Microsoft's Windows Recall feature is coming back in October
ghacks.net
ghacks.net
Even then, we're still talking about a perfect surveillance engine that allows any future person to observe your behaviour across your past. Imagine what it would mean for the police to retroactively search your entire life for the past 30 days when they arrest someone. Or how this might affect people living with abusive partners, or LGBTQ+ kids in non-supportive households.
This technology, no matter the implementation, puts vulnerable people at risk.
steal their browser data. i haven't wiped my browser history in years, and that is just easy to search list of URLs dont need to be parsed out of some db blob (not something many anti-LGBTQ parents know how to / are going to do...). Steal their cookies and access their logged in social media accounts directly. Steal their saved passwords. Browse through the cached images and videos.
> Even then, we're still talking about a perfect surveillance engine
not even close. not going to beat this to a pulp but just to give you an idea, this does not scale well, not at all. are you going to look through 25 gb of photos? what if it's 90% cat pictures.
Now contrast that with a 100% legal and already preinstalled keylogger 2.0, which is not only logging keypresses but everything. And it is on every home and work PC in the world. Of course the number of people tempted to use it to spy on the strangers will be about a 1000 times bigger than amount of people installing keyloggers today. And it will not only replace premediated planned spying, similar to the keylogger. But it will also allow spontaneous spying on every random PC you can see. Like walking past unattended unlocked PC and voila - you can check all history without going back in time to install keylogger in advance.
The scale of the problem is the real problem. That's the point.
If the parent has access to the computer, then they'll generally already have all documents, browser/application history, and chat logs.
> Now contrast that with a 100% legal and already preinstalled keylogger 2.0, which is not only logging keypresses
Windows Recall doesn't log keypresses, to my understanding.
> Like walking past unattended unlocked PC and voila - you can check all history without going back in time to install keylogger in advance.
I feel extracting browser passwords and all their documents would typically be more damaging.
Passwords give you control - not just view-only access. You could transfer over much of what they own (money, servers, games, projects, ...) to yourself, use their identity for phishing their friends/colleagues, etc.
Even just for viewing data, I think having all files and passwords can be a greater level of invasion:
* You don't just have screenshots of some files they happened to open recently on this device (which for some formats, like audio, is useless) - you have every file they have saved on this device, every file they have in online/cloud storage, and every file on work network shares they have access to
* You don't just have a screenshot of them typing a subset of recent emails and chat messages - you have their full emails and chatlogs going back years, and can likely make a data access request to get a significantly larger portion of "everything done with the account" than recent snapshots would give you
* You don't just have their location the couple of times recent snapshots show Google Maps open - you have full location history from their phone
It should also be opt out by default for Microsoft.
I personally see a lot of use for this if it was running entirely local. I always find myself in a position where there's things which I've browsed or come across but it's difficult retrieving it from my history.
Vulnerable people often do not have a choice in the matter. Pre-installed, widely-advertised features are significantly more dangerous because somebody who is controlling isn't necessarily thinking of new ways to monitor, but they'll sure take advantage of any they know about.
It's the same problem as Apple's AirTags: GPS trackers existed long before them (and are harder to detect), but you can get a 4-pack of AirTags at the store and they're super easy to use.
As long as this impossibility is achieved, we’re good!
No matter what 'guarantees' they offer, they're just an update and group policy setting away from removing them. Maybe they'll offer 'Recall Enterprise' for company owners, and normalize employers spying on their users while selling them the sales pitch of automating away their employees.
If it was a genuine value add, it would be a boxed product, possibly made by a third party, that people would pay money for.
Is it? I thought the screenshots were stored and analyzed locally. This seems like something that can be verified with Wireshark.
If you mean they could sneaikily update Windows in the future to start sending screenshots to their server - I feel they could do that regardless of whether or not this local search tool exists, and it'd still get caught almost immediately. If anything, it'd seem counter-intuitive to draw lots of attention/scrutiny through marketing this feature.
First, they store it locally - then they merge it to your Microsoft account so you can have the Copilot experience anywhere you go, but they are deeply concerned about your privacy.
Then they start processing it, and voila - they have the AI to replace you.
I'm sure they have plans to undertake these steps, each one innocuous enough to not warrant reaction, but they'll nickel and dime you down, and they'll do it too. If they overreach and there's pushback they'll split the steps into two. Hide it, schmooze the regulators etc.
