Microsoft Makes AI Recall Feature Off by Default After Security Concerns

Microsoft changes its upcoming Recall AI feature to be off by default after security researchers show that hackers could access the unencrypted data it collects.

Microsoft changes its upcoming Recall AI feature to be off by default after security researchers reveal that attackers could potentially access the underlying user data. The feature, designed for new Copilot+ PCs, captures screenshots of user activity to enable easy searching of past actions. Pavan Davuluri, Microsoft’s head of Windows and Surface devices, confirms that users now have to proactively choose to turn the tool on.

Security experts raise significant concerns about how Recall handles sensitive information. They release software demonstrating that the feature stores everything locally in an unencrypted SQLite database and saves screenshots in a simple PC folder. This lack of encryption worries professionals who fear attackers could easily develop tools to extract usernames and passwords from the captured images.

The shift highlights Microsoft's ongoing struggle to balance rapid AI integration with user privacy and security. Unlike cloud-dependent tools like ChatGPT, Recall operates entirely on the local device, which intensifies the focus on its data storage methods. Microsoft is now adding extra security protections to Recall as CEO Satya Nadella continues to push a broader company-wide shift toward prioritizing security following recent government criticism.

Read More at the original source →