and search histories. It’s a gold mine for hackers—and a disaster for anyone who becomes a target.
wired.com/story/infostealer-ma…
teilten dies erneut
The Flight Attendant, your auntifa liza 🇵🇷 🦛 🦦, Nicole Parsons und Tuckers Nuts Resist! 🇺🇦 haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •XDA Developers, who were a good source of behind the scenes info during the Microsoft Recall saga, are saying Microsoft have kicked Recall into the long grass and they think it may never launch. xda-developers.com/thread/micr…
It’s been almost two months since Microsoft said it would launch for Insiders in “weeks” instead.
Microsoft wants you to forget about Copilot+ Recall, it seems
XDAteilten dies erneut
Freight, Paul Shryock und Nicole Parsons haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft now say Recall will available for Insider testing in October on select Copilot+ PCs.
As a community we’ll need to test the security implications out extensively.
Due to hardware requirements this will obviously be a problem, unless we can hack it to install on non-NPU systems again - I don’t know if that has been ‘fixed’ or not.
theverge.com/2024/8/21/2422543…
Microsoft’s Recall AI feature won’t be available for Windows testers until October
Tom Warren (The Verge)Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft says its Recall uninstall option in Windows 11 is just a bug
Tom Warren (The Verge)teilten dies erneut
Aljoscha Rittner (beandev), Überlebenskünstler (er/ihm), Freight, The Flight Attendant und Lucas James haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Recall is back.
Overall the planned changes here are much more robust.
Some of the things are boomerangs - eg they said it wasn’t uninstallable weeks ago, but it is now. Also they said it wasn’t developed under Secure Future Initiative a few months ago.. but now say it was originally under SFI.
The proof is in the pudding obviously so hands on tests will be required. They’ve locked it to Copilot+ PC systems now, which will limit research.
theverge.com/2024/9/27/2425572…
Microsoft’s more secure Windows Recall feature can also be uninstalled by users
Tom Warren (The Verge)teilten dies erneut
Freight und Ulrich Junker haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Typical Microsoft! Disabling Windows Recall is Breaking File Explorer
Sourav Rudra (It's FOSS News)teilten dies erneut
Hans, Erik Jonker, Simon Zerafa, Freight und The Flight Attendant haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft have recalled Recall again.
It still hasn't even made it to Insider preview yet, that's been delayed too, now in December.
Good, by the way. They should take the time to get it right. I still don't know what they were thinking when they had the CEO stand on stage and say it was launching on devices 6 months ago and would be fully secure, when they hadn't even done a basic security review of it.
theverge.com/2024/10/31/242845…
Microsoft just delayed Recall again
Tom Warren (The Verge)teilten dies erneut
Freight, Andrew 🌻 Brandt 🐇 und The Flight Attendant haben dies geteilt.
Asta [AMP]
Als Antwort auf Kevin Beaumont • • •I want them to realize there is literally no 'secure' or 'right' way to do this. It is always going to cause more harm than anything else.
I'll accept delaying, I guess.
Irenes (many)
Unbekannter Ursprungsbeitrag • • •Irenes (many)
Als Antwort auf Asta [AMP] • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I'd be surprised if it is released in December btw, as Redmond is a ghost town in the office from basically now until mid January.
I guess a cynical version is they're trying to rush out the Insider preview during Christmas so nobody actually reviews it.. but, well, I don't think that would happen as it'd be another own goal. It probably needs 6 months in Insider release with a bug bounty, to avoid exploits dropping like Joker 2 at the box office on release.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •In a newly released blog entitled "Windows: AI-powered, cloud-enabled, and secure", Microsoft say the business versions of Windows will ship with Recall disabled by default - IT departments will have to enable the feature before it is available.
This is a smart move and frankly it was incredible that the original idea was to ship this enabled by default in business - it was never, ever going to fly and hopefully Microsoft is rightly humbled by the experience.
techcommunity.microsoft.com/bl…
teilten dies erneut
Freight hat dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft are getting positive press for calling Recall “one of the most secure experiences it has built”.
I’d point out - they haven’t provided a Preview build to Insiders still, and there’s been no externally provided build (outside of NDA), so nobody has been able to assess the security and talk about it. There’s no specific bug bounty for it either.
