{"id":34123,"date":"2024-06-08T12:26:34","date_gmt":"2024-06-08T10:26:34","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=34123"},"modified":"2024-06-08T12:27:19","modified_gmt":"2024-06-08T10:27:19","slug":"microsoft-improves-ai-function-recall-and-adds-security-measures-is-that-enough","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/06\/08\/microsoft-improves-ai-function-recall-and-adds-security-measures-is-that-enough\/","title":{"rendered":"Microsoft improves AI feature Recall and adds \"security measures\" &#8211; is that enough?"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/06\/08\/microsoft-bessert-ai-funktion-recall-nach-und-fgt-eine-sicherung-ein-reicht-das\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]It was an absolute bombshell when Microsoft unveiled its \"Copilot+PC\" concept including the AI function Recall. Security experts tore Recall apart as an absolute nightmare because it opens up the possibility for cybercriminals to access user information. After a powerful headwind, Microsoft has now announced that Recall will be made available as an \"opt-in\" under Windows 11. In addition, security is to be provided by means of Windows Hello. But is this accurate, or is Recall simply bullshit?<\/p>\n<p><!--more--><\/p>\n<h2>Copilot+AI and Recall<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/bf9abdcbaf3a40eaa47f5db89e66ea2a\" alt=\"\" width=\"1\" height=\"1\" \/>In my the blog post <a href=\"https:\/\/borncity.com\/win\/2024\/05\/21\/microsofts-ai-pc-with-copilot-some-thoughts\/\">Microsoft's AI PC with Copilot \u2013 some thoughts \u2013 Part 1<\/a> &#8211; Part 1, I discussed the \"Copilot+PC\" concept presented by Microsoft. There, the so-called recall feature was also mentioned briefly. The feature enables Windows to constantly take screenshots of the user's screen (or rather to save a snapshot each time, which also includes input and mouse movements). The results are stored in an SQL Light database in the user profile and can be analyzed and searched using a generative AI model. For example, the user should be able to ask \"what did I look at recently as a travel destination\" and then be shown the relevant documents, websites, emails etc. by Recall.<\/p>\n<h2>Shitstorm and PR disaster over Microsoft's recall<\/h2>\n<p>Satya Nadella, the head of Microsoft, dismissed the initial concerns of the questioner during an interview to present the Copilot+PC concept &#8211; everything runs locally. But security researchers were immediately up in arms about this feature because it offers the possibility of accessing everything the user does on the Windows PC. This also includes access to deleted information, passwords or login data or confidential documents.<\/p>\n<p>In the blog post <a href=\"https:\/\/borncity.com\/win\/2024\/06\/06\/copilotai-recall-a-security-disaster-ai-assisted-theft\/\">Copilot+AI: Recall, a security disaster \u2013 AI-assisted theft<\/a>, I extracted an excerpt of what you should know about the function and how you could deactivate it via group policies. On Github there is the tool <a href=\"https:\/\/github.com\/xaitax\/TotalRecall\" target=\"_blank\" rel=\"noopener\">TotalRecall<\/a>, which enables the reading of the database via script (see <a href=\"https:\/\/github.com\/Pennyw0rth\/NetExec\/pull\/335\" target=\"_blank\" rel=\"noopener\">Add Recall module for dumping all users Microsoft Recall DBs &amp; screenshot<\/a> on GitHub).<\/p>\n<p><a href=\"https:\/\/x.com\/d0tslash\/status\/1797837316205195442\"><img decoding=\"async\" src=\"https:\/\/i.postimg.cc\/WzXHRrgk\/image.png\" alt=\"Meme: Microsoft's customer relation ship\" \/><\/a><\/p>\n<p>This is PR for Microsoft, as Windows Central states in <a href=\"https:\/\/www.windowscentral.com\/software-apps\/windows-11\/microsoft-has-lost-trust-with-its-users-windows-recall-is-the-last-straw\" target=\"_blank\" rel=\"noopener\">this article<\/a>, noting that \"Microsoft has lost the trust of its users, and Windows Recall is the straw that breaks the camel's back\".<\/p>\n<p>The above meme, which someone posted as a <a href=\"https:\/\/x.com\/d0tslash\/status\/1797837316205195442\" target=\"_blank\" rel=\"noopener\">tweet on X<\/a>, sums it up perfectly. The user actually only wants Windows as a working platform for launching programs, but Microsoft imposes a function that overwhelms everything. I read somewhere recently that Microsoft management, who approve functions such as Recall, are far removed from what normal users need on a daily basis. Users don't have 20 tabs open and have to quickly search through hundreds of emails to find out when they last went on a trip to the Maldives.