Live data from Hacker News

TotalRecall: Extracts and displays data from the Windows 11 Recall feature

github.com

41–50 of 98 posts

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#41
post #18

Earlier quoted context omitted.

Weren't were told it was encrypted and that this sort of access wouldn't be possible?

Can you quote anything? I don't remember microsoft saying you couldn't access your own data. The fact that a different user can get to it so easily is bad though. And the FAQ claims that remote access is possible but does not elaborate, so that's confusing.

The point is that the existence of this code proves that remote access is possible, you just use any one of the many proven malware vectors to get the user to install a binary that does the same thing as this repo does but ships it over the network to your servers.

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#42

Security aside, I'm genuinely unsure what problem Recall is even meant to solve. Like most AI products and features announced over the past 18 months, it feels like a bunch of product people got into a meeting where they looked at the capabilities of the latest OpenAI model and then started spitballing feature ideas based not on user needs but on what GPTs can do. "Oh, these models can do OCR... why don't we screensh…

If the goal was to train a large model to interact with the OS, this data would be extremely useful. But that can't possibly be their ultimate goal, because they've assured us that the data remains local. I do wonder if there's a gray area where verbatim data remains local, but maybe a substantially transformed version like a UI state-transition diagram is shared with MSFT to "enable product improvements".

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#43
post #18

Earlier quoted context omitted.

Weren't were told it was encrypted and that this sort of access wouldn't be possible?

Can you quote anything? I don't remember microsoft saying you couldn't access your own data. The fact that a different user can get to it so easily is bad though. And the FAQ claims that remote access is possible but does not elaborate, so that's confusing.

A different user could also get your browser cache, your cookies, and install all sorts of horrible programs running as Admin as well.

This isn't really different.

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#44

Earlier quoted context omitted.

"this is wrong. Data can be accessed remotely" is not a super illuminating FAQ item. how can it be accessed remotely?

With any available information stealing malware: https://doublepulsar.com/recall-stealing-everything-youve-ev...

okay, so the only "pwning" of recall is that if your computer is already hacked, the hackers can get the recall data along with all the other data on your computer...

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#45
post #14

I understand that this feature is highly controversial and I myself have mixed feelings about it. But I don’t understand what is being “pwned” here: isn’t providing a photographic memory of everything you do on your PC exactly what this is supposed to do? Yes, you can access the data through other means than the official UI - this is the case for every software that runs on my PC.

> isn’t providing a photographic memory of everything you do on your PC exactly what this is supposed to do? Yes, but look at the Q&A at the bottom: apparently Microsoft told the BBC that hackers would have to have physical access to the device in order to access the data. This repo proves that's nonsense because all an attacker would have to do is install this code on your computer, which is something we already kno…

So MS lied in an interview. Or the press person was not very knowledgeable. But how would that even work, that data can only be accessed locally? How does a computer decide if the intent to access a file is coming from the user in front of the PC or from someone who installed malware that sends keystrokes or mouse clicks on behalf of the user?

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#46

Earlier quoted context omitted.

Can you quote anything? I don't remember microsoft saying you couldn't access your own data. The fact that a different user can get to it so easily is bad though. And the FAQ claims that remote access is possible but does not elaborate, so that's confusing.

The point is that the existence of this code proves that remote access is possible, you just use any one of the many proven malware vectors to get the user to install a binary that does the same thing as this repo does but ships it over the network to your servers.

That seems like an unreasonably broad definition of remote access to me. If installing a local program that proxies data counts, then the only true way to make "remote access" impossible is by installing it in a secure room with no networking and where no other electronics are allowed in. How many people interpreted that claim as SCIF-equivalency?

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#47

Earlier quoted context omitted.

See the README under "Q: But the BBC said data cannot be accessed remotely by hackers."

Where's the disproof of that? Am I missing something? "this is wrong" is not a sufficient counterargument.

The repo is along the lines of "2+2=4". GP said there is nothing interesting in that, to which I pointed to the QnA entry which shows that MS did tell a journalist that "2+2=22", so to speak. What else is there to disprove?

The significance of the repo is not to show 2+2=4 but that 2+2 != 22

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#48

Earlier quoted context omitted.

With any available information stealing malware: https://doublepulsar.com/recall-stealing-everything-youve-ev...

okay, so the only "pwning" of recall is that if your computer is already hacked, the hackers can get the recall data along with all the other data on your computer...

Yes. With the difference that now the have the DB which they can interrogate with a prompt like "list all credit card numbers entered in the past 3 months". The post touches on your question/remark.

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#49
post #37

If an intruder gets into my local account, I'm far more worried about them stealing my cookies or accessing company IP than my browser history. With cookies and browser access, they could get into my emails, family photos, bank accounts, and even read desktop notifications from my phone's SMSs. For developers, the real risk lies in the variety of dependencies our apps have, which could get compromised. So, this isn't…

It's more than just browser history. What if the screenshot that is safed is taken while you have a password in plain sight? Companies will use it to check on their employees. Hackers will get material to extort you. "Interesting porn you watched three weeks ago". No need to caught you in the act. It's enough to get access some time later. Abusers can control their partners.

When do you have a password in plain sight? On the other hand, a key logger that extracts the passphrase for my password manager and steals the database file of it would be a disaster. I’d rather have an attacker browse through years of screenshots.

Re: TotalRecall: Extracts and displays data from the Windows 11 Recall feature

#50

Security aside, I'm genuinely unsure what problem Recall is even meant to solve. Like most AI products and features announced over the past 18 months, it feels like a bunch of product people got into a meeting where they looked at the capabilities of the latest OpenAI model and then started spitballing feature ideas based not on user needs but on what GPTs can do. "Oh, these models can do OCR... why don't we screensh…

If the goal was to train a large model to interact with the OS, this data would be extremely useful. But that can't possibly be their ultimate goal, because they've assured us that the data remains local. I do wonder if there's a gray area where verbatim data remains local, but maybe a substantially transformed version like a UI state-transition diagram is shared with MSFT to "enable product improvements".

This is completely my opinion, but this data is definitely going to be accessible to law enforcement/intelligence agencies when it's more widely used and running by default. All the compute and AI work is done locally and a simple database is given on request.
Post reply on HN