GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 17-Apr-2025 22:35:37 JST Kevin Beaumont Kevin Beaumont

    I'm trying to map out time to go back and deep dive on Microsoft Recall and security implications and changes since last year.

    Are there any current writeups on it? I'm trying to figure out what needs concentrating on - when I'm googling, I'm just finding my own blog.

    In conversation about 6 months ago from cyberplace.social permalink
    • Embed this notice
      Xavier Ashe :donor: (xavier@infosec.exchange)'s status on Thursday, 17-Apr-2025 22:41:22 JST Xavier Ashe :donor: Xavier Ashe :donor:
      in reply to

      @GossiTheDog Here's one tool that may help you figure out a plan of attack.
      https://github.com/xaitax/TotalRecall

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        GitHub - xaitax/TotalRecall: This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots.
        This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots. - xaitax/TotalRecall
    • Embed this notice
      Ainsley Lowbeer (ainsleylowbeer@mastodon.social)'s status on Thursday, 17-Apr-2025 22:44:13 JST Ainsley Lowbeer Ainsley Lowbeer
      in reply to

      @GossiTheDog Do you have a Copilot PC?

      In conversation about 6 months ago permalink
    • Embed this notice
      Xavier Ashe :donor: (xavier@infosec.exchange)'s status on Thursday, 17-Apr-2025 22:44:42 JST Xavier Ashe :donor: Xavier Ashe :donor:
      in reply to

      @GossiTheDog And this article is the most recent thing I've seen. Good bits of details here.
      https://nguard.com/sa-microsofts-recall-saga-continuous-coverage-and-latest-news/

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: nguard.com
        Microsoft’s Windows 11 Recall: Revolution or Privacy Nightmare?
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 17-Apr-2025 22:59:17 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • James Forshaw :donor:

      summon @tiraniddo

      In conversation about 6 months ago permalink

      Attachments


    • Embed this notice
      CannedTuna (madcannedtuna@mastodon.social)'s status on Thursday, 17-Apr-2025 23:46:29 JST CannedTuna CannedTuna
      in reply to

      @GossiTheDog

      Not sure if this helps, it links a few demonstrations of vulnerabilities. One is a link to a tool someone else already mentioned, one is to you, and another is to someone on xitter.

      https://www.securityweek.com/researchers-show-how-malware-could-steal-windows-recall-data/

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.securityweek.com
        Researchers Show How Malware Could Steal Windows Recall Data
        from @https://twitter.com/EduardKovacs
        Cybersecurity researchers are demonstrating how malware could steal data collected by the new Windows Recall feature.
    • Embed this notice
      James Forshaw :donor: (tiraniddo@infosec.exchange)'s status on Friday, 18-Apr-2025 00:30:29 JST James Forshaw :donor: James Forshaw :donor:
      in reply to

      @GossiTheDog I never managed to the get the updated version working on the ARM CoPilot laptop I bought specifically for that purpose. I don't know of any current write ups other than the puffery from MS.

      I'd certainly focus on the encryption, how it ties into Windows Hello, whether there's any obvious bypasses and also whether you can still hoover up the details _if_ the user has unlocked it first (as in how hard is it to access the database once the key is available).

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 18-Apr-2025 00:56:54 JST Kevin Beaumont Kevin Beaumont
      in reply to

      After a bunch of discussions with a bunch of folks, it’s pretty clear there’s been zero published research on Copilot Recall in almost a year - all the news articles have just reprinted Microsoft’s talking points saying it is secure now.

      So that’s not in a happy place.

      In conversation about 6 months ago permalink
    • Embed this notice
      Alex Hagenah (xaitax@cyberplace.social)'s status on Friday, 18-Apr-2025 21:05:09 JST Alex Hagenah Alex Hagenah
      • Xavier Ashe :donor:

      @GossiTheDog @Xavier I briefly did in the early versions after re-release on Insider. Found some smaller things, but will have a deeper look once it's considered final.

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 18-Apr-2025 23:20:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I set aside 7 hours today to set a fresh Copilot+ PC up (I want to make 100% sure it is representative) and investigate the security of Microsoft Recall in depth..

      I’m currently 6 hours in and I’m still waiting for updates to install to get Recall working. The initial Copilot+ Windows setup failed three times too as sdx.microsoft.com kept going offline, I had to debug the setup process.

