• About
  • Advertise
  • Privacy & Policy
  • Contact
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Review
    The new PopSockets grip is so thin you’ll forget it’s even there

    The new PopSockets grip is so thin you’ll forget it’s even there

    These mechanical keyboards are two very different sides of the same beautifully made coin

    These mechanical keyboards are two very different sides of the same beautifully made coin

    Honor’s Magic V6 sets three foldable firsts

    Honors Magic V6 sets three foldable firsts

    This portable light is great for way more than camping

    This portable light is great for way more than camping

    I’ve found the Goldilocks of portable MIDI controllers

    I’ve found the Goldilocks of portable MIDI controllers

    I went to the woods to drink surprisingly great espresso

    I went to the woods to drink surprisingly great espresso

  • Gaming
    Xbox is closing down Hellblade creator Ninja Theory

    Xbox is closing down Hellblade creator Ninja Theory

    Xbox turmoil continues with a studio closure and executive departures

    Xbox turmoil continues with a studio closure and executive departures

    Roblox exec says ticking a box for age verification is ‘not enough anymore’

    Roblox exec says ticking a box for age verification is ‘not enough anymore’

    Google Earth’s flight simulator is now available in your browser

    Google Earths flight simulator is now available in your browser

    Sealed Super Mario Bros. sells for a record $3 million

    Sealed Super Mario Bros. sells for a record $3 million

    Microsoft hasn’t ruled out spinning off Xbox

    Microsoft hasnt ruled out spinning off Xbox

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    We now know how DJI’s dual camera Osmo Pocket 4P compares to Insta360’s

    We now know how DJIs dual camera Osmo Pocket 4P compares to Insta360s

    Kodak’s collectible Charmera camera is getting new Y2K-inspired designs

    Kodaks collectible Charmera camera is getting new Y2K-inspired designs

    My first 24 hours with Siri AI on the Mac

    My first 24 hours with Siri AI on the Mac

    Framework delays its first Laptop 13 Pro shipments by a month

    Framework delays its first Laptop 13 Pro shipments by a month

    Insta360’s Luna Ultra 8K stabilized camera is now available in the US

    Insta360s Luna Ultra 8K stabilized camera is now available in the US

    The screenless Camp Snap 2 is slimmer and comes with more filters

    The screenless Camp Snap 2 is slimmer and comes with more filters

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    Fujifilm X-T2 review: The definition of a great camera

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

    SpaceX targets February 18 for Dragon resupply mission to ISS

  • Applications
    Apple 2027 rumors: AirPods with cameras for AI and the second folding iPhone

    Apple 2027 rumors: AirPods with cameras for AI and the second folding iPhone

    Apple’s smart home camera service is starting to impress me

    Apples smart home camera service is starting to impress me

    Apple’s weird anti-nausea dots cured my car sickness

    Apples weird anti-nausea dots cured my car sickness

    Apple’s new AI photo editing tools mostly work, for better and worse

    Apples new AI photo editing tools mostly work, for better and worse

    Siri is good now??

    Siri is good now??

    Siri won’t be your AI girlfriend

    Siri wont be your AI girlfriend

  • Security

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    National Academy of Sciences endorses embryonic engineering

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    The Warby Parker of hair color, Madison Reed, scores new funding and a CMO

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

No Result
View All Result
  • Home
  • Review
    The new PopSockets grip is so thin you’ll forget it’s even there

    The new PopSockets grip is so thin you’ll forget it’s even there

    These mechanical keyboards are two very different sides of the same beautifully made coin

    These mechanical keyboards are two very different sides of the same beautifully made coin

    Honor’s Magic V6 sets three foldable firsts

    Honors Magic V6 sets three foldable firsts

    This portable light is great for way more than camping

    This portable light is great for way more than camping

    I’ve found the Goldilocks of portable MIDI controllers

    I’ve found the Goldilocks of portable MIDI controllers

    I went to the woods to drink surprisingly great espresso

    I went to the woods to drink surprisingly great espresso

  • Gaming
    Xbox is closing down Hellblade creator Ninja Theory

    Xbox is closing down Hellblade creator Ninja Theory

    Xbox turmoil continues with a studio closure and executive departures

    Xbox turmoil continues with a studio closure and executive departures

    Roblox exec says ticking a box for age verification is ‘not enough anymore’

