A PR disaster: Microsoft has lost trust with its users, and Windows Recall is the straw that broke the camel's back

Windows Recall
(Image credit: Windows Central)

Recent updates

Update noon ET June 7, 2024: Microsoft has released a statement noting it is making three significant changes to how Recal works including making it opt-in during setup, requiring Windows Hello to enable Recall, proof of presence is now required to view your timeline, and search in Recall, and adding additional layers of data protection including “just in time” decryption protected by Windows Hello Enhanced Sign-in Security (ESS) so that snapshots will only be decrypted and accessible when the user authenticates.


It's a nightmare scenario for Microsoft. The headlining feature of its new Copilot+ PC initiative, which is supposed to drive millions of PC sales over the next couple of years, is under significant fire for being what many say is a major breach of privacy and security on Windows. That feature in question is Windows Recall, a new AI tool designed to remember everything you do on Windows.

On paper, it's a cool idea. As CEO Satya Nadella described it, Windows now has a photographic memory that uses AI to triage and index everything you've ever done on your computer, enabling you to semantically search for things you've seen using natural language. It's a new and improved way of finding things on Windows, and in our testing of the feature, it works really well.

However, for a tool like this to be feasible, trust between the user and the platform is required, a luxury Microsoft doesn't appear to have with its Windows user base right now. Recall operates by taking and storing captures of your screen every few seconds to build a database that the user can later search, with screenshots as visual aids. That database is stored locally on your device and never uploaded to the cloud.

In fact, Microsoft goes so far as to promise that it cannot see the data collected by Windows Recall, that it can't train any of its AI models on your data, and that it definitely can't sell that data to advertisers. All of this is true, but that doesn't mean people believe Microsoft when it says these things. In fact, many have jumped to the conclusion that even if it's true today, it won't be true in the future.

Microsoft eroded user trust on Windows with bad practices that are now biting them back

Microsoft employs some bad practices on Windows 11 to squeeze money out of its users. (Image credit: Microsoft)

Microsoft is fully aware that the concept of Windows Recall sounds creepy. I know that the company spent a lot of time internally figuring out how to communicate this feature to the world, but it turns out there's no good way to communicate something like this when your users don't trust you.

Users are describing the feature as literal spyware or malware, and droves of people are proclaiming they will proudly switch to Linux or Mac in the wake of it. Microsoft simply doesn't enjoy the same benefit of the doubt that other tech giants like Apple may have.

People think Windows Recall is malware or spyware. (Image credit: Windows Central)

Had Apple announced a feature like Recall, there would have been much less backlash, as Apple has done a great job building loyalty and trust with its users, prioritizing polished software experiences, and positioning privacy as a high-level concern for the company.

Microsoft, on the other hand, has done a lot to degrade the Windows user experience over the last few years. Everything from obtrusive advertisements to full-screen popups, ignoring app defaults, forcing a Microsoft Account, and more have eroded the trust relationship between Windows users and Microsoft. 

Here is a list of just some of the practices Microsoft has employed on Windows that users do not like:

While Microsoft has now addressed some of these issues (thanks to the EU forcing its hand), the damage has already been done. It's clear that Microsoft and Apple prioritize their OS platforms in very different ways. Apple ensures its operating systems are clean, polished, and without bloat. Microsoft, on the other hand, views Windows as a platform that should be making money from its users, filling it with ads and bloatware where it can, sometimes at the expense of user choice and OS polish.

It doesn't bode well for a feature like Windows Recall, which relies on complete trust between the user and the platform. If Microsoft considers Windows quality assurance an afterthought, how can it expect people to trust a feature like Windows Recall? 

It's no surprise that users are already assuming that Microsoft will eventually end up collecting that data and using it to shape advertisements for you. That really would be a huge invasion of privacy, and people fully expect Microsoft to do it, and I can't help but feel like it's those bad Windows practices that have led people to this conclusion. 

The concept of Windows Recall comes with risks on an open platform like Windows

Windows Recall data is stored unencrypted, and that's not good. (Image credit: Windows Central)

With Windows being an open platform, a built-in tool designed to collect data about everything you've ever seen is a recipe for disaster. Unlike iOS, iPadOS, and even Android, users and apps have complete access to the entire OS.

While some mitigations exist to ensure users and apps don't mess around with system files on Windows, these can be bypassed. It has been discovered that Windows Recall seemingly stores its data unencrypted, which is a huge security concern for many people. This means that third-party apps could reach in and grab that data to learn everything about you.

Many immediately point to malware, which is certainly a concern. However, even third-party apps that you trust could potentially reach in there to learn about you. Your favorite web browser, video editor, or music streaming app of choice could release an update that begins scraping data from Windows Recall and uploading it to its own backend.