      In conversation about 6 months ago permalink

      Attachments



    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 03:00:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      After 10 hours, I've finally got Recall installed.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/360/263/621/565/438/original/e4badad98aa3c337.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 03:32:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Okay, the Recall database is still an SQLite database in AppData. Same path.

      Accessible without admin rights and without triggering UAC using TotalRecall.

      It's encrypted using a .net now, AesGcm - https://learn.microsoft.com/en-us/dotnet/api/system.security.cryptography.aesgcm

      I think I've found the decryption key, one for another day as I've teevee to watch now.

      In conversation about 6 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        http://TotalRecall.It/

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 03:55:02 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Some first impressions with Recall is they definitely took some feedback on board

      - the Windows setup does ask you if you want to enable now

      - first setup needs Windows Hello with biometrics (doesn't work with PIN), checked and it doesn't save anything before that

      - it scans (don't know how effective) for passwords and attempts to exclude from snapshots, by default

      Architecture under the hood is still largely the same as May last year. The userland processes are taking over 1.2gb of RAM.

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 03:57:12 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Snapshot processing is actually done on the NPU now it appears, at least there's usage. Prior it actually ran on CPU.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/360/490/114/209/871/original/4ccf9a7907c66e16.png
    • Embed this notice
      Carsten (cblte@nrw.social)'s status on Saturday, 19-Apr-2025 04:01:37 JST Carsten Carsten
      in reply to

      @GossiTheDog For whatever reason do you ever want to enable such a surveillance system?

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 04:05:16 JST Kevin Beaumont Kevin Beaumont
      in reply to

      One big thing to be aware of for domestic violence scenarios - I just managed to access the Recall UI (to browse and search snapshots) using my Windows Hello PIN. It doesn't need biometrics, that failed for me as the light isn't on in my room.

      In conversation about 6 months ago permalink
    • Embed this notice
      AnneH (annehargreaves@ioc.exchange)'s status on Saturday, 19-Apr-2025 04:06:11 JST AnneH AnneH
      • Infoseepage

      @Infoseepage @GossiTheDog Not just yourself. If you're on say, a Teams call then it'll clock the other people, and them you if they have it. I realise ppl could have taken screengrabs anyway, but this takes it to another level.

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 04:22:34 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here's what the folder structure looks like, it's basically the same as before.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/360/589/910/200/551/original/b10e5bd0ed567f5c.png
      Rich Felker, Paul Cantrell and Silver Huskey and 3 others repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 04:34:22 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Recall still scoops up WhatsApp and Signal chats, haven't tried others yet. Fully searchable and stored as text in the local Recall database. My blur on screenshot.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/360/635/466/118/621/original/c74ff5c8ad8bdc68.png
    • Embed this notice
      🌱 Ligniform :donor:​ (ligniform@infosec.exchange)'s status on Saturday, 19-Apr-2025 04:43:42 JST 🌱 Ligniform :donor:​ 🌱 Ligniform :donor:​
      in reply to

      @GossiTheDog Does it still refuse to pick up on DRM though?

      In conversation about 6 months ago permalink
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Saturday, 19-Apr-2025 05:04:22 JST da_667 da_667
      in reply to

      @GossiTheDog 1.2gb of ram. holy shit, lmao.

      In conversation about 6 months ago permalink
    • Embed this notice
      Rodeo (rodeo@cyberplace.social)'s status on Saturday, 19-Apr-2025 05:05:26 JST Rodeo Rodeo
      in reply to

      @GossiTheDog So... It's literally a digital print scanner for oil companies?

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 05:13:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      They've done a lot of work on Recall under the hood, it's definitely improved. It needs a lot of time spending on it to properly assess, and right now I've got trash TV (Celebrity Big Brother!) to watch.

      IMHO they should allow apps to exclude themselves easily, an API or some such, for privacy scenarios.