When they first announced Recall, they called it totally secure - which was laughably inaccurate. It feels like a lot of premature high fiving
teilten dies erneut
Maxi 10x 💉, Freight, Tuckers Nuts Resist! 🇺🇦 , The Flight Attendant, Volt4ire und Lord Caramac the Clueless, KSC haben dies geteilt.
CatSalad🐈🥗 (D.Burch)
Als Antwort auf Kevin Beaumont • • •DJGummikuh
Als Antwort auf Kevin Beaumont • • •Tuckers Nuts Resist! 🇺🇦
Unbekannter Ursprungsbeitrag • • •🥥 Our C-Suite is happy to announce that Acme Corporation's new Orphan Crushing Machine is 500% more efficient at crushing orphans than ever before thought possible.
High fives all around!
(PS: Ryan, "percent" in this post is deliberately misused in order to conform to the Corporatespeak Style Manual.)
Unabogie has voted Kamala!
Unbekannter Ursprungsbeitrag • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft Recall is now available for testing.
theregister.com/2024/11/22/mic…
It’s only available on Qualcomm Snapdragon-powered Copilot+ PCs. My feeling is we’re probably going to want to hook one up to the internet and hack RDP for unlimited sessions, to allow research - I’ll look into it.
I’ve been told Recall is eligible for bug bounty as part of the Insider programme. I think the process is supposed to be sandboxed so in theory (my reading) the payout limit should be $20k.
Now’s your chance to try Microsoft’s controversial Windows Recall ... maybe
Iain Thomson (The Register)teilten dies erneut
The Boxing Kangaroo, Simon Zerafa, Florian Schmidt, The Flight Attendant und Freight haben dies geteilt.
Clifton Royston
Als Antwort auf Unabogie has voted Kamala! • • •I think everyone is. Nobody seems too confused about what Microsoft wants to get out of it. (*All* your data, once they quietly change the terms of service a year or two down the road.)
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Microsoft are rolling out Recall to users in Windows Insider (testing) before a wider rollout to all compatible systems.
It's definitely one to watch (and yes, I am) from a security point of view.
bbc.co.uk/news/articles/cj3xjr…
Copilot Recall: Microsoft rolls out AI screenshot tool
Imran Rahman-Jones (BBC News)teilten dies erneut
RayneToday, The Flight Attendant und SocProf haben dies geteilt.
Luuk
Als Antwort auf Kevin Beaumont • • •Ľuboš Moščovič
Als Antwort auf Kevin Beaumont • • •Why Not Zoidberg? 🦑
Als Antwort auf Kevin Beaumont • • •VessOnSecurity
Als Antwort auf Kevin Beaumont • • •Steven Op de beeck
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •I've took a look at the past year of work Microsoft has done on Recall, which is due to roll out to compatible Windows devices soon
tl;dr it's much better from a security and privacy point of view. My partner managed to hack my Recall memory in 5 minutes to browse prior Signal discussions, by guessing my Windows Hello PIN.
There's a bunch of risks people who enable it need to understand.
doublepulsar.com/microsoft-rec…
Microsoft Recall on Copilot+ PC: testing the security and privacy implications
Kevin Beaumont (DoublePulsar)teilten dies erneut
Quixoticgeek, Luk, Marcus Adams, Florian Schmidt, Jürgen 🌗🪐🌌, conscientious objector🇨🇭🪂, The Flight Attendant und Tuckers Nuts Resist! 🇺🇦 haben dies geteilt.
Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
Simon Zerafa, Timo Ollech, your auntifa liza 🇵🇷 🦛 🦦, P. S. F., Daniel Ares, Marcus Adams, Florian Schmidt, Roy #EatTheRich Pardee 🇺🇸, Daniel AJ Sokolov, CrazyDogLadysezBreatheWithMe, Martin Seeger, The Flight Attendant, Tuckers Nuts Resist! 🇺🇦 , coderipper und Anna Christina haben dies geteilt.
T2R
Als Antwort auf Kevin Beaumont • • •David Whelan
Als Antwort auf Kevin Beaumont • • •Daniel AJ Sokolov
Als Antwort auf Kevin Beaumont • • •Robert Link
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •In depth with Windows 11 Recall—and what Microsoft has (and hasn’t) fixed
Andrew Cunningham (Ars Technica)Alan Miller 🇺🇦
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •teilten dies erneut
GunChleoc, Marcus Adams, The Flight Attendant und Autoerotic Defenestration haben dies geteilt.
raffitz
Als Antwort auf Kevin Beaumont • • •Jonly
Unbekannter Ursprungsbeitrag • • •Ainsley Lowbeer
Unbekannter Ursprungsbeitrag • • •Honestly, if I were still working at the soft, I'd enable it instantly. It's perfect for that scenario.
