Live data from Hacker News

Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

wired.com

1–10 of 25 posts

Re: Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

#2
This stood out to me:

"Dubbed TotalRecall—yes, after the 1990 sci-fi film—the tool can pull all the information that Recall saves into its main database on a Windows laptop. “The database is unencrypted. It’s all plain text,” Hagenah says."

Re: Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

#5

This stood out to me: "Dubbed TotalRecall—yes, after the 1990 sci-fi film—the tool can pull all the information that Recall saves into its main database on a Windows laptop. “The database is unencrypted. It’s all plain text,” Hagenah says."

Is Microsoft intentionally making this exploitable? I knew it was only a matter of time before Recall would be compromised, but this shows they aren't even trying to secure it.

Re: Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

#6
post #3

You too can be a hacker by using... get this... any SQLite client/library of your choice. You're welcome!

“View Source” in web browsers is also a little-known hacker tool! [1]

[1] https://arstechnica.com/tech-policy/2021/10/viewing-website-...

Re: Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

#8

This stood out to me: "Dubbed TotalRecall—yes, after the 1990 sci-fi film—the tool can pull all the information that Recall saves into its main database on a Windows laptop. “The database is unencrypted. It’s all plain text,” Hagenah says."

Is Microsoft intentionally making this exploitable? I knew it was only a matter of time before Recall would be compromised, but this shows they aren't even trying to secure it.

It’s supposedly only accessible to LocalSystem. If they were to encrypt it, it could just be decrypted anyway. Still, it’s a huge liability and a major blunder by Microsoft.

Re: Hacker Tool Extracts All the Data Collected by Windows' New Recall AI

#9
post #8

Earlier quoted context omitted.

Is Microsoft intentionally making this exploitable? I knew it was only a matter of time before Recall would be compromised, but this shows they aren't even trying to secure it.

It’s supposedly only accessible to LocalSystem. If they were to encrypt it, it could just be decrypted anyway. Still, it’s a huge liability and a major blunder by Microsoft.

Wonder if they could enclave it similar to Cred Guard
Post reply on HN