By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
AIComputingMicrosoftSecurityTech

Microsoft’s new Recall feature promises search perfection, but experts warn it’s a security nightmare

Recall lets you search your entire digital life, but Microsoft's implementation could compromise security and privacy by storing screenshots and transcripts in a vulnerable plain text database.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Jun 4, 2024, 7:54 AM EDT
Share
Microsoft Recall AI explorer feature
Image: Microsoft
SHARE

Microsoft is on the verge of launching a controversial new feature called Recall. This AI-powered tool for Copilot Plus PCs, set for release on June 18th, has cybersecurity experts worried. They warn Recall could be a major security risk.

Related /

  • Recall: the AI-powered time machine for your PC
  • Microsoft announces Copilot Plus PCs with AI chips and GPT-4 support

How Ai-powered Recall feature works

Recall utilizes local AI to capture screenshots of everything you do on your PC. These screenshots are then searchable, allowing you to find anything you’ve seen on your computer in seconds. It even offers a visual timeline for easy exploration. Microsoft emphasizes that everything with Recall stays on your device, and no data is used to train their AI models on external servers.

Security concerns raised

Despite Microsoft’s assurances of a secure and encrypted experience, cybersecurity expert Kevin Beaumont identified potential security flaws. Beaumont, who previously worked for Microsoft, discovered that Recall stores data in an unencrypted, plain text database. This raises concerns that malware could easily exploit this vulnerability to steal the database and its contents.

https://twitter.com/GossiTheDog/status/1796218726808748367

“Every few seconds, screenshots are taken,” Beaumont explained in a detailed blog post. “These are turned into text using optical character recognition (OCR) by Azure AI running locally on your device. The resulting text is then stored in a plain text SQLite database within the user’s folder. This database essentially contains a record of everything you’ve ever done on your PC.”

Beaumont provided evidence on X (formerly Twitter), criticizing Microsoft for misleading media outlets about the possibility of hackers remotely stealing Recall data. While the database is stored locally, it’s accessible from the AppData folder for anyone with administrator privileges. Beaumont argues that the database can even be accessed by non-admins, a claim corroborated by two Microsoft engineers at a recent conference.

The primary concern is that Recall makes it much easier for malware and attackers to steal information. Malware already exists that targets PCs to steal login credentials and other sensitive data. “With Recall, attackers can automate the process of stealing everything you’ve ever looked at on your computer, all within seconds,” warns Beaumont.

Beaumont even went a step further, extracting his own Recall database and creating a website where users can upload their databases for instant search. However, he’s withholding technical details to give Microsoft time to address the security issues before the feature launches.

Privacy concerns and backlash

The announcement of Recall has been met with swift criticism. Privacy advocates have labeled it a potential “privacy nightmare,” and the UK’s Information Commissioner’s Office has begun investigating Microsoft’s use of this AI-powered feature.

Microsoft maintains that Recall is an optional feature with built-in privacy controls. Users can choose to exclude specific URLs and applications, and Recall won’t store any information protected by digital rights management (DRM) tools. Additionally, Microsoft clarifies that Recall doesn’t take screenshots during private browsing sessions in various web browsers.

However, a major concern remains: Recall doesn’t filter content, meaning it won’t hide sensitive information like passwords or financial account numbers captured in screenshots. “This data may be stored in the screenshots on your device, especially when websites don’t use proper security protocols like masking password entry fields,” warns Microsoft.

Noticeably absent from Microsoft’s explanation is how they plan to address the potential for malware to steal the Recall database. They emphasize that Recall data is stored on the local hard drive of Copilot Plus PCs and is protected using disk encryption and BitLocker (on Windows 11 Pro and enterprise versions).

Beaumont argues that disk encryption has limitations. “Encryption only works in specific situations,” he explains. “When you’re logged in and using your PC, the data needs to be decrypted for you to access it. Encryption at rest only protects your data if someone physically steals your laptop. That’s not how cybercriminals operate.”

The road ahead for Recall

Microsoft may be forced to rework, or even recall (pun intended), the Recall feature. The way data is stored has clear vulnerabilities that require immediate attention. Additionally, making Recall an opt-out feature raises concerns among privacy advocates. This launch comes just weeks after Microsoft CEO Satya Nadella stressed security as the company’s “top priority,” even if it means sacrificing new features.

“If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” said Nadella. “In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.”

Whether Microsoft can address these concerns and ensure Recall lives up to its promises of security and privacy remains to be seen.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Topic:LaptopMicrosoft CopilotWindows 11
Most Popular

Perplexity Computer is now inside Microsoft Teams

Apple gives up on Vision Pro after M5 refresh fails

Google Docs now lets you set custom instructions for Gemini

Google Workspace now has a central hub to control all AI and agent access

Apple’s rumored 32-inch iMac Ultra sounds absolutely wild

Also Read
Perplexity illustration. Abstract illustration of a transparent glass cube refracting beams of light into rainbow-like streaks across a dark, textured surface, symbolizing clarity, synthesis, and the convergence of multiple perspectives.

Perplexity Agent API now ships with Finance Search for structured financial insight

Apple showing off Siri’s updated logo at WWDC 2024.

Apple faces $250 million payout after overselling AI Siri on iPhone 16

The OpenAI logo displayed in white against a deep blue gradient background. The logo consists of a stylized hexagonal geometric shape resembling an interlocking pattern or aperture on the left, paired with the text "OpenAI" in a clean, modern font on the right. The background features subtle lighting effects with darker edges and a brighter blue glow in the upper right corner, creating a professional and technological atmosphere.

OpenAI’s rumored ChatGPT phone targets 2027 launch window

Minimal promotional graphic featuring the text “GPT-5.5 Instant” centered inside a rounded white rectangle, set against a soft abstract background with blurred pastel gradients in pink, purple, orange, and blue tones.

GPT-5.5 Instant replaces GPT-5.3 as OpenAI’s everyday ChatGPT model

Promotional interface mockup for Perplexity Computer focused on professional finance workflows, showing an “NVDA Post Earnings Impact Memo” with financial tables, charts, and analysis sections alongside a task panel requesting an AI-generated NVIDIA earnings summary with market insights and semiconductor industry implications.

Perplexity launches Computer for Professional Finance

Abstract 3D illustration of a flowing metallic ribbon with reflective gold and silver surfaces, curved in a wave-like shape against a dark background with bright light reflections and glossy highlights.

Perplexity health search gets a major upgrade with Premium Sources

Illustration of Google Chrome enhanced autofill showing three side-by-side form examples for loyalty card numbers, vehicle license plates, and travel confirmation numbers. Each input field displays a dropdown suggestion card with saved information and management options against a blue background.

Google Chrome’s enhanced autofill completely changes how you fill out tedious online forms

Close-up of the Google Drive webpage showing the Drive logo, the heading “Drive,” and text about storing, accessing, and sharing files, with a “Get started” button visible.

Google Drive API now supports large-scale CSE file migrations

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.

Advertisement
Amazon Summer Beauty Event 2026