Skip to main content

A new test shows Microsoft Recall’s continued security problems

Recall screenshot.
Microsoft

Microsoft is currently previewing its latest version of Recall to Windows Insiders on Snapdragon-, Intel-, and AMD-based Copilot+ PCs — and the topic on most users’ minds is security. The company updated its security and privacy architecture for the feature in September, but, according to tests run by Tom’s Hardware, it still might not be good enough.

The new version of Recall includes a sensitive information filter that’s supposed to detect when there’s information like credit card numbers and Social Security numbers on the screen. If it detects them, it will avoid taking a screenshot. When Tom’s Hardware put this filter to the test, however, it failed in a number of situations.

Recommended Videos

It seems that right now at least, Recall is best at detecting standard checkout pages where people input their payment details — and as for everything else, it’s not very good. Recall captured card numbers and passwords typed into a Notepad window, Social Security information on a PDF loan application, and payment info typed into a simple HTML page.

Microsoft recall capturing credit card info.
Tom's Hardware

Granted, these tests were designed to push the limits — but the filter probably ought to work in more than a single situation. Microsoft made sure not to promise any particular results, however. Its blog post on the updated architecture simply says the sensitive content filtering “helps reduce” the number of passwords, national ID numbers, and credit card numbers being stored in Recall.

In response to the Tom’s Hardware tests, the company pointed out that it plans to “improve this functionality” and encourages people to send examples to the Feedback Hub. Because the discourse around Recall is all about security, there really is no room for mistakes.

If you’re going to make a feature that screenshots everything everyone does on their PCs, you’ve got to make it airtight. We’ll see in the coming weeks if Recall’s encryption and everything going on under the hood is as secure as Microsoft claims it is. Hopefully, the company can get things sorted before its time for the larger rollout.

Willow Roberts
Willow Roberts has been a Computing Writer at Digital Trends for a year and has been writing for about a decade. She has a…
AI can do a lot of things but it can’t make games — or even play them yet
Claude playing Pokemon on Twitch.

As AI tools improve, we keep getting encouraged to offload more and more complex tasks to them. LLMs can write our emails for us, create presentations, design apps, generate videos, search the internet and summarize the results, and so much more. One thing they're still really struggling with, however, is video games.

So far this year, two of the biggest names in AI (Microsoft and Anthropic) have tried to get their models to generate or play games, and the results are probably a lot more limited than many people expect.

Read more
Windows 11’s controversial AI Recall feature is coming to your Copilot+ PC very soon
The Surface Pro 11 on a white table in front of a window.

As AI strides on, it inevitably finds its way onto our personal devices, with tech giants announcing new features that rely on accessing our private information and media to serve us better. While some might find this useful, others are bound to find it creepy, and one such feature is Microsoft's controversial AI Recall, which takes screenshots of everything you do on a Copilot+ PC so it's easier to trace back your steps and find something specific later. After being announced last year, and then witnessing a few delays, Recall is finally rolling out to a broader group of Windows 11.

Microsoft recently announced Recall is coming to Windows 11 with the latest Release channel update with build 26100.3902 (KB5055627). The feature's availability in the Windows 11 Release Preview channel, which succeeds the Beta channel in the Windows Insider program, means it is in the initial phases of being available to a wider audience of folks who own Copilot+ PC. This category of PCs currently includes a whole wide range of laptops with specialized hardware in the form of a neural processing unit (NPU) dedicatedly for running AI tasks, though we might see desktops joining the club soon.

Read more
Google Gemini’s best AI tricks finally land on Microsoft Copilot
Copilot app for Mac

Microsoft’s Copilot had a rather splashy AI upgrade fest at the company’s recent event. Microsoft made a total of nine product announcements, which include the agentic trick called Actions, Memory, Vision, Pages, Shopping, and Copilot Search. 

A healthy few have already appeared on rival AI products such as Google’s Gemini and OpenAI’s ChatGPT, alongside much smaller players like Perplexity and browser-maker Opera. However, two products that have found some vocal fan-following with Gemini and ChatGPT have finally landed on the Copilot platform. 

Read more