    Roblox exec says ticking a box for age verification is ‘not enough anymore’

    Google Earth’s flight simulator is now available in your browser

    Google Earths flight simulator is now available in your browser

    Sealed Super Mario Bros. sells for a record $3 million

    Sealed Super Mario Bros. sells for a record $3 million

    Microsoft hasn’t ruled out spinning off Xbox

    Microsoft hasnt ruled out spinning off Xbox

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    We now know how DJI’s dual camera Osmo Pocket 4P compares to Insta360’s

    We now know how DJIs dual camera Osmo Pocket 4P compares to Insta360s

    Kodak’s collectible Charmera camera is getting new Y2K-inspired designs

    Kodaks collectible Charmera camera is getting new Y2K-inspired designs

    My first 24 hours with Siri AI on the Mac

    My first 24 hours with Siri AI on the Mac

    Framework delays its first Laptop 13 Pro shipments by a month

    Framework delays its first Laptop 13 Pro shipments by a month

    Insta360’s Luna Ultra 8K stabilized camera is now available in the US

    Insta360s Luna Ultra 8K stabilized camera is now available in the US

    The screenless Camp Snap 2 is slimmer and comes with more filters

    The screenless Camp Snap 2 is slimmer and comes with more filters

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    Fujifilm X-T2 review: The definition of a great camera

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

    SpaceX targets February 18 for Dragon resupply mission to ISS

  • Applications
    Apple 2027 rumors: AirPods with cameras for AI and the second folding iPhone

    Apple 2027 rumors: AirPods with cameras for AI and the second folding iPhone

    Apple’s smart home camera service is starting to impress me

    Apples smart home camera service is starting to impress me

    Apple’s weird anti-nausea dots cured my car sickness

    Apples weird anti-nausea dots cured my car sickness

    Apple’s new AI photo editing tools mostly work, for better and worse

    Apples new AI photo editing tools mostly work, for better and worse

    Siri is good now??

    Siri is good now??

    Siri won’t be your AI girlfriend

    Siri wont be your AI girlfriend

  • Security

    To regain advertiser trust, Facebook is tracking ads by the millisecond

    National Academy of Sciences endorses embryonic engineering

    Google has been asked to take down over a million websites

    Watch Dogs 2 Update Coming This Week, Here’s What It Does

    The Warby Parker of hair color, Madison Reed, scores new funding and a CMO

    Shopify CEO attempts to defend continued hosting of Breitbart’s online store

No Result
View All Result
The Latest Tech News | Breaking Bews In Thchnology
No Result
View All Result
Home Microsoft

Microsoft faces fresh Windows Recall security concerns

admin by admin
April 16, 2026
Microsoft faces fresh Windows Recall security concerns
Share on FacebookShare on Twitter

When Microsoft tried to launch Recall, an AI-powered Windows feature that screenshots most of what you do on your PC, it was labeled a “disaster” for cybersecurity and a “privacy nightmare.” After the backlash and a year-long delay to redesign and secure Recall, it’s once again facing security and privacy concerns.

Cybersecurity expert Alexander Hagenah has created TotalRecall Reloaded, a tool that extracts and displays data from Recall. It’s an update to the TotalRecall tool that demonstrated all the weaknesses in the original Recall feature before Microsoft redesigned it.

Microsoft’s redesign focused on creating a secure vault for Recall data, with Windows Hello authentication and a secure environment through a Virtualization-based Security Enclave. Recall requires users to authenticate using a face or fingerprint to gain access to data and to enable snapshots to be recorded. “This restricts attempts by latent malware trying to ’ride along’ with a user authentication to steal data,” said Microsoft in a September 2024 blog post.

“My research shows that the vault is real, but the trust boundary ends too early,” says Hagenah. “TotalRecall Reloaded makes that ‘latent malware’ ride along.” The TotalRecall Reloaded tool can silently run in the background and activate the Recall timeline to force a user into authenticating with a Windows Hello prompt. Once the authentication has taken place, TotalRecall Reloaded can then extract everything that Windows Recall has ever captured. “That is precisely the scenario Microsoft’s architecture is supposed to restrict,” says Hagenah.

Recall stores much more than just screenshots, with the history of text that has appeared on your screen, messages, emails, documents, browsing history, and much more. Microsoft’s changes to Recall security came months after CEO Satya Nadella told employees “If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security.”

