Get the latest tech news

Windows Recall demands an extraordinary level of trust that Microsoft hasn’t earned


Op-ed: The risks to Recall are way too high for security to be secondary.

Copilot+ PCs are required to have a fast neural processing unit (NPU) so that processing can be performed locally rather than sending data to the cloud; local snapshots are protected at rest by Windows’ disk encryption technologies, which are generally on by default if you’ve signed into a Microsoft account; neither Microsoft nor other users on the PC are supposed to be able to access any particular user’s Recall snapshots; and users can choose to exclude apps or (in most browsers) individual websites to exclude from Recall’s snapshots. This all sounds good in theory, but some users are beginning to use Recall now that the Windows 11 24H2 update is available in preview form, and the actual implementation has serious problems. The short version is this: In its current form, Recall takes screenshots and uses OCR to grab the information on your screen; it then writes the contents of windows plus records of different user interactions in a locally stored SQLite database to track your activity.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Microsoft

Microsoft

Photo of trust

trust

Photo of Windows Recall

Windows Recall

Related news:

News photo

Microsoft violates children’s privacy – but blames your local school

News photo

Snowflake CEO Is Seeking AI Deals in Battle With Databricks, Microsoft and Amazon

News photo

Microsoft deprecates Windows NTLM authentication protocol