---
title: "Windows Feature That Records Everything You Do Can Easily Be Hacked"
description: "Microsoft announced an AI Windows feature called Recall that regularly takes screenshots. It's a cybersecurity mess that can easily be hacked."
date: "2024-06-06"
modified: "2024-06-06"
authors:
  - name: "Victor Tangermann"
    job_title: "Senior Editor"
    link: "https://futurism.com/authors/victor"
url: "https://futurism.com/the-byte/windows-recall-hacked"
categories:
  - "Artificial Intelligence"
tags:
  - "ai chatbots"
  - "cybersecurity"
  - "microsoft"
  - "the digest"
  - "windows"
---

# Windows Feature That Records Everything You Do Can Easily Be Hacked

![Microsoft announced an AI Windows feature called Recall that regularly takes screenshots. It's a cybersecurity mess that can easily be hacked.](<https://futurism.com/wp-content/uploads/2024/06/windows-recall-hacked.jpg>)
*\<em\>Image: Getty / Futurism\</em\>*

## Total Recall

Microsoft [recently announced](<https://support.microsoft.com/en-gb/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c>) a new AI-enabled Windows feature called Recall that tracks quite literally everything you do on your computer by regularly taking screenshots and scanning them for relevant information to be recovered later.

If you're wondering how this isn't a massive cybersecurity disaster waiting to happen — you'd be right to be concerned.

As [*Wired* reports](<https://www.wired.com/story/total-recall-windows-recall-ai/>), security researchers have already shown — two weeks ahead of the tool's official launch — that the screenshots the feature takes are stored in an unencrypted database, a glaring oversight that could easily allow bad actors to access any information that has ever graced the screen of your Windows device.

Cybersecurity expert Alex Hagenah created an aptly named tool called TotalRecall, which can exploit this oversight by pulling all the data Recall can extract — a public demonstration to warn others of the feature's daunting implications.

"The database is unencrypted. It’s all plain text," he told *Wired*. "It’s a Trojan 2.0 really, built in," he added, referring to commonly-used spyware.

## Everything History

Microsoft is hoping to turn Recall into a "[magical](<https://www.youtube.com/watch?v=uHEPBzYick0&t=257s>)" way of retroactively summoning any potentially lost information, from forgotten browser tabs to misplaced files, using AI chatbot-style natural language prompts.

"Search across time to find the content you need," Microsoft promises in [official documentation](<https://support.microsoft.com/en-gb/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c>). "Then, re-engage with it. With Recall, you have an explorable timeline of your PC’s past."

But as Hagenah demonstrates with his nifty tool, the screenshots created by Recall can easily be swiped from an unsuspecting machine, laying out all of your most sensitive data to hackers on a platter. Even encrypted messages sent over secure messaging platforms like Signal and WhatsApp could easily be recovered.

In short, the potential for abuse is astronomical.

"InfoStealer trojans, which automatically steal usernames and passwords, are a major problem for well over a decade — now these can just be easily modified to support Recall," cybersecurity researcher Kevin Beaumont noted in a [blog post](<https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e>).

Worse yet, as *Wired* reports, Microsoft has essentially admitted that it won't hide passwords or other highly sensitive information — and researchers [have already found easy ways](<https://x.com/awakecoding/status/1797724492812431677>) to recover this data.

For now, Recall is only available in a "preview," and may go through changes before it's released later this month.

To cybersec experts, however, the damage has already been done.

"It’s an act of self harm at Microsoft in the name of AI, and by proxy real customer harm," Beaumont wrote.

"In my opinion — they should recall Recall and rework it to be the feature it deserves to be, delivered at a later date," he added. "They also need to review the internal decision-making that led to this situation, as this kind of thing should not happen."

**More on Microsoft:** *[Microsoft CEO Bashes Human-Like AI After OpenAI's Scarlett Johansson Scandal](<https://futurism.com/the-byte/microsoft-ceo-openai-ai-scarlett-johansson>)*

## Author
I've been at Futurism since 2017, where my role has evolved to encompass design, writing, and increasingly editing. I've always been fascinated by space exploration and advanced transportation, which I've leaned into by interviewing luminaries in those fields while closely following the dimensions of policy and regulation that allow next-generation projects to succeed -- or, sometimes, to fail. I'm also keenly interested in the effects of generative AI on society, policies, and democratic institutions, as well as clean energy, physics and biology, and the vagaries of tech leadership. My work for Futurism has been cited by publications including Ars Technica, Gizmodo, PC Magazine, Jalopnik, Fox News, and the New York Post. I spent my childhood living in locations including Manila, the Philippines, and Geneva, Switzerland, attended McGill University, and now live in Toronto, Canada. Before Futurism I worked at AskMen and a small photography studio. In my free time, I'm an avid gardener, foodie, and craft beer lover, as well as a maker of artisanal hot pepper sauces. I have a magnificent dog named Freida.

### Author social links  
[Bluesky](<https://bsky.app/profile/vtanger.bsky.social>)