Security Tool Exposes Vulnerability in Windows 11’s Copilot+ Recall Feature

A security tool has revealed vulnerabilities in Windows 11's Recall feature, part of Microsoft's Copilot+ suite, raising renewed privacy concerns. Microsoft responded with significant security changes, including encryption and tighter user authentication. The episode highlights challenges in balancing local AI-powered productivity tools with safeguarding user data.

ShareShare

A recently developed tool called "TotalRecall Reloaded" has brought fresh scrutiny to the security of Windows 11’s Recall feature, part of Microsoft’s Copilot+ suite introduced two years ago. Copilot+ was designed to leverage new neural processing units (NPUs), specialised chips that accelerate artificial intelligence (AI) applications directly on user devices, offering benefits such as improved privacy by keeping data local.

Recall was among the first features to use this local AI capability, promising to help users by logging activity through frequent screenshots of their desktop. These data were intended to make it easier for users to retrieve details of past work or actions on their computers. However, the implementation soon became controversial. Early versions of Recall stored screenshots and user activity in unencrypted files, making them accessible to anyone with local or remote access—potentially exposing weeks or months of highly sensitive information if the database was compromised.

Security researchers and tech journalists identified and reported these shortcomings, sparking concern in both business and consumer communities reliant on Microsoft's Windows platform. The critiques focused on the risks posed by unencrypted files containing such detailed histories, which potentially undermined the privacy gains AI-powered on-device features were designed to provide.

In response, Microsoft significantly delayed Recall’s initial public release by nearly a year and carried out a comprehensive security overhaul. The company moved to encrypt all data locally and required users to authenticate with Windows Hello—a biometric login or PIN—before accessing Recall's history. Furthermore, Microsoft implemented mechanisms to better detect and prevent sensitive information, including financial data, from being recorded. The feature was also set to be disabled by default to give users conscious control before opting in.

These adjustments represent an ongoing challenge for software developers seeking to introduce AI-powered tools that can drive productivity while safeguarding user privacy and security. As local AI features—like Recall—become more common in consumer and enterprise technology, maintaining trust through robust privacy protections remains an industry imperative.

For now, the saga of Recall underscores the delicate balance between innovation and user security—an issue that is particularly prominent as more companies integrate advanced AI features into their core products.

Source: arstechnica.com

Related Posts

Microsoft Introduces Scout, an OpenClaw-Inspired Personal Assistant

Microsoft has launched Scout, a personal assistant platform inspired by OpenClaw. The new assistant leverages artificial intelligence to enhance user productivity and streamline digital interactions.

Majority of CEOs Predict Job Losses from AI Within Two Years

A global survey indicates 99% of CEOs expect artificial intelligence to reduce jobs within two years, marking a significant shift in workplace expectations. The findings highlight growing executive confidence in AI technologies and their likely impact on employment.

E.ON Modernises Energy Grid with SAP S/4HANA and AI

E.ON is leveraging SAP S/4HANA to standardise grid data, streamline infrastructure, and enable AI-powered applications such as predictive maintenance and customer automation. The company is focusing on internal technical capabilities, cybersecurity, and embedding digital tools directly into core operations to support reliability and growth in the energy sector.

The Essential Weekly Update

Stay informed with curated insights delivered weekly to your inbox.