“TotalRecall Reloaded” tool finds a side entrance to Windows 11’s Recall database



The problem, as detailed by Hagenah on the TotalRecall GitHub page, isn’t with the security around the Recall database, which he calls “rock solid.” The problem is that, once the user has authenticated, the system passes Recall data to another system process called AIXHost.exe, and that process doesn’t benefit from the same security protections as the rest of Recall.

“The vault is solid,” Hagenah writes. “The delivery truck is not.”

The TotalRecall Reloaded tool uses an executable file to inject a DLL file into AIXHost.exe, something that can be done without administrator privileges. It then waits in the background for the user to open Recall and authenticate using Windows Hello. Once this is done, the tool can intercept screenshots, OCR’d text, and other metadata that Recall sends to the AIXHost.exe process, which can continue even after the user closes their Recall session.

“The VBS enclave won’t decrypt anything without Windows Hello,” Hagenah writes. “The tool doesn’t bypass that. It makes the user do it, silently rides along when the user does it, or waits for the user to do it.”

A handful of tasks, including grabbing the most recent Recall screenshot, capturing select metadata about the Recall database, and deleting the user’s entire Recall database, can be done with no Windows Hello authentication.

Once authenticated, Hagenah says the TotalRecall Reloaded tool can access both new information recorded to the Recall database as well as data Recall has previously recorded.

Bug or not, Recall is still risky

For its part, Microsoft has said that Hagenah’s discovery isn’t actually a bug and that the company doesn’t plan to fix it. Hagenah originally reported his findings to Microsoft’s Security Response Center on March 6, and Microsoft officially classified it as “not a vulnerability” on April 3.



Source link

  • Related Posts

    Ikea’s Varmblixt smart lamp review: A sweet treat

    Ikea’s popular Varmblixt lamp just got a smart home glow-up. The delightfully bulbous light now features color-changing, dimming, and smart home control. I tested the new smart lamp in my…

    Boston Dynamics’ robot dog now reads gauges and thermometers with Google’s AI

    Robots such as Boston Dynamics’ four-legged Spot can now accurately read analog thermometers and pressure gauges while roaming around factories and warehouses. Those improvements come courtesy of Google DeepMind’s newest…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Sotomayor apologizes for criticizing Kavanaugh over ICE arrests, in rare public Supreme Court clash

    Sotomayor apologizes for criticizing Kavanaugh over ICE arrests, in rare public Supreme Court clash

    Kanye West postpones France show

    Kanye West postpones France show

    John Hardy Opens New Flagship in SoHo

    John Hardy Opens New Flagship in SoHo

    Ikea’s Varmblixt smart lamp review: A sweet treat

    Ikea’s Varmblixt smart lamp review: A sweet treat

    Les Leyne: Eby backtracks again as DRIPA crisis drags on

    Les Leyne: Eby backtracks again as DRIPA crisis drags on

    Russia pummels Ukraine with drone and missile strikes, killing at least 12 | Russia

    Russia pummels Ukraine with drone and missile strikes, killing at least 12 | Russia