Windows is recording every keystroke on devices with handwriting recognition enabled

Facepalm: From the moment you first handwrote or enabled handwriting recognition on your PC, your WaitList.dat file began compiling every text file the PC received. In my own file on my Windows tablet, I found documents I’ve written, PDFs I’ve downloaded, and emails sent to me.

The purpose of the file is to record what you write so that future text can be predicted, allowing Windows to better determine what you’re trying to handwrite. Many phone keyboards work in a similar fashion, but it would have been nice to know that the file existed – it dates to at least Windows 8, if not Windows 7. The file’s lack of protection is an issue, however, as it can be copied in under a second and will likely contain sensitive information or passwords on many people’s computers.

It was first noticed and experimented upon by Digital Forensics and Incident Response expert Barnaby Skeggs, who found that “text from every document and email which is indexed by the Windows Search Indexer service is stored in WaitList.dat. Not just the files interacted via the touchscreen writing feature.”

“On my PC, and in my many test cases, WaitList.dat contained a text extract of every document or email file on the system, even if the source file had since been deleted,” Skeggs revealed in an interview with ZDnet.com. “If the source file is deleted, the index remains in WaitList.dat, preserving a text index of the file.” ..Read More..

Leave a Reply

Your email address will not be published.

top