Q. Is this really as harmful as you think?

A. Go to your parents house, your grandparents house etc and look at their Windows PC, look at the installed software in the past year, and try to use the device. Run some antivirus scans. There’s no way this implementation doesn’t end in tears — there’s a reason there’s a trillion dollar security industry, and that most problems revolve around malware and endpoints.

  • Adanisi@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    “If sensitive information is not saved” is doing a lot of heavy lifting for you there. The issue is that it saves everything.

    • NoiseColor@startrek.website
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      But it doesn’t save completely everything. It does snapshots as far as I understand. So it’s unlikely a whole password would be there on a snapshot. And again, it had to be mentioned that anything can be excluded from recall or disabled completely.

      At this point it has to be again highlighted that gaining access to a computer is very hard and that in itself is game over scenario. More information can be gained from a keylogger than this recall feature.

      • Spotlight7573@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        A keylogger isn’t retroactive to before the keylogger was installed though. Recall is. Also, with Recall you don’t need to write keylogging software and get it past antimalware scans (and keep it from getting detected), you just have to get an infostealer past them one single time to take the Recall database.

          • Spotlight7573@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            The video posted by Moorshou literally shows someone getting a password and a credit card number from it. Yes, the password was due to someone clicking the show password button momentarily but do we just never expect people to use those or to not use a password manager that would show the password on screen at some point? Due to it doing text recognition, you would literally be able to just search for “credit card” to find all the times when it was displaying a credit card field on a checkout page or “password” to find all the times someone is logging in or using their password manager.