On May 20th, Microsoft announced a new category of computers under the Windows brand. These will be the Copilot+ PCs, that is, those that can run the latest Windows innovations in terms of artificial intelligence.
Due to the way this operating system and its AI tools work, users will be able to find everything they have seen when using their computer: they organize information based on relationships and associations and allow users to navigate through a timeline of their work in all applications, websites, and documents.
The problem with all of this arises when we stop to think that the tool that allows all this timeline, called Recall, is dedicated to taking screenshots of everything we do… at all times. So, isn’t it dangerous for Windows to record absolutely everything we do with our computer?
That’s what we’re going to discuss now, first explaining what this application is all about, Recall, and then reviewing the possible privacy issues that arise once we’ve thought about it for more than 10 minutes.
How does the Windows tool called Recall work?
In its presentation of the Copilot+PC recovery feature, the company explained that if you search for a specific item, such as a “blue dress,” using the recovery function, it will scan the web browsing history and any other visual mention or match with the search term to find it wherever the item is mentioned.
To remember all this information, Recall will take frequent snapshots of users’ active screens every few seconds. Once the user finds the snapshot they were looking for in Recall, it will be analyzed to offer interaction options with the content.
The feature will allow users to open the snapshot in the original application in which it was created. As the feature is perfected over time, Recall will open the actual source document, website, or email in a screenshot.
Is Recall a privacy issue for users?
Although some have expressed concern that this feature poses privacy risks and have compared it to a “spy program”, Microsoft claims that all snapshots taken by Recall will be encrypted and stored locally on the user’s PC.
Users can choose to delete snapshots of certain items and adjust/remove timelines of their work through the settings. Users can also filter apps and websites to prevent them from being saved, reducing the risk of the feature tracking confidential information.
Recall also does not take screenshots of certain types of content, including InPrivate web browsing sessions in Microsoft Edge.
Microsoft claims that Recall captures are linked to specific user profiles on a computer and are not shared with other users of the device. The snapshots are also not shared with Microsoft for targeted advertising.
However, it is important to note that, according to Microsoft’s frequently asked questions about this feature, content moderation is not practiced. “It will not hide information such as passwords or financial account numbers.” This is especially dangerous, as it would have all our registered users and passwords, making it the number 1 target for hackers.
That data can be in the snapshots stored on the device, especially when websites do not follow standard Internet protocols, such as hiding the input of passwords,” the company explains.
United Kingdom is investigating the legality of Microsoft Recall for users
According to a report from the BBC, the United Kingdom’s Information Commissioner’s Office (ICO) is conducting an investigation into the retrieval function to gather more information about the safeguards that Microsoft has put in place to ensure user privacy when using this feature.
A spokesperson for the ICO has told the BBC that companies must “thoroughly assess and mitigate the risks to individuals’ rights and freedoms” before launching new products to the market.
Microsoft will have to assure regulators that this new tool does not compromise the privacy of its users and customers. In a time where AI is everything, we cannot lose focus. The future can be dangerous if we deviate from the path.