Security Expert Calls Microsoft's Windows Recall Feature Dangerously Insecure

A prominent security researcher reveals severe vulnerabilities in Microsoft's upcoming Windows Recall AI tool, arguing the company needs to pull the feature entirely before its official release.

A leading security researcher publicly calls on Microsoft to recall its newly announced Windows Recall feature before it even launches. The expert highlights that the AI-powered tool, which continuously takes screenshots of user activity to create a searchable visual history, contains woefully inadequate security protections that put highly sensitive user data at immediate risk.

The investigation reveals that Microsoft stores these unencrypted Recall snapshots in a basic, easily accessible database folder on the user's local hard drive. This poor architectural choice means that malware and malicious actors easily bypass the tool's meager safeguards, allowing unauthorized access to everything from private passwords and financial records to personal conversations without requiring administrator privileges.

This severe security oversight raises massive privacy concerns for everyday consumers and enterprise users alike as Microsoft prepares to roll out the feature on new Copilot+ PCs. Until the software giant fundamentally redesigns Recall with proper encryption and strict access controls, critics insist the tool remains an undeniable liability rather than a helpful productivity boost.

Read More at the original source →