<\/p>\n<h2>Microsoft tries to fix what can't be fixed<\/h2>\n<p>Microsoft is now trying to catch what should actually be scrapped. While Recall was previously activated by default, the function will only be rolled out as an \"opt-in\" in future. Pavan Davuluri &#8211; Corporate Vice President, Windows + Devices at Microsoft &#8211; announced this under the heading \"We've heard your feedback\" in the blog post <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2024\/06\/07\/update-on-the-recall-preview-feature-for-copilot-pcs\/\" target=\"_blank\" rel=\"noopener\">Update on the Recall preview feature for Copilot+ PCs<\/a> on June 7, 2024.<\/p>\n<p><img decoding=\"async\" title=\"Recall opt-in\" src=\"https:\/\/i.postimg.cc\/NMHcZKk7\/image.png\" alt=\"Recall opt-in\" \/><br \/>\n<em>Recall Opt-in<\/em><\/p>\n<p>During Windows setup, users should be given the option to explicitly activate the Recall function via opt-in (see image above). Furthermore, registration via Windows Hello authentication will be required as a security measure for recall activation. Proof of presence is required in order to use or search the recall function and the timeline of screenshots.<\/p>\n<p>Furthermore, an additional data protection layer will be added that allows just-in-time decryption through Windows Hello Enhanced Sign-in Security (ESS). The recall snapshots can then only be decrypted and retrieved if the user authenticates themselves. In addition, the search index database has been encrypted. The whole thing should take effect from June 18, 2024. The <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2024\/06\/07\/update-on-the-recall-preview-feature-for-copilot-pcs\/\" target=\"_blank\" rel=\"noopener\">blog post<\/a> contains further details on how great they are and what else they are securing.<\/p>\n<h2>Comment: Too late, just dump it<\/h2>\n<p>If you think about Recall, you can only conclude that Microsoft has completely lost its grip. They are driving AI through the village, implementing a Recall function that monitors everything and rolling it out on millions of Windows computers, which are primarily used as work devices. A monitoring feature like Recall will be a wet dream for all surveillance enthusiasts &#8211; bit i's a nightmare for all others.<\/p>\n<p>There's the old saying: \"Where there's a trough, the pigs will come\". The fact remains that even with opt-in, there will be enough \"simpletons\" who activate this option. Any information that is processed by these people (including emails, posts, messages, documents etc. from third parties) goes into the recall database. An absolute nightmare, and cybercriminals will find ways to circumvent Microsoft's ridiculous security measures. What's more, who's to say that Recall won't suddenly be rolled out to users as a \"philosopher's stone\" by Microsoft in the future?<\/p>\n<p>In my opinion, there is only one thing to do: stamp it out and concentrate on other things. For users, the question arises as to whether Microsoft can still be the bank for IT solutions with its products. Microsoft has neither its on-premises software nor its cloud solutions under control in terms of reliability, maintainability, low error rates and security.<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/05\/21\/microsofts-ai-pc-with-copilot-some-thoughts\/\">Microsoft's AI PC with Copilot \u2013 some thoughts \u2013 Part 1<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/05\/23\/microsofts-copilotpc-a-privacy-and-security-nightmare-part-2\/\">Microsofts Copilot+PC, a privacy and security nightmare<\/a> \u2013 Part 2<br \/>\n<a href=\"https:\/\/borncity.com\/win\/2024\/06\/06\/copilotai-recall-a-security-disaster-ai-assisted-theft\/\">Copilot+AI: Recall, a security disaster \u2013 AI-assisted theft<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]It was an absolute bombshell when Microsoft unveiled its \"Copilot+PC\" concept including the AI function Recall. Security experts tore Recall apart as an absolute nightmare because it opens up the possibility for cybercriminals to access user information. After a powerful &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/06\/08\/microsoft-improves-ai-function-recall-and-adds-security-measures-is-that-enough\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[2756,2857,69,2643],"class_list":["post-34123","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-ai","tag-recall","tag-security","tag-windows-11"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=34123"}],"version-history":[{"count":3,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34123\/revisions"}],"predecessor-version":[{"id":34126,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/34123\/revisions\/34126"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=34123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=34123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=34123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}