Microsoft "Fixed" Windows Recall, But It's Still Dangerous
Linus Tech TipsJune 5, 202515 min912,599 views
21 connectionsΒ·31 entities in this videoβRecall's Troubled History
- π Last year, Microsoft rushed Windows Recall into public testing, an AI feature designed to record and catalog all user interactions for easy searching.
- β οΈ The initial rollout was a disaster, with security experts quickly highlighting how insecure the feature was, despite CEO Satya Nadella's call for prioritizing security.
- π Microsoft postponed Recall in response to community backlash, but it has now returned a year later.
How Recall Works and Its Security Claims
- πΈ Windows Recall takes screenshots (snapshots) of user activity every few seconds.
- π§ These snapshots are then processed by AI for optical text recognition and image analysis, storing everything in a local database.
- π‘ The stated purpose is to allow users to ask questions like "What was that Korean restaurant Alice mentioned?" and get an answer from a snapshot.
- π Microsoft now claims Recall is more secure, with data encrypted, protected by Bit Locker, and requiring Windows Hello authentication.
Security Vulnerabilities and Microsoft's Claims
- π Despite new encryption, the original Recall's database was found to be plain text, easily accessible with free tools.
- πΌοΈ Similarly, image files were not truly encrypted and could be previewed and opened.
- π A major flaw allowed any user on the same machine to access another user's Recall snapshots, a dangerous oversight for journalists or abuse victims.
- π€₯ Microsoft claimed Recall didn't record incognito windows, but this was proven false, with incognito sessions being captured.
Improvements and Lingering Concerns
- β Recall is now opt-in instead of on by default, a significant improvement.
- π Data is now reportedly AES encrypted, and the image store is also protected.
- β οΈ However, the speaker argues Microsoft still hasn't done enough to educate users on the dangers, especially with shared accounts.
- π§© The feature's reliance on AI to detect sensitive information is questionable, and the potential for Microsoft's own apps to access the data remains a concern.
The Fundamental Privacy Problem
- π Even if a user doesn't enable Recall, people they communicate with might have it enabled, posing a risk to shared information.
- π The existence of Recall makes Windows a less secure platform by default, providing a convenient target for attackers.
- π The feature demands an extraordinary level of trust in Microsoft that, according to the speaker, has not been earned.
Knowledge graph31 entities Β· 21 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
31 entities
Chapters7 moments
Key Moments
Transcript58 segments
Full Transcript
Topics14 themes
Whatβs Discussed
Windows RecallMicrosoftAI PCsData PrivacySecurityEncryptionBit LockerWindows HelloScreenshotsOptical Character RecognitionLocal DatabaseOpt-in FeatureData BrokersDigital Security
Smart Objects31 Β· 21 links
CompaniesΒ· 4
ProductsΒ· 12
PeopleΒ· 3
ConceptsΒ· 11
MediaΒ· 1