Microsoft Recall on Copilot+ PC: testing the security and privacy implications
ID: 02608d33-e5e8-53ef-9e4b-20894199c2da
STIX ID: report--02608d33-e5e8-53ef-9e4b-20894199c2da
Feed Name: DoublePulsar
Threat Score
The report shows that Microsoft Recall only requires biometrics during initial onboarding but thereafter can be unlocked with a Windows Hello PIN, allowing an attacker who knows or guesses the PIN to search, view, export, and reenable Recall to record activity, including deleted content; tests reproduced access by a non-technical person and found sensitive-data filtering unreliable (e.g., credit card details were recorded).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
