10 ms·
Microsoft Recall still storing credit card, social security numbers
- geekinchief 2y ago[flagged]
- deleted 2y ago[deleted]
- Terr_ 2y ago> When I entered a credit card number and a random username / password into a Windows Notepad window, Recall captured it, despite the fact that I had text such as “Capital One Visa” right next to the numbers. That undesirable outcome doesn't surprise me at all. Even if someone coded up logic to look for surrounding clues that X is a secret, that other data ("X is a password") might only become available seconds or weeks later. For the foreseeable future, these idiot-savant systems (especially with append-only autocomplete at their core) will continue to be smart enough to get into trouble but not smart enough to get out of it.
- dangus 2y agoI don’t even know if this is a negative aspect of what Recall is intended to do. The whole point of Recall seems to be to allow you to…recall previous work you were doing. It reminds me a lot of whole-device backups. If you have some secrets in plain view then the backup itself is going to need to be secured. From the Microsoft website: > To use Recall you need to opt in to saving snapshots, which are screenshots of your activity. Snapshots and the contextual information derived from them are saved and encrypted to your local hard drive. Recall does not share snapshots or associated data with Microsoft or third parties, nor is it shared between different Windows users on the same device. Windows will ask for your permission before saving snapshots. You are always in control, and you can delete snapshots, pause or turn them off at any time. Any future options for the user to share data will require fully informed explicit action by the user.
- iAMkenough 2y agoIt's doing what Microsoft intends, but not what customers intend. Entering my credit card or social security details in a secure form should not result in it being copied to a different folder on my local storage or added to my backups without my approval. Snapshots present a new way of circumventing data protection implemented by other apps and websites (if it was visible on your screen, that data is now copied somewhere else). Yes you can delete snapshots AFTER you've determined something sensitive has been inappropriately captured, but you are not warned or prompted to do so and at that point why even use the feature.
- Terr_ 2y ago> what customers intend This customer, at least, is firmly entrenched into "if I wanted you to remember it I'd tell you so", which actually describes many everyday activities like saving a document with a filename, clicking "save" in my password-manager, making a browser bookmark, etc. In contrast, any assistant that is "constantly looking over my shoulder" (human or AI) to implicitly remember things needs to be trustworthy to (a) have my best-interests at heart, and (b) to understand what it's seeing and what my intent is. I don't think the current bleeding-edge is ready to provide both of those. P.S.: An interesting exception might be automatically-kept data like bash history or browser-history, however I feel those are very different from "anything I type anywhere", since each is a narrow and regimented kind of data/purpose. Both also have "forgetting" rules as a required feature. > but you are not warned or prompted And perhaps not even capable of noticing the problem, such as where a semi-transparent border-decor of a window overlaps the secret password text just enough that you can't see it but an aggressive OCR proess can pick it out. More generally, I fear a world where someone uses a botnet to make a funny picture go viral, and the picture contains subtle pixels to make each victim's Artificial Stupidity Assistant exfiltrate all their passwords back to the attacker.
- dangus 2y agoDo you think you would describe yourself as above or below average in technical ability? For example, do you know what terms like "3-2-1 backup" and "swap file" mean? If you answered yes to either, I don't think you are the primary customer. You are the type of person who will turn this off and move on with their day. I think this argument you are making is essentially the same that a person would make for preferring a manual transmission car instead of automatic. But we all know that 90% of people just want the car to go when the right pedal is pressed down, they don't really care about their ability to tell the car exactly what to do. Personally I think the average person would be very excited to have a feature that can recall things they were working on or looking at that they forgot to save. I don't know how many times I've had to tell the non-tech inclined "sorry you didn't save it, it's gone." As far as capturing sensitive information, I'm not really sure it's all that much worse than anything else the non-technical people do. I think at all these attack vectors are no worse than someone convincing you to install conventional malware. Both require you to elevate permissions and dismiss strong warnings.
