|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
몇 초마다 사용자의 활성 화면 스크린샷을 찍는 마이크로소프트의 곧 출시될 AI 기반 윈도우 '리콜' 기능은 보안 전문가들의 반발에 따라 몇 가지 변화를 겪을 예정이다.

Microsoft has announced some changes to its upcoming AI-powered Windows “Recall” feature following backlash from security experts.
Microsoft는 보안 전문가들의 반발에 따라 곧 출시될 AI 기반 Windows "리콜" 기능에 대한 일부 변경 사항을 발표했습니다.
The feature, which takes screenshots of users’ active screen every few seconds, came under fire immediately after it was announced on May 20, with Malwarebytes calling it a “built-in keylogger” and software engineer and Web3 critic Molly White calling it “spyware.”
몇 초마다 사용자의 활성 화면 스크린샷을 찍는 이 기능은 5월 20일 발표된 직후부터 비난을 받았습니다. Malwarebytes는 이를 "내장 키로거"라고 불렀고, 소프트웨어 엔지니어이자 Web3 평론가인 Molly White는 이를 "스파이웨어"라고 불렀습니다. .”
The concerns were largely due to the fact that Recall does not censor sensitive information in the snapshots it takes, such as passwords or financial information. This would potentially make the database of Recall snapshots on a user’s computer a gold mine for hackers, with tons of sensitive data all in one place and easily searchable using the AI-powered search feature.
이러한 우려는 주로 Recall이 스냅샷에서 비밀번호나 금융 정보와 같은 민감한 정보를 검열하지 않는다는 사실에 기인했습니다. 이는 잠재적으로 사용자 컴퓨터의 Recall 스냅샷 데이터베이스를 해커의 금광으로 만들 수 있으며, 수많은 민감한 데이터가 한 곳에 모두 있고 AI 기반 검색 기능을 사용하여 쉽게 검색할 수 있습니다.
Microsoft insisted users’ privacy was protected due to all Recall data being stored locally and encrypted by Device Encryption or BitLocker. The feature, which would be enabled by default on Copilot+ PCs, could also be disabled and configured to not record specific sites and apps.
Microsoft는 모든 리콜 데이터가 로컬에 저장되고 장치 암호화 또는 BitLocker에 의해 암호화되기 때문에 사용자의 개인 정보가 보호된다고 주장했습니다. Copilot+ PC에서 기본적으로 활성화되는 이 기능을 비활성화하고 특정 사이트와 앱을 기록하지 않도록 구성할 수도 있습니다.
However, in the weeks since Recall was announced, multiple security pros have put available previews to the test and demonstrated ways the Recall database can be accessed and exploited to steal sensitive data en masse.
그러나 Recall이 발표된 후 몇 주 동안 여러 보안 전문가가 테스트에 사용 가능한 미리 보기를 적용하고 Recall 데이터베이스에 액세스하여 민감한 데이터를 대량으로 도용하는 방법을 시연했습니다.
For example, Alex Hagenah, head of cyber controls at SIX Group and technical advisory board member at HackerOne, developed a “very simple’ proof-of-concept tool called “TotalRecall,” which copies, searches and extracts information from the Recall database file.
예를 들어, SIX Group의 사이버 통제 책임자이자 HackerOne의 기술 자문 위원인 Alex Hagenah는 Recall 데이터베이스 파일에서 정보를 복사, 검색 및 추출하는 "TotalRecall"이라는 "매우 간단한" 개념 증명 도구를 개발했습니다. .
Additionally, James Forshaw, a security research in Google Project Zero, published a blog post about bypassing access control lists, which includes an edit revealing that the Recall database can be accessed by a user without administrative privileges by using a token from the Windows AIXHost.exe process or simply rewriting the discretionary access control list, as the database is considered to be owned by the user.
또한 Google Project Zero의 보안 연구원인 James Forshaw는 액세스 제어 목록 우회에 대한 블로그 게시물을 게시했습니다. 여기에는 Windows AIXHost의 토큰을 사용하여 관리자 권한 없이 사용자가 Recall 데이터베이스에 액세스할 수 있다는 내용이 포함되어 있습니다. exe 프로세스를 실행하거나 데이터베이스를 사용자가 소유한 것으로 간주하므로 임의 액세스 제어 목록을 다시 작성하면 됩니다.
In response to “customer feedback,” Microsoft announced in a blog post on Friday that Recall would no longer be activated by default, requiring users to opt-in to use the feature. Additionally, users will need to complete the Windows Hello biometric enrollment process to enable Recall, lowering the chance that a hacker could enable it on the machine of a user who had opted out.
"고객 피드백"에 대한 응답으로 Microsoft는 금요일에 블로그 게시물을 통해 리콜이 더 이상 기본적으로 활성화되지 않으며 사용자가 이 기능을 사용하도록 선택해야 한다고 발표했습니다. 또한 사용자는 Windows Hello 생체 인식 등록 프로세스를 완료하여 회수를 활성화해야 하며, 이를 통해 해커가 옵트아웃한 사용자의 컴퓨터에서 회수를 활성화할 가능성이 줄어듭니다.
Proof of presence through Windows Hello will be required to view the Recall timeline and use the AI-powered search tool, and the snapshots will only be decrypted upon user authentication via Windows Hello Enhanced Sign-in Security, Microsoft said.
리콜 타임라인을 보고 AI 기반 검색 도구를 사용하려면 Windows Hello를 통한 존재 증명이 필요하며, 스냅샷은 Windows Hello 향상된 로그인 보안을 통해 사용자 인증 시에만 해독될 것이라고 Microsoft는 밝혔습니다.
“We want to reinforce what has previously been shared from David Weston, vice president of Enterprise and OS Security, about how Copilot+ PCs have been designed to be secure by default,” the blog post stated.
블로그 게시물에는 "우리는 Copilot+ PC가 기본적으로 어떻게 보안되도록 설계되었는지에 대해 엔터프라이즈 및 OS 보안 담당 부사장인 David Weston이 이전에 공유한 내용을 강화하고 싶습니다."라고 명시되어 있습니다.
Kevin Beaumont, a security researcher and former senior threat intelligence analyst at Microsoft, who has been a vocal critic of Recall since its announcement, responded positively to the update.
보안 연구원이자 Microsoft의 전 수석 위협 인텔리전스 분석가이자 Recall이 발표된 이후부터 이를 비판해 온 Kevin Beaumont는 이 업데이트에 대해 긍정적인 반응을 보였습니다.
“Turns out speaking up works,” Beaumont wrote on X.
Beaumont는 X에 이렇게 썼습니다. “말하는 것이 효과가 있는 것으로 나타났습니다.
“There are obviously going to be devils in the details – potentially big ones – but there’s some good elements here. Microsoft needs to commit to not trying to sneak users to enable it in the future, and it needs turning off by default in Group Policy and Intune for enterprise orgs,” Beaumont added.
“세부 사항에는 분명히 악마가 있을 것입니다. 잠재적으로 큰 것일 수도 있지만 여기에는 몇 가지 좋은 요소가 있습니다. Microsoft는 앞으로 사용자가 이 기능을 활성화하도록 몰래 시도하지 않도록 노력해야 하며 그룹 정책 및 기업 조직용 Intune에서 기본적으로 꺼야 합니다.”라고 Beaumont는 덧붙였습니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































