市值: $2.1805T -1.29%
體積(24小時): $60.1052B -11.86%
  • 市值: $2.1805T -1.29%
  • 體積(24小時): $60.1052B -11.86%
  • 恐懼與貪婪指數:
  • 市值: $2.1805T -1.29%
加密
主題
加密植物
資訊
加密術
影片
頭號新聞
加密
主題
加密植物
資訊
加密術
影片
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

加密貨幣新聞文章

在安全專家強烈反對後,微軟對即將推出的人工智慧驅動的 Windows「召回」功能進行了更改

2024/06/08 05:07

微軟即將推出的人工智慧驅動的Windows「召回」功能,每隔幾秒鐘就截取用戶活動螢幕的螢幕截圖,在安全專家的強烈反對後,該功能將進行一些更改。

在安全專家強烈反對後,微軟對即將推出的人工智慧驅動的 Windows「召回」功能進行了更改

Microsoft has announced some changes to its upcoming AI-powered Windows “Recall” feature following backlash from security experts.

在遭到安全專家的強烈反對後,微軟宣布對其即將推出的人工智慧驅動的 Windows「召回」功能進行一些更改。

The feature, which takes screenshots of users’ active screen every few seconds, came under fire immediately after it was announced on May 20, with Malwarebytes calling it a “built-in keylogger” and software engineer and Web3 critic Molly White calling it “spyware.”

該功能每隔幾秒鐘就截取用戶活動螢幕的螢幕截圖,在5 月20 日宣布後立即受到批評,Malwarebytes 稱其為“內置鍵盤記錄器”,軟體工程師兼Web3 評論家Molly White 稱其為“間諜軟體" ".

The concerns were largely due to the fact that Recall does not censor sensitive information in the snapshots it takes, such as passwords or financial information. This would potentially make the database of Recall snapshots on a user’s computer a gold mine for hackers, with tons of sensitive data all in one place and easily searchable using the AI-powered search feature.

這些擔憂主要是由於 Recall 不會審查其拍攝的快照中的敏感訊息,例如密碼或財務資訊。這可能會使用戶電腦上的 Recall 快照資料庫成為駭客的金礦,大量敏感資料都集中在一個地方,並且可以使用人工智慧驅動的搜尋功能輕鬆搜尋。

Microsoft insisted users’ privacy was protected due to all Recall data being stored locally and encrypted by Device Encryption or BitLocker. The feature, which would be enabled by default on Copilot+ PCs, could also be disabled and configured to not record specific sites and apps.

微軟堅稱用戶的隱私受到保護,因為所有 Recall 資料都儲存在本地並透過裝置加密或 BitLocker 進行加密。此功能預設在 Copilot+ PC 上啟用,也可以停用並配置為不記錄特定網站和應用程式。

However, in the weeks since Recall was announced, multiple security pros have put available previews to the test and demonstrated ways the Recall database can be accessed and exploited to steal sensitive data en masse.

然而,自 Recall 宣布以來的幾週內,多名安全專家已經對可用的預覽進行了測試,並演示了存取和利用 Recall 資料庫來批量竊取敏感資料的方法。

For example, Alex Hagenah, head of cyber controls at SIX Group and technical advisory board member at HackerOne, developed a “very simple’ proof-of-concept tool called “TotalRecall,” which copies, searches and extracts information from the Recall database file.

例如,SIX Group 網路控制主管兼 HackerOne 技術顧問委員會成員 Alex Hagenah 開發了一種名為「TotalRecall」的「非常簡單」的概念驗證工具,該工具可以從 Recall 資料庫檔案中複製、搜尋和提取資訊。

Additionally, James Forshaw, a security research in Google Project Zero, published a blog post about bypassing access control lists, which includes an edit revealing that the Recall database can be accessed by a user without administrative privileges by using a token from the Windows AIXHost.exe process or simply rewriting the discretionary access control list, as the database is considered to be owned by the user.

此外,Google 零號專案的安全研究人員 James Forshaw 發表了一篇有關繞過存取控制清單的部落格文章,其中包含一項編輯,顯示沒有管理權限的使用者可以使用 Windows AIXHost 的令牌來存取 Recall 資料庫。 exe 進程或簡單地重寫自主存取控制列表,因為資料庫被認為由使用者擁有。

In response to “customer feedback,” Microsoft announced in a blog post on Friday that Recall would no longer be activated by default, requiring users to opt-in to use the feature. Additionally, users will need to complete the Windows Hello biometric enrollment process to enable Recall, lowering the chance that a hacker could enable it on the machine of a user who had opted out.

為了回應“客戶回饋”,微軟在周五的一篇部落格文章中宣布,預設將不再啟動 Recall,需要用戶選擇使用該功能。此外,使用者需要完成 Windows Hello 生物辨識註冊程序才能啟用 Recall,從而降低駭客在選擇退出的使用者的電腦上啟用它的機會。

Proof of presence through Windows Hello will be required to view the Recall timeline and use the AI-powered search tool, and the snapshots will only be decrypted upon user authentication via Windows Hello Enhanced Sign-in Security, Microsoft said.

微軟表示,要查看召回時間表並使用人工智慧驅動的搜尋工具,需要透過 Windows Hello 提供存在證明,並且只有透過 Windows Hello 增強登入安全性進行使用者驗證後,快照才會被解密。

“We want to reinforce what has previously been shared from David Weston, vice president of Enterprise and OS Security, about how Copilot+ PCs have been designed to be secure by default,” the blog post stated.

「我們希望強化企業和作業系統安全副總裁 David Weston 之前分享的關於 Copilot+ PC 如何設計為預設安全的內容,」該部落格文章表示。

Kevin Beaumont, a security researcher and former senior threat intelligence analyst at Microsoft, who has been a vocal critic of Recall since its announcement, responded positively to the update.

微軟安全研究員、前高級威脅情報分析師凱文·博蒙特(Kevin Beaumont)對此次更新做出了積極回應,自 Recall 發布以來,他一直直言不諱地批評它。

“Turns out speaking up works,” Beaumont wrote on X.

「事實證明,大聲疾呼是有效的,」博蒙特在 X 上寫道。

“There are obviously going to be devils in the details – potentially big ones – but there’s some good elements here. Microsoft needs to commit to not trying to sneak users to enable it in the future, and it needs turning off by default in Group Policy and Intune for enterprise orgs,” Beaumont added.

「顯然,細節中會存在一些問題——可能是大問題——但這裡也有一些好的元素。微軟需要承諾未來不會試圖欺騙用戶啟用它,並且需要在企業組織的群組原則和 Intune 中預設關閉它,」Beaumont 補充道。

免責聲明:info@kdj.com

所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!

如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。

2026年08月01日 其他文章發表於