Sponsored
Displayed for 0 seconds
Displayed for 0 seconds
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Review
    Ikea’s smart donut lamp is a sweet treat

    Ikea’s smart donut lamp is a sweet treat

    More phone cameras should come with telephoto lenses

    More phone cameras should come with telephoto lenses

    Sony’s latest gaming headset offers great open-back audio

    Sonys latest gaming headset offers great open-back audio

    The Hisense UR9 is a great first shot against OLED’s bow

    The Hisense UR9 is a great first shot against OLEDs bow

    You don’t have to spend more than $50 on a great USB-C dock for your Switch 2

    You dont have to spend more than $50 on a great USB-C dock for your Switch 2

    I tested three Windows laptops in the MacBook Neo’s price range — there’s no contest

    I tested three Windows laptops in the MacBook Neos price range — theres no contest

  • Gaming
    Microsoft’s new Xbox chief starts making her mark

    Microsofts new Xbox chief starts making her mark

    The new Tomodachi Life is made to be shared — even if Nintendo doesn’t want you to

    The new Tomodachi Life is made to be shared — even if Nintendo doesnt want you to

    Sony’s new 1440p OLED gaming monitor seems a lot better than its first

    Sonys new 1440p OLED gaming monitor seems a lot better than its first

    Anbernic’s new handheld is a pocket-friendly Android device with a swiveling screen

    Anbernics new handheld is a pocket-friendly Android device with a swiveling screen

    Alienware’s new gaming monitor offers a 240Hz QD-OLED panel for just $350

    Alienwares new gaming monitor offers a 240Hz QD-OLED panel for just $350

    Bloodborne is being turned into an R-rated animated film

    Bloodborne is being turned into an R-rated animated film

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Leaked images reveal a dual-lens pro version of DJI’s next Osmo Pocket camera

    Leaked images reveal a dual-lens pro version of DJIs next Osmo Pocket camera

    GoPro goes bigger and pro-er with support for Micro Four Thirds lenses

    GoPro goes bigger and pro-er with support for Micro Four Thirds lenses

    Allow me to explain why I love this camera that can’t shoot color

    Allow me to explain why I love this camera that cant shoot color

    GoPro is cutting 23 percent of its workforce

    GoPro is cutting 23 percent of its workforce

    At $150 off, the new MacBook Air is now cheaper than last year’s model

    At $150 off, the new MacBook Air is now cheaper than last years model

    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    Fujifilm X-T2 review: The definition of a great camera

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

    SpaceX targets February 18 for Dragon resupply mission to ISS

  • Applications
    The nine best ways to protect, customize, and accessorize your MacBook Neo

    The nine best ways to protect, customize, and accessorize your MacBook Neo

    Microsoft counters the MacBook Neo with freebies for students

    Microsoft counters the MacBook Neo with freebies for students

    Nothing makes it easy to share files between any Android phone and a Mac

    Nothing makes it easy to share files between any Android phone and a Mac

    Grok’s sexual deepfakes almost got it banned from Apple’s App Store. Almost. 

    Groks sexual deepfakes almost got it banned from Apples App Store. Almost. 

    The heist of iOS 26

    The heist of iOS 26

    The Apple Watch Series 11 has returned to best-ever price

    The Apple Watch Series 11 has returned to best-ever price

  • Security

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    National Academy of Sciences endorses embryonic engineering

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    The Warby Parker of hair color, Madison Reed, scores new funding and a CMO

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

No Result
View All Result
  • Home
  • Review
    Ikea’s smart donut lamp is a sweet treat

    Ikea’s smart donut lamp is a sweet treat

    More phone cameras should come with telephoto lenses

    More phone cameras should come with telephoto lenses

    Sony’s latest gaming headset offers great open-back audio

    Sonys latest gaming headset offers great open-back audio

    The Hisense UR9 is a great first shot against OLED’s bow

    The Hisense UR9 is a great first shot against OLEDs bow

    You don’t have to spend more than $50 on a great USB-C dock for your Switch 2

    You dont have to spend more than $50 on a great USB-C dock for your Switch 2

    I tested three Windows laptops in the MacBook Neo’s price range — there’s no contest

    I tested three Windows laptops in the MacBook Neos price range — theres no contest