Jurjen Heeck 🍋
Als Antwort auf Kevin Beaumont • • •Stephen Borrill
Als Antwort auf Kevin Beaumont • • •Brian Clark
Als Antwort auf Kevin Beaumont • • •abadidea
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Copilot+ PCs are the most performant Windows PCs ever built, now with more AI features that empower you every day
Windows Experience Blogteilten dies erneut
gwendolenau, Marcus Adams, GunChleoc, StreetDogg, Autoerotic Defenestration, The Flight Attendant, jesterchen42 und koehntopp ~ : haben dies geteilt.
Newk
Als Antwort auf Kevin Beaumont • • •Jernej Simončič �
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Tabletop scenario for you:
Employee gets into a dispute with employer, leaves, had sensitive role. Employer revokes access, devices etc. Employee had logged in via BYOD to email, IM etc.
Due to Recall, employee walks away with 6 months of screenshots of everything she's ever worked on in a text indexed form - every email, chat, document, Teams call with video snapshots, transcripts of verbal calls etc - even if they set M365 to not store documents locally.
What does the employer do now?
teilten dies erneut
your auntifa liza 🇵🇷 🦛 🦦, GunChleoc, MrCopilot, Autoerotic Defenestration, The Flight Attendant, diana 🏳️⚧️🦋🌱, Nicole Parsons, The Boxing Kangaroo, JustRosy 🇺🇦, jesterchen42, koehntopp ~ :, Carl, Reinder Dijkhuis Does Art, tom w wolf und Chaz Haws haben dies geteilt.
VessOnSecurity
Als Antwort auf Kevin Beaumont • • •The Turtle
Als Antwort auf Kevin Beaumont • • •Dan 🔓, powered by sarcasm
Als Antwort auf Kevin Beaumont • • •Fi 🏳️⚧️
Als Antwort auf Kevin Beaumont • • •I mean, clearly, this means BYOD cannot be allowed for windows shops;
credentials must only be managed in ways where they can be automatically rotated,
and offboarding must be centrally managed in a way that allows immediate and irrevocable lockdown of all access simultaneously.
Professor Emeritus Blake Y Rat
Als Antwort auf Kevin Beaumont • • •Simon Zerafa
Als Antwort auf Kevin Beaumont • • •The moral here is to reject BYOD devices with Recall enabled.
Issue your own strictly for business use devices without that nonsense even installed, if that's remains possible in the future.
Chris
Als Antwort auf Kevin Beaumont • • •Sadie
Als Antwort auf Kevin Beaumont • • •It should sue itself for allowing Recall in its environment.
Which I guess means no BYOD
Hugo Mills
Als Antwort auf Kevin Beaumont • • •Professor Emeritus Blake Y Rat
Unbekannter Ursprungsbeitrag • • •groff
Als Antwort auf Kevin Beaumont • • •James Wells
Als Antwort auf Simon Zerafa • • •@simonzerafa
You need to emphasize `PHYSICAL DEVICE` here, even more than normal. With VDIs, they still need a device to access said VDI's, and will often use their personal devices, which will have Recall on and happily chugging away on the data that is being displayed from the VDI's graphical interface.
As for @GossiTheDog , you really really need to hope that your company is dealing with honorable / honest people or this won't end well.
(roll m3tti)
Als Antwort auf Kevin Beaumont • • •da_667
Unbekannter Ursprungsbeitrag • • •Ricky Boone
Als Antwort auf Kevin Beaumont • • •But think of the opportunities! This opens the door for Microsoft and security vendors to come up with new solutions to sell to concerned companies! It's a win/win scenario... If you exclude the customer/user.
/s
GunChleoc
Unbekannter Ursprungsbeitrag • • •NosirrahSec 🏴☠️
Unbekannter Ursprungsbeitrag • • •@da_667 hahahahah
User devices running around with a fucking DB of searchable private IP is such a massive "fuck yes" moment for criminals, state-sponsored, or otherwise.
