SN 976: The 50 Gigabyte Privacy Bomb

Beep boop - this is a robot. A new show has been posted to TWiT…

What are your thoughts about today’s show? We’d love to hear from you!

Regarding Recall on Windows 11, how is this different to Windows Search or Spotlight on the Mac, apart from it is indexing information in applications that don’t understand the Recall API? Or various other search systems over the years?

The screenshots are made for apps that don’t support the Recall API by doing an OCR scrape of the screenshot, AFAIK, and adding that into the search model. I’m assuming, if the browser is Recall compliant, as I expect most will be over time, then Windows won’t be screenshotting them and if they are in private browsing mode, they won’t be adding the sites you visit to the Recall search database.

Given that the search database (which doesn’t contain the screenshots, they are scraped for text and disposed of, AFAIK) is encrypted on a per user key and can only be decrypted when the user logs themselves onto the PC (it is also, currently, local only, so no cloud syncing, so if you have multiple devices, you have to remember what you did where, if you want to find it again!), there isn’t much of a security problem. This is Windows 11, a Windows NT based system, so it has had separate user accounts for each user since its inception, unlike Windows 9x or earlier versions of Windows, which had a single desktop for all users and no user rights on files and folders to restrict views.

I am a very privacy conscious person and against many things Microsoft does, but screaming privacy violation at this is privacy theatre, a case of “don’t look over there, look here!” distraction from real security violations going on in Big Tech, and especially at Microsoft. There are so many genuine reasons to berate Microsoft, such as the 700+ partners they share your outlook.com mailbox with(!), that concentrating on ones, where they seem to actually take the privacy, at least on the surface, seriously, detracts from the real scandals that are going on all around us.

2 Likes

Sounds less of a privacy issue than your web browser history, that is shared between devices, via some Cloud I assume.

1 Like