After Microsoft eroded Windows users' trust with bad practices for years, Recall is a PR disaster, as users remain skeptical despite the company's assurances
inside the Copilot+ Recall disaster. Andrew Cunningham / Ars Technica : Windows Recall demands an extraordinary level of trust that Microsoft hasn't earned Alex / xaitax on GitHub : TotalRecall - a ‘privacy nightmare’? Matt Burgess / Wired : This Hacker Tool Extracts All the Data Collected by Windows' New Recall AI Thomas Claburn / The Register : Microsoft Research chief scientist has no issue with Windows Recall Omar Gallaga / CNET : Microsoft's AI Recall Feature for Copilot Plus PCs Sees Backlash From Security Experts Rob Thubron / TechSpot : Microsoft Research scientist gives non-answer when asked about Windows Recall privacy concerns The Hacker News : The AI Debate: Google's Guidelines, Meta's GDPR Dispute, Microsoft's Recall Backlash Omar Gallaga / CNET : Microsoft's AI Recall Feature May Not Even Hit Your PC, but Here's How to Disable It Mastodon: Matt Burgess / @mattburgess@infosec.exchange : Turns out that it's even easier to pull data from Microsoft's Recall tool than we thought — Security researchers have now found the one remaining security protection can be trivially defeated — @agreenberg has the story: — https://www.wired.com/... @confluency@hachyderm.io : This Recall thing is a prime example of how bad we are at understanding when something is a systemic problem. It doesn't matter if *you* disable it. It doesn't matter if *you* install Linux. It doesn't matter if *you* set your computer on fire and move to a Luddite commune. If you have *ever* sent sensitive data, no matter how securely, to another person who now has this shit enabled, and they find your data and look at it, your data is compromised, and there's nothing you can do about it. @Kierkegaanks@beige.party : @Techmeme personally i trust microsoft assurances because they never lied or manipulated me before @0xabad1dea@infosec.exchange : I've finally worked out why Microsoft's communication on Recall has been so strange and counterfactual. As an organization, they've become so cloudpilled that “it is stored locally (not in the cloud)” and “it cannot be accessed remotely” sound like the same statement to them, and they don't see how “it's just an sqlite file in a folder” is relevant. … Tim Kellogg / @kellogh@hachyderm.io : it'll be fascinating to read a hindsight analysis of the #recall debacle in 5 years. i think it represents a significant business failure, maybe a critical one. i know there's a lot of undercurrents and dynamics at play, it'll be a great case study down the road @USBTypeSteve@infosec.exchange : If this doesn't clearly indicate that Microsoft has a systemic security culture/awareness problem, I don't know what does. Sacrificing security because “we're in the AI revolution” is astoundingly tone-deaf. https://www.theregister.com/ ... Stu / @tehstu@hachyderm.io : “Asked to explore the data privacy issues arising from Microsoft Recall, the Windows maker's poorly received self-surveillance tool, Jaime Teevan, chief scientist and technical fellow at Microsoft Research, brushed aside concerns.” — Into the sea with these people. — #Windows #Recall … Steve Bellovin / @SteveBellovin@mastodon.lawprofs.org : There are features, such as the ability to delay patch installation, that at least at some point Microsoft enabled for enterprise versions of Windows but not for consumers. I wonder if they'll do the same for Recall. (As noted by others, Recall is a gift to hackers and opposing counsel, which means that any decent-sized enterprise will disable it or not run Windows. … @sinbad@mastodon.gamedev.place : Microsoft's “nothing to see here” attitude is beyond galling. Deep in the hole over Recall and just keeps digging https://www.theregister.com/ ... @skye@toot.cat : i have been thinking about that microsoft recall thing and — this is not the first time something like this has happened, isn't it? this situation feels so familiar. people losing their minds over an incredibly bad idea that came out of nowhere and is now getting pushed out irregardless of the consequences … Bluesky: @clearspark.bsky.social : I need to test it, but I thought OneDrive with default backup settings (which most people won't change especially with coercive UI & UX choices) uploaded our %AppData% folders (where the Recall spyware logs are stored). [embedded post] X: Steven Sinofsky / @stevesi : In Microsoft culture speak, @GossiTheDog is executing a “technical buzzsaw” which is how the company internally dismantled competitive features or industry developments it didn't agree with. It's a brutal, but necessary skill. I learned the skill in early 1990s on C++ v Borland. [image] Steven Sinofsky / @stevesi : “Stealing everything you've ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster.” https://doublepulsar.com/... @techau : @stevesi @WholeMarsBlog Shocker, with admin rights to the PC, you can get data from the machine. Andy Greenberg / @a_greenberg : As the security backlash has grown against Microsoft's Recall feature, it at least seemed the screenshots it takes every 5 seconds are stored such that a hacker would need admin privileges to access them. Turns out even that safeguard is easily bypassed. https://www.wired.com/... Steven Sinofsky / @stevesi : @techAU @WholeMarsBlog This is the part I find the most nuts. Kevin Beaumont / @gossithedog : Microsoft told media outlets a hacker cannot exfiltrate Copilot+ Recall activity remotely. Reality: how do you think hackers will exfiltrate this plain text database of everything the user has ever viewed on their PC? Very easily, I have it automated. HT detective [image] Zac Bowden / @zacbowden : Microsoft has gone radio silent on Windows Recall. [image] Simon Willison / @simonw : I keep seeing Microsoft's Recall described as an “AI” feature, anyone know what makes it “AI”? Is it just that the OCR uses a machine learning model, or are there other AI components in the mix here? Robert Scoble / @scobleizer : Windows Recall is similar to @LimitlessAI which I use on my Macintosh. The PR backlash should have been expected. People are not ready to record everything they do and say on a computer. Yet. I am. You might be. But the everyday user? No way. Shows the advantage of Kevin Beaumont / @gossithedog : WIRED has a piece about Total Recall, a now released tool which dumps keypresses, text and screenshots (they're JPEGs) made in the last few months using Microsoft Recall. https://www.wired.com/... Total Recall software by @xaitax https://github.com/... Andi / @nexuist : Amazing how much trouble Microsoft got themselves in by not shipping a toggle. I can think of plenty of great use cases for Recall - browsing developer docs, reading news articles, shopping, etc. I can also think of many bad cases. Just put in a menu switch so I can choose Kevin Beaumont / @gossithedog : One Recall that keeps coming up - can data be changed? Answer: yes, done. Anybody or any software running as can user, including remotely, can change both the screenshots and the text in the OCR'd database - there's no security on it at all. Tool drop later, called SatyaFake. Edwin Hayward / @edwinhayward : Another reason to run a million miles from Microsoft's new Windows Recall feature. It's a gigantic privacy hole waiting to be plundered. Gergely Orosz / @gergelyorosz : Given Microsoft has pretty large security teams, and a newfound focus on security: How did Recall pass security review - if it even did? Details coming out make it seem like while building this cool-sounding AI feature, there was no emphasis on common-sense security and privacy. Jake Williams / @malwarejake : I don't think Microsoft can pull back on Recall, given that it's the feature they sold tons of consumers on for preordering their Qualcomm powered laptops. No question in my mind that this was a rush to market, but hardware likely set the delivery date. Go security! Mick Douglas / @bettersafetynet : An open letter/thread to @msftsecurity and @Microsoft 🧵 MSFT, please listen. I get that you've invested a TON into the Recall product line. Hopefully, you've heard the concerns of the infosec community. If not, I recommend review of @GossiTheDog's recent work. 1 Roger McNamee / @moonalice : It is increasingly true, Big Tech does not have customers or even “users”. It has marks. The goal is to extract value while shifting risk to the mark. Microsoft's Windows Recall seems like a perfect example. Kevin Beaumont / @gossithedog : Does anybody know the name of the exec at Microsoft who signed off Recall? I have various tooling and info to drop, and want to name them after the exec - so history remembers with future breaches, write ups to boards, insurers etc. Accountability. Kevin Beaumont / @gossithedog : On Recall, I had a question about me (and Satya, lol) using the phrase “screenshot” where all of the documentation says snapshot, and MSFT people say it's just snapshots. They're screenshots. They're just JPEG files, a constant stream of. On a 1tb PC it allocates enough space... [image] Kevin Beaumont / @gossithedog : If you're in cyber or privacy and you're bored of Recall tweets, don't worry, you've just got another 10 years of your life where incidents feature: - ‘how did they figure out how to use our bespoke money transfer system?!’ - ‘how did they get our meeting chat?!’ - 'how did our... Kevin Beaumont / @gossithedog : Youtube reacts to Recall. There's hundreds of widely watched videos. I found one positive video, from a Windows fan site. Content creators have discovered it records credit card numbers and how to exfiltrate them so that's probably the next content cycle. [image] Kevin Beaumont / @gossithedog : Since this cat is bagless - you don't need admin rights to steal the Recall database. https://infosec.exchange/... [image] @vxunderground : > wake up > check news > more ransomware attacks against critical infra > more problems found in microsoft recall > more malware campaign findings shared > more company databases leak > more twitter dm spam Gergely Orosz / @gergelyorosz : Remember, how 19 years ago, a bug in Firefox resulted in two users using the same machine to see what sites the other user used? And it caused a couple to split up (but filed the bug!) Microsoft Recall allows for much more invasive “spying”, in its current form. [image] @vxunderground : Security Researcher Alexander Hagenah has developed a proof-of-concept which programmatically extracts data out of Microsoft Recall Microsoft said it would be safe, but as is tradition, it was beaten with a stick before it was even fully deployed https://github.com/... Kevin Beaumont / @gossithedog : Microsoft's enterprise customer briefings about Recall [Image of a gate on a path, with no fence, and that can be easily passed around “Don't worry, it's encrypted"] Kevin Beaumont / @gossithedog : I don't think they're saying anything here, it's just marketing fluff. Somebody at MSFT did say to me today I was spreading fake news as Recall is “secure from the chip to cloud” so I was really confused - it looks like another crap customer talking point. Lukasz Olejnik / @lukolejnik : Microsoft Windows Recall constantly makes screen screenshots (by default always on). OCR's text. Command to disable it: Set-ItemProperty HKLM:\SOFTWARE\Microsoft\PolicyManager\ default\WindowsAI\DisableAIDataAnalysis -Name Value -Value 1 https://gist.github.com/... (via: @awakecoding... [image] Kevin Beaumont / @gossithedog : Microsoft: Recall processing is all locally, it doesn't get sent to us (this is currently correct). Microsoft marketing: We secure Recall “from the chip to the cloud”. [image] Dare Obasanjo / @carnage4life : Microsoft talked up the privacy aspect of its Recall feature by saying all the data is stored locally on your device. Sadly it didn't pay as much attention to security as the data is stored in plaintext. So a hacker tool (TotalRecall) now exists to query the screenshots it takes [image] Han / @hanchunglee : there. there's the code. all your images are in a sqlite3 database. microsoft doesn't care about security. it's just a matter of time when recall gets recalled, after half a dozen promotions. [image] Alex Garcia / @agarcia_me : so Microsoft is using a vector index (DiskANN) stored in SQLite to power their new “Recall” AI features storing vectors in SQLite is the way @grummz : This recent abuse of your data by @Adobe in Photoshop and creative cloud, mirrors Microsoft's Recall and telemetry. This is a big rush to collect AI data. In AI, whoever has the best, highest quality data, wins. Everybody wants it, and nobody is compensating users for... Andrew Case / @attrc : The entire Recall disaster is mind blowing to me. Microsoft knows that it is under intense scrutiny for major security failures and decides the best course of action is to add built in software that can only be described as fully invasive spyware - and then enables it by default! Daniel Feldman / @d_feldman : @simonw Many of the column names in all 3 DBs contain the word “diskann” . I believe that is a reference to this work from MS Research — basically a lightweight vector index you can use in any database https://github.com/... Michael Schneider / @0x6d69636b : Disable Recall - User [HKEY_CURRENT_USER\Software\Policies\Mi crosoft\Windows\WindowsAI] “DisableAIDataAnalysis"=dword:00000001 Disable Recall - Machine (not yet official) [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\M icrosoft\Windows\WindowsAI] “DisableAIDataAnalysis"=dword:00000001 Zac Bowden / @zacbowden : The narrative around Windows Recall has snowballed into a major PR disaster. People don't trust Microsoft, and that means features like Recall aren't welcome in the eyes of many Windows users. EDITORIAL: https://www.windowscentral.com/ ... #Windows11 #WindowsRecall @swiftonsecurity : I'm seeing Microsoft Recall piercing the normie space on TikTok random jokes about Microsoft recording everything you do. What the fuck is leadership doing. You're torching yourself for a press release. Zac Bowden / @zacbowden : Do you trust Microsoft with a feature like Windows Recall? Kevin Beaumont / @gossithedog : If you want to know how Microsoft have got themselves into this giant mess with Recall, here's what the documentation says between the lines: you, the customer, are a simpleton who doesn't want to be an AI genius yet. Have a caveman mode. [image] Kevin Beaumont / @gossithedog : ArsTechnica enabled Recall on Windows 11 box and tested the claim that only you can access ‘your Recall’ By logging in as another user they could access the database and screenshots. https://arstechnica.com/... [image] LinkedIn: Prof Bill Buchanan : “The world is up-in-arms over Windows Recall, but why? It stems from Microsoft's seeming lack of care for Windows and its users.” https://lnkd.in/... Derek A. : Let's recall Recall for a fun Friday post. Recall is like a drinking problem, it's getting worse. — “Microsoft is fully aware that the concept of Windows Recall sounds creepy. … Martin von Stein : I was wrong. Let it never be said that I'm not willing to eat some humble pie. Windows Recall actually IS inexplicably awful. … Esko Kurvinen : Microsoft Copilot+ Recall developers should watch Black Mirror S1 E3 on Netflix. — I'm not talking about data security here (which is also a problem) … Arnaud Pavon : TotalRecall was released to exploit data from Copilot+ Recall sqlite database/screenshots stored locally. — https://lnkd.in/... … Gabe Knuth : Wow. This is scary stuff. It's what I was worried about, but...um...somehow way worse. #Copilot #Microsoft #AI #Security Grzegorz Adamowicz : Have you heard about Windows Recall? It's awesome how it gathers data about your activity and can tell you all about it. … Fred Wu : This is wild. Windows' upcoming Recall feature apparently stores all captured screenshots unencrypted in a SQLite database that other tools can read … Ali Salih : “But let's put it this way: Microsoft is building a feature into Windows that is monitoring and logging a ton of data about you and the way you use your PC. … Ciarán McNally : A tool has been released to grab or view the data stored in a Microsoft Recall database, very convenient for attackers once they compromise your system, eh? … Mathew Clark : Windows Recall is a new “feature” set to release to Windows 11 very soon. it's listed as a great feature to help you recall anything you've worked … Mike Wilkes : Kevin is someone that knows stuff... heed his warnings and concern. — “I think they are probably going to set fire to the entire Copilot brand due … Derek A. : Well that didn't take long to show that Microsoft's Recall is not safe and secure and it's just as bad, really worse, than browser stored creds. … Kevin Wennemuth : Worst move in cybersecurity since a decade by Microsoft. — „A lot of Windows users just want their PCs so they can play games, watch porn … Derek A. : The Recall saga gets even worse. I guess Satya giving that interview and explaining Recall security as “lol trust me bro” isn't really holding up to testing. … Forums: r/technews : Microsoft's Recall Feature Is Even More Hackable Than You Thought r/pcmasterraceFR : Windows Recall demands an extraordinary level of trust that Microsoft hasn't earned r/technology : Microsoft Research chief scientist has no issue with Recall r/france : Windows Recall demands an extraordinary level of trust that Microsoft hasn't earned r/aiwars : Sooner than expected: AI trained on all your private computer files without consent
Context & Ripple Effects
Recall began as a Copilot+ PC feature intended to make past Windows activity searchable through a visual timeline. Its launch immediately raised alarm because the system would retain screenshots and OCR text for months by default, as detailed in early privacy and security scrutiny.
The dispute is not solely about an AI feature’s utility: it is about whether users can rely on Microsoft’s local-only processing assurances when sensitive activity is collected by default. That gap turned the initial Recall announcement into a test of Windows consent and security design.
First-order effects
- Windows users and prospective Copilot+ PC buyers face a new privacy trade-off: a searchable activity history can expose credentials, financial details, and private communications if local protections fail.
- Microsoft’s assurances are weakened by reports that Recall data is held in an accessible local SQLite database and by tools that can extract it, making the feature an immediate reputational liability.
Second-order effects
- Microsoft must devote launch and product-design effort to demonstrating meaningful consent, authentication, encryption, and data-exposure safeguards rather than treating Recall as a straightforward Copilot+ differentiator.
- Security researchers and enterprise IT teams gain a concrete new endpoint-risk surface to audit, while rival PC and operating-system vendors can position less persistent data collection as a trust advantage.
Third-order effects
- If on-device AI increasingly depends on comprehensive personal context, privacy controls and tamper resistance will become product-adoption requirements rather than secondary compliance features.
- The episode suggests that vendors’ accumulated trust record can constrain deployment of ambient AI: technically local processing may not overcome skepticism unless users can verify collection and access boundaries.
The trend: Consumer AI is shifting from discrete prompts toward persistent, device-level context collection, making user trust and local security architecture central competitive constraints.