If one chats/mails with a person using Windows, despite using secure private protocols, every message will be stored by Microsoft’s Windoze Recall. Either I’m missing something but this feature seems like the most grotesque breach in online privacy/security.
What are ways to avoid this except for using obfuscated text?
Ugh, I didnt think about that😬
Me neither! Microsoft needs to be taken to court over this because it is a serious breach of privacy to not only record the users but even random bystanders as well. Now I am convinced this is just a backdoor for the government hiding in plain sight. Fuck them.
Oh this 100% is the government backdoor that they’ve been begging for. “If you can innovate your way into it, you can innovate a way out of it.”
That was in regards to Apple phones belonging to Boston bombers being encrypted and locked.
It’s no surprise that behind closed doors, the government asked these companies to create backdoors for them to spy on people.
If it leaves your device, you cannot control it.
Right but you could at least be reasonably sure it wouldn’t be outright spied on from the person you’re sending it to. Now it’s almost a guarantee.
Like if I sent something to a friend of mine, I could be fairly certain it wouldn’t end up in the wrong hands unless they got compromised or did something stupid. I could trust their competence.
Now everyone that isn’t actively managing their own windows installation is absolutely compromised, as a rule. Like I can’t just send an email to my mom anymore, from now on its always my Mom and Copilot.
Can’t control what other people do so you might be out of luck.
It’s more about what Microsoft enforces—spyware—than what other people do.
Yes, and that’s a valid concern, but there’s no good answer here. That’s why it’s such a problem. From now on, one of the most widely used operating systems in the world is going to be harvesting data from any and everything that appears on it. Meaning any software you use to send any form of electronic communication, if a Windows computer opens it, and the user either hasn’t bothered or doesn’t know how to disable recall, your information has been harvested by Microsoft.
There’s just no way to limit or avoid this. We need regulation.
I meant you can’t stop then from using Recall.
To my knowledge, there isn’t. But you can ask the person to turn off recall. I’m going to be running 11 in a VM myself so /me shrugs
The code for Recall is in the code for File Manger. Recall cannot be turned off if you want Windows to load and function.
Is this not accurate (anymore)? https://www.windowscentral.com/software-apps/windows-11/how-to-disable-windows-recall#section-how-to-uninstall-windows-recall
That’s just the off button. But you can’t remove it because they tied it to explorer as a depenacy. Off or not, explorer doesn’t work with out recall.
Turning it off is a good step 1, but what’s stopping some malicious software, such as every windows update, from turning it back on and selling our data for profit.
There’s literally an option to turn it off
like all the privacy toggles on facebook? or the “dont upload my start menu searches to bing pretty please” group policy on windows that doesn’t fucking work anymore?
Don’t forget that while they managed the PR better, apple “Intelligence” also has access to damn near everything on your devices.
People also willing submit to the cult if Apple and just believe everything they say. People are likely more frequently forced to use windows due to work or just the lack of choice for less technically confident people.
Yet there’s no backlash because they’re not so stupid as to say “we’re gonna take screenshots as you go so we can improve your digital life kthxbye”.
“Private cloud” as if that isn’t an oxymoron.
I’m in Europe :p
I’m afraid this comment shows a severe underestimation of the gravity of the issue. Windows recall doesn’t stop at borders even if it were illegal there.
Well, it’s not here yet. And I do use windows 11, as does my mom, my grandparents and other pc’s I’m the one helping with. I don’t recall any recalls :p
And if they do push it here, it’s probably followed by a news headline “eu fined Microsoft 10 billion for gdpr violation” or something like that
EU fines take way longer then that, give it a couple years of data collection and if we’re lucky they get fined
who cares? try to prove anything
You can’t, at that point you assume your correspondent is compromised. It’s not just recall but also malware and credential stealers. Doesn’t matter if recall is taking screenshots, if the messaging client itself is pwned via malware then they have full access to as much history as is available.
Wow, valid issue.
Spitballing, potentially a secure app could run memory only, blah, blah, blah. Nope, you’ve given M$ your screen FFS, it’s all over. If you care, move elsewhere, tell your friends…
As you point out, codes are an option, but it’s not a slippery slope, it’s a waterslide.
Turn off your computer, move to a cave in the mountains, and abandon society.
A bit extreme but there is nothing you can do to stop your messages from appearing on Windows machines except not sending them to anyone who might view them on Windows machines…which will definitely be nearly impossible in 2024
I couldn’t wait to post this obligatory fragment of Park and Recreation - Ron vs. Online Privacy: https://youtu.be/8xn1rO1oQmk
Works great until some hikers take a photo with you in the background, that gets backed up to iCloud, then they want to show the photo to a friend, download it to their computer, open it and BOOM, Microsoft AI knows your face
If you tell something to someone else, assume it’s compromised.
“Three can keep a secret if two of them are dead.”
(Even then I’m not so sure)
You must start spreading libre software effectively. You don’t control their device. You must show them how to fix it.
Last year I did so by writing the essay “What if I paid for all my free software?” It came across well. Now I’m thinking of ways to reach a broader audience in order to not only be preaching to the choir.
I would focus on those directly around you first (not online strangers) and showing them by example to do the same, like my last post. Rather than telling them, find ways to make them want to ask you themselves. Make them start the conversation.
Rest assured, I do that too ;)
If the content CNA be displayed, it can be parsed by recall.
The only way I can see to bypass it is to obtain DRM keys and display your content on a website only if widevine is active, like Netflix does. Surely it can’t screenshot DRM protected content, but also this is Microsoft .
Either use secure, encrypted VoIP calls (e.g. over Signal or another secure messenger with an end-to-end encrypted call feature)
Or you use a secure messenger that only runs on smartphones and doesn’t have a desktop client
This is just horrible, fuck big tech and their services
Absolutely
If there’s anything sensitive I’m communicating with someone digitally, I make sure that the person in question has basic tech security skills and knowledge about privacy, including telling them to stop using Windows. Including taking the time to teach them basic stuff (like full disk encryption, VPN and Tor usage, explaining E2EE, etc) myself. If you have a high threat model but are talking to non-techy people, you should be taking the time out of your day to do this.
If you’re thinking “wow I can’t be bothered to do all that”, your messaging is probably not sensitive enough for this to be a significant concern. Not that “if you have nothing to hide you have nothing to fear”, but just “the amount of time you put into security and privacy should be proportionate to your threat model and the cost of compromise”.
So is there a way for businesses to disable this garbage feature through managed device settings or something? I’m guessing corporate legal departments aren’t going to be too thrilled with this feature.
There’s a CSP for disabling it on windows enterprise devices at least. Not sure if there’s a way for pro and home machines.
There must be. Recall and info sec is mutually excluding by definition!