- jazzyjackson 2y agoWell it's just kind of silly that Microsoft is silo'd enough that they didn't just use data loss prevention that they've implemented elsewhere in the office stack. Microsoft outlook stops me from sending bank wire details over email. With a DLP policy, you can identify, monitor, and automatically protect sensitive items across: Microsoft 365 services such as Teams, Exchange, SharePoint, and OneDrive accounts Office applications such as Word, Excel, and PowerPoint Windows 10, Windows 11, and macOS (three latest released versions) endpoints non-Microsoft cloud apps on-premises file shares and on-premises SharePoint Fabric and Power BI workspaces Microsoft 365 Copilot (preview) DLP detects sensitive items by using deep content analysis, not by just a simple text scan. Content is analyzed: For primary data matches to keywords By the evaluation of regular expressions By internal function validation By secondary data matches that are in proximity to the primary data match DLP also uses machine learning algorithms and other methods to detect content that matches your DLP policies https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp https://learn.microsoft.com/en-us/purview/dlp-learn-about-dl...
- ethernot 2y agoIf you start with a sieve and try and plug all the holes to make a bucket you're going to end up with a leaky bucket.
- deleted 2y ago[deleted]
- jfghi 2y agoI read that as Steve.
- fxtentacle 2y agoI like that first comment: "Microsoft continues to have a terrible abusive relationship with its customers. It's what Microsoft wants, not what the customer wants." Yup, that pretty much sums up why I left for Linux.
- hypeatei 2y agoRecall was the catalyst for me switching to Linux. I do not wish to tinker with Windows so that it doesn't feed my credit card information into an AI black box. Telemetry by default is unacceptable as well, but not to that degree.
- eGQjxkKF6fif 2y agoGood choice. I got Ubuntu, Lubuntu, Manjaro, Endeavour, Mx Linux, Fedora, Red Hat, Debian, Gentoo galore. Desktop Linux has come a long way, and if you like true unix here let me tell you some more. I got GhostBSD (https://www.ghostbsd.org/ https://www.ghostbsd.org/) rocking MATE IDE, if you want lightweight Linux desktop I got LXDE, LXFC, Gnome, KDE, and a whole lot more. If you want true freedom, ditch the spyware and head on over to desktop Linux where we'll welcome you with open arms. The excuse of 'But this... and that...' let me stop you right there. You don't need to configure anything. Download Kubuntu and have fun with customizing everything in the settings. When it comes to Windows and Microsoft products the answer is 'No.' Keep it that way. Freedom matters.
- bilekas 2y agoSounds like you have some commitment issues with picking a distro? Or are you just trying them all out to let us know? Because you've named a few that are all the same family. People who are unfamiliar with Linux will look at this list and just ignore it as too complicated. When in reality it's much simpler.
- water-data-dude 2y agoIt rhymes! I’m assuming it matches the meter/rhyme scheme of a particular song, but I’m music stupid, so I can’t really make a guess. But the point is to be funzies and light hearted :)
- macspoofing 2y ago>Microsoft Recall screenshots credit cards and Social Security numbers, even with the "sensitive information" filter enabled Because PII detection is a probabilistic exercise. You will miss things.
- chawco 2y agoWhile I agree as a whole, there are parts that are easily captured even with some small false positive rate, like credit card numbers. I do think it's acceptable to do PII detection probabilistically for some classes of identifiers/quasi-identifiers, because you can't really do any better without crazy false positive rates, things like credit card numbers have enough structure that it's more work to do it entirely via an ML model with a higher chance of failure, versus just building a simple heuristic for it. Add to that the fact that missing a credit card number is way higher stakes than missing something like a zip code, you can understand why something like this is just not acceptable in a product like this, with the resources Microsoft has at their disposal.
- kiratp 2y agoSpecifically regarding credit card security, it’s not really my problem is it? It’s the bank’s problem. The law makes it so.
- HideousKojima 2y agoDoesn't make it not a pain in the ass to resolve if your card information is stolen.
- drdaeman 2y agoStolen how? I don't get the fuss. Please correct me if I'm wrong, but IIRC Recall is opt-in and keeps data on-device, and doesn't share it with any other systems or parties. And if one's device is compromised, they're screwed either way (keyloggers, password managers' data, etc), so while Recall data can be an interesting target, it's not like it's some game changer. I could be wrong, but I believe first iteration was user-accessible SQLite3 database (which was an issue), but Microsoft had tightened the permissions and isolated those files, so AFAIK it now requires additional authentication to access. I don't currently use Windows, so I can't really check, but that's what I've read. If something is opt-in, local-only and partitioned away (inaccessible to regular-user processes to avoid easier abuse by malware and exploits) that sounds like a decent privacy-respecting option to me. There are plenty of crappy anti-user moves Microsoft had pulled with Windows, but Recall doesn't seem like one to me. Unless, of course, they're forcing this on people (like how they aggressively do with Edge and OneDrive), or pull this data somewhere despite saying they don't do it, etc etc.