  • Gaming
    Microsoft’s new Xbox chief starts making her mark

    Microsofts new Xbox chief starts making her mark

    The new Tomodachi Life is made to be shared — even if Nintendo doesn’t want you to

    The new Tomodachi Life is made to be shared — even if Nintendo doesnt want you to

    Sony’s new 1440p OLED gaming monitor seems a lot better than its first

    Sonys new 1440p OLED gaming monitor seems a lot better than its first

    Anbernic’s new handheld is a pocket-friendly Android device with a swiveling screen

    Anbernics new handheld is a pocket-friendly Android device with a swiveling screen

    Alienware’s new gaming monitor offers a 240Hz QD-OLED panel for just $350

    Alienwares new gaming monitor offers a 240Hz QD-OLED panel for just $350

    Bloodborne is being turned into an R-rated animated film

    Bloodborne is being turned into an R-rated animated film

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Leaked images reveal a dual-lens pro version of DJI’s next Osmo Pocket camera

    Leaked images reveal a dual-lens pro version of DJIs next Osmo Pocket camera

    GoPro goes bigger and pro-er with support for Micro Four Thirds lenses

    GoPro goes bigger and pro-er with support for Micro Four Thirds lenses

    Allow me to explain why I love this camera that can’t shoot color

    Allow me to explain why I love this camera that cant shoot color

    GoPro is cutting 23 percent of its workforce

    GoPro is cutting 23 percent of its workforce

    At $150 off, the new MacBook Air is now cheaper than last year’s model

    At $150 off, the new MacBook Air is now cheaper than last years model

    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    Anker’s power bank with built-in cables is one of my favorite gadgets, and it’s cheaper than usual

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    Fujifilm X-T2 review: The definition of a great camera

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

    SpaceX targets February 18 for Dragon resupply mission to ISS

  • Applications
    The nine best ways to protect, customize, and accessorize your MacBook Neo

    The nine best ways to protect, customize, and accessorize your MacBook Neo

    Microsoft counters the MacBook Neo with freebies for students

    Microsoft counters the MacBook Neo with freebies for students

    Nothing makes it easy to share files between any Android phone and a Mac

    Nothing makes it easy to share files between any Android phone and a Mac

    Grok’s sexual deepfakes almost got it banned from Apple’s App Store. Almost. 

    Groks sexual deepfakes almost got it banned from Apples App Store. Almost. 

    The heist of iOS 26

    The heist of iOS 26

    The Apple Watch Series 11 has returned to best-ever price

    The Apple Watch Series 11 has returned to best-ever price

  • Security

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    National Academy of Sciences endorses embryonic engineering

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    The Warby Parker of hair color, Madison Reed, scores new funding and a CMO

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

No Result
View All Result
The Latest Tech News | Breaking Bews In Thchnology
No Result
View All Result
Home Microsoft

Microsoft faces fresh Windows Recall security concerns

admin by admin
April 16, 2026
Microsoft faces fresh Windows Recall security concerns
Share on FacebookShare on Twitter

When Microsoft tried to launch Recall, an AI-powered Windows feature that screenshots most of what you do on your PC, it was labeled a “disaster” for cybersecurity and a “privacy nightmare.” After the backlash and a year-long delay to redesign and secure Recall, it’s once again facing security and privacy concerns.

Cybersecurity expert Alexander Hagenah has created TotalRecall Reloaded, a tool that extracts and displays data from Recall. It’s an update to the TotalRecall tool that demonstrated all the weaknesses in the original Recall feature before Microsoft redesigned it.

Microsoft’s redesign focused on creating a secure vault for Recall data, with Windows Hello authentication and a secure environment through a Virtualization-based Security Enclave. Recall requires users to authenticate using a face or fingerprint to gain access to data and to enable snapshots to be recorded. “This restricts attempts by latent malware trying to ’ride along’ with a user authentication to steal data,” said Microsoft in a September 2024 blog post.

“My research shows that the vault is real, but the trust boundary ends too early,” says Hagenah. “TotalRecall Reloaded makes that ‘latent malware’ ride along.” The TotalRecall Reloaded tool can silently run in the background and activate the Recall timeline to force a user into authenticating with a Windows Hello prompt. Once the authentication has taken place, TotalRecall Reloaded can then extract everything that Windows Recall has ever captured. “That is precisely the scenario Microsoft’s architecture is supposed to restrict,” says Hagenah.