      In conversation about 6 months ago permalink
    • Embed this notice
      RootWyrm 🇺🇦:progress: (rootwyrm@weird.autos)'s status on Saturday, 19-Apr-2025 05:15:44 JST RootWyrm 🇺🇦:progress: RootWyrm 🇺🇦:progress:
      in reply to
      • da_667

      @da_667 @GossiTheDog oh, it's even more trivially readable. Because I can pretty much fucking guarantee you that the SQLite isn't ACTUALLY encrypted. Because presumably they're using Microsoft.Data.Sqlite. Which means no proper encryption. So there's a fleet of trucks sized hole there.

      https://learn.microsoft.com/en-us/dotnet/standard/data/sqlite/encryption?tabs=net-cli

      In conversation about 6 months ago permalink
    • Embed this notice
      da_667 (da_667@infosec.exchange)'s status on Saturday, 19-Apr-2025 05:15:45 JST da_667 da_667
      in reply to

      @GossiTheDog ..which means that its recoverable by bad guys, which means that this is just as much an infostealer now as it was before.

      In conversation about 6 months ago permalink
    • Embed this notice
      NosirrahSec 🏴‍☠️ guillotine enthusiast (nosirrahsec@infosec.exchange)'s status on Saturday, 19-Apr-2025 05:16:12 JST NosirrahSec 🏴‍☠️ guillotine enthusiast NosirrahSec 🏴‍☠️ guillotine enthusiast
      in reply to

      @GossiTheDog Explicit exclusions on all apps unless opted in, by the fucking user, or "the org" if it's on an enterprise license.

      In conversation about 6 months ago permalink
    • Embed this notice
      James Widman (jameswidman@mastodon.social)'s status on Saturday, 19-Apr-2025 07:56:19 JST James Widman James Widman
      in reply to

      @GossiTheDog request for clarification: is there an option to install windows 11 *without* installing Recall?

      If it's optional: is it an opt-in thing or an opt-out thing?

      In conversation about 6 months ago permalink
    • Embed this notice
      Drew Mochak (drew@akkomane.social)'s status on Saturday, 19-Apr-2025 08:02:44 JST Drew Mochak Drew Mochak
      in reply to

      @GossiTheDog This is default behaviour you can change, right? Can you exclude them (and other apps) from the snapshots? I imagine it hoovers up an incredible amount of sensitive stuff by default. Probably not something most people are aware of when they buy their new Del!

      In conversation about 6 months ago permalink
    • Embed this notice
      axleyjc (axleyjc@federate.social)'s status on Saturday, 19-Apr-2025 18:29:17 JST axleyjc axleyjc
      • NosirrahSec 🏴‍☠️ guillotine enthusiast

      @GossiTheDog @NosirrahSec how are they determining when a browser window is a private browsing window? Using their privileged OS position to snoop on window titles?

      In conversation about 6 months ago permalink
    • Embed this notice
      Liam (liachra@infosec.exchange)'s status on Saturday, 19-Apr-2025 18:50:40 JST Liam Liam
      in reply to
      • Liam

      @GossiTheDog @liachra
      Stored as plaintext? This is beyond a mistake, this is intentional. What the hell is Microsoft thinking?!

      In conversation about 6 months ago permalink
    • Embed this notice
      GeneralX ⏳ (generalx@freeradical.zone)'s status on Saturday, 19-Apr-2025 20:13:21 JST GeneralX ⏳ GeneralX ⏳
      in reply to

      @GossiTheDog what about Teams and Outlook?

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 20:16:09 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • da_667

      Searching for cat finds a @da_667 post via visual recognition, of course.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/364/338/166/335/869/original/507ca218d3ae95f1.png
      GreenSkyOverMe (Monika) repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 21:27:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      When you press "File Explorer results" in Microsoft Recall, you get this security prompt every time saying it may be harmful to your computer (it happens for any search). When you press "How do I decide wherever to open this file?", it redirects to https://support.microsoft.com/en-us/windows which is a generic Windows website with no help at all

      Another thing I've noticed is Recall frequently craps out and stops taking snapshots. E.g. today it hasn't snapshot Vivaldi (a web browser) at all - but it did yesterday

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/364/610/805/362/713/original/29ba897d8018def7.png
      2. Domain not in remote thumbnail source whitelist: support.microsoft.com
        Windows help and learning
        Find help and how-to articles for Windows operating systems. Get support for Windows and learn about installation, updates, privacy, security and more.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 22:14:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Recall captures video games continuously while playing too, and classifies the images on each screenshot and OCRs text on the screen, you can search for animals and it finds animal NPCs and such 😆 :catjam:

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/364/796/993/544/293/original/2aeb2c707b5aed0d.png

      2. https://cyberplace.social/system/media_attachments/files/114/364/802/679/253/678/original/cd85f11329d7384b.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 22:24:45 JST Kevin Beaumont Kevin Beaumont
      in reply to

      One other thing I've noticed - if you disable Recall, reboot, then set it back up - it works without biometrics, I covered the camera and it will reenable with just the user PIN.

