Microsoft makes Recall feature off-by-default after security and privacy backlash

Windows Hello authentication, additional encryption being added to protect data.

https://arstechnica.com/gadgets/2024/06/microsoft-makes-recall-feature-off-by-default-after-security-and-privacy-backlash/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

Microsoft is reworking Recall after researchers point out its security problems

Windows Hello authentication, additional encryption being added to protect data.

Ars Technica
@arstechnica Additional? I thought it was using a plaintext sqlite database?
@wagesj45 @arstechnica Microsoft recall now featuring: at rest encryption with keys in plaintext in the database!
@arstechnica I am so glad I am running Linux and LibreOffice!
@arstechnica Too late, damage has already been done
@arstechnica while I won't go back to Windows, off by default is not enough. The fact that it is even there and can be turned on is a major issue for me. It's like the sword of Damocles hanging over your head. What makes this even worse is managers using this to super micro manage people god forbid you spend 5 min here or there doing something else out of 8 hours in a day. Nope. Microsoft can F right off with this crap.

@arstechnica too late. Copilot being the focus of all of your development for the forseeable future was bad.

The fact that you even have this nightmare as part of your OS has made Win11 being on anything that connects to my network a complete no go.

@arstechnica Consider for a moment that, if you do enable the utility, an attacker can easily read the database from unencrypted RAM (can't work properly otherwise). And even if you do not enable the utility, an attacker can silently enable it for you.

@arstechnica

Too late, I'm, already in love with Mint.

@arstechnica Defective by design.
@arstechnica your org should definitely keep trusting these clowns with Azure, tho