The plan is in motion the only question is the timetable. I bet those GPU farms will be churning using those screenshots come a year or so.
Would you be willing to make a monetary bet with me, to be resolved 2026-08-23?
I'm curious if you yourself would view the event as a big deal if your data had been sent or if you would simply take the "life is short, who gives a shit?" scenic route.
If you read the article, you would see that the earliest release date for standard Windows versions is planned for early 2025, so you're even kinda baiting the parent from a position of cowardice -- a good faith opening bet would suggest Feb 2026 for the date at the least:)
Depends a lot on the criteria that torginus and I agree on (if we do). I believe the given scenario itself, Microsoft issuing an update that breaks their guarantee by exfiltrating your snapshots for training their LLMs/etc., is very unlikely. But torginus may argue it's something Microsoft are likely to do in secret and successfully lie about such that lack of admission/evidence is not sufficient to determine it hasn't happened, so the criteria may need to be something weaker about Microsoft having made changes that make it in theory possible for them to be secretly training LLMs on the snapshots (e.g: setting them to store unencrypted in OneDrive).
> I'm curious if you yourself would view the event as a big deal if your data had been sent or if you would simply take the "life is short, who gives a shit?" scenic route.
I think training generative AI on private data would be a huge violation and a big deal. There's the chance of exact regurgitation (bank account details, passwords, API keys), but even without that it's pretty much inherently teaching the model things it should not know and would now be able to talk about.
> If you read the article, you would see that the earliest release date for standard Windows versions is planned for early 2025, so you're even kinda baiting the parent from a position of cowardice -- a good faith opening bet would suggest Feb 2026 for the date at the least:)
Not entirely sure what you mean - the date I proposed (2026-08-23) is a full two years from now. Even from the launch of Windows Recall on non-Copilot+ PCs, if that's what we're measuring from, it should give more than "a year or so".
My bad, I could have sworn I read 2025-08-23.
>I think training generative AI on private data would be a huge violation and a big deal.
Just to be clear, I think a local LLM user input leak is by itself a big enough deal before getting into using it as training data for a public MS LLM. The former is getting hit by a car, the latter is getting hit by a train depending on how bad a "mixer" the public LLM being trained is.
I would take a $100 bet that has me winning if there is a data leak or shown to accessible by a third party or a case where it has been used as training data by 2026-08-23 provided it's released by Jan 2025.
That would be fine, as long as the employees are told ahead of time and is part of their employment contract (which i assume would be, because software such as crowdstrike already would be just as nominally intrusive).
As for non-enterprise windows users, this should be at best an opt-in feature. Otherwise, it would be a huge breach of privacy.
No.
Even if it's built in a fully-local, privacy-first manner, I have no confidence it will stay that way.
Microsoft has shown itself again and again to prioritize turning Windows into an ad platform, over sound technical decisions.
Why would this be any different?
I could be ignorant. I could be paranoid. I could be wrong. I want to be wrong.
But I don't think I am. And you aren't either. That's what's scary.
And when this feature exists on all machines, and Microsoft has access to the codebase, you don't think other portions of the company will pitch a "+X revenue if we just used it for Y" re-use of the existing data?
Most of Google and Apple's recent user-hostile decisions can be traced directly back to too much potential revenue to refuse (ad tracking data, app store lock-in). Microsoft isn't immune to those same strategic marketing pressures.
Some data is too tempting to use for evil, that the only sane approach is to ensure there's no centralized manner to access it at scale.
Most people use them, some heavy privacy/security oriented people don't. Even many of those of us who are conscious about the security/privacy issues, use them because we find their use outweighs the risk.
I can't answer what will happen with a recall type feature, but one has to weigh the value vs risk.
Personally, I'm not sure of the significant value (then again, in being really analytical, I'm now unsure of the significant value of the browser history). How often is one going to dig into recall recorded state.
This same logic applies to browser history, how often does on really look at it? It provides 2 forms of value, 1) showing what you already clicked (i.e. a constant low level value) and 2) being able to find URLs you know you saw, but can't seem to find at the moment (a higher value, but much rarer, similar to recall value). Are these valuable enough?