Recall stores much more than just screenshots, with the history of text that has appeared on your screen, messages, emails, documents, browsing history, and much more. Microsoft’s changes to Recall security came months after CEO Satya Nadella told employees “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security.”

Hagenah responsibly disclosed his latest findings to Microsoft last month, but the company closed the report and said there was no vulnerability. “We appreciate Alexander Hagenah for identifying and responsibly reporting this issue. After careful investigation, we determined that the access patterns demonstrated are consistent with intended protections and existing controls, and do not represent a bypass of a security boundary or unauthorized access to data,” says David Weston, corporate vice president of Microsoft Security, in a statement to The Verge. “The authorization period has a timeout and anti-hammering protection that limit the impact of malicious queries.”

In messages to The Verge, Hagenah disputes Microsoft’s timeout protections. “I can re-poll the data, and what I am doing in my tool [is] to bypass it. And the timeout is patched out,” says Hagenah. “My biggest issue still is them saying in their official announcement that the enclave prevents ‘latent malware riding along,’ which it clearly doesn’t.”

TotalRecall Reloaded can also extract the latest cached Windows Recall screenshot without Windows Hello authentication, or totally wipe the entire capture history. But the type of malware that Hagenah describes could sit in the background on a PC and take screenshots anyway, with or without Windows Recall.

Microsoft doesn’t think there’s a vulnerability here because this is simply how Windows works. Regular user-mode processes have the ability to inject code into themselves as a normal and often legitimate behavior in Windows, but this flexibility also creates opportunities for abuse.

A similar infostealer malware could sit and extract 1Password data or your browsing history, if it was undetected by the various other Windows security tools and memory protection efforts. The bigger concern is that Recall stores a lot more sensitive data than just passwords or browsing history, and Microsoft’s original promise that Recall would protest against malware riding along in the background.

Despite the concerns, Microsoft got a lot right with its Recall redesign. “The VBS enclave is rock solid,” says Hagenah. “The authentication model is stateless and race-free (thousands of probes, zero bypasses).” Hagenah just thinks Microsoft could, and should, go a step further to meet its security design goals for Recall. “The fundamental problem isn’t the crypto, the enclave, the authentication, or the PPL,” he says. “It’s sending decrypted content to an unprotected process for rendering. The vault door is titanium. The wall next to it is drywall.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

  • Tom Warren

    Tom Warren

    Tom Warren

    Posts from this author will be added to your daily email digest and your homepage feed.

    See All by Tom Warren

  • Microsoft

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Microsoft

  • Report

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Report

  • Tech

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Tech

  • Windows

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Windows

Tags: Microsoft privacy issuesWindows Recall security
admin

admin

Next Post
The new Tomodachi Life is made to be shared — even if Nintendo doesn’t want you to

The new Tomodachi Life is made to be shared — even if Nintendo doesnt want you to

Please login to join discussion

Recommended.

Pokopia Pokédex review: a classic, reimagined

Pokopia Pokédex review: a classic, reimagined

March 11, 2026
Panic’s gaming ambitions hinge on the weird and whimsical

Panics gaming ambitions hinge on the weird and whimsical

March 10, 2026

Trending.

The Neo Effect: How Apple’s cheapest Mac is changing the PC game

The Neo Effect: How Apple’s cheapest Mac is changing the PC game

April 8, 2026
Netflix’s TV games get a big boost with Jackbox collection

Netflix’s TV games get a big boost with Jackbox collection

April 9, 2026
I finally get the iPhone Air

I finally get the iPhone Air

April 9, 2026
Framework is teasing a lot of Linux for its April 21st event

Framework is teasing a lot of Linux for its April 21st event

April 9, 2026
The team behind 1000xResist is making a game about convincing an AI that it isn’t human

The team behind 1000xResist is making a game about convincing an AI that it isnt human

April 9, 2026
The Latest Tech News | Breaking Bews In Thchnology

Stay ahead of the tech curve. Our website delivers clear, concise updates on the latest gadgets, AI breakthroughs, and software, empowering your digital future.

Follow Us

  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2025 | Website Made By earmpro.com.

No Result
View All Result
  • Home
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2025 | Website Made By earmpro.com.