Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs

Alfonso Maruccia

Posts: 2,604   +978
Staff
Editor's take: Windows Recall continues to raise security concerns. Microsoft has redesigned the feature to improve data and identity protection following public outcry, but a new tool is now reigniting the controversy. I have to suspect that few people in their right mind would choose to enable or use it at this point.

Alexander Hagenah previously exposed issues affecting Windows Recall with his TotalRecall tool, prompting Microsoft to redesign the feature around stronger architectural principles. Now, the security researcher is once again highlighting Recall's weaknesses with TotalRecall Reloaded. The updated tool can reportedly bypass protections in Recall and access private user data stored by the controversial AI-based feature.

The TotalRecall Reloaded GitHub page explains that the tool does not require admin access or elevated privileges to function. It operates within a standard user account, does not exploit any kernel vulnerability, and does not need to bypass or decrypt Recall's encrypted data. Instead, it uses standard COM calls to interact with "AIXHost.exe," the process responsible for rendering the Recall timeline while users browse captured data.

Hagenah argues that AIXHost.exe is the true weak point in the redesigned Recall system. He says the data collection mechanism itself is relatively robust, citing the use of VBS enclaves, AES-256-GCM encryption, Windows Hello authentication, and other security measures that create a "vault" for storing captured user data.

TotalRecall Reloaded does not bypass these security features, and it still requires the user to authenticate through Windows Hello biometric verification. After obtaining valid authentication, the tool "rides along" with the AIXHost.exe process to access, extract, and potentially misuse previously recorded data.

Hagenah said that "Recall doesn't just take screenshots. It builds a comprehensive behavioral profile of everything you do on your computer. Every few seconds, it captures a screenshot, runs OCR and (supposedly) AI classification on it, and stores the result in an encrypted SQLite database."

The developer says he reported his findings to Microsoft, as he had done previously. However, this time the company responded that the behavior demonstrated by TotalRecall Reloaded does not indicate any new vulnerability or bug. Microsoft stated that Recall's security boundaries are not being bypassed, and that the Windows Hello authentication period includes timeout and anti-hammering protections designed to limit the impact of unauthorized queries.

Hagenah warned that Microsoft's explanation is questionable. He said his tool can bypass timeout protections by re-polling the database to access data repeatedly. In his view, Recall is functioning as intended: "Your entire digital life, indexed and searchable. As intended." He also noted that privacy-focused tools and services are now actively interfering with Recall's data collection capabilities.

Permalink to story:

 
And the problem is ... where exactly??

Users can access their data after authenticating, which is exactly as it should be.
The so called tool does not decrypt data, as the title erroneously claims, it's merely able to access the data available to the user after authentication.
 
Microsoft will never release something that would actually, protect a users files. There's always a hidden thing such as the above or the whole bitlocker incident where upon a warrant, authorities can get access.

It's just privacy for the average joe.
 
Microsoft will never release something that would actually, protect a users files. There's always a hidden thing such as the above or the whole bitlocker incident where upon a warrant, authorities can get access.

"April 14, 2016: Microsoft filed a lawsuit with the U.S. District Court for the Western District of Washington in Seattle challenging the U.S. government’s use of indefinite and overly broad secrecy orders that prevent us from telling customers when the government accesses their data...."

"Sep 6: 2016: Long list of groups backs Microsoft in case involving digital-data privacy

Scores of technology companies, media enterprises, corporations, organizations and former law-enforcement officials filed briefs Friday in support of Microsoft’s lawsuit against the U.S. government that contends a procedure used by federal investigators to collect digital data is unconstitutional...."
 
However, this time the company responded that the behavior demonstrated by TotalRecall Reloaded does not indicate any new vulnerability or bug. Microsoft stated that Recall's security boundaries are not being bypassed, and that the Windows Hello authentication period includes timeout and anti-hammering protections designed to limit the impact of unauthorized queries.
They are technically correct, in their assessment of the situation. Accessing metadata about what Recall is doing, while it performs its duties, does not constitute a security compromise...and that's part of the problem. Recall is itself, already a keylogger, a data miner and scrapper. Using Recall to "remember what you're doing on your computer", is akin to keeping a copy of your browsing history saved on a cloud drive, where every category of thing you searched for is indexed as a separate file. So, the system doesn't know exactly what you searched for on Amazon, but it can see broadly that you looked for things in "Automobiles" or "Woodworking", for example, and commonly attached to products in those categories are SEO flags describing things like manufacturer and product type. Socially-engineering someone, in this manner, would constitute a "side-channel attack", and also is not a bug or exploit in Recall.

Just like how you don't need to see the literal contents of someone's mail, to deduce that an envelope addressed to them with the word "Overdue" strