If one chats/mails with a person using Windows, despite using secure private protocols, every message will be stored by Microsoft’s Windoze Recall. Either I’m missing something but this feature seems like the most grotesque breach in online privacy/security.

What are ways to avoid this except for using obfuscated text?

  • GetOffMyLan@programming.dev
    link
    fedilink
    arrow-up
    1
    ·
    1 minute ago

    It can be turned off so it’s up to the person you’re messaging. Once you send something the person at the other end is in control of what happens to it.

  • MalReynolds@slrpnk.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    20 minutes ago

    Wow, valid issue.

    Spitballing, potentially a secure app could run memory only, blah, blah, blah. Nope, you’ve given M$ your screen FFS, it’s all over. If you care, move elsewhere, tell your friends…

    As you point out, codes are an option, but it’s not a slippery slope, it’s a waterslide.

  • MentalEdge@sopuli.xyz
    link
    fedilink
    arrow-up
    12
    ·
    edit-2
    2 hours ago

    Don’t forget that while they managed the PR better, apple “Intelligence” also has access to damn near everything on your devices.

  • themoonisacheese@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    28 minutes ago

    If the content CNA be displayed, it can be parsed by recall.

    The only way I can see to bypass it is to obtain DRM keys and display your content on a website only if widevine is active, like Netflix does. Surely it can’t screenshot DRM protected content, but also this is Microsoft .

  • reddig33@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    4 hours ago

    So is there a way for businesses to disable this garbage feature through managed device settings or something? I’m guessing corporate legal departments aren’t going to be too thrilled with this feature.

    • egonallanon@lemm.ee
      link
      fedilink
      arrow-up
      4
      ·
      3 hours ago

      There’s a CSP for disabling it on windows enterprise devices at least. Not sure if there’s a way for pro and home machines.

    • jaxiiruff@lemmy.zip
      link
      fedilink
      arrow-up
      11
      ·
      3 hours ago

      Me neither! Microsoft needs to be taken to court over this because it is a serious breach of privacy to not only record the users but even random bystanders as well. Now I am convinced this is just a backdoor for the government hiding in plain sight. Fuck them.

      • CosmicTurtle0@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        42 minutes ago

        Oh this 100% is the government backdoor that they’ve been begging for. “If you can innovate your way into it, you can innovate a way out of it.”

        That was in regards to Apple phones belonging to Boston bombers being encrypted and locked.

        It’s no surprise that behind closed doors, the government asked these companies to create backdoors for them to spy on people.

  • hddsx@lemmy.ca
    link
    fedilink
    arrow-up
    7
    ·
    5 hours ago

    To my knowledge, there isn’t. But you can ask the person to turn off recall. I’m going to be running 11 in a VM myself so /me shrugs

  • Max-P@lemmy.max-p.me
    link
    fedilink
    arrow-up
    2
    ·
    4 hours ago

    You can’t, at that point you assume your correspondent is compromised. It’s not just recall but also malware and credential stealers. Doesn’t matter if recall is taking screenshots, if the messaging client itself is pwned via malware then they have full access to as much history as is available.