Microsoft is reviewing its Copilot+ integrations, and is saying internally that Microsoft Recall has failed.
So @xaitaxAlex Hagenah has cracked Microsoft Recall, he's got access to the encrypted database and has automated dumping of screenshots and all text from screenshots.
I've looked at most recent Recall and yep, you can just read the database as a user process. The database also contains all manner of fields which aren't publicly disclosed for tracking the user's activity.
No AV or EDR alerts triggered, world's #1 in infostealer 馃槄
* you can just read it in plain text
If you have a fediverse account, you can quote this note from your own instance. Search https://cyberplace.social/users/GossiTheDog/statuses/116211359321826804 on your instance and quote it. (Note that quoting is not supported in Mastodon.)

