• sylver_dragon@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    7 days ago

    so Recall snapshots will only be decrypted and accessible when the user authenticates.

    So basically, they may as well not be encrypted. If the decryption key is always available to users, it’s always available to a script running in the context of the user. Things like Lumma Stealer are going to incorporate pulling this stuff, the minute it becomes mainstream.