Microsoft Copilot's recall feature: Difference between revisions
m cat |
→Microsoft's response: added response |
||
| (3 intermediate revisions by 2 users not shown) | |||
| Line 1: | Line 1: | ||
{{Stub}} | {{Stub}} | ||
{{Cleanup|Issue 1 = Citations need to be checked. There was at one that was missing multiple fields where info was available (website, date, access-date); there could be others affected.}} | {{Cleanup|Issue 1 = Citations need to be checked. There was at least one that was missing multiple fields where info was available (website, date, access-date); there could be others affected.}} | ||
{{IncidentCargo | {{IncidentCargo | ||
|Company=Microsoft | |Company=Microsoft | ||
| Line 11: | Line 11: | ||
}} | }} | ||
Recall is a feature of [[Windows 11]] that records the user's activity using snapshots and allows users to retrace their previous activity., using [[Microsoft Copilot|Copilot]], [[Microsoft]]'s [[Artificial intelligence]](AI) assistant. It takes screenshots of the user's desktop every few seconds to be used by Copilot. It was initially impossible to remove this from your computer and its screenshots were unencrypted.<ref>{{Cite web |last=Warren |first=Tom |date=2024-09-27 |title=Microsoft’s more secure Windows Recall feature can also be uninstalled by users |url=https://www.theverge.com/2024/9/27/24255721/microsoft-windows-recall-ai-security-improvements-overhaul-uninstall |url-status=live |website=The Verge |archive-url=http://web.archive.org/web/20260101111442/https://www.theverge.com/2024/9/27/24255721/microsoft-windows-recall-ai-security-improvements-overhaul-uninstall |archive-date=1 Jan 2026}}</ref><ref name=":0">{{Cite web |title=Retrace your steps with Recall - Microsoft Support |url=https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c |access-date=2025-08-23 |archive-url=http://web.archive.org/web/20260121194712/https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c |archive-date=21 Jan 2026}}</ref> | Recall is a feature of [[Windows 11]] that records the user's activity using snapshots and allows users to retrace their previous activity., using [[Microsoft Copilot|Copilot]], [[Microsoft]]'s [[Artificial intelligence]](AI) assistant. It takes screenshots of the user's desktop every few seconds to be used by Copilot. It was initially impossible to remove this from your computer and its screenshots were unencrypted.<ref name=":1">{{Cite web |last=Warren |first=Tom |date=2024-09-27 |title=Microsoft’s more secure Windows Recall feature can also be uninstalled by users |url=https://www.theverge.com/2024/9/27/24255721/microsoft-windows-recall-ai-security-improvements-overhaul-uninstall |url-status=live |website=The Verge |archive-url=http://web.archive.org/web/20260101111442/https://www.theverge.com/2024/9/27/24255721/microsoft-windows-recall-ai-security-improvements-overhaul-uninstall |archive-date=1 Jan 2026}}</ref><ref name=":0">{{Cite web |title=Retrace your steps with Recall - Microsoft Support |url=https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c |access-date=2025-08-23 |archive-url=http://web.archive.org/web/20260121194712/https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c |archive-date=21 Jan 2026}}</ref> | ||
==Background== | ==Background== | ||
In 2024, Microsoft unveiled Recall for Copilot+ PCs,<ref>{{Cite web |date=2002-01-25 |title=Competitive Processes, Anticompetitive Practices And Consumer Harm In The Software Industry: An Analysis Of The Inadequacies Of The Microsoft-Department Of Justice Proposed Final Judgment |url=https://www.justice.gov/atr/competitive-processes-anticompetitive-practices-and-consumer-harm-software-industry-analysis |url-status=live |website=U.S. Department of Justice |archive-url=http://web.archive.org/web/20251118112915/https://www.justice.gov/atr/competitive-processes-anticompetitive-practices-and-consumer-harm-software-industry-analysis |archive-date=18 Nov 2025}}</ref> marketed as a way for users to search through what they have done on their computer by recording their screen. This sparked controversy,<ref>{{Cite web |last=Allan |first=Darren |date=2024-05-23 |title=Microsoft’s controversial Recall feature for Windows 11 could already be in legal hot water |url=https://www.techradar.com/computing/windows/microsofts-controversial-recall-feature-for-windows-11-could-already-be-in-legal-hot-water |url-status=live |website=Techradar |archive-url=http://web.archive.org/web/20251002141424/https://www.techradar.com/computing/windows/microsofts-controversial-recall-feature-for-windows-11-could-already-be-in-legal-hot-water |archive-date=2 Oct 2025}}</ref> especially among security experts<ref>{{Cite web |last=Hassan |first=Nilhad |title=Privacy and security risks surrounding Microsoft Recall |url=https://www.techtarget.com/searchenterpriseai/feature/Privacy-and-security-risks-surrounding-Microsoft-Recall |website=TechTarget |date=4 Nov 2024 |access-date=23 May 2026 |url-status=live |archive-url=http://web.archive.org/web/20251209084156/https://www.techtarget.com/searchenterpriseai/feature/Privacy-and-security-risks-surrounding-Microsoft-Recall |archive-date=9 Dec 2025}}</ref> who worried about the security of screenshots, since it could easily document private information like social-security numbers, bank-account information, and passwords, as well as user browsing behavior. A massive security oversight was the '''initial''' version of Microsoft Recall gathering information into a '''plain text database'''<ref>{{Cite web |last=Beaumont |first=Kevin |date=2024 |title=Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster |url=https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e |archive-url=https://web.archive.org/web/20250128195155/https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e?gi=e57abd81f3e3 |archive-date=2025-01-28 |access-date=2025-10-18 |website=Medium}}</ref>. Later versions of Recall subsequently encrypt the database.