this post was submitted on 07 Jun 2024
454 points (97.5% liked)
Technology
59148 readers
3105 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
They store it unencrypted in 2024? This should be illegal. Now every fucking Program you run can basically know everything you ever did since every shit is spyware nowadays to get that sweet data collection going
Even if they encrypt it, the computer needs access to the data thus needs the decryption key. So it's not very secure anyway.
I guess the solution would involve keys on the TPM so that they shouldn't need to be sat on attached storage or in memory. Although I'm not sure I'd trust all TPM implementations to have the performance necessary for the extra load (I believe bitlocker keys get cached in memory once you have unlocked the drive, for example)
Well yeah, but they should atleast store the key outside of userspace
The key is stored in
$APPDATA\WelcomeMat
Even if it were encrypted, if access to it doesn't involve explicit confirmation and a password then it can be automated.
And if it can be automated then malware that gets on the machine will be able to access it whether it's encrypted or not.
But let's be real, the whole reason Microsoft is doing this is so they can parse your data for AI. And storing it unencrypted makes it easier for them.
Also "the data won't leave your machine" is a red herring. Yeah the data won't; but the results of AI processing will. They'll take what they need and transfer that out, and leave you holding the bag.
They will have your computer calculating hyperspecific queries for ads.
I would be happy to provide my energy to microsoft's openai /s