7 ms·
TotalRecall: Extracts and displays data from the Windows 11 Recall feature
- zorrn 2y agoI really love how there are already ways to run this and people that took the time to find all this! Props to everyone
- fossr 2y agoThis is cool. What would be a good way to prevent this type of extraction? We just launched OpenRecall https://github.com/openrecall/openrecall https://github.com/openrecall/openrecall with which we want to offer a fully open source/auditable and privacy/security focused alternative.
- wiredfool 2y agoDon't collect the data.
- carl_dr 2y agoFrom your link : > Your data is stored locally on your device, and you have the option (soon to be implemented) to encrypt it with a password for added security. Security focused my ass.
- yifanl 2y agoWhat privacy/security features make this meaningfully different than Microsoft's offering?
- dns_snek 2y agoEncrypting the data with a key that's stored on - or only accessible using a hardware token like a YubiKey would be a good start. That way the data can't be decrypted without explicit user action.
- nerdjon 2y agoI have not taken the time to fully read your GitHub, but here is my view. You making this is inherently different than Microsoft including this by default in all future versions of Windows. If someone downloads your tool they are making the conscious choice to give up some data protection for and admittedly cool feature. It is also a more limited number of people with data stored in a particular way. Every Windows 11 having it, is painting a target on everyone's back since it would be somewhat easy to assume, if Windows 11 this is probably enabled. It is also not properly educating people on the risks. Personally I don't have a problem with the tool, or necessarily how it is designed (it could be better, don't get me wrong). But it has to be opt in, properly educate on the risks, and probably shouldn't be built into the OS.
- whalesalad 2y agoThe movie poster for Total Recall hit a core memory. I am gonna need to re-watch that classic tonight.
- 1234554321a 2y agoThis comment got downvoted because you’re about to watch a racist and problematic movie.
- whalesalad 2y agoUhh. What? I've never heard that before in my life. What am I missing?
- JTyQZSnP3cQGa8B 2y agoNever heard of that theory either. Enjoy the movie, it’s a good one.
- simonw 2y agoHere's what a SQL search looks like against it: SELECT c1, c2 FROM WindowCaptureTextIndex_content WHERE c1 LIKE '%{search_term}%' OR c2 LIKE '%{search_term}%' https://github.com/xaitax/TotalRecall/blob/28a9f75de005a3d8234b22605e4a32262c01d428/totalrecall.py#L119 https://github.com/xaitax/TotalRecall/blob/28a9f75de005a3d82...
- 1121redblackgo 2y agoWell that's not ideal
- gigel82 2y agoPwned in what way? This is just a SQLite database, you can "pwn" it with any SQLite client of your choice.
- JohnFen 2y agoWeren't were told it was encrypted and that this sort of access wouldn't be possible?
- Dylan16807 2y agoCan you quote anything? I don't remember microsoft saying you couldn't access your own data. The fact that a different user can get to it so easily is bad though. And the FAQ claims that remote access is possible but does not elaborate, so that's confusing.
- lolinder 2y agoThe point is that the existence of this code proves that remote access is possible, you just use any one of the many proven malware vectors to get the user to install a binary that does the same thing as this repo does but ships it over the network to your servers.
- Dylan16807 2y agoThat seems like an unreasonably broad definition of remote access to me. If installing a local program that proxies data counts, then the only true way to make "remote access" impossible is by installing it in a secure room with no networking and where no other electronics are allowed in. How many people interpreted that claim as SCIF-equivalency?
- lolinder 2y ago> How many people interpreted that claim as SCIF-equivalency? Basically everyone who isn't employed in tech? This is what the BBC said [0]: > And it said a would-be hacker would need to gain physical access to your device, unlock it and sign in before they could access saved screenshots. Those of us here can readily see that this "physical access" claim is bunk, but that's what Microsoft represented to the BBC and what the BBC is telling the world. [0] https://www.bbc.com/news/articles/cpwwqp6nx14o https://www.bbc.com/news/articles/cpwwqp6nx14o
- nerdjon 2y agoAre we really surprised by this point? Over the last 2 years (and really longer if you look at Google) time and time again privacy has been put in the background, properly vetting tools for reliability has been put in the background, all in the name of shoving AI into every single thing for investors or because they are scared. In a few months we will have the next horrible privacy invasive AI thing from one of these companies that is being shoved at us if we want it or not. On the topic of this actually existing, this is opt out and not opt in I assume? Which just makes this 100% worse. Will be honest, when this was announced I did not even think of the ability for trojans to get onto your computer and get a lot of sensitive data. I was more concerned about this data being synced between devices and stored on a server somewhere. But that really is one hell of a problem that could cause a lot of issues. I just think about how often for some game launchers I need to open 1Password to copy my password. This just makes it more and more that Windows is only for gaming and I will never do anything serious on Windows again. Not looking forward to this hitting the corporate world, I am sure some companies won't get the memo and just leave this feature enabled. The secrets that are going to be leaked. Screw message retention policies.