<ref | In 2024, Microsoft unveiled Recall for Copilot+ PCs,<ref>{{Cite web |date=2002-01-25 |title=Competitive Processes, Anticompetitive Practices And Consumer Harm In The Software Industry: An Analysis Of The Inadequacies Of The Microsoft-Department Of Justice Proposed Final Judgment |url=https://www.justice.gov/atr/competitive-processes-anticompetitive-practices-and-consumer-harm-software-industry-analysis |url-status=live |website=U.S. Department of Justice |archive-url=http://web.archive.org/web/20251118112915/https://www.justice.gov/atr/competitive-processes-anticompetitive-practices-and-consumer-harm-software-industry-analysis |archive-date=18 Nov 2025}}</ref> marketed as a way for users to search through what they have done on their computer by recording their screen. This sparked controversy,<ref>{{Cite web |last=Allan |first=Darren |date=2024-05-23 |title=Microsoft’s controversial Recall feature for Windows 11 could already be in legal hot water |url=https://www.techradar.com/computing/windows/microsofts-controversial-recall-feature-for-windows-11-could-already-be-in-legal-hot-water |url-status=live |website=Techradar |archive-url=http://web.archive.org/web/20251002141424/https://www.techradar.com/computing/windows/microsofts-controversial-recall-feature-for-windows-11-could-already-be-in-legal-hot-water |archive-date=2 Oct 2025}}</ref> especially among security experts<ref>{{Cite web |last=Hassan |first=Nilhad |title=Privacy and security risks surrounding Microsoft Recall |url=https://www.techtarget.com/searchenterpriseai/feature/Privacy-and-security-risks-surrounding-Microsoft-Recall |website=TechTarget |date=4 Nov 2024 |access-date=23 May 2026 |url-status=live |archive-url=http://web.archive.org/web/20251209084156/https://www.techtarget.com/searchenterpriseai/feature/Privacy-and-security-risks-surrounding-Microsoft-Recall |archive-date=9 Dec 2025}}</ref> who worried about the security of screenshots, since it could easily document private information like social-security numbers, bank-account information, and passwords, as well as user browsing behavior. A massive security oversight was the '''initial''' version of Microsoft Recall gathering information into a '''plain text database'''<ref>{{Cite web |last=Beaumont |first=Kevin |date=2024 |title=Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster |url=https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e |archive-url=https://web.archive.org/web/20250128195155/https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e?gi=e57abd81f3e3 |archive-date=2025-01-28 |access-date=2025-10-18 |website=Medium}}</ref>. Later versions of Recall subsequently encrypt the database.<ref name=":1" /> But Gaming Copilot has traces of the Recall Software which failed all the privacy tests it was given.<ref>{{cite web |first=Kevin |last=Beaumont |website=DoublePulsar |title=Microsoft builds on Recall with Gaming Copilot — fails basic privacy tests |url=https://doublepulsar.com/microsoft-builds-on-recall-with-gaming-copilot-fails-basic-privacy-tests-52988576bcc8 |url-status=live |date=23 Oct 2025 }}</ref> | ||
===System requirements for Recall=== | ===System requirements for Recall=== | ||
| Line 25: | Line 25: | ||
===Microsoft's response=== | ===Microsoft's response=== | ||
{{ | On 7 June 2024, Microsoft responded to the criticism and recognized that they need to make Recall's privacy and security stronger and the feature would be opt-in instead of opt-out. | ||
<blockquote> | |||
Even before making Recall available to customers, we have heard a clear signal that we can make it easier for people to choose to enable Recall on their Copilot+ PC and improve privacy and security safeguards. [...] First, we are updating the set-up experience of Copilot+ PCs to give people a clearer choice to opt-in to saving snapshots using Recall.<ref name="blogResponse">{{cite web |first=Pavan |last=Davuluri |title=Update on the Recall preview feature for Copilot+ PCs |url=https://blogs.windows.com/windowsexperience/2024/06/07/update-on-the-recall-preview-feature-for-copilot-pcs/ |date=7 Jun 2024 |website=Windows Blogs |url-status=live |archive-url=https://web.archive.org/web/20260601045608/https://blogs.windows.com/windowsexperience/2024/06/07/update-on-the-recall-preview-feature-for-copilot-pcs/ |archive-date=2026-06-01}}</ref> | |||
</blockquote> | |||
In the same blogpost, Microsoft has shared three security points that would enhance and protect Recall: | |||
<blockquote> | |||
*All Copilot+ PCs will be Secured-core PCs | |||
*Microsoft Pluton security processor will be enabled by default on all Copilot+ PCs. | |||
*All Copilot+ PCs will ship with Windows Hello Enhanced Sign-in Security (ESS).<ref name="blogResponse"/> | |||
</blockquote> | |||
Additionally, the feature are expanded and clarified: | |||
<blockquote> | |||
*Snapshots are stored locally. | |||
*Snapshots are not shared. | |||
*You will know when Recall is saving snapshots. | |||
*Digital rights managed or InPrivate browsing snapshots are not saved. | |||
*You can pause, filter and delete what’s saved at any time. | |||
*Enterprise and customer choice.<ref name="blogResponse"/> | |||
</blockquote> | |||
==Consumer response== | ==Consumer response== | ||