I'm wondering out loud if the first value (of showing links you already visited) could be solved in a more privacy friendly manner of a 1 way hash of url with salt. Store the hashed URLs instead of a the URL string itself. Even if an attacker vacuums up your "history database", all they get is a bunch of hashes. Even if they get the salt, they would have to hash their entire dictionary of URLs against the salt. (A counter argument is that the set of URLs in the dictionary they would want to hash against to blackmail you, might not be "so big" and hence tractable, so this doesn't gain you much).
Does that mean we should not care about our data, and expose every bit and piece to the system? Should we max out data exposure, or still fight against it?
1) I said that users care about the benfits provided to them more than the security/privacy they give up and can see that from practical history.
2) I questioned the value of recall and asked is what one gives up worth that value
3) I compared to browser history and even provided a mechanism to get some of the value without giving up privacy.
ex: they exploit the browser to get to your userspace, which while they can access / modify your files, they can't elevate it to root to make the exploit more persistent. Therefore, they just vacuum up what they can at that moment (not even analyzing it, that's for later, this is just the collection phase) and move onto someone else.
But yes, I agree with you, if one's more concerned about the possibility of offline attacks, there are other ways to mitigate it / you have bigger problems if those mitigations fail.
Right?
Are all of those things you said, and do, readily available in one easy to siphon up database? Easily searchable and reportable to nation state entities? Can I or LEOs read your Hacker News posts and comments, and easily determine exactly who you are and that your previously open tabs where porn and anarchy related websites?
No. RECALL is a damn privacy and security nightmare. Don't act like it's saving the world, it's intent is to close the walls in around you.
Not directly but in combination to other information it could.
The fact is, these kind of recording tools are not meant to publish your information to everyone.
> Don't act like it's saving the world,
I am not acting like that. I have no plan to use RECALL (I don't even use a single windows computer) nor any similar software.
However I find it funny that in any news about RECALL you see so many "privacy nightmare, will someone think of the children" comments while similar open source or proprietary projects for MacOs and Linux, or browser extensions predating RECALL were unanimously praised for their usefulness.
As any tool, you have to balance the risk of a leak in case your systems (or those that host your data) are compromised but it isn't in any way different than any other data you have online or locally on your computer.
You have as much if not much more to lose if your primary email account is compromised and you kept received email in the mailbox.
its an attempt by microsoft to flex about their new "AI PC" which just means it comes with this npu that is optimized for the processing workloads associated with various ai usecases. an attempt to profit on the AI hype by pitching their users reason to buy a new computer.
Nobody is using the AI components on these devices yet, but I've heard plenty of stories from developers with MacBooks about how nice it is to have NPU acceleration for whatever models they're running. I've got Jetbrains' offline AI code suggestions enabled and I imagine widespread availability of NPUs would save a lot of random CPU usage spikes for that kind of workload.
General consumers probably don't get much out of AI (the models if any value are too big to run on these small client machines) but I can't say I'd hate a world where NPUs are cheap and abundant.
Personally I have no memex alike, but I use versioned org-mode notes for anything, meaning my NixOS boot into EXWM with the daily note opened and that note is partially auto-generated to summarize things I might want to see in a single place, NixOS config itself as Emacs config are org-mode notes as well, so it's a kind of full-text-searcheable base with history as well. I've not automated things like Firefox places.sqlite and other data source simply because it's too long to being worth the effort and way to specific and might change "suddenly" following upstream decisions, but essentially that's enough for my needs and I've chosen daily notes model for a reason: I still generate too much "noise" to keep an useful and clean note-base. Chronological division allow to keep the noise "might be useful in future" without polluting too much, collecting screnshots like Recall it's definitively way too much for personal usage, while might be a nice mine of behavioral data for deep analysis on someone else CPU and storage...
Now that I know it's possible, I still cannot think of a valid use case for me.
Recall is just screenshots too; no audio. If we thought we needed to go back and scrutinize what someone said, we'd record the interview, but we don't.
As we saw in the recent US v Google decision experts are teaching courts and the public that pre-installation and "default settings" are in effect a means of control.
In theory, any software or "feature" is a "good idea" as long as no one is forced or tricked into installing or using it. In practice, so-called "tech" companies strategically pre-install and remove or obfuscate consumer choice.
By definition, it's not only you who can recall what happened a month ago, it's also the cops, burglars, your partners, your children... everyone with access to your machine now has access to everything you did.