Hagenah responsibly disclosed his latest findings to Microsoft last month, but the company closed the report and said there was no vulnerability. “We appreciate Alexander Hagenah for identifying and responsibly reporting this issue. After careful investigation, we determined that the access patterns demonstrated are consistent with intended protections and existing controls, and do not represent a bypass of a security boundary or unauthorized access to data,” says David Weston, corporate vice president of Microsoft Security, in a statement to The Verge. “The authorization period has a timeout and anti-hammering protection that limit the impact of malicious queries.”

In messages to The Verge, Hagenah disputes Microsoft’s timeout protections. “I can re-poll the data, and what I am doing in my tool [is] to bypass it. And the timeout is patched out,” says Hagenah. “My biggest issue still is them saying in their official announcement that the enclave prevents ‘latent malware riding along,’ which it clearly doesn’t.”

TotalRecall Reloaded can also extract the latest cached Windows Recall screenshot without Windows Hello authentication, or totally wipe the entire capture history. But the type of malware that Hagenah describes could sit in the background on a PC and take screenshots anyway, with or without Windows Recall.

Microsoft doesn’t think there’s a vulnerability here because this is simply how Windows works. Regular user-mode processes have the ability to inject code into themselves as a normal and often legitimate behavior in Windows, but this flexibility also creates opportunities for abuse.

A similar infostealer malware could sit and extract 1Password data or your browsing history, if it was undetected by the various other Windows security tools and memory protection efforts. The bigger concern is that Recall stores a lot more sensitive data than just passwords or browsing history, and Microsoft’s original promise that Recall would protest against malware riding along in the background.

Despite the concerns, Microsoft got a lot right with its Recall redesign. “The VBS enclave is rock solid,” says Hagenah. “The authentication model is stateless and race-free (thousands of probes, zero bypasses).” Hagenah just thinks Microsoft could, and should, go a step further to meet its security design goals for Recall. “The fundamental problem isn’t the crypto, the enclave, the authentication, or the PPL,” he says. “It’s sending decrypted content to an unprotected process for rendering. The vault door is titanium. The wall next to it is drywall.”

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

  • Tom Warren

    Tom Warren

    Tom Warren

    Posts from this author will be added to your daily email digest and your homepage feed.

    See All by Tom Warren

  • Microsoft

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Microsoft

  • Report

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Report

  • Tech

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Tech

  • Windows

    Posts from this topic will be added to your daily email digest and your homepage feed.

    See All Windows

Tags: Microsoft privacy issuesWindows Recall security
admin

admin

Next Post
The new Tomodachi Life is made to be shared — even if Nintendo doesn’t want you to

The new Tomodachi Life is made to be shared — even if Nintendo doesnt want you to

Recommended.

Microsoft Ugly Sweaters 2023: Clippy, Xbox, & Zune Designs Are Back!

Microsoft Ugly Sweaters 2023: Clippy, Xbox, & Zune Designs Are Back!

December 1, 2025
"CalDigit TS4 Thunderbolt 4 Dock: Unmatched Port Availability for Ultimate Connectivity"

CalDigit TS4 Thunderbolt 4 Dock: Unmatched Port Availability for Ultimate Connectivity

November 17, 2025

Trending.

PlayStation exclusives aren’t coming to PC anymore

PlayStation exclusives aren’t coming to PC anymore

May 18, 2026
LG will release the first 1000Hz, 1080p gaming monitor this year

LG will release the first 1000Hz, 1080p gaming monitor this year

May 19, 2026
Nintendo keeps finding new ways to reinvent platformers

Nintendo keeps finding new ways to reinvent platformers

May 19, 2026
Xbox fans want exclusives, more backward compatibility, and free online multiplayer

Xbox fans want exclusives, more backward compatibility, and free online multiplayer

May 19, 2026
Apple’s accessibility features add more AI-powered processing

Apples accessibility features add more AI-powered processing

May 19, 2026
earmpro tech news

Stay ahead of the tech curve. Our website delivers clear, concise updates on the latest gadgets, AI breakthroughs, and software, empowering your digital future.

Follow Us

  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2025 | Website Made By earmpro.com.

No Result
View All Result
  • Home
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2025 | Website Made By earmpro.com.