That would, of course, be a huge invasion of privacy, but it would technically be possible, and that's thanks to Windows' open nature and the reported lack of security around stored Windows Recall data. Even your employer could build a tool that's preloaded onto your work laptop that's designed to scrape that data. It's all quite concerning. 

The fact that Windows is an open platform means anyone can do anything if they want to. That's a blessing and a curse, and it means an app like Recall, in an unencrypted state, doesn't really work on Windows currently.

On iOS and iPadOS, users are locked out of important system files, and app developers are sandboxed and have no ability to read or modify system files outside of documented APIs. So, if iPadOS had its own version of Recall, that data could be stored unencrypted and still be safe from third-party attackers. It's the same story on Android. 

Windows enjoys no such luxury, so Microsoft needs to put extra effort into ensuring Windows Recall is secure. It needs to ensure that only the Windows Recall app can read and understand that data. If that data is unencrypted, anyone can read it. Everything it collects is reportedly stored in a plaintext SQLite database, making it easy to parse information from it.

People won't trust Windows Recall regardless of how the data is stored locally.

Windows Recall can't run secretly, as it places a visual indicator on the Taskbar that cannot be removed when it's enabled. (Image credit: Windows Central)

There's quite a bit of hysteria over the discovery that Windows Recall stores data unencrypted. It's important to remember that Windows Recall isn't actually out yet, so Microsoft could update Windows Recall before launch to address this, or perhaps even potentially delay the feature to ensure security.

Assuming Microsoft does eventually fix these security concerns, I don't think that's going to change much for people. Many have already assumed the worst; that Windows Recall will eventually be used as a means to sell data to advertisers and train AI models, and that if it's not happening today, it's only a matter of time.

People think Microsoft are lying about Recall not uploading data to the cloud. (Image credit: Windows Central)

Many are even convinced that Microsoft will attempt to enable Windows Recall on PCs that have chosen not to use it via updates down the line. That's just the sort of company people think Microsoft is like. I think this stems from the fact that people don't understand how Windows Recall works.

Microsoft has built a number of safety features into Windows Recall to ensure that the service can't run secretly in the background. When Windows Recall is enabled, it places a permanent visual indicator icon on the Taskbar to let the user know that Windows Recall is capturing data. This icon cannot be hidden or moved.

People are ready to assume Microsoft will enable Windows Recall in a future update. (Image credit: Windows Central)

It's also important to remember that Microsoft has no monetary incentive to force people to use Windows Recall. The data it collects is of no value to Microsoft, as it can't see any of it. Windows Recall is a selling point for new hardware, built as a means to improve user productivity, not sell advertising. But that's hard for people to believe, and perhaps that's rightly so.

With that in mind, there would be no reason for Microsoft to automatically enable Windows Recall in an update down the line. If it does happen, the user will be able to instantly tell thanks to that that visual indicator and turn it off again.

Microsoft chose to keep Windows Recall a secret, and that hasn't helped things.

Windows Recall went through several iterations internally... and public testing could have helped spot issues. (Image credit: Windows Central)

Some insider baseball here, but for some reason Microsoft was overly secretive about Windows Recall during development. It didn't want anyone to know about it. If you wanted to test the feature internally, you needed to be accepted into a tented program first, which I understand wasn't easy to get into. When I leaked the existence of Windows Recall (AI Explorer) and Copilot+ PCs (CADMUS) back in December 2023, I heard from sources that the company wasn't pleased.

Microsoft has the Windows Insider Program, yet to maintain secrecy, it chose not to test this feature openly. I can't think of a single feature that would have benefitted from public testing more than Windows Recall. This is the kind of feature that needs to be built in the open so that users can learn to trust you with it.

Had it been tested openly, these security concerns would have definitely been pointed out well ahead of general availability, and likely fixed before mass hysteria could ensue. Of course, the true reason Windows Recall wasn't tested openly was because the company wanted to make it exclusive to new Copilot+ PCs, and you can't really do that if you're testing the feature on existing PCs where it works quite well.

Microsoft also wanted to keep Windows Recall a secret so it could have a big reveal on May 20. Except, it wasn't really much of a big reveal. Many of us in the tech press already knew it was coming, even without being briefed on the feature ahead of time. 

You can't have Windows Recall anyway

Windows Recall is only enabled on new hardware. (Image credit: Windows Central)

Ultimately, you can't have Windows Recall anyway. It's a feature reserved exclusively for new PCs shipping under the Copilot+ umbrella, which means if you want to use it, you'll have to buy a new device with a neural processing unit (NPU) that can output 40 TOPS of power first. Your existing Windows 11 PC is not eligible to run Windows Recall and very likely never will be.