This will probably happen soon, but I wonder what are the disk space requirements for saving screenshots of everything you do
I think it got shipped a bit hastily, but also dont think hackers will find it more attractive than dropping keyloggers, banking trojans, or ransomware. And screenshots can be photoshopped, so I don't know, I really doubt anyone will care to flip through 25 gb of screenshots.
Also, I'd be interested in a feature like this enabled while interviewing candidates as well as interviewing with potential employers, or while taking courses online, probably a lot of stuff ive not yet thought about too.
If anything, I think employers are more likely to opt out of Recall because of security fears and cost of hardware rather than replace existing device management tools with this
Windows is already a privacy farce. The OS and 3rd party drivers capture a large chunk of what you do. Imagine having everything you do in one tidy location that can and will be used against you at the drop of a hat.
And Windows suffers from that.
No thanks.
Linux so easy your mamas can use it. No seriously, works out of the box. Microsoft aint gonna be screenshottin' NOBODIES SCREEN. Shady ass company. After that Crowdstrike stuff, this is some monopolistic act of terrorism.
6 CVEs, two notably: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38193 and https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
One being where North Korea can take over ring0 entirely? Don't see this AI snapshot stuff ending badly at all, no sir-e!
Linux for days.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-20... - the mitre.org link in my original comment.
I pay attention to all the CVEs daily (or as much as I can). the other one is something found in IPv6 by a research group that allows root level remote code execution by exploiting IPv6 packets, but what I'm getting at is, Windows I'll be trusting, absolutely not if it's going to be playing with this 'Recall' thing.
I'm pro-privacy and I highly feel this Recall system opens up a new attack/exploit vector in new unprecedented ways that I don't even want to begin to imagine. I mean, it reads your screen and recalls everything you've ever done..
Torrent files, pretty much anything. It's not that scary at the moment.
Browsers can do it now. It's an age old 'feature' -> https://github.com/garywill/LAN-port-scan-forbidder
uBlock apparently blocks your browser from reaching out to your LAN though, but; no 'sandbox escapes' needed, just javascript being loaded.
Our browsers could have been exploiting things behind NAT this entire time. Smart TVs, Smart watches, phones, anything pingable on your LAN.
Go here and see it in action: http://samy.pl/webscan/
Maybe if they’re running an HTTP server (which isn’t too uncommon for IoT devices) while allowing the attacker website via CORS (less likely). An IoT device listening for WebSocket or WebRTC connections won’t benefit from CORS, but those are relatively rare and ought to have other mitigations in place.
All your links show is the ability to scan ports, not even read the responses to the fetch() requests made to local IP addresses. That could be useful to an attacker, but a far cry from exploiting any smart device or having the ability to send “outgoing crafted packets” from the browser. You cannot even open arbitrary sockets or craft arbitrary HTTP requests.
Meanwhile, in reality, it's easier than ever to be MS-free, thanks to the rise of web-based applications. There's lots of alternatives to MS Office, including MS's own Office365 online, as well as Google docs, LibreOffice, and others. Most users just use their computers for web browsing anyway, and that can be done on any computer. 20+ years ago, people had much better excuses, because most software was run locally, so if they used some proprietary Windows-only application, they were basically stuck unless they could get it running in WINE, but those days are mostly gone.
But people want to stick with what they know (even though it's actually constantly changing with every new Windows version), so they'll put up with whatever crap MS wants to put in Windows: spyware, ads, etc.
Of course, some people are rebelling and leaving Windows, as we saw in the recent article about Linux desktop usage being at an all-time high, but it's still only about 5%, though that's a lot better than 20 years ago.
But Linux isn’t a greener pasture for the only thing I use windows for. For the things in which it is, I already use Linux or other non windows based operating systems.
I assume you’re talking about “non IT” people though I suppose who may only be able to facilitate the usage of one operating system at a time.
I call it the "GMail Searchification Effect", that heavily focuses on "The Experience", is driven more by the UX and marketing teams rather than the technical team.
They implement the features with no real configuration, no interoperability, no local options, no way to point to another server implementation, etc. Probably no way to script it, either.
and already developer apis for interop.. https://learn.microsoft.com/en-us/windows/ai/apis/recall
Thanks for the links and the info, but I still believe it'll pan out in a very specific way. Time will tell I guess.
More discussion: https://news.ycombinator.com/item?id=41321911
Yeah, maybe recall data are stored locally. Windows accounts were always local some time ago. Remember. A frog is boiled slowly.