Technology Microsoft Recall caught capturing credit card and Social Security numbers despite reassurances it won't

jamey910111

Level 2
Thread author
Jun 7, 2024
97
According to Microsoft, the updated version of Recall still captures screenshots, but those screenshots are now supposed to be encrypted and have a "Filter sensitive information" setting enabled by default. This filter is meant to stop Recall from capturing apps or websites that show sensitive personal information like credit card numbers and Social Security numbers.

The sensitive information filter doesn't appear to work

Unfortunately, this filter does not seem to be working. Our colleague, Avram Piltch, at Tom's Hardware, tested the revamped Recall and reported that the filter only worked a couple of times, "leaving a gaping hole in the protection it promises."

 

Marko :)

Level 24
Verified
Top Poster
Well-known
Aug 12, 2015
1,314
Like we in Croatia say... ako prođe, prođe (lit. if it passes, it passes). Phrase you jokingly use when someone intentionally tries to scam you and unfortunate for him, you realize it.

I'm starting to think Microsoft works like this. I have no doubt everything they make is intentional behavior, but when they're caught doing bad things, only then they'll intervene and say they made a mistake. Same was with SmartScreen. They said full URLs collected weren't being associated with user accounts, when in fact they were. They didn't even try to hide it.

I actually trust Google more than Microsoft, even though they both collect bunch of data from us. Google at least gives you ability to turn everything off, Microsoft only let's you "delete" collected data, but doesn't let you disable data collection.
 
Last edited:

jamey910111

Level 2
Thread author
Jun 7, 2024
97
Yea great point about intentional behaviour.
Regarding Smart Screen, long time ago i blocked it using my firewall as well - if there is anything suspicious either I won’t execute/download or my AV will catch it instead.
 

Marko :)

Level 24
Verified
Top Poster
Well-known
Aug 12, 2015
1,314
Yea great point about intentional behaviour.
Regarding Smart Screen, long time ago i blocked it using my firewall as well - if there is anything suspicious either I won’t execute/download or my AV will catch it instead.
I disabled it everywhere I could. But for some reason, smartscreen.exe keeps launching on my PC. And I can't get rid of it.
 

Marko :)

Level 24
Verified
Top Poster
Well-known
Aug 12, 2015
1,314
I assume you killed it via Task Manager? And it still launched again?
It doesn't launch again immediately; but it certainly is active again after some time. It also launches with every boot.

It's funny because I disabled it with Group Policy Editor and it really should honor that.
 

jamey910111

Level 2
Thread author
Jun 7, 2024
97
It doesn't launch again immediately; but it certainly is active again after some time. It also launches with every boot.

It's funny because I disabled it with Group Policy Editor and it really should honor that.
At least if firewall blocked it cannot send any info - upon trying it says it is being blocked from accessing the net or something - i think this is enough cause it’s not a memory hugging app
 

Marko :)

Level 24
Verified
Top Poster
Well-known
Aug 12, 2015
1,314
To be fair, it doesn't have any network activity from what I can see, and it's using just 2 MB of RAM. But I want it gone out of spite.

Group Policy is the strongest set of settings which should be respected by the OS and it's apps. And if I disable a certain feature I don't plan to use, it should be completely disabled and not only partially.
 
Last edited:

TairikuOkami

Level 37
Verified
Top Poster
Content Creator
Well-known
May 13, 2017
2,685
I disabled it everywhere I could. But for some reason, smartscreen.exe keeps launching on my PC. And I can't get rid of it.
That is the reason I remove it and I apply my remediation settings at every shutdown, since Windows updates (+SFC) love to restore them. :rolleyes:
Code:
takeown /s %computername% /u %username% /f "%WinDir%\System32\smartscreen.exe"
icacls "%WinDir%\System32\smartscreen.exe" /grant:r %username%:F
taskkill /im smartscreen.exe /f
del "%WinDir%\System32\smartscreen.exe" /s /f /q
At least if firewall blocked it cannot send any info - upon trying it says it is being blocked from accessing the net or something - i think this is enough cause it’s not a memory hugging app
Assuming that it is smartscreen.exe sending info only, not MsMpEng.exe or svchost.exe MS philosophy is, if you fail, try and try again. Windows is great in reinstalling installed updates. 😅
I have uninstalled and blocked Recall via a presumed domain based on copilot, but not sure if it helps, since I have never used it. maybe someone, who actually uses it, can confirm, please?!
capture_12142024_153844.jpg
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top