Skip to main content
  1. Home
  2. Computing
  3. News

Windows improves handwriting-recognition skills at the peril of users’ security

Add as a preferred source on Google
Microsoft Surface Pro and Surface Pen 2017
Kyle Wiggers/Digital Trends

Windows has a built-in tool for improving its own handwriting recognition capability, and like many modern, smart features that increase their accuracy over time, it employs user data to do that. Some are concerned, however, that the way it stores that information could prove to be a security risk, as researchers have discovered everything from the content of emails to passwords stored in a single file.

Handwriting recognition was introduced in Windows 8 as part of its big drive toward touchscreen functionality. It automatically translates touch or stylus (these are the best ones) inputs into formatted text, improving its readability for the user, and giving other applications the ability to comprehend it. To help improve its accuracy, it looks at commonly used words in other documents, storing such information in a file called WaitList.dat. But digital forensics expert Barnaby Skeggs has highlighted that it stores just about any text on your system — not just handwritten content.

Recommended Videos

“Once [handwriting recognition] is on, text from every document and email which is indexed by the Windows Search Indexer service is stored in WaitList.dat. Not just the files interacted via the touchscreen writing feature,” Skeggs told ZDnet.

Considering how ubiquitous the Windows search indexing system is, this could mean that the content of most documents, emails, and forms ends up inside the WaitList file. The concern is that someone with access to the system — via a hack or malware attack — could find all sorts of personally identifiable information about the system’s owner. Worse yet, WaitList can store information even after the original files have been deleted, potentially opening up even greater security holes.

PowerShell command:

Stop-Process -name "SearchIndexer" -force;Start-Sleep -m 500;Select-String -Path $env:USERPROFILEAppDataLocalMicrosoftInputPersonalizationTextHarvesterWaitList.dat -Encoding unicode -Pattern "password"

— Barnaby Skeggs (@barnabyskeggs) August 26, 2018

This is something that has purportedly been known about in the forensics space for some time and has provided researchers with a useful way to prove the prior existence of a file and in some cases its contents, even if the original had been scrubbed from existence.

Although typically such a potential security hole would warrant contacting Microsoft about the issue before making the public aware of it, Skeggs has reportedly not done so, since the handwriting recognition feature is working as intended. This isn’t a bug, even if it’s potentially exploitable.

If you want to close up that potential security hole on your system, you can delete WaitList.dat manually by going to C:\Users\%User%\AppData\Local\Microsoft\InputPersonalization\TextHarvester. If you don’t find that folder, you don’t have handwriting recognition enabled, so you should be secure.

Well, you should be secure against this potential security flaw at least. We’d still recommend you enable Windows Defender and use one of the best anti-malware solutions.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
I didn’t think fake shopping could trick my brain until I tried the viral dopamine websites
On these fake shopping and delivery sites, nothing ever ships or costs a cent, yet the dopamine hit still felt real.
fake-shopping-on-viral-dopamine-websites

I spent some time in the internet's fakest mall, filling a shopping cart with things I could not buy, hunting for discounts on products that do not exist, and checking out three separate times for a grand total of $0.00. Then I placed a fake food order and smoked a cigarette I could not taste, with strangers I will never meet, on a rooftop that does not exist either. My bank balance never changed, but my brain, annoyingly, did.

When I first heard about South Korea's growing "dopamine sites," I assumed they were another internet oddity I would poke around for five minutes and forget by lunch. Instead, I found a surprisingly clever idea hiding beneath the absurdity. You can browse endless imaginary products, add everything to your cart, and complete a purchase that never actually exists. These websites aren't trying to sell you anything. They're trying to recreate the feeling of shopping while removing the part that empties your wallet.

Read more
LG wants to build humanoid robots, and NVIDIA is giving it the brains
This isn't just another robot teaser. LG and NVIDIA just outlined actual hardware.
Robot, Appliance, Device

With time, more and more legacy hardware companies seem to be racing to bolt a humanoid robot onto their roadmap. The latest entrant is LG, joining the race with tentative timelines.

The company's bipedal humanoid, built on Nvidia's robotics stack, is planned for early 2027, and it's backed by a broader push into AI factories and self-driving vehicle platforms.

Read more
Googlebook may use older Snapdragon chips to build more affordable laptops
Snapdragon X Plus and X Elite models could be in development
Googlebook

Google has already confirmed that Googlebook will support more than one chipmaker, and a new leak may have revealed the first Snapdragon models in development.

New code references uncovered by GbookHub reportedly link two Googlebook designs, codenamed Annite and Pic, to Qualcomm’s Snapdragon X Plus X1P-42-100 processor. Both are also said to be tied to a board platform called Mica.

Read more