James Forshaw
Als Antwort auf Kevin Beaumont • • •Atomic Orbitals
Als Antwort auf Kevin Beaumont • • •Michael Link (ksmichel)
Als Antwort auf Kevin Beaumont • • •Cityhallin
Als Antwort auf Kevin Beaumont • • •Carsten
Als Antwort auf Kevin Beaumont • • •Carsten
Als Antwort auf Simon Zerafa • • •James Forshaw
Unbekannter Ursprungsbeitrag • • •sortius
Als Antwort auf Kevin Beaumont • • •Croutons for breakfast 🪓
Als Antwort auf Kevin Beaumont • • •Dave 🐶
Als Antwort auf James Wells • • •Simon Zerafa
Als Antwort auf Dave 🐶 • • •@Cyberoutsider @nikatjef
I'd be more worried about it honouring Group Policy settings to disable snapshots.
Including ensuring that it's not accidentally or deliberately reenabled 🫤
Marco Mastropaolo
Unbekannter Ursprungsbeitrag • • •Marco Mastropaolo
Unbekannter Ursprungsbeitrag • • •cR0w
Unbekannter Ursprungsbeitrag • • •wall-e / Daniel
Als Antwort auf Kevin Beaumont • • •Not much use having confidential conversations and a disappearing messages feature when one part of the conversation is constantly screenshoting everything
Adrian Sanabria
Als Antwort auf Kevin Beaumont • • •Adrian Sanabria
Unbekannter Ursprungsbeitrag • • •@reijomancer @munin 1. what’s the benefit of BYOD on the other side of the scale? Surely it is greater than the risk.
Reijo Pitkänen
Als Antwort auf Fi 🏳️⚧️ • • •@munin So, BYOD dies a messy death because the oroborus of capitalism decides it's cheaper to pay for work devices and real MDM instead of letting employees float the cost of their off-hours wage slavery?
Ugly, but sign me up.
Throw more self-interest entropy into this farce called Recall.
Adrian Sanabria
Als Antwort auf Dave 🐶 • • •XenoPhage
Als Antwort auf Adrian Sanabria • • •@sawaba Sure, but not everyone does that as a regular habit, so it's usually not a big problem. But now, anyone with a Windows machine will be doing that without even knowing it.
I'm not sure what the security around it looks like, but this could be a massive way to leak a ton of data that wouldn't normally be local on a machine. Especially for stuff that's typically accessed via "secure” gateways. Sales folks will have screenshots of client lists, engineers could potentially have screenshots of passwords and configurations.
This feels like a really, really bad idea to me..
James Wells
Als Antwort auf Adrian Sanabria • • •@sawaba
So the trick there is that from within your VDI, you can screenshot to your heart's content... It is just that some VM services have a feature that is supposed to be able to to block you from being able to take screenshots of your VDI's virtual display.
But yes, I live by the screenshot too much to want to disable that feature when I don't have to.
@Cyberoutsider @simonzerafa @GossiTheDog
Adrian Sanabria
Unbekannter Ursprungsbeitrag • • •if you’re on a box, can’t you just do the equivalent of Recall with malware? It definitely makes the job of an attacker easier and more streamlined, but not sure it adds up to a massive increase in risk.
Also, anyone that figures out how to eliminate that one hour every day the planet spends trying to find stuff on their computer could maybe add 10% to global GDP. How much risk is that worth?
(not that Recall is that solution, but it could be, right?)
Graham Sutherland / Polynomial
Als Antwort auf Adrian Sanabria • • •Adrian Sanabria
Als Antwort auf XenoPhage • • •infosec_j
Als Antwort auf Kevin Beaumont • • •so how many months do we think it'll be before Microsoft deploys an admin template for intune to require that Recall is disabled on a system
Because given what I've been dealing with lately, I'm betting more than 12
XenoPhage
Als Antwort auf Adrian Sanabria • • •@sawaba I may be, yes. But I guess my point is, folks screenshot specific things for the workflows they use. But they won't screenshot everything. Now they'll be screenshotting everything which makes the problem much worse.
Screenshotting has always been a way around DLP solutions. It makes me laugh when I deal with companies who think that locking developers into an AWS workspace with cut/paste to the host disabled will somehow keep their code secure. All they end up doing is frustrating the developers and losing good talent.
I'm just concerned that now the average user will suddenly have screenshots of all of their activity stored on their machines and may not even know it. That goes for home users too where it can be far more problematic since home users generally don't have encryption turned on, etc. Not to mention domestic situations where an abuser can now use this to spy on everything their partner is doing.