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 22:29:54 JST Kevin Beaumont Kevin Beaumont
      in reply to

      What Recall looks like in action - it captures me writing the above tool, and also the bit I deleted.

      And if you're wondering why it's capturing Vivaldi again now - I removed Signal from the list of apps not to capture. If you add Signal, it stops capturing Vivaldi - I've no idea why.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/364/856/006/194/571/original/7d5799fec2b6cf20.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 22:46:24 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here's another example - I searched for "cat on some books", it found it via the visual prompt. The text with backgrounds is all indexed too.. and the text on the books in the photo is also indexed, there's me copying some handwriting on a book. Even the vertical text in the photo is indexed into the local database.

      I private messaged somebody a photo of a friend here, which has never been public - it indexed it and identified who the friend was. On a technical level it's really impressive.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/364/919/419/057/423/original/c39dd8115cace3d3.png
      Steve's Place and Rich Felker repeated this.
    • Embed this notice
      raspberryswirl (raspberryswirl@chaos.social)'s status on Saturday, 19-Apr-2025 22:58:37 JST raspberryswirl raspberryswirl
      in reply to

      @GossiTheDog wait a sec, you have this active and using mastodon? 😅

      In conversation about 6 months ago permalink
    • Embed this notice
      raspberryswirl (raspberryswirl@chaos.social)'s status on Saturday, 19-Apr-2025 22:58:38 JST raspberryswirl raspberryswirl
      in reply to

      @GossiTheDog nightmare communicating with someone who has this active, without knowing ofc

      In conversation about 6 months ago permalink
    • Embed this notice
      Carsten (cblte@nrw.social)'s status on Saturday, 19-Apr-2025 23:06:17 JST Carsten Carsten
      in reply to

      @GossiTheDog I wonder how this impacts performance of the games. Me basically playing Factorio but for upcoming BL4 I think I will stay on Win10 for a while.

      In conversation about 6 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 19-Apr-2025 23:26:50 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Here's another Recall issue I see.

      I have the sensitive information filter option enabled, highlighted. If I update my credit card on Microsoft's website, it captures the card number, CVV and details, and indexes it into the text database too and stores it under 'credit card', accessible in search.

      The only details obscured are by me altering the screenshot to remove some PII.

      In conversation about 6 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/114/365/071/404/362/851/original/7a8f7387fb61c794.png
    • Embed this notice
      João Tiago Rebelo (NAFO J-121) (jt_rebelo@ciberlandia.pt)'s status on Sunday, 20-Apr-2025 22:40:36 JST João Tiago Rebelo (NAFO J-121) João Tiago Rebelo (NAFO J-121)
      in reply to
      • ninjascum

      @ninjascum as long as someone you have contact with uses this, your PII will be at risk whatever the OS you use. That's what @GossiTheDog has saved us from once (and I hope he and others can do it again).

      In conversation about 6 months ago permalink
    • Embed this notice
      ninjascum (ninjascum@infosec.exchange)'s status on Sunday, 20-Apr-2025 22:40:37 JST ninjascum ninjascum
      in reply to

      @GossiTheDog That's why I'm on Linux for more than 20 years...you should switch too.

      In conversation about 6 months ago permalink
      Rich Felker repeated this.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Monday, 05-May-2025 19:42:43 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I’ve been using Recall for a few weeks now on my daily driver.

      It scooped up my credit card statements after I logged into online banking - both screenshots (text indexed) of the PDFs, transaction history from the website, and my name, date of birth and security question reminders.

      Sensitive filtering mode only kicked in when I viewed my cards CVV number.

      Worth excluding bank websites from Recall’s options, if you see it enabled.

      In conversation about 6 months ago permalink
    • Embed this notice
      Wuzzy (wuzzy@cyberplace.social)'s status on Monday, 05-May-2025 19:47:48 JST Wuzzy Wuzzy
      in reply to

      @GossiTheDog 😂 This really is the gift that keeps on giving. Why did anyone think this was a great idea?

      In conversation about 6 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.