Microsoft describes Recall's new security features, says the feature is opt-in
After a major PR blunder, Microsoft is detailing its Recall's new security model.
Microsoft is set to bring back Recall, the Copilot+ feature it, well, recalled back in June just before its release due to security concerns and negative feedback. Today, the company released a detailed blog post authored by president, OS security and enterprise David Weston explaining all of the security-based changes that it made to Recall. The blog post doesn't list a specific release date for the feature, but Microsoft previously said Insiders would see Recall come back in October.
Weston reiterated that Recall "is an opt-in experience" that you decide on when first setting up a Copilot+ PC. "If a user doesn't proactively choose to turn it on, it will be off, and snapshots will not be taken or saved," he wrote. "Users can also remove recall entirely by using the optional features settings in Windows." (This is seemingly a reversal of what Microsoft said earlier this month when Recall was found in a list of features you could disable.)
The snapshots that Recall takes will be encrypted with the Trusted Platform Module and tied to your account through Windows Hello. Weston states that the snapshots "can only be used by operations within a secure environment called a Virtualization-based security Enclave (VBS Enclave)," which prevents other users on your PCs from decrypting and seeing your information. The only data that ever leaves the enclave is what you specifically request while using Recall.
Recall is also using Windows Hello as authorization to change settings, with your Windows PIN as a fallback measure in case your camera or fingerprint reader is damaged. Microsoft says Recall will prevent malware attacks with "rate-limiting and anti-hammering measures."
Not all of this is brand new, however. Some of it has been previously detailed in previous blog posts.
VBS Enclaves, Biometrics, and Privacy Controls
The VBS Enclave is the key to Microsoft's security approach for Recall, which Weston describes as a "locked box" that uses Windows Hello authorization as the key, and serves as an "isolation boundary" from both users with administrative privileges and the Windows kernel. This means that you need to have biometrics enabled in order to use Recall, and you'll need to repeatedly use it as the authorization will expire.
Weston reiterated that Recall only takes snapshots when you have turned the feature on, and that the data isn't shared with Microsoft or third party companies.
"You are always in control, and you can delete snapshots, pause, or turn them off at any time," Weston wrote. "Any future options for the user to share data will require fully informed explicit action by the user."
Weston also shared a list of customization tools that you can use to adjust what gets saved for you in Recall:
- In-private browsing in supported browsers is never saved
- Users can filter out specific apps or websites viewed in supported browsers
- Users can control how long Recall content is retained and how much disk space is
- allocated to snapshots
- Sensitive content filtering is on by default and helps reduce passwords, national ID
- numbers, and credit card numbers from being stored in Recall. The same library powers Microsoft’s Purview information protection product which is deployed in enterprises globally.
- Find something you didn’t mean to save? You can delete a time range, all content from an app or website, or anything and everything found in Recall search.
- An icon in the system tray will help you know when snapshots are being saved and makes it easy to quickly pause saving snapshots.
He also notes, however, that some diagnostic data may end up going back to Microsoft based on settings, "like any Windows feature."
MIcrosoft detailed three sets of tests and assessments, some of which sound like they will be ongoing, for Recall's security. They include Microsoft's Offensive Research and Security Engineering team working on "months" of penetration testing and reviews, as well as working with an unnamed third-party security company and a "Responsible AI Impact Assessment."
Can Recall win hearts and minds?
It isn't yet clear when Recall will get a wide rollout, but considering the strong messaging from Microsoft and Weston, I do wonder if it will be soon.
The initial Recall announcement was met with surprise, especially among the security community. It may not be until the new Recall is inspected by the same people who met it with such shock that people using Windows start to trust it — or they try it and find out whether or not they think it's useful.
But for now, it's good to see Microsoft being transparent about chances — and that it's making Recall optional for those who are still wary about the AI feature.
Stay On the Cutting Edge: Get the Tom's Hardware Newsletter
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.
Andrew E. Freedman is a senior editor at Tom's Hardware focusing on laptops, desktops and gaming. He also keeps up with the latest news. A lover of all things gaming and tech, his previous work has shown up in Tom's Guide, Laptop Mag, Kotaku, PCMag and Complex, among others. Follow him on Threads @FreedmanAE and Mastodon @FreedmanAE.mastodon.social.
-
USAFRet Q to Microsoft - Who asked for this insane level of "undo"?Reply
I'm expecting that to be 'no one'.
This came about from the brain of a couple of devs. "Hey, it would be neat if we added this!"
Then, Marketing ran with it.
I know people like that. I work with people like that. I despise people like that. -
RichardtST Well sure. It's all optional NOW. But we know how that goes... It will be mandatory in 5 years or less. Guaranteed.Reply -
palladin9479 USAFRet said:Q to Microsoft - Who asked for this insane level of "undo"?
I'm expecting that to be 'no one'.
This came about from the brain of a couple of devs. "Hey, it would be neat if we added this!"
Then, Marketing ran with it.
I know people like that. I work with people like that. I despise people like that.
I'm positive the answer to that question is "various governments" and all those security / privacy measures are just smoke screens because those same governments will have access reguardless.
As the average computer user becomes more educated on basic information security and privacy, governments have an even stronger incentive to bypass those security and privacy. -
Giroro "Don't worry, the data will be tied to your real identity through your Microsoft Account, and absolutely nobody will be able to access your data except us, our employees, our contractors, and local/international law enforcement"Reply
-Executive in charge of selling user data to anybody who wants it
But really though, the part where Microsoft says its optional and can be removed absolutely cannot be trusted. I'm sure we've all suffered through Windows updates that have done nothing except reinstall disabled features, run unclosable ads for Microsoft products features, or tried to set the edge browser back to default. Not to mention they continue to retroactively change their Terms of Use in ways that drastically affect your legal rights on a monthly basis. -
Sluggotg "He also notes, however, that some diagnostic data may end up going back to Microsoft based on settings, "like any Windows feature.""Reply
Of course Microsoft would never sell any "Diagnostic Data" to third parties for "Quality Assurance" Purposes. We all know it will become mandatory and third parties will get access to our screen shots. What is the upside for consumers? It looks like a plan for Microsoft to create a vast data base of information on Windows users that they can sell to Vendors as the most detailed database of Windows User's habits, hobbies, friends, relatives, politics, spending etc.
I do screen shots in World of Warcraft. I don't do them when I am accessing my retirement accounts, paying bills etc. -
hotaru251 if it exists even as opt in theres going to be bad actors who can make it work for them as a spy tool.Reply -
kyzarvs I don't want to be that guy - but the formatting on that bullet point list should never have been published on a 'professional' site - almost every bullet is in the wrong place.Reply