- HideousKojima 2y ago>Recall is opt-in For now, until Microsoft decides to silently enable it an update like they already do with all of the telemetry and similar features in Windows 10 and 11. Barring a legally binding promise that they will never reenable it without consent they are not trustworthy enough to believe on this >And if one's device is compromised, they're screwed either way With Recall the level of screwed we're talking can be significantly higher, because the kinds of information that can be captured are things that wouldn't necessarily be captured by other methods (and Recall will have been capturing data from before the computer was compromised too). >but Microsoft had tightened the permissions and isolated those files, so AFAIK it now requires additional authentication to access Which, as you yourself already mentioned, would be trivial to access because you can already put a keylogger or similar on the device to get what you need to access the Recall files.
- brunoqc 2y agoCan we disable recall?
- _joel 2y agoDon't use windows?
- drdaeman 2y agoSure, just... don't enable it? Last I've heard, it's opt-in.
- pavel_lishin 2y agoIt sure is today!
- alkonaut 2y agoSpecifically for credit card numbers those should be easy to detect as they are a specific format. But generally for PII, passwords etc there is no way to know when something is or isn’t secret or sensitive so either you should accept that the recordings are protected enough or just not record. Did this controversy arise from Microsoft first assuming that the ”recordings are safely stored” would be enough but then public reception was negative and now they are trying to ”fix” it?
- solarkraft 2y agoThey could have prevented a lot of the backlash by not forcing it on people.
- spogbiper 2y agowho did they force it on?
- JohnMakin 2y agoThe fact it is on your machine at all and cannot be removed means it is forced. The fact that it is for now opt-in is irrelevant; windows is well known for enabling features without user permission that were previously not.
- int_19h 2y agoThe initial iteration (that was scrapped) was opt-out rather than opt-in.
- araes 2y agoHow is this even possibly a valid software pattern to enable on normal users? Regularly capturing screenshots of their entire desktop, that 90% of users likely do not comprehend, and obviously associate with malware behavior. Screenshots. They're not even capturing the forms, or the specific input data. Taking entire desktop pictures of typing on Notepad. Using a software that's difficult to tell whether it's installed. And then it keeps the credentials, makes it difficult to tell whether they've been stored, what info has been stored, whether they've been deleted correctly, and makes it difficult for the actual computer user to even access the stored images. The screenshots appear to be files in a subfolder called AsymStore. I couldn’t open those either and I tried to open them as PNGs, BMPs or JPGs. Perhaps hackers will figure out how to open these files, but as far as I could tell, a typical user can’t open them outside of the Recall app. This reads like a virus pattern. Several notable examples of malware, creepware, Remote Access Trojans (RAT) that do almost this exact activity: Agent Tesla [1], Dark Comet [2], Bifrost [3], and just the general category of Remote Access Trojans [4]. Corporate malware. [1] https://en.wikipedia.org/wiki/Agent_Tesla https://en.wikipedia.org/wiki/Agent_Tesla [2] https://en.wikipedia.org/wiki/DarkComet https://en.wikipedia.org/wiki/DarkComet [3] https://en.wikipedia.org/wiki/Bifrost_(Trojan_horse) https://en.wikipedia.org/wiki/Bifrost_(Trojan_horse) [4] https://en.wikipedia.org/wiki/Remote_desktop_software#RAT https://en.wikipedia.org/wiki/Remote_desktop_software#RAT
- drdaeman 2y agoIt would be, if it would be stealthy enabled, unbeknown to machine owner. That - and not the fact it records screen - is what differentiates malware from legit software. It is opt-in, which makes it equivalent of user explicitly setting up a camera to record their work, for a well-intended ability to review those recordings if they need to recall something. If we'll start saying that end-users are somehow incapable of comprehending what screen recording means, then we're basically giving up our agency and arguing we need a nanny. I sincerely hope we don't. Like, literally, it's a screen recording, anyone with a working brain (no matter whenever they're technically literate or not) should be able to tell what consequences - positive and negative it would have. I found a screenshot - the opt-in prompt literally says "Allow Windows to save snapshots of your screen?" If that's not clear or comprehensible, I don't know what is. People who are caught by this must simply ignore and not read what it says on the screen.
