Snowflake Account Attacks: Cloud Data Is Only as Safe as the Login
June 11, 2024The CDK Global Ransomware Attack: When One Vendor Freezes an Entire Industry
June 24, 2024In June 2024, Microsoft faced a sharp backlash over Recall, a feature for its AI-enabled PCs that periodically captures screenshots of user activity so it can be searched later. Researchers quickly showed the stored data was not well protected, and Microsoft delayed the rollout to add encryption, opt-in consent, and authentication before viewing.
A preview of things to come
Recall is an early example of a broader trend: AI features that quietly build local archives of everything you see and do. If an attacker gains access to the device, they can search a history of your screens, including passwords and confidential messages that were never meant to persist. For organizations handling regulated data under PIPEDA, silent screen recording raises real questions about consent and retention.
How to approach AI features that capture data
- Inventory what the feature stores and where, before enabling it on managed devices.
- Default to off for any capability that records screens, keystrokes, or audio until vetted.
- Use management policy to control such features on corporate endpoints.
Takeaway: Before you let a productivity feature build a persistent record of sensitive activity, decide who can read it and how it is protected. If the answer is unclear, keep it disabled.
