Skip to main content

A new test shows Microsoft Recall’s continued security problems

Recall screenshot.
Microsoft

Microsoft is currently previewing its latest version of Recall to Windows Insiders on Snapdragon-, Intel-, and AMD-based Copilot+ PCs — and the topic on most users’ minds is security. The company updated its security and privacy architecture for the feature in September, but, according to tests run by Tom’s Hardware, it still might not be good enough.

The new version of Recall includes a sensitive information filter that’s supposed to detect when there’s information like credit card numbers and Social Security numbers on the screen. If it detects them, it will avoid taking a screenshot. When Tom’s Hardware put this filter to the test, however, it failed in a number of situations.

Recommended Videos

It seems that right now at least, Recall is best at detecting standard checkout pages where people input their payment details — and as for everything else, it’s not very good. Recall captured card numbers and passwords typed into a Notepad window, Social Security information on a PDF loan application, and payment info typed into a simple HTML page.

Microsoft recall capturing credit card info.
Tom's Hardware

Granted, these tests were designed to push the limits — but the filter probably ought to work in more than a single situation. Microsoft made sure not to promise any particular results, however. Its blog post on the updated architecture simply says the sensitive content filtering “helps reduce” the number of passwords, national ID numbers, and credit card numbers being stored in Recall.

In response to the Tom’s Hardware tests, the company pointed out that it plans to “improve this functionality” and encourages people to send examples to the Feedback Hub. Because the discourse around Recall is all about security, there really is no room for mistakes.

If you’re going to make a feature that screenshots everything everyone does on their PCs, you’ve got to make it airtight. We’ll see in the coming weeks if Recall’s encryption and everything going on under the hood is as secure as Microsoft claims it is. Hopefully, the company can get things sorted before its time for the larger rollout.

Willow Roberts
Willow Roberts has been a Computing Writer at Digital Trends for a year and has been writing for about a decade. She has a…
Microsoft outlines Recall security: ‘The user is always in control’
Recall promotional image.

Microsoft just released an update regarding the security and privacy protection in Recall. The blog post outlines the measures Microsoft is taking to prevent a data privacy disaster, including security architecture and technical controls. A lot of the features highlight that Recall is optional, and that's despite the fact that Microsoft recently confirmed that it cannot be uninstalled.

Microsoft's post is lengthy and covers just about every aspect of the security challenges that its new AI assistant has to face. One of the key design principles is that "the user is always in control." Users will be given the choice of whether they want to opt in and use Recall when setting up their new Copilot+ PC.

Read more
Microsoft is giving up control of the Copilot key
Windows 11 logo on a laptop.

In a Windows Insider Blog post, Microsoft recently announced that it is rolling out the Windows 11 Insider Preview Build 22635.4225 (KB5043186) update. It's a relatively small update, but it finally gives users control of the dedicated Copilot key that's showing up on an increasing number of laptops.

In the blog post, Microsoft detailed how it is giving users more customization freedom by adding the option to configure the Copilot key, which can open an app that's MSIX packaged and signed. This is good news since the app meets security and privacy requirements to keep your PC safe. When the option is available more broadly, you should find it by going to Settings > Personalization> Text Input.

Read more
Microsoft’s controversial Recall feature can’t be uninstalled
Recall promotional image.

The Recall saga continues. As it turns out, Microsoft's controversial AI feature cannot be uninstalled, although that was spotted as an option in the latest version of Windows 11 24H2.

The ability to uninstall it was initially observed by Desk Modder as a part of the "Turn Windows features on and off" menu in Control Panel, but Microsoft has now confirmed to The Verge that it was merely a bug. The statement to The Verge says that being listed in that menu is an issue that "will be fixed in an upcoming update."

Read more