Skip to main content

A new test shows Microsoft Recall’s continued security problems

Recall screenshot.
Microsoft

Microsoft is currently previewing its latest version of Recall to Windows Insiders on Snapdragon-, Intel-, and AMD-based Copilot+ PCs — and the topic on most users’ minds is security. The company updated its security and privacy architecture for the feature in September, but, according to tests run by Tom’s Hardware, it still might not be good enough.

The new version of Recall includes a sensitive information filter that’s supposed to detect when there’s information like credit card numbers and Social Security numbers on the screen. If it detects them, it will avoid taking a screenshot. When Tom’s Hardware put this filter to the test, however, it failed in a number of situations.

Recommended Videos

It seems that right now at least, Recall is best at detecting standard checkout pages where people input their payment details — and as for everything else, it’s not very good. Recall captured card numbers and passwords typed into a Notepad window, Social Security information on a PDF loan application, and payment info typed into a simple HTML page.

Microsoft recall capturing credit card info.
Tom's Hardware

Granted, these tests were designed to push the limits — but the filter probably ought to work in more than a single situation. Microsoft made sure not to promise any particular results, however. Its blog post on the updated architecture simply says the sensitive content filtering “helps reduce” the number of passwords, national ID numbers, and credit card numbers being stored in Recall.

In response to the Tom’s Hardware tests, the company pointed out that it plans to “improve this functionality” and encourages people to send examples to the Feedback Hub. Because the discourse around Recall is all about security, there really is no room for mistakes.

If you’re going to make a feature that screenshots everything everyone does on their PCs, you’ve got to make it airtight. We’ll see in the coming weeks if Recall’s encryption and everything going on under the hood is as secure as Microsoft claims it is. Hopefully, the company can get things sorted before its time for the larger rollout.

Willow Roberts
Willow Roberts has been a Computing Writer at Digital Trends for a year and has been writing for about a decade. She has a…
Nearly six months later, you can finally try out Windows 11 Recall
Recall promotional image.

After a tumultuous initial reaction and months of reworking, Microsoft is finally releasing the first preview of its controversial Recall feature today. If you're a Windows Insider with a Qualcomm Copilot+ PC, you can install a new build of Windows 11 that includes both Recall and Click to Do.

If you're not part of the Windows Insider Program but you want to try out this feature, it's pretty easy to sign up on the Microsoft website. Recall was first announced back before any of the Copilot+ PCs were released and was meant to be available at launch, but an outcry of privacy and security concerns forced Microsoft to delay it.

Read more
With Copilot Actions, Microsoft brings AI agents to Outlook, Teams, and more
microsoft expanding ai agents 365 copilot early 2025 actions2

Microsoft plans to roll out a slew of new features for its business-facing 365 Copilot products starting early next year, the company announced during its Microsoft Ignite 2024 event on Tuesday.

365 Copilot, which was rebranded from just Copilot in September, enables businesses to incorporate Microsoft Copilot generative AI into its Microsoft 365 family of apps (as well as in Teams) for a $30/employee/month subscription.

Read more
Microsoft calls Recall one of ‘the most secure experiences’ it’s ever built
Recall promotional image.

As part of its Ignite 2024 announcements, Microsoft has provided an update on how its AI-powered Recall feature will work in the context of an IT department. Noting that the company has "heard your feedback," specifically in terms of it needing it to be more "secure and controllable," Microsoft claims to have gotten its ducks in a row for the launch of its controversial new Windows 11 feature.

Microsoft says that Recall "will ship with meaningful security enhancements, including additional layers of data encryption and Windows Hello protection, making it one of the most secure experiences we have ever built." Whether or not this will be enough to satisfy the security community, however, is still to be determined.

Read more