Stealing Your Data Via TotalRecall Reloaded Is A Feature, Not A Bug?
From The Author of TotalRecall Comes A Terrifying New Sequel
Microsoft did score some points by ensuring their security nightmare disguised as a convenient way to recall what you were looking at on your PC in the past is now disabled by default. Their original push, which enabled Recall on any and all Copilot laptops automatically was as welcome as injecting Copilot into Notepad. The fact it wasn’t properly encrypted was also horrific, something they did indeed fix for those that wanted to enable Recall. Recall is more secure that it was, but that doesn’t mean snooping ne’er-do-wells can’t access it.
There is a new vulnerability which was discovered by the same security researcher, Alexander Hagenah, who created TotalRecall to demonstrate how ridiculously insecure the original implementation of Recall was. Unfortunately in this case Microsoft has taken the position it is a feature and not a bug.
If you have enabled Recall, the database of screenshots is secure, however the way in which Windows saves the data to the secured database is not. The process, AIXHost.exe is vulnerable to a DLL injection, one which does not require admin privileges ‘can intercept screenshots, OCR’d text, and other metadata,’ in real time and can even do so once a user closes their Recall session. As awful as that sounds, don’t expect a fix as Microsoft stated they do not consider this a vulnerability.
One of the first Copilot+ features was Recall, a feature that promised to track all your PC usage via screenshot to help you remember your past activity. But as originally implemented, Recall was neither private nor secure
More Tech News From Around The Web
- Raspberry Pi OS ends open-door policy for sudo @ The Register
- Microsoft: Some Windows servers enter reboot loops after April patches @ Bleeping Computer
- QUIC will soon be as important as TCP – but it’s vastly different @ The Register
- Newly Unsealed Records Reveal Amazon’s Price-Fixing Tactics @ Slashdot
- Microsoft Finally Ups FAT32 Size Limit @ Hackaday
- Recent advances push Big Tech closer to the Q-Day danger zone @ Ars Technica
- Intel refreshes non-Ultra Core CPUs with new silicon for the first time @ Ars Technica
- Wearable Circuit Sculpture Is One Smart Bracelet @ Hackday
- Data breach at edtech giant McGraw Hill affects 13.5 million accounts @ Bleeping Computer
- Ancient Excel bug comes out of retirement for active attacks @ The Register
- Cisco says critical Webex Services flaw requires customer action @ Bleeping Computer
- Researchers Induce Smells With Ultrasound, No Chemical Cartridges Required @ Slashdot


