Sign up to save tools and stay up to date with the latest in AI
bg
bg
1

This Hacker Tool Extracts All the Data Collected by Windows’ New Recall AI

Jun 05, 2024 - wired.com
Microsoft's new AI tool, Windows Recall, which takes screenshots of user activity every five seconds and stores them on the device, has raised security concerns. Researchers have found that the tool stores the screenshots in an unencrypted database, which could be exploited by attackers. Cybersecurity strategist Alex Hagenah has created a demo tool, TotalRecall, that can extract and display all the data recorded by Recall, demonstrating the potential for misuse.

Critics have compared Recall to spyware or stalkerware, and Hagenah has urged Microsoft to make changes before the tool's full launch. The UK’s data protection regulator has asked Microsoft for more details about Recall and its privacy implications. Microsoft has not yet responded to these concerns.

Key takeaways:

  • Microsoft's new Windows AI tool, Recall, which takes screenshots of user activity every five seconds, has been criticized by security experts for storing the data in an unencrypted database, making it vulnerable to attacks.
  • A cybersecurity strategist and ethical hacker, Alex Hagenah, has created a demo tool called TotalRecall that can extract and display everything Recall records on a laptop, demonstrating the potential risks.
  • Recall's data includes screenshots of desktop activity, messages sent on encrypted messaging apps, websites visited, and all text displayed on the PC, which could be a gold mine for hackers or domestic abusers.
  • Despite the criticisms, Microsoft maintains that Recall does not send the captured information to its servers and users have the option to disable saving screenshots, pause the system, filter applications where screenshots are taken, and delete what is gathered at any time.
View Full Article

Comments (0)

Be the first to comment!