If one chats/mails with a person using Windows, despite using secure private protocols, every message will be stored by Microsoft’s Windoze Recall. Either I’m missing something but this feature seems like the most grotesque breach in online privacy/security.

What are ways to avoid this except for using obfuscated text?

  • @glimse
    link
    741 minutes ago

    Turn off your computer, move to a cave in the mountains, and abandon society.

    A bit extreme but there is nothing you can do to stop your messages from appearing on Windows machines except not sending them to anyone who might view them on Windows machines…which will definitely be nearly impossible in 2024

  • Autonomous User
    link
    English
    1
    edit-2
    20 minutes ago

    You must start spreading libre software effectively. You don’t control their device. You must show them how to fix it.

    • @toynbee
      link
      329 minutes ago

      “Three can keep a secret if two of them are dead.”

      (Even then I’m not so sure)

  • @[email protected]
    link
    fedilink
    English
    8
    edit-2
    2 hours ago

    Wow, valid issue.

    Spitballing, potentially a secure app could run memory only, blah, blah, blah. Nope, you’ve given M$ your screen FFS, it’s all over. If you care, move elsewhere, tell your friends…

    As you point out, codes are an option, but it’s not a slippery slope, it’s a waterslide.

  • @[email protected]
    link
    fedilink
    52 hours ago

    It can be turned off so it’s up to the person you’re messaging. Once you send something the person at the other end is in control of what happens to it.

    • @[email protected]OP
      link
      fedilink
      English
      41 hour ago

      Once you send something the person at the other end is in control of what happens to it.

      True, but this is the beauty of trust. I decide to communicate one way or another with someone depending on the level of trust. Them deciding to break that trust is a risk I chose to take. However, I do not choose to communicate with Microsoft, whatsoever. Windows Recall is the most blatant piece of spyware ever; beyond comprehension how this is so normalized.

      • @BananaTrifleViolin
        link
        English
        459 minutes ago

        Then you have to trust the person you are communicating with has turned off windows recall. That has to be the starting position.

        Tools will come to block or break windows recall but it will still be based on trust that the recipient is using them. Privacy centred apps like Signal wouldn’t want windows screen shotitng every message for example. There are many apps and tools including in the professional sphere that would not want their data leaking via recall so it will come.

        Unfortunately it may come late in the professional realm probably after scandals break. Employers using recall data to investigate staff for example - it’s bound to happen eventually.

        My own organisation, a huge health organisation, has opted in to CoPilot. It’s crazy in my view, even if our data is ring fenced in some way. I don’t want private patient information being used to train Microsoft shitty tools, or stored on their servers. Regulation and the law is way behind when it comes to this stuff.

      • @[email protected]
        link
        fedilink
        150 minutes ago

        You have to trust the person you’re communicating with has turned it off. That’s my point. It’s an optional feature

  • MentalEdge
    link
    fedilink
    17
    edit-2
    3 hours ago

    Don’t forget that while they managed the PR better, apple “Intelligence” also has access to damn near everything on your devices.

    • @Pappabosley
      link
      118 minutes ago

      People also willing submit to the cult if Apple and just believe everything they say. People are likely more frequently forced to use windows due to work or just the lack of choice for less technically confident people.

  • @pHr34kY
    link
    696 hours ago

    If it leaves your device, you cannot control it.

  • @Alexstarfire
    link
    817 hours ago

    Can’t control what other people do so you might be out of luck.

    • jaxiiruff
      link
      fedilink
      135 hours ago

      Me neither! Microsoft needs to be taken to court over this because it is a serious breach of privacy to not only record the users but even random bystanders as well. Now I am convinced this is just a backdoor for the government hiding in plain sight. Fuck them.

      • @[email protected]
        link
        fedilink
        English
        23 hours ago

        Oh this 100% is the government backdoor that they’ve been begging for. “If you can innovate your way into it, you can innovate a way out of it.”

        That was in regards to Apple phones belonging to Boston bombers being encrypted and locked.

        It’s no surprise that behind closed doors, the government asked these companies to create backdoors for them to spy on people.

  • @reddig33
    link
    146 hours ago

    So is there a way for businesses to disable this garbage feature through managed device settings or something? I’m guessing corporate legal departments aren’t going to be too thrilled with this feature.

    • @[email protected]
      link
      fedilink
      65 hours ago

      There’s a CSP for disabling it on windows enterprise devices at least. Not sure if there’s a way for pro and home machines.

    • @[email protected]OP
      link
      fedilink
      English
      5
      edit-2
      1 hour ago

      I’m afraid this comment shows a severe underestimation of the gravity of the issue. Windows recall doesn’t stop at borders even if it were illegal there.

      • @[email protected]
        link
        fedilink
        025 minutes ago

        Well, it’s not here yet. And I do use windows 11, as does my mom, my grandparents and other pc’s I’m the one helping with. I don’t recall any recalls :p

        And if they do push it here, it’s probably followed by a news headline “eu fined Microsoft 10 billion for gdpr violation” or something like that

  • @[email protected]
    link
    fedilink
    02 hours ago

    If the content CNA be displayed, it can be parsed by recall.

    The only way I can see to bypass it is to obtain DRM keys and display your content on a website only if widevine is active, like Netflix does. Surely it can’t screenshot DRM protected content, but also this is Microsoft .

  • @[email protected]
    link
    fedilink
    67 hours ago

    To my knowledge, there isn’t. But you can ask the person to turn off recall. I’m going to be running 11 in a VM myself so /me shrugs

  • Max-P
    link
    fedilink
    36 hours ago

    You can’t, at that point you assume your correspondent is compromised. It’s not just recall but also malware and credential stealers. Doesn’t matter if recall is taking screenshots, if the messaging client itself is pwned via malware then they have full access to as much history as is available.