在安全强烈反对后,微软将默认关闭召回功能
Microsoft will switch off Recall by default after security backlash

原始链接: https://www.wired.com/story/microsoft-recall-off-default-security-concerns/

微软的新 Window 功能最初名为 Recall,旨在代表设备的先进、人工智能驱动的内存功能。 然而,最近发生的事件让这个术语有了不同的含义——微软承认产品问题需要纠正。 上周,微软透露了对 Recall 实施的重大修改。 这包括使其成为可选功能而不是默认设置,特别是在 Copilot+ 兼容的 Windows 版本中。 此外,微软还推出了增强的安全功能,旨在保护数据加密并在激活 Recall 或检索其保存的信息时验证用户访问权限。 这些修改是在技术社区对 Recall 之前的行为提出批评之后进行的,其中包括在未经明确同意的情况下每五秒捕获一次用户活动的屏幕截图。 批评者谴责 Recall 是一种潜在风险,认为它的行为就像新 Windows 系统上预装的、未经请求的间谍软件。 收集到的本地数据(包括银行登录信息、密码和成人网站访问等敏感信息)仍然容易受到任何对配备 Recall 的设备的短暂控制的人的攻击,从而为入侵者提供了对受害者数字生活的长期洞察。 作为回应,微软选择加入 Recall,并在启用或访问其数据时要求更强的身份验证方法。 然而,尽管有这些改进,人们仍然担心 Recall 中潜在的漏洞,特别是考虑到捕获的信息与系统的交织程度有多深。

本文讨论了围绕微软产品 Recall 的担忧,据报道该产品未经同意泄露了用户数据。 作者认为,这一事件凸显了非技术产品经理的影响力日益增长以及技术的易于获取。 他们认为,召回是一个伪装成隐私问题的安全问题,这一事件的发生表明微软内部多个级别的领导层对潜在后果的疏忽或漠不关心。 作者进一步将当前情况与过去的做法进行了比较,过去的做法是消费者在产品注册期间故意提供个人详细信息。 他们认为,微软承诺在需要时存储并可能利用所有用户数据,这引起了人们的严重担忧,即使数据仍未上传。 拟议的更改包括多因素身份验证和加密,以降低风险。 此外,作者还分享了与 Microsoft 软件相关的挫败感,特别是在保存文件和浏览文件夹结构方面。 他们认为旧的方法(例如使用 API 来定位常用文件夹)可能会解决这些问题,但承认用户通常不会选择此类解决方案。 文本最后批评了微软缺乏对用户需求的考虑以及对实施变革的偏好。
相关文章

原文

When Microsoft named its new Windows feature Recall, the company intended the word to refer to a kind of perfect, AI-enabled memory for your device. Today, the other, unintended definition of “recall”—a company's admission that a product is too dangerous or defective to be left on the market in its current form—seems more appropriate.

On Friday, Microsoft announced that it would be making multiple dramatic changes to its rollout of its Recall feature, making it an opt-in feature in the Copilot+ compatible versions of Windows where it had previously been turned on by default, and introducing new security measures designed to better keep data encrypted and require authentication to access Recall's stored data.

“We are updating the set-up experience of Copilot+ PCs to give people a clearer choice to opt-in to saving snapshots using Recall,” reads a blog post from Pavan Davuluri, Microsoft's corporate vice president for Windows and devices. “If you don’t proactively choose to turn it on, it will be off by default.”

The changes come amid a mounting barrage of criticism from the security and privacy community, which has described Recall—which silently stores a screenshot of the user's activity every five seconds as fodder for AI analysis—as a gift to hackers: essentially unrequested, preinstalled spyware built into new Windows computers.

In the preview versions of Recall, that screenshot data, complete with the user's every bank login, password, and porn site visit would have been indefinitely collected on the user's machine by default. And though that highly sensitive data is stored locally on the user's machine and not uploaded to the cloud, cybersecurity experts have warned that it all remains accessible to any hacker who so much as gains a temporary foothold on a user's Recall-enabled device, giving them a long-term panopticon view of the victim's digital life.

"It makes your security very fragile,” as Dave Aitel, a former NSA hacker and founder of security firm Immunity, described it—more charitably than some others—to WIRED earlier this week. “Anyone who penetrates your computer for even a second can get your whole history. Which is not something people want.”

In addition to making Recall an opt-in feature, Microsoft’s Davuluri also writes that the company will make changes to better safeguard the data Recall collects and more closely police who can turn it on, requiring that users prove their identity via its Microsoft Hello authentication function any time they either enable Recall or access its data, which can require a PIN or biometric check of the user’s face or thumbprint. Davuluri says Recall’s data will remain encrypted in storage until the user authenticates.

All of that is a “great improvement,” says Jake Williams, another former NSA hacker who now serves as VP of R&D at the cybersecurity consultancy Hunter Strategy, where he says he's been asked by some of the firm's clients to test Recall's security before they add Microsoft devices that use it to their networks. But Williams still sees serious risks in Recall, even in its latest form.

联系我们 contact @ memedata.com