This is cool. What would be a good way to prevent this type of extraction? We just launched OpenRecall https://github.com/openrecall/openrecall with which we want to offer a fully open source/auditable and privacy/security focused alternative.
TotalRecall: Extracts and displays data from the Windows 11 Recall feature
11–20 of 98 posts
Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#12Over the last 2 years (and really longer if you look at Google) time and time again privacy has been put in the background, properly vetting tools for reliability has been put in the background, all in the name of shoving AI into every single thing for investors or because they are scared.
In a few months we will have the next horrible privacy invasive AI thing from one of these companies that is being shoved at us if we want it or not.
On the topic of this actually existing, this is opt out and not opt in I assume? Which just makes this 100% worse.
Will be honest, when this was announced I did not even think of the ability for trojans to get onto your computer and get a lot of sensitive data. I was more concerned about this data being synced between devices and stored on a server somewhere. But that really is one hell of a problem that could cause a lot of issues.
I just think about how often for some game launchers I need to open 1Password to copy my password.
This just makes it more and more that Windows is only for gaming and I will never do anything serious on Windows again.
Not looking forward to this hitting the corporate world, I am sure some companies won't get the memo and just leave this feature enabled. The secrets that are going to be leaked. Screw message retention policies.
Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#13Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#14Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#15This is cool. What would be a good way to prevent this type of extraction? We just launched OpenRecall https://github.com/openrecall/openrecall with which we want to offer a fully open source/auditable and privacy/security focused alternative.
You making this is inherently different than Microsoft including this by default in all future versions of Windows. If someone downloads your tool they are making the conscious choice to give up some data protection for and admittedly cool feature. It is also a more limited number of people with data stored in a particular way.
Every Windows 11 having it, is painting a target on everyone's back since it would be somewhat easy to assume, if Windows 11 this is probably enabled. It is also not properly educating people on the risks.
Personally I don't have a problem with the tool, or necessarily how it is designed (it could be better, don't get me wrong). But it has to be opt in, properly educate on the risks, and probably shouldn't be built into the OS.
Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#16Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#17With cookies and browser access, they could get into my emails, family photos, bank accounts, and even read desktop notifications from my phone's SMSs.
For developers, the real risk lies in the variety of dependencies our apps have, which could get compromised.
So, this isn't really news. There are also tools to access all your iMessage history from a Mac, for example.
I believe the feature is really useful, and for sure you can turn it off.
Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#18Pwned in what way? This is just a SQLite database, you can "pwn" it with any SQLite client of your choice.
Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature
#19Like most AI products and features announced over the past 18 months, it feels like a bunch of product people got into a meeting where they looked at the capabilities of the latest OpenAI model and then started spitballing feature ideas based not on user needs but on what GPTs can do. "Oh, these models can do OCR... why don't we screenshot everything that a user has ever done, OCR it, and make it searchable!"
I'm genuinely interested to know if there are use cases that people see for this beyond the obvious retroactive infostealing on a grand scale. What would you do with this feature if you had it?