- api 2y ago[flagged]
- planb 2y agoI understand that this feature is highly controversial and I myself have mixed feelings about it. But I don’t understand what is being “pwned” here: isn’t providing a photographic memory of everything you do on your PC exactly what this is supposed to do? Yes, you can access the data through other means than the official UI - this is the case for every software that runs on my PC.
- croes 2y agoThe data is supposed to be stored secure and encrypted. It's not, so it's a selfpwn by MS
- smarx007 2y agoSee the README under "Q: But the BBC said data cannot be accessed remotely by hackers."
- Dylan16807 2y agoWhere's the disproof of that? Am I missing something? "this is wrong" is not a sufficient counterargument.
- smarx007 2y agoThe repo is along the lines of "2+2=4". GP said there is nothing interesting in that, to which I pointed to the QnA entry which shows that MS did tell a journalist that "2+2=22", so to speak. What else is there to disprove? The significance of the repo is not to show 2+2=4 but that 2+2 != 22
- Dylan16807 2y agoThe BBC quote says "a would-be hacker". I interpreted that as a general claim about windows security, not saying that this particular feature is invisible to malware. They have to break the security of your particular device, the data is nowhere else.
- tomphoolery 2y agoAfter years of watching spyware make a ton of money on their platform, Microsoft took a page out of Apple's book and created their own spyware for Windows.
- dlivingston 2y agoWhat's the Apple reference to?
- cientifico 2y agoIf an intruder gets into my local account, I'm far more worried about them stealing my cookies or accessing company IP than my browser history. With cookies and browser access, they could get into my emails, family photos, bank accounts, and even read desktop notifications from my phone's SMSs. For developers, the real risk lies in the variety of dependencies our apps have, which could get compromised. So, this isn't really news. There are also tools to access all your iMessage history from a Mac, for example. I believe the feature is really useful, and for sure you can turn it off.
- jdthedisciple 2y agoHow is it useful unless you suffer from complete amnesia? Since when is storing plaintext passwords on disk not a security concern anymore, which is precisely what this tool will do?
- croes 2y agoIt's more than just browser history. What if the screenshot that is safed is taken while you have a password in plain sight? Companies will use it to check on their employees. Hackers will get material to extort you. "Interesting porn you watched three weeks ago". No need to caught you in the act. It's enough to get access some time later. Abusers can control their partners.
- planb 2y agoWhen do you have a password in plain sight? On the other hand, a key logger that extracts the passphrase for my password manager and steals the database file of it would be a disaster. I’d rather have an attacker browse through years of screenshots.
- pseudalopex 2y ago> When do you have a password in plain sight? When I generate a new password.
- 2y ago
- lolinder 2y agoSecurity aside, I'm genuinely unsure what problem Recall is even meant to solve. Like most AI products and features announced over the past 18 months, it feels like a bunch of product people got into a meeting where they looked at the capabilities of the latest OpenAI model and then started spitballing feature ideas based not on user needs but on what GPTs can do. "Oh, these models can do OCR... why don't we screenshot everything that a user has ever done, OCR it, and make it searchable!" I'm genuinely interested to know if there are use cases that people see for this beyond the obvious retroactive infostealing on a grand scale. What would you do with this feature if you had it?
- rebolek 2y ago> What would you do with this feature if you had it? I would disable it.
- zdragnar 2y agoI trust that disabling it will disable interacting with it. I'm less convinced that it will disable the collection of the data, especially given the occasional stories of updates changing people's settings. Instead, I'm going back to Linux for everything but gaming. Nothing of any actual import will happen in Windows. My most recent purchase i left as a plain, single boot windows setup to see if WSL was all that it was cracked up to be. I thought I'd finally accepted that it wasn't as unpleasant as I anticipated, but there's gotta be a line in the sand somewhere.
- wvenable 2y ago"Summarize what I worked on last week"
- Dylan16807 2y agoI would like to have full text search of websites I've been to, since I often don't remember enough exact details to re-find something. That doesn't need the AI model or screenshots though. A retroactive ability to screenshot recent things would also be nice to have.
- 2y ago
- darkwater 2y agoNeat tool, kudos, but is it "pwning"? I don't think so. It's more like another viewer for the same data. You need to have the right permissions to access the SQLite and JPEG files anyway.
- deleted 2y ago[deleted]
- jdthedisciple 2y agoThis was obviously bound to become a thing. I never got why Microsoft created this "feature" despite the self-evidently drastic risks, though I suppose I'm not too surprised. What's more surprising though is how I remember HN folk being curiously welcoming to the whole thing when it was first announced.
- roncesvalles 2y agoRecall sounds like a gigantic pile of "fuck no". It's crazy that Microsoft just lets some PMs scrunch up and throw out the company's reputation.
- cptnqusr 2y agowas about to post url myself lol. good thing i switched to linux yesterday
- MELEKE 2y ago[dead]