Microsoft Recall screenshots credit cards and Social Security numbers, even with the "sensitive information" filter enabled

Computer with recall
(Image credit: Shutterstock (1025458759))

Microsoft’s Recall feature recently made its way back to Windows Insiders after having been pulled from test builds back in June, due to security and privacy concerns. The new version of Recall encrypts the screens it captures and, by default, it has a “Filter sensitive information,” setting enabled, which is supposed to prevent it from recording any app or website that is showing credit card numbers, social security numbers, or other important financial / personal info. In my tests, however, this filter only worked in some situations (on two e-commerce sites), leaving a gaping hole in the protection it promises.

When I entered a credit card number and a random username / password into a Windows Notepad window, Recall captured it, despite the fact that I had text such as “Capital One Visa” right next to the numbers. Similarly, when I filled out a loan application PDF in Microsoft Edge, entering a social security number, name and DOB, Recall captured that. Note that all info in these screenshots is made up, but I also tested with an actual credit card number of mine and the results were the same.

Latest Videos FromTom's Hardware
Avram Piltch
Managing Editor: Special Projects

Avram Piltch is Managing Editor: Special Projects. When he's not playing with the latest gadgets at work or putting on VR helmets at trade shows, you'll find him rooting his phone, taking apart his PC, or coding plugins. With his technical knowledge and passion for testing, Avram developed many real-world benchmarks, including our laptop battery test.

  • ezst036
    A feature nobody wanted anyways, and were furious about it initially that it had to be canned for a period.

    But Microsoft continues to have a terrible abusive relationship with its customers. It's what Microsoft wants, not what the customer wants.
    Reply
  • hotaru251
    again this type of "tracking" should literally be illegal to even WANT to implement.

    There is no benefit in storing that info on a digital device. If there is even chance it could get recorded should be immediate reason to block it from being used further.
    Reply
  • JamesJones44
    Not surprising that an ML model has difficulty detecting sensitive areas based on capturing a random image. IMO for this to work correctly MS needs apps to populate some kind of metadata that they can associate with an image and location. That way the ML model can use hints in the metadata to understand that an area of the image contains a sensitive field based on the specified HTML tag for example. Without that, this will always be difficult to be accurate with sensitive field detection.
    Reply
  • palladin9479
    ezst036 said:
    A feature nobody wanted anyways, and were furious about it initially that it had to be canned for a period.

    But Microsoft continues to have a terrible abusive relationship with its customers. It's what Microsoft wants, not what the customer wants.

    End users aren't the customers for this "Feature", government agencies are. This is just another way for Microsoft to get paid to spy for various governments.
    Reply
  • DS426
    ezst036 said:
    ...
    But Microsoft continues to have a terrible abusive relationship with its customers. It's what Microsoft wants, not what the customer wants.
    This ^. "Abusive" is actually kind of astute thinking IMO as indeed many "need" or at least rely on Windows and M365 in various ways and appreciate the good aspects (esp. those not found in the Linux or Mac camps), yet MS will give and take as they please with minimal regard to how that changes the quality of life of affected customers.

    The effort that went into developing Recall could have been used elsewhere for much better use -- opportunity cost.
    Reply
  • yahrightthere
    A: Switch to Linux.
    B: I see a class action in MS future.
    Reply
  • hotaru251
    palladin9479 said:
    This is just another way for Microsoft to get paid to spy for various governments.
    like cortana (in early days of WIN10) & rest of their data scalping...users will block block it.
    Reply
  • 8086
    ezst036 said:
    A feature nobody wanted anyways, and were furious about it initially that it had to be canned for a period.

    But Microsoft continues to have a terrible abusive relationship with its customers. It's what Microsoft wants, not what the customer wants.
    Windows 7 was the last time MS ever did anything we wanted and then they took it away from us and every single day now, linux is just looking that much better.
    Reply
  • palladin9479
    hotaru251 said:
    like cortana (in early days of WIN10) & rest of their data scalping...users will block block it.

    Knowledgeable users can and will, those are a minority. The majority of users purchase their computers through OEMs with the OS preinstalled and all these settings left on default, which is maximum collection. Few of those OEM users will then bother with disabling these "features", especially if someone is selling it as somehow beneficial. The result is that government agencies will have access to user screenshots for a large part of the population.
    Reply
  • derekullo
    Microsoft's AI is so advanced that it recognized that you were trying to trick it with fake information!
    Reply