Great...
Instead of fixing their shiat MS just keeps adding new attack vectors to their OS...
Windows 11 users in the European Economic Area will shortly receive a new Recall Export feature, allowing Recall snapshots to be shared with third-party apps and websites. Since Recall snapshots are encrypted, users are presented with an export code the first time Recall is opened or snapshots are turned on in Settings. The …
If you can't remember the keys, well, you should ask any of the three letter agencies(*) for a copy of the entire snapshot stream. I'm sure they keep it all on file, just in case. Please, remember to ask very nicely.
(*) I guess some countries have four or two letter agencies. It'll fit, on average.
Let's look at the official statement: Microsoft said it "does not have access to your export code and cannot help you recover it if it is lost."
"does not have access" implies that the code is actually saved somewhere.
"cannot help you" covers both business decisions and physical limitations. Just like I cannot help you rob a bank.
"Losing the code (or if a malicious actor gets hold of it) will require resetting Recall – generating a new code will delete all previously saved snapshots."
I so dearly hope that is true.
It is not as good as having Recall not at all. But being able to wipe the key and make all Recall snapshot become digital noise is at least second best.
Somehow, I fear there is a catch, and someone will still be able to access the Recall snapshots without the user key.
Why does even exist in the first place? Are people really so disorganised that they want this? I can't for the life of me think of a single good reason for this to exist that outweighs the likely-hood of it being a security nightmare. And no matter how "optional" this may be at the moment, it WILL be opt-out eventually. And even your opt-out choice will almost certainly
default back to "on" whenever an update is applied, as we already see with many user "choices" already.