Microsoft Recall caught capturing credit card and Social Security numbers despite reassurances it won't

The Windows Rec
(Image credit: Tom's Guide/Microsoft)

Since its announcement in June, Microsoft's Windows Recall feature has been controversial and bumpy for a few months. It faced immediate backlash over security concerns when it was revealed. The concern was mainly around the fact that Recall takes screenshots of your entire PC so that you can find information later if desired.

The AI tool for Copilot + Pilots was recalled so Microsoft could tweak the program and work on the security issues. Since then, it's been delayed several times, and only recently became available for Windows Insiders, Microsoft's version of beta testers for early adopters.

"We’ve updated Recall to detect sensitive information like credit card details, passwords, and personal identification numbers. When detected, Recall won’t save or store those snapshots. We’ll continue to improve this functionality, and if you find sensitive information that should be filtered out for your context, language, or geography, please let us know through Feedback Hub. We’ve also provided an option in Settings that we encourage you to enable that will anonymously share the apps and sites you prefer to be excluded from Recall to help us improve the product."

What does Recall actually do?

Since few people have been able to try out Recall, here's a brief rundown of what the feature is supposed to do for you.

Microsoft pitches the tool to help you find things better by searching your PC for anything you've seen on it using natural language.

To do this, Recall takes "snapshots" of your screen at regular intervals, which are stored locally on your computer and analyzed and indexed by AI.

The obvious concern here is that this digital record of everything on your PC and things you've done on your PC can potentially be accessed by bad actors. When Recall first appeared in the spring, it didn't even have encryption on the snapshots, and the database was stored as plain text. Those things have changed in the past few months.

Microsoft has also made Recall opt-in, which was previously an opt-out option.

The new Recall does have the mentioned filter and appears to encrypt data. Login also requires biometric data and passwords. And information can only be viewed in the Recall app.

That said, a determined bad actor with access to your password or PIN could bypass the biometric checks. And you can view the Recall app via TeamViewer, which allows for popular remote access.

For now, if the filter isn't working, it means your data is being captured and that a series of missteps could make that information available to a bad actor.

More from Tom's Guide

Category
Arrow
Arrow
Back to Gaming Laptops
Brand
Arrow
RAM
Arrow
Storage Size
Arrow
Price
Arrow
Any Price
Showing 9 of 9 deals
Filters
Arrow
(15.6-inch 512GB)
Our Review
1
MSI Cyborg 15 15.6” 144Hz FHD...
Amazon
Low Stock
(1TB SSD)
Our Review
3
Cyborg 15 AI A1VFK-060CA...
Walmart
(15.6-inch 1TB)
Our Review
4
Msi Cyborg 15 15.6" Gaming...
Macy's
Our Review
5
MSI Cyborg 15 - 15.6' 144Hz...
Sam's Club US
(512GB)
Our Review
6
MSI Cyborg 15 A13VE 218US...
HSN
(15.6-inch 1TB)
Our Review
7
MSI Cyborg 15 Gaming Laptop,...
Amazon
(15.6-inch 1TB)
Our Review
8
Msi Computers 15.6" Cyborg 15...
Macy's
(15.6-inch 1TB)
Our Review
9
MSI Cyborg 15 A13VF 1278US...
HSN
Scott Younker
West Coast Reporter

Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the lastest tech news. He’s been involved in tech since 2011 at various outlets and is on an ongoing hunt to build the easiest to use home media system. When not writing about the latest devices, you are more than welcome to discuss board games or disc golf with him. He also handles all the Connections coverage on Tom's Guide and has been playing the addictive NYT game since it released.