Microsoft says itâs making its new Recall feature in Windows 11 that screenshots everything you do on your PC an opt-in feature and addressing various security concerns. The software giant first unveiled the Recall feature as part of its upcoming Copilot Plus PCs last month, but since then, privacy advocates and security experts have been warning that Recall could be a âdisasterâ for cybersecurity without changes.
Technology
Windows won’t take screenshots of everything you do after all — unless you opt in
Microsoft is making its controversial AI-powered Recall feature optional. The changes come after security experts warned the feature could be a disaster for cybersecurity.
Thankfully, Microsoft has listened to the complaints and is making a number of changes before Copilot Plus PCs launch on June 18th. Microsoft had originally planned to turn Recall on by default, but the company now says it will offer the ability to disable the controversial AI-powered feature during the setup process of new Copilot Plus PCs. âIf you donât proactively choose to turn it on, it will be off by default,â says Windows chief Pavan Davuluri.
Microsoft will also require Windows Hello to enable Recall, so youâll either authenticate with your face, fingerprint, or using a PIN. âIn addition, proof of presence is also required to view your timeline and search in Recall,â says Davuluri, so someone wonât be able to start searching through your timeline without authenticating first.
This authentication will also apply to the data protection around the snapshots that Recall creates. âWe are adding additional layers of data protection including âjust in timeâ decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so Recall snapshots will only be decrypted and accessible when the user authenticates,â explains Davuluri. âIn addition, we encrypted the search index database.â
Recall uses local AI models to screenshot mostly everything you see or do on your computer and then give you the ability to search and retrieve anything in seconds. An explorable timeline lets you scroll through these snapshots with ease to look back on what you did on a particular day on your PC. Everything in Recall is designed to remain local and private on-device, so no data is used to train Microsoftâs AI models.
Microsoftâs changes to the way the database is stored and accessed come after cybersecurity expert Kevin Beaumont discovered that Microsoftâs AI-powered feature currently stores data in a database in plain text. That could have made it easy for malware authors to create tools that extract the database and its contents. Several tools have appeared in recent days, promising to exfiltrate Recall data.
TotalRecall extracts the Recall database so you can easily view what text is stored and the screenshots that Microsoftâs feature has generated. NetExec appears to be getting its own Recall module soon that can access Recall folders and dump them so you can view the screenshots easily. These tools are all possible because there is currently no full encryption or protection on the Recall database.
Microsoft developed the Recall feature under its new Secure Future Initiative (SFI) that the company has put in place to overhaul its software security after major Azure cloud attacks. Microsoft has had a rough few years of cybersecurity incidents, and the SFI is supposed to focus on security above all else.
Microsoft CEO Satya Nadella even called on employees to make security Microsoftâs âtop priorityâ recently, even if that means prioritizing it over new features. âIf youâre faced with the tradeoff between security and another priority, your answer is clear: Do security,â said Nadella (emphasis his) in an internal memo obtained by The Verge. âIn some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.â
Davuluri references Microsoftâs SFI principles in todayâs response, noting that the company is taking action to improve Recall security. But it appears to be largely down to security researchers flagging these issues rather than Microsoftâs own security principles because surely these issues should have been flagged internally far before this launch.
Microsoft is also keen to stress that Recall will only be available on new Copilot Plus PCs that are designed to be secure-core PCs with advanced firmware safeguards and the companyâs Pluton security processor thatâs designed to protect against personal data theft from a PC.
âAs we always do, we will continue to listen to and learn from our customers, including consumers, developers and enterprises, to evolve our experiences in ways that are meaningful to them,â says Davuluri âWe will continue to build these new capabilities and experiences for our customers by prioritizing privacy, safety and security first. We remain grateful for the vibrant community of customers who continue to share their feedback with us.â