Adrian Sanabria
Als Antwort auf Graham Sutherland / Polynomial • • •@gsuberland true, but infostealers often get access to most of the things that would be getting screenshotted. I need to think through the different scenarios where an adversary would find something like Recall data useful versus just grabbing tokens and creds…
Just trying to figure out where this lives on defenders’ neverending list of top priorities that will never get done
Jonas
Als Antwort auf Kevin Beaumont • • •Tired: Microsoft have announced they are rolling out Copilot+ Recall
Wired (what I read): Microsoft have announced a recall of Copilot+ roll out
Adrian Sanabria
Als Antwort auf XenoPhage • • •@XenoPhage yeah, I’ve been thinking about how using recall would change how people use their computers. Regularly seeing screenshots of your own activity might prevent you from doing personal stuff on a work computer, ironically.
But if you don’t realize it is on, it’s just a liability.
Either way, in a corporate setting, I imagine this would be useful for HR to abuse employees. Tons of evidence to use against you if they wanted to.
It would have to massively solve the “find my shit” problem for all the downsides to be worth it.
Fi 🏳️⚧️
Als Antwort auf Adrian Sanabria • • •@sawaba @reijomancer
Excellent question.
Yes, all major operating systems do in fact allow screenshotting,
however!
Use of the snipping tool can be disabled for some or all users of a system with a registry entry; this control is made ineffective by Recall
Use of the snipping tool or a third-party application to make screen captures is an auditable action; Recall performs these captures automatically
User-controlled screen capturing is not inherently indexed nor processed in ways that make the contents machine-readable
User-controlled screen capturing does not necessarily have a consistent location on-disk where the records of such captures are stored, where an adversary would be able to script wholesale extraction of said records
There are other issues as well, but these are sufficient to make the point that recall's automated screenshotting, collation, and storage of captures without the specific agency or control of the user is sufficiently different from the prior model as to need a recontextualization and re-evaluation of extant controls to determine efficacy.
Adrian Sanabria
Als Antwort auf Fi 🏳️⚧️ • • •Phillip
Unbekannter Ursprungsbeitrag • • •Ok it looks like recall excludes rdp sessions and drm streaming, so that’s good to know.
support.microsoft.com/en-us/wi…
Privacy and control over your Recall experience - Microsoft Support
support.microsoft.comPhillip
Als Antwort auf Kevin Beaumont • • •chrisp
Als Antwort auf Kevin Beaumont • • •DarkAthena 💙🏳️🌈🧑🏻💻💫
Als Antwort auf Kevin Beaumont • • •Jason Haar
Unbekannter Ursprungsbeitrag • • •SouthFresh
Als Antwort auf Kevin Beaumont • • •John Keates
Als Antwort auf Kevin Beaumont • • •isn’t this the general issue with data access control anyway? As soon as you can see something with your eyeballs, so can a phone with a camera.
Putting a native infostealer in Windows is definitely another order of sillyness, but the idea that anyone can contain data while it’s visible to arbitrary eyeballs/cameras has not really held up for quite a while. I suppose DRM failed the same way, which recall also breaks.
A similar problem exists with a previous product that would have you carry around a camera so it could take pictures of your life for you; if you sat in front of your computer it would store that too. IIRC, Microsoft had one of those too. I guess history just keeps repeating.
XenoPhage
Als Antwort auf Adrian Sanabria • • •🦃 Kat Callahan 🦃
Als Antwort auf Kevin Beaumont • • •As an IT professional: oh no
As a union organiser: yo go, girl, get that settlement, sign an NDA, and hand over the data from your BYOD.
In any dispute, I automatically side with the worker, never management.
skry
Als Antwort auf Kevin Beaumont • • •Scenario 2: Employee leaves BYOD in Lyft.
4-digit PIN is guessed by offshore hardware resellers, who sell the company's data and the employee's nudes to the highest bidder. Everyone keeps a copy just in case.
JustRosy 🇺🇦
Als Antwort auf Kevin Beaumont • • •JustRosy 🇺🇦 hat dies geteilt.
JustRosy 🇺🇦
Als Antwort auf Kevin Beaumont • • •So. Much. BS in that blog ad. Lies everywhere. Everyone *hates* AI with a passion, and hates Microsoft almost as much. Literally, both are costing people their jobs and their ability to survive. F them both.