That's good news for those who don't want Windows Recall, as it means there's nothing you need to do to avoid it. Just keep using your existing device, and you should be safe from the all-seeing eye that is Windows Recall.

If you do happen to acquire a Copilot+ PC, you can choose not to use Windows Recall. There's some discourse around the feature being potentially enabled by default, but I'm told via sources that this is being reconsidered. I suspect Microsoft will give the user a choice to turn Windows Recall on or off during the setup process on Copilot+ PCs. 

If it doesn't, that's just another bad Windows practice to add to the list.

It's a shame because Windows Recall is really good.

I've really enjoyed using Windows Recall over the last week. (Image credit: Windows Central)

I think it's fair to say that a feature can be both insecure and good at what it does. That's Windows Recall for me right now. I've been testing it over the last week, and it's a great tool for finding things you only half remember, or have deleted, accidentally or otherwise.

In fact, it came in clutch for this very article. I had deleted a paragraph earlier in the day as I didn't think it was relevant, only later to realize I could reuse that paragraph elsewhere in the story. On a normal PC, that paragraph is gone, and I'd have to rewrite it from scratch. But with Windows Recall, I was able to go back to that point in time when I originally wrote it, copy it from there, and paste it back into my CMS.

The ability to search for things using natural language is genuinely great, and it works really well for a 1.0 product. But there's a very dark cloud hanging over this feature right now, and a lot of privacy conscious people are simply not going to be able to subscribe to the idea of Windows Recall in its current form.

Microsoft told me at the event where Windows Recall was announced that it plans to rapidly update this feature now that it's shipping. I suspect this means we will see new features and capabilities added to Windows Recall over the coming months, along with updates to ensure the data it collects is secure on the device.

What happens now?

Examples of people not trusting Microsoft

Microsoft is the villain in many people's eyes. (Image credit: Windows Central)

So what happens now? Will Microsoft delay Windows Recall, or maybe even cancel it? Will people ever be able to trust it?

I don't think Microsoft will delay or cancel it. I think Windows Recall will ship on June 18 as was originally announced, with the promise of an update coming shortly after to fix the security concerns people have with it. 

With Windows Recall being exclusive to Copilot+ PCs, I imagine the number of PCs that could even be targeted with Recall malware over the next few months will be in the low thousands, which gives Microsoft some time to update Windows Recall with better security before more people adopt Copilot+ devices.

I definitely think Microsoft will make Windows Recall an optional feature that you can choose to enable or disable during Windows setup. It would be a really bad look to have it as opt-out rather than opt-in at this current time.

Windows Recall is a feature that ships as part of Windows 11 version 24H2, which technically won't be generally available until this fall for existing PCs. Even when that happens, Windows Recall won't be enabled on your existing device.

Zac Bowden
Senior Editor

Zac Bowden is a Senior Editor at Windows Central. Bringing you exclusive coverage into the world of Windows on PCs, tablets, phones, and more. Also an avid collector of rare Microsoft prototype devices! Keep in touch on Twitter and Threads

  • Davy Strange
    This article is all insinuation and slander, "Just because Microsoft say they won't do something doesn't mean they won't", you endlessly imply.

    If they did, that would be a major pr disaster, whereas keeping to their word, after Satya Nadella has told the company to focus on security, suggests they are probably going to keep their word.

    They are a large company with countless people checking up on them, if they started to cheat, we'd know about it pretty damned quickly.

    Putting adverts in your products says nothing about your honesty when it comes to keeping data secure. Linking the two creates a clearly unjustified sense of mistrust.

    This article is drivel and the author should be ashamed of themselves.
    Reply
  • ShinyProton
    Conceptually, Recall is pretty outstanding - with no equivalent from the competitors.

    Many reporters and bloggers started shouting about the feature security without really having understood the underlying implementation.
    They also seem to conveniently forget that if you run your PC with a administrative account, ANYTHING you spawn can access your entire computer - Recall or not.

    Thus, when you're compromised, your data is not yours anymore - again, Recall or not.

    Finally, I don't think Microsoft developed this feature over several months (considering how polished it appears to be) and never had anyone auditing the security side of it.

    And if you don't want it, just deactivate it.

    So please, shut up and stop the drama.
    Reply
  • robinglumbergkidd
    What a slanderous and utter garbage article loaded with false accusations and fear mongering. For shame. Microsoft should seriously consider a liable and slanderous case against your team and organisation.
    Reply
  • robinglumbergkidd
    ShinyProton said:
    Conceptually, Recall is pretty outstanding - with no equivalent from the competitors.

