TotalRecall breaks Microsoft's secure Recall

Recall, Windows 11's flagship AI feature, 2024 was released alongside the first wave of Copilot+ computers, users met the feature with a lot of skepticism, which later turned into a lot of problems for Microsoft when security researchers showed how easy it was to extract all of a user's data.

This forced Microsoft to recall in Recall or to withdraw the feature and re-release it months later with new security measures.

Discover more articles in search results.

But even these security measures are not enough.

A recently updated tool, aptly named TotalRecall, proves that the data captured by Windows Recall remains insecure.

Alexander Hagenah published his application on GitHub, revealing that although Recall information appears to be stored securely, the way Windows 11 delivers the data is very easy to crack, and Microsoft has no problem with that.

The updated version of TotalRecall, which is now publicly available, uses the AIXHost.exe process to obtain all the application snapshots. The researcher explains that “the process that renders the Recall timeline has no PPL, AppContainer, or code integrity enforcement, which allows code injection and data extraction once the user authenticates with Windows Hello.

The idea is to stay in the background, wait for the user to authenticate (let's say you want to use Recall as intended), and then suck up your data without any problems.

Alexander Hagenah submitted his findings to Microsoft before making them public, but the company stated that TotalRecall is not a security bypass or vulnerability.

Now, TotalRecall Reloaded is publicly available and you can get it from GitHub.

follow us

Google preferences

Leave a Comment

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).