Here's how, too:
support.microsoft.com/en-us/wi…
Privacy and control over your Recall experience - Microsoft Support
support.microsoft.comJustRosy 🇺🇦 hat dies geteilt.
OsamaSalah
Als Antwort auf Kevin Beaumont • • •Adrian Sanabria
Als Antwort auf XenoPhage • • •Adrian Sanabria
Unbekannter Ursprungsbeitrag • • •Tim Ward ⭐🇪🇺🔶 #FBPE
Als Antwort auf Kevin Beaumont • • •fedops 💙💛
Als Antwort auf Kevin Beaumont • • •I have yet to see one actual valid use case for this.
Though the Citric screen capture bypass does come close. 😂
Martijn Vos
Als Antwort auf Kevin Beaumont • •@Kevin Beaumont
Companies dealing with sensitive info should ban all computers capable of running Recall from their networks.
soc
Als Antwort auf Reijo Pitkänen • • •@reijomancer @munin In which world does "BYOD" not include MDM?
So the obvious answer to Kevin's question is "the employer wipes the device" – case closed.
soc
Unbekannter Ursprungsbeitrag • • •sysfrank 🇺🇸
Als Antwort auf Kevin Beaumont • • •I could offer a suggestion, but I wouldn't want to give the whiz kids at DOGE any ideas.
🤣🤣🤣
Martijn Vos
Unbekannter Ursprungsbeitrag • •@Kevin Beaumont @Fi 🏳️⚧️ @soc @Reijo Pitkänen
Stopping malicious leaks is almost impossible, but Recall sounds to me like it makes even accidental leaks trivial.
soc
Als Antwort auf Martijn Vos • • •Kevin Beaumont
Als Antwort auf Kevin Beaumont • • •Signal have rolled out an update to all users that stops Microsoft Recall from capturing Signal conversations.
I’ve tested this and it works. Brilliant work by the @signalapp team. 💪
They call on Microsoft to build better, as there was no standardised way as an app developer to do this. Because Signal is open source, now app developers have a template to protect their users from Windows.
signal.org/blog/signal-doesnt-…
By Default, Signal Doesn't Recall
Signal Messengerteilten dies erneut
Rad und Tat, Extra_Special_Carbon, Eric Burger, @PrivacyMatters, Neblib, RayneToday, your auntifa liza 🇵🇷 🦛 🦦, javigus, GinevraCat, Third spruce tree on the left, Nicole Parsons, Simon Zerafa, technicat, Mycotropic, Zack Whittaker, Axel ⌨🐧🐪🚴😷 | R.I.P Natenom, Donaupiratin, Luke Kanies, mcc, Marcus Adams, Caro S., The Flight Attendant, Billiglarper, Mallory Knodel, ein kleines z, zynmaster, Martin Schröder, Henrik Schönemann, A Temporary Collection, Weltschmerz à Gogo, Glyn Moody, RiaResists, Dawning Sun, Federico Mena Quintero, Vladimir Chicken, Roy #EatTheRich Pardee 🇺🇸, Nico Jensen, Jess👾, ghostdancer, Mirishuli, Andreas Albrecht, Veronika Cheplygina, Strght, Erik Wessel, Argie, elala@nrw.social und Dorothee Janssen haben dies geteilt.
your auntifa liza 🇵🇷 🦛 🦦
Als Antwort auf Kevin Beaumont • • •Rob Carlson
Als Antwort auf Kevin Beaumont • • •Jake Rayson
Als Antwort auf Kevin Beaumont • • •r0k
Als Antwort auf Kevin Beaumont • • •Third spruce tree on the left
Als Antwort auf Kevin Beaumont • • •@signalapp And by using #Microsoft's own #DRM protections to do it too. THat's brilliant.
I have #Signal but don't use it (I don't know anyone else on it) - but I still pay a recurring donation monthly because THIS is the user(privacy, rights, security)-focused product management that I want to encourage. Way to go Meredith and team.
your auntifa liza 🇵🇷 🦛 🦦 hat dies geteilt.
Three LLMs in a Trenchcoat
Als Antwort auf Kevin Beaumont • • •phoenix🐧🏕🏞🚀🍝
Als Antwort auf Kevin Beaumont • • •Using DRM for a change to work "for the user" is a very clever idea to prevent Windows Recall from making Screenshots.
Kudos @signalapp for the creative solution👏👏
your auntifa liza 🇵🇷 🦛 🦦 hat dies geteilt.
