By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
AIComputingMicrosoftSecurityTech

Microsoft’s new Recall feature promises search perfection, but experts warn it’s a security nightmare

Recall lets you search your entire digital life, but Microsoft's implementation could compromise security and privacy by storing screenshots and transcripts in a vulnerable plain text database.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Jun 4, 2024, 7:54 AM EDT
Share
Microsoft Recall AI explorer feature
Image: Microsoft
SHARE

Microsoft is on the verge of launching a controversial new feature called Recall. This AI-powered tool for Copilot Plus PCs, set for release on June 18th, has cybersecurity experts worried. They warn Recall could be a major security risk.

Related /

  • Recall: the AI-powered time machine for your PC
  • Microsoft announces Copilot Plus PCs with AI chips and GPT-4 support

How Ai-powered Recall feature works

Recall utilizes local AI to capture screenshots of everything you do on your PC. These screenshots are then searchable, allowing you to find anything you’ve seen on your computer in seconds. It even offers a visual timeline for easy exploration. Microsoft emphasizes that everything with Recall stays on your device, and no data is used to train their AI models on external servers.

Security concerns raised

Despite Microsoft’s assurances of a secure and encrypted experience, cybersecurity expert Kevin Beaumont identified potential security flaws. Beaumont, who previously worked for Microsoft, discovered that Recall stores data in an unencrypted, plain text database. This raises concerns that malware could easily exploit this vulnerability to steal the database and its contents.

https://twitter.com/GossiTheDog/status/1796218726808748367

“Every few seconds, screenshots are taken,” Beaumont explained in a detailed blog post. “These are turned into text using optical character recognition (OCR) by Azure AI running locally on your device. The resulting text is then stored in a plain text SQLite database within the user’s folder. This database essentially contains a record of everything you’ve ever done on your PC.”

Beaumont provided evidence on X (formerly Twitter), criticizing Microsoft for misleading media outlets about the possibility of hackers remotely stealing Recall data. While the database is stored locally, it’s accessible from the AppData folder for anyone with administrator privileges. Beaumont argues that the database can even be accessed by non-admins, a claim corroborated by two Microsoft engineers at a recent conference.

The primary concern is that Recall makes it much easier for malware and attackers to steal information. Malware already exists that targets PCs to steal login credentials and other sensitive data. “With Recall, attackers can automate the process of stealing everything you’ve ever looked at on your computer, all within seconds,” warns Beaumont.

Beaumont even went a step further, extracting his own Recall database and creating a website where users can upload their databases for instant search. However, he’s withholding technical details to give Microsoft time to address the security issues before the feature launches.

Privacy concerns and backlash

The announcement of Recall has been met with swift criticism. Privacy advocates have labeled it a potential “privacy nightmare,” and the UK’s Information Commissioner’s Office has begun investigating Microsoft’s use of this AI-powered feature.

Microsoft maintains that Recall is an optional feature with built-in privacy controls. Users can choose to exclude specific URLs and applications, and Recall won’t store any information protected by digital rights management (DRM) tools. Additionally, Microsoft clarifies that Recall doesn’t take screenshots during private browsing sessions in various web browsers.

However, a major concern remains: Recall doesn’t filter content, meaning it won’t hide sensitive information like passwords or financial account numbers captured in screenshots. “This data may be stored in the screenshots on your device, especially when websites don’t use proper security protocols like masking password entry fields,” warns Microsoft.

Noticeably absent from Microsoft’s explanation is how they plan to address the potential for malware to steal the Recall database. They emphasize that Recall data is stored on the local hard drive of Copilot Plus PCs and is protected using disk encryption and BitLocker (on Windows 11 Pro and enterprise versions).

Beaumont argues that disk encryption has limitations. “Encryption only works in specific situations,” he explains. “When you’re logged in and using your PC, the data needs to be decrypted for you to access it. Encryption at rest only protects your data if someone physically steals your laptop. That’s not how cybercriminals operate.”

The road ahead for Recall

Microsoft may be forced to rework, or even recall (pun intended), the Recall feature. The way data is stored has clear vulnerabilities that require immediate attention. Additionally, making Recall an opt-out feature raises concerns among privacy advocates. This launch comes just weeks after Microsoft CEO Satya Nadella stressed security as the company’s “top priority,” even if it means sacrificing new features.

“If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” said Nadella. “In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.”

Whether Microsoft can address these concerns and ensure Recall lives up to its promises of security and privacy remains to be seen.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Topic:LaptopMicrosoft CopilotWindows 11
Most Popular

The $19 Apple polishing cloth supports iPhone 17, Air, Pro, and 17e

Apple MacBook Neo: big power, surprising price, one clear target — Windows

Everything Nothing announced on March 5: Headphone (a), Phone (4a), and Phone (4a) Pro

OpenAI’s GPT-5.4 is coming — and it’s sooner than you think

BenQ’s new 5K Mac monitor costs $999 — here’s what you’re getting

Also Read
Close-up of a person holding the Google Pixel 10 Pro Fold in Moonstone gray with both hands, rear-facing triple camera array and Google "G" logo prominently visible, worn against a silver knit top and blue jacket with a poolside background.

Pixel Care+ makes owning a Pixel a lot less scary — here’s why

Woman with blonde curly hair sitting outside in a lush park, holding a blue Google Pixel 10 and smiling at the screen.

Pixel 10a, Pixel 10, Pixel 10 Pro: one winner for every buyer

Google Search AI Mode showing Canvas in action, with a split-screen view of a conversational AI chat on the left and an "EE Opportunity Tracker" scholarship and grant tracking dashboard on the right, displaying a total funding secured amount of $5,000, scholarship cards with deadlines, and status labels including "To Apply" and "Awarded."

Google’s Canvas AI Mode rolls out to everyone in the U.S.

Google NotebookLM app listing on the Apple App Store displayed on an iPhone screen, showing the app icon, tagline "Understand anything," a Get button with In-App Purchases noted, 1.9K ratings, age rating 4+, and a chart ranking of No. 36 in Productivity.

NotebookLM Cinematic Video Overviews are live — here’s what’s new

A Google Messages conversation on an Android phone showing a real-time location sharing card powered by Find Hub and Google Maps, displaying a live map view near San Francisco Botanical Garden with a blue location dot, labeled "Your location – Sharing until 10:30 AM," within a chat about meeting up for coffee.

Google Messages real-time location sharing is here — here’s how it works

Screenshot of the Perplexity Pro interface with the model picker dropdown open, displaying GPT-5.4 labeled as New with the Thinking toggle switched on, and other available models including Sonar, Gemini 3.1 Pro, Claude Sonnet 4.6, Claude Opus 4.6 (Max-only), and Kimi K2.5.

GPT-5.4 is now on Perplexity — here’s what Pro/Max users get

A Microsoft Excel spreadsheet titled "Consumer Full 3 Statement Model" displaying a Balance Sheet in millions of dollars with historical financial data across four years (2020A–2023A), showing line items including cash and equivalents, accounts receivable, inventory, PP&E, goodwill, total assets, accounts payable, current debt maturities, and total liabilities, alongside an open ChatGPT sidebar panel where a user has asked ChatGPT to build an EBITDA-to-free-cash-flow conversion bridge with charts placed on the Balance Sheet tab, and the AI is actively responding by planning the analysis, filling in financing cash rows, and executing multiple actions in real time.

ChatGPT for Excel is here — and it runs on GPT‑5.4

ChatGPT logo and wordmark in white on a soft blue and orange gradient background, representing OpenAI’s ChatGPT platform.

OpenAI’s GPT-5.4 can click, type, and work your PC for you

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.