Aller au contenu
Advertisement

L'outil "TotalRecall Reloaded" trouve une entrée latérale à la base de données Recall de Windows 11

"Le coffre-fort est solide. Le camion de livraison ne l'est pas."

schedule 20:36 visibility 78 vues
L'outil "TotalRecall Reloaded" trouve une entrée latérale à la base de données Recall de Windows 11
Source: Ars Technica

Two years ago, Microsoft launched its first wave of “Copilot+” Windows PCs with a handful of exclusive features that could take advantage of the neural processing unit (NPU) hardware being built into newer laptop processors. These NPUs could enable some AI and machine learning features that could be run locally rather than in someone’s cloud, theoretically enhancing security and privacy.

One of the first Copilot+ features was Recall, a feature that promised to track all your PC usage via screenshot to help you remember your past activity. But as originally implemented, Recall was neither private nor secure; the feature stored its screenshots plus a giant database of all user activity in totally unencrypted files on the user’s disk, making it trivial for anyone with remote or local access to grab days, weeks, or even months of sensitive data, depending on the age of the user’s Recall database.

After journalists and security researchers discovered and detailed these flaws, Microsoft delayed the Recall rollout by almost a year, substantially overhauling its security. All locally stored data would now be encrypted and viewable only with Windows Hello authentication; the feature now did a better job detecting and excluding sensitive information, including financial information, from its database; and Recall would be turned off by default, rather than enabled on every PC that supported it.

Read full article

Comments

newspaper

Originally published at

Ars Technica

open_in_new Read Full Article

Articles connexes

Lire la suite