Skip to content

Conversation

@jonaharagon
Copy link
Member

These instructions are based on these and I haven't tested them myself (not on Windows): https://docs.security.tamu.edu/docs/endpoint-security/Policies/MSRecall/

I am going to keep this marked as a draft until someone with Windows 11 confirms it's accurate, or I fire up a Windows computer somewhere and check myself. If someone can let me know that'd be great :)

@github-actions
Copy link

github-actions bot commented Mar 8, 2025

Your preview is ready!

Name Link
🔨 Latest commit a9ca52d
😎 Preview https://pr2932.unreviewed.privacyguides.dev/en/

@jonaharagon jonaharagon marked this pull request as ready for review April 12, 2025 04:19
Copilot AI review requested due to automatic review settings April 12, 2025 04:19
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot reviewed 1 out of 1 changed files in this pull request and generated 2 comments.

@ph00lt0
Copy link
Member

ph00lt0 commented Apr 12, 2025

I don't think this is finished?

@redoomed1 redoomed1 added the c:os operating systems and related topics label Apr 12, 2025
@dngray dngray self-requested a review April 17, 2025 05:48
<div class="admonition info" markdown>
<p class="admonition-title">Windows Recall</p>

Windows 11 recently introduced a feature called **Recall**, which records all your activity and creates a searchable archive of that activity history. This is a massive privacy vulnerability, because those archives can potentially store highly sensitive information (essentially anything displayed on your screen), and can be trivially accessed by local administrators or malicious actors with user-level access to your device.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Recall doesn't let other users access your info and it's stored encrypted, protected by the TPM and biometrics. It's definitely not true that it can be trivially bypassed. It also by default tries to exclude sensitive data like passwords and credit cards, and you can tell it to exclude certain sensitive apps like a web browser or messenger. I think info on how to disable it is fine but maybe some more info on the different settings and how to configure it might be useful as well.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is the only available setting related to Recall in gpedit as far as I can tell, so there are no additional configuration settings to talk about in this particular guide.

@github-project-automation github-project-automation bot moved this from Unreviewed to Needs Changes in PR Review Status Apr 24, 2025
@jonaharagon
Copy link
Member Author

jonaharagon commented May 6, 2025

@ph00lt0 what isn't finished?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

c:os operating systems and related topics

Projects

Status: Needs Changes

Development

Successfully merging this pull request may close these issues.

6 participants