- ghelmer 2y agoI'm not apologizing for MS, and I have no idea what PII protection Recall actually has. If Recall does have real PII logic, it should recognize that a legitimate VISA payment card numbers must start with '4' + be 16 digits in length, and AmEx cards must start with '34' or '37' + be 15 digits in length; also, the LUHN algorithm must be satisfied over the card digits. With Recall, it seems false positives for PII-type protection rules would be more acceptable than false negatives. But with the negative press already around the technology. I'm not sure it will ever gain acceptance.
- Rygian 2y agoThere are card numbers that don't satisfy Luhn.
- drdaeman 2y agoI'm really curious now - which cards don't conform? I always thought it's basically an industry standard and no network issues cards that don't have a correct checksum.
- exikyut 2y agoTIL, although this isn't a field I need perfect knowledge of. I wonder if people with such cards have inexplicable problems with certain payment systems? Edit: just saw the sibling comment, was viewing an old copy of the page
- 2y ago
- johnklos 2y agoIf there isn't a law yet, there should be: if something can be done incorrectly, Microsoft will do it incorrectly multiple ways. Granted, we're a somewhat technical bunch here, so I have to ask: do regular people not know that Microsoft is so bad at security and self awareness that they literally can't do something like protect users from their own products? Do people still think, "Oh, well - 80% of the world can't be wrong"? I bet they're going to make it exceedingly difficult to disable or uninstall, like Edge, once it becomes a mandatory part of Windows, aren't they?
- weikju 2y ago> Do people still think, "Oh, well - 80% of the world can't be wrong"? Yes and “if they’re so big they must be doing something right” And “if they did something wrong the govt would come down on them” And “they already have all my data anyway so who cares?” I’ve heard all of those and more.
- hulitu 2y ago> do regular people not know that Microsoft is so bad at security and self awareness that they literally can't do something like protect users from their own products? Some people don't know, some are paid to not know. /s
- nerdjon 2y agoHonestly at this point did they actually bother to make something specifically built and trained to remove sensitive data or did they just modify a system prompt to "Don't save possibly sensitive data like credit card numbers" and hope that an LLM could magically handle this properly? Why do I have a feeling its the later given all of the other issues around this entire thing.
- sitzkrieg 2y agoi will never move off windows 10 LTSC :-)
- josefritzishere 2y agoWorst product ever. I think Microsoft's "telemetry" initiative has acclimated them to the point where they're just making naked malware features now.
- doright 2y agoI find it interesting that searchable history of computer activity is a problem with enough interest that independent developers have worked on solutions themselves, some of them open source. But a company like Microsoft ought to have much more resources such that they can fix these edge cases or realize they can't fix them all and design the service accordingly. So I guess my question is: is a company as big as Microsoft that approaches this problem space doomed to fail from the start, because of the perception issues? Would this be any different if say Apple had developed a Recall alternative and they also found it impossible to censor credit card information in an arbitrary Notes window someone whipped up as an edge case, like in the article? Or could a stricter (outward) stance on privacy make it palatable again? Suppose if everything were assured to be kept under enough layers of encryption and the data wasn't synced online at all, would storing a credit card number surreptitiously captured on my computer be seen as much better if it's Microsoft/Apple I have to trust to engineer their AI recall feature in a secure manner?
- alt227 2y agoI never heard anything bad about https://rewind.ai https://rewind.ai which was launched exclusively on Mac before Recall was, in fact it was praised.
- deleted 2y ago[deleted]
- int_19h 2y agoAs a third party app, most people haven't even heard about Rewind. Recall, by virtue of being a core OS feature - and the one enabled by default at that - got a lot more coverage.
- luma 2y agoOne major difference would be in how it is distributed. Rewind is an app you go find, install, and deploy. Not a lot of concerns around consent there. Building it into the OS, potentially default on, is the same sort of technology. It's not the same sort of consent.
- sydbarrett74 2y agoMy plan is to run HardenedBSD for most things, MacOS for games, and Windows for anything that absolutely won't run otherwise. Nadella has shown his contempt for power users way too often.
- jgalt212 2y agoSo long as MSFT stock remains airborne, there will no changes to its behavior.
- soraminazuki 2y ago> We’ve updated Recall to detect sensitive information like credit card details, passwords, and personal identification numbers. What's up with companies giving these kinds of non-answers? It rubs me the wrong way every single time. This is definitely not an answer to the author specifically telling MS that their defense measures aren't working.