    Many reporters and bloggers started shouting about the feature security without really having understood the underlying implementation.
    They also seem to conveniently forget that if you run your PC with a administrative account, ANYTHING you spawn can access your entire computer - Recall or not.

    Thus, when you're compromised, your data is not yours anymore - again, Recall or not.

    Finally, I don't think Microsoft developed this feature over several months (considering how polished it appears to be) and never had anyone auditing the security side of it.

    And if you don't want it, just deactivate it.

    So please, shut up and stop the drama.
    Well said!
    Reply
  • joshcsmith13
    Interesting that most of the comments here are in support of MS. I pretty much have to agree with them though. Your article certainly doesn't do anything to assuage the FUD. Especially when you post your own headline stating, "Windows Recall seemingly stores its data unencrypted." Even in that article it is explained that is not exactly true.
    Reply
  • JamesDax3
    This is just a mole hill that the so called media made into a mountain. WTF kind of BS article is this? smdh, shame!
    Reply
  • Davy Strange
    I look forward to being able to buy a Copilot+ PC, Recall will greatly enhance my productivity.

    If you are so happy with Apple and how they treat their users as sponges of money to be wrung ever harder dry, go and get a Mac and stop writing daft claptrap about Windows.
    Reply
  • Daniel Rubino
    robinglumbergkidd said:
    What a slanderous and utter garbage article loaded with false accusations and fear mongering. For shame. Microsoft should seriously consider a liable and slanderous case against your team and organisation.
    Shiver my timbers. Such drama!
    Reply
  • Daniel Rubino
    JamesDax3 said:
    This is just a mole hill that the so called media made into a mountain. WTF kind of BS article is this? smdh, shame!
    Your critique would carry more water if you could point to the "BS" parts and what is factually incorrect. We'll happily amend with citation any errors we have made if the evidence is sufficient.
    Reply
  • Jack Pipsam
    Actions speak louder than words.

    Microsoft makes users jump through loops to setup a computer they purchased (with a legitimate Windows key) without a forced Microsoft Account. How can you trust Microsoft when they actively fight their customers by trying to patch-out workarounds for offline activation?

    I've listed to the Windows Central Podcast, I've heard "Oh well Android makes you do it!" as if Google doing something dodgy is a justification for Microsoft doing this for a PC. Funny how Mac & Linux don't need this, funny how previous versions of Windows don't need this... FUNNY HOW WINDOWS 11 DOESN'T NEED IT.

    It might be very well easy for you or me to set-up a computer with an account. I've had Microsoft Account forever now, it ties in decades of Email, Xbox, Windows Phone, etc. My OneDrive remembers photos I took on my Windows Phone in the latter years of high-school. However I am not so lacking of grass-touching that I cannot see that this is a major issue for general and broader users. It is a mistake of tech-writers to not consider the possiblites for those who don't live with smart-home lights synced to their smart-watches.

    Forcing online & online accounts a terrible practice. Full stop. It's not great for parents gifting a laptop for their child to be first greeted with an account sign-up page. Not ideal for seniors (or even other normies) who struggle with computers to be first greeted with an internet/sign-up page. My senior neighbour (bless her) is always needing my help accessing her Outlook emails. Imagine if she had to setup a Windows 11 system on her own?

    There's a local charity that you can donate laptops to and they'll refresh them with Windows before donating them to children in need in Papua New Guinea for school etc. Let me tell you, the PNG isn't exactly awash with home internet access, some villages might have one or two phones if lucky. So do those kids just not get a laptop anymore? - Now the logical choice, swap to Linux, or stick with Windows 10.

    Heck, plenty of regional areas of Australia, United States, Canada etc have spotty or lack of internet. Imagine gifting a set of laptops to a remote Indigenous community in the Kimberley (and yes they have schools and laptops), but they might not have a steady internet access, only radio. Well, fuck you if you get a Windows 11 laptop kids. You cannot even get to the desktop.

    Microsoft doesn't care, they are the owner of the world's largest operating system. An overwhelming amount of market-share. But that's not good enough apparently, being a trillion dollar company isn't good enough. You need to squeeze every drip of data from users, an in the process cut off those without internet, those who aren't tech-savy and those who aren't over 13 (who you can legally suck the data from).

    So no, I don't trust Microsoft with Recall. Why would you? They force an internet connection and a Microsoft Account when there's literally no reason other than greed. It is not unreasonable to assume an alternative motive for Recall when Microsoft hasn't even shown the bare minimum pretense of care for their own customers.

    People want their computers to be easy, fast and stable. They couldn't give a toss about a MSN News widget.
    Reply