250
Signal downplays encryption key flaw, fixes it after X drama
(www.bleepingcomputer.com)
This is a most excellent place for technology news and articles.
True that Recall collects more than Signal, but copying actual files, browser session cookies / passwords, mailbox content if desktop mail client is used makes more sense if you have access to device. Recall is also not supposed to collect data from private sessions from popular web browsers. I assume for that it uses some hard coded list of exceptions with an option to add your own.
Both should have protected that kind of data with additional safeguards so that merely copying that data without authentication would have no value.
it makes one wonder how well that works; if it's based on OCR, does it "redact" the bounding box corresponding to the private window? What happens with overlapping windows; how does it handle windows with transparency; I can't help to think there's a high probability their solution is flaky.
Here is a video demonstration. Snapshots contain window that is in focus not the whole desktop and for exclusions I assume it would just base it on process name + additional parameters (private browser windows have same process name so must be something additional). You can also add websites for exclusions. Here is an article that lists other things that are not being captured like DRM protected content and one time WhatsApp images.
Also from support article: