The initial announcement of the AI feature Recall is a great example of shooting yourself in the foot. When Microsoft announced Recall, it floated on a wave of positive and encouraging AI news and developments.
Recall was never tested in Insider builds prior to the announcement, at least to my knowledge. While the reason for that decision is unknown, it is possible that Microsoft wanted to launch the new Copilot+ PCs with a banger.
Microsoft did not anticipate the criticism that it received after the announcement. These complaints were valid and could have been avoided if Microsoft would have received feedback from beta testers outside the company.
Privacy and security were at the center of the issue. Recall was enabled by default, which meant that users had to disable it, if they did not want to use it. It recorded the screen every 5 seconds and saved the data in a database that was not protected during runtime.
Microsoft pulled Recall shortly thereafter and promised to do better. Today. Microsoft revealed the improved version of Recall on its Windows Experience website.
Has it improved? Lets find out.
Recall Security
Microsoft makes four statements in regards to security:
- Recall is opt-in — The option is shown during the setup experience and users need to enable the feature to use it.
- Recall data is encrypted — Snapshots and information is stored in an encrypted database. Keys are protected using TPM and are linked to the user’s Windows Hello Enhanced Sign-in Security identity.
- A core service is further isolated — Microsoft says that the service responsible for accessing snapshots and data runs in a secure VBS Enclave. Only data that the user requests is getting outside, according to Microsoft.
- Recall uses Windows Hello Enhanced Sign-in Security – This is done to authorize Recall operations.
Particularly interesting is the fact that users may uninstall Recall. Microsoft introduced the option under Optional Features some time ago, then pulled it again saying that it was a bug. Now it turns out that Recall can be uninstalled fully, if the user so desires.
Microsoft addresses main criticisms with the change. Making Recall opt-in will reduce usage, but it ensures that unsuspecting users do not have screenshots of their activity taken every five seconds by the feature.
Recall Privacy
Next to security, Microsoft says that it has also improved privacy controls. Apart from making Recall opt-in, Microsoft highlights the following options to users who choose to enable the AI-feature.
- In-private browsing data is never captured or saved. This is true for supported browsers. Microsoft lists Edge, Chrome, Firefox, Opera and other Chromium-based browsers.
- Specific apps or websites viewed in browsers may be filtered. Works only in Edge, Chrome, Firefox and Opera.
- Users control how much disk space Recall uses and how long content is retained.
- Sensitive content filtering is enabled by default. This helps protect passwords, credit card numbers and the like to a degree.
- Options to delete a time range, or all content from an app or website, or “anything and everything found in Recall search”.
- An icon visualizes when snapshots are saved. Allows to pause snapshots.
Closing Words
Some of the features existed in the first version already. Microsoft has addressed the major points of criticism. While it is too early to tell how this will all work out, as Recall has not been released yet, it is giving users who are interested in the feature more control and better security.
Those who have no interest in the feature can either ignore it, by making sure not to opt-in during setup, or to remove it from the system entirely, if they prefer that.
You can check out the full blog post, which includes many security details, here.
What is your take on the changes? Do they go far enough, or is still something amiss? Feel free to leave a comment down below.