Skip to main content

Microsoft’s hallmark AI feature dubbed a security disaster just days away from Apple’s privacy-focused AI launch at WWDC

Microsoft has a target on Apple’s back with its AI-centric Copilot Plus PC models. When the computers were announced, the company repeatedly claimed that they outperformed the latest M3 MacBook Airs. Today a new ad campaign sought to further entice switchers away from the Mac.

It turns out, not every aspect of the Copilot Plus PCs is ready for prime time. The hallmark AI feature Microsoft formerly demoed, Recall, has been exposed by an expert as being a security disaster.

Recall could make your entire computing life available to hackers

Recall was one of the most impressive, but also eerie, moments from Microsoft’s Copilot Plus PCs presentation. It’s a feature that tracks everything you do on your computer at all times, and saves a record of it. Every click, every Zoom meeting, files viewed and deleted, keystrokes typed—all of it is saved by Recall.

Why? So the AI-powered system can later present you with whatever information you need about your past activity. Recall gives you a photographic memory of your PC life.

Top comment by James

Liked by 3 people

I'm not sure this is really a 'disaster'. If a user gets a trojan on their Mac, the attacker can access all of the user's iMessages, Safari browsing history, social media accounts, gmail, etc. This is no different: user installs malware and sensitive data is exfiltrated. The onus is on the user to keep their machine patched and protected to avoid compromise.

View all comments

Microsoft touted its work to ensure Recall is secure and private, but now, the feature’s security claims have been convincingly disputed by a security expert who got a hold of the software.

Beaumont fleshes this out further on his blog:

Q. The data is processed entirely locally on your laptop, right?

A. Yes! They made some smart decisions here, there’s a whole subsystem of Azure AI etc code that process on the edge.

Q. Cool, so hackers and malware can’t access it, right?

A. No, they can.

Q. But it’s encrypted.

A. When you’re logged into a PC and run software, things are decrypted for you. Encryption at rest only helps if somebody comes to your house and physically steals your laptop — that isn’t what criminal hackers do.

For example, InfoStealer trojans, which automatically steal usernames and passwords, are a major problem for well over a decade — now these can just be easily modified to support Recall.

9to5Mac’s Take

This is an extremely bad look for Microsoft, but hopefully the company will take immediate action to address Recall’s security issues, even if it means pushing the feature’s public release back significantly. As Beaumont’s research highlights, these security flaws would be an absolute disaster for Microsoft, and its users, if they begin spreading to a broad audience of Copilot Plus PC users.

This report makes me all the more interested to see how Apple plans to emphasize its privacy-heavy approach for AI features at WWDC next week. The company has long promoted itself as putting user privacy first, now with iOS 18 and its other software platforms, it has the chance to further prove that value in the age of AI.

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ryan Christoffel Ryan Christoffel

Ryan got his start in journalism as an Editor at MacStories, where he worked for four years covering Apple news, writing app reviews, and more. For two years he co-hosted the Adapt podcast on Relay FM, which focused entirely on the iPad. As a result, it should come as no surprise that his favorite Apple device is the iPad Pro.

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications