Replying to Avatar Jac

Bruce Schneier on Microsoft Recall: 🧐

Because Recall is “default allow” (it relies on a list of things not to record) ... it’s going to vacuum up huge volumes and heretofore unknown types of data, most of which are ephemeral today. The “we can’t avoid saving passwords if they’re not masked” warning Microsoft included is only the tip of that iceberg. There’s an ocean of data that the security ecosystem assumes is “out of reach” because it’s either never stored, or it’s encrypted in transit. All of that goes out the window if the endpoint is just going to...turn around and write it to disk. (And local encryption at rest won’t help much here if the data is queryable in the user’s own authentication context!)

This:

The fact that Microsoft’s new Recall thing won’t capture DRM content means the engineers do understand the risk of logging everything. They just chose to preference the interests of corporates and money over people, deliberately.

This:

Microsoft Recall is going to make post-breach impact analysis impossible. Right now IR processes can establish a timeline of data stewardship to identify what information may have been available to an attacker based on the level of access they obtained. It’s not trivial work, but IR folks can do it. Once a system with Recall is compromised, all data that has touched that system is potentially compromised too, and the ML indirection makes it near impossible to confidently identify a blast radius.

This:

You may be in a position where leaders in your company are hot to turn on Microsoft Copilot Recall. Your best counterargument isn’t threat actors stealing company data. It’s that opposing counsel will request the recall data and demand it not be disabled as part of e-discovery proceedings.

I need to change my desktop to Linux yesterday 😬

Reply to this note

Please Login to reply.

Discussion

Try windows 10

Hadn’t thought of that option đŸ€”

You can always run Linux and put Windows in a gnome boxes VM. It’s fairly easy and better than nothing.

And disable connectivity. Windows shouldn't be anywhere near the internet.

I’ll have to research gnome boxes. And good tip about disabling connectivity. Thanks, plebs.

Do you have an alias set on your profile? Or maybe my relays are not fetching it?

No

Less people will engage with you đŸ€·đŸ»

Maybe. Those who value the message more than the messenger will care.

I will bet heavily that statistically less people engage with null pfp and null alias. Not sure why you’d handicap your social potential on a social platform. Literally any random noun would be better.

I respect your choice regardless đŸ€·đŸ»