Claus Cramon Houmann
Als Antwort auf Kevin Beaumont • • •your auntifa liza 🇵🇷 🦛 🦦
Als Antwort auf Third spruce tree on the left • • •“And by using #Microsoft's own #DRM protections to do it too. THat's brilliant.”
that’s exactly what caught my eye. they didn’t have to hack anything. it’s there in Microsoft’s own APIs. they’ve turned the monster of their own creation against them.
@tezoatlipoca @GossiTheDog @signalapp
Jennifer Kayla | Theogrin 🦊
Als Antwort auf your auntifa liza 🇵🇷 🦛 🦦 • • •@blogdiva @tezoatlipoca @signalapp
The obvious next step is for someone to use those selfsame APIs to create a tool which stops Recall from recording anything.
You love to see it.
your auntifa liza 🇵🇷 🦛 🦦 hat dies geteilt.
Third spruce tree on the left
Als Antwort auf Jennifer Kayla | Theogrin 🦊 • • •omg a browser plugin that marks any open tab as containing DRM enforced content.
edit: sadly, very very hard to do. there are no "standard" DRM protocols for html and related ascii text content.
your auntifa liza 🇵🇷 🦛 🦦 hat dies geteilt.
Craig Stewart
Als Antwort auf Kevin Beaumont • • •RalfMaximus
Als Antwort auf Kevin Beaumont • • •@signalapp
Feel like this is the opening salvo in an escalating war, the same way youtube is fighting off uBlock Origin.
For example, that DRM attribute might soon be disabled for "non media containers" since it was devised to protect copyrighted works. Sure, that'd be petty. But it's Microsoft we're talking about here.
Then of course Signal posts a workaround, which Microsoft quickly--
NosirrahSec 🏴☠️
Als Antwort auf Kevin Beaumont • • •デイヴ
Als Antwort auf Kevin Beaumont • • •tomas
Als Antwort auf Third spruce tree on the left • • •DasSkelett
Als Antwort auf Kevin Beaumont • • •> “Take a screenshot every few seconds” legitimately sounds like a suggestion from a low-parameter LLM that was given a prompt like “How do I add an arbitrary AI feature to my operating system as quickly as possible in order to make investors happy?”
🔥
F4GRX Sébastien
Als Antwort auf Kevin Beaumont • • •Third spruce tree on the left
Unbekannter Ursprungsbeitrag • • •@f4grx @tomas @signalapp So I don't know if its what #Signal app did (I don't have the spoons to go digging around their repo rn), but one way to invoke the #Windows #DRM protections on your app is to set the display affinity of your main window handle:
`SetWindowDisplayAffinity(hwnd, WDA_MONITOR)`
learn.microsoft.com/en-us/wind…
where `hwnd` is your main window handle and `WDA_MONITOR` sez only show on the monitor, all other purposes get no content.
SetWindowDisplayAffinity function (winuser.h) - Win32 apps
learn.microsoft.comF4GRX Sébastien
Als Antwort auf tomas • • •Third spruce tree on the left
Als Antwort auf Third spruce tree on the left • • •@f4grx @tomas @signalapp
Sadly, only the application itself can set its own window display affinity; I know I just tried for an hour to write one - Windows User Interface Priviledge Isolation IUPI security prevents almost any attempt of one process to muck w/ the main window of another.
Otherwise that would be the coolest thing ever. run a little app that blacks out another app's window.
Tanawts
Als Antwort auf Kevin Beaumont • • •alihan_banan
Als Antwort auf Kevin Beaumont • • •v
Als Antwort auf Kevin Beaumont • • •jablkoziemne
Als Antwort auf Kevin Beaumont • • •@signalapp Fun, I wander if something similar can be done on #linux with #wayland so I dont accidentally leak all my DMs because of missclick when using #obs and #xdg_desktop_portal, maybe not to the level of application always denying capture ( #drm applications), but it would be cool to have an rejectlist in your linux #desktop to add/remove applications you explicitly dont want to be able to capture (with default values pulled from their #flatpak manifest or something)
If current #xdg specification doesnt allow that, does any of the desktops like #gnome, #kde, #cosmic or #hyperland thought about that?
truh
Als Antwort auf Kevin Beaumont • • •Kevin Beaumont
Unbekannter Ursprungsbeitrag • • •Pavel Machek
Als Antwort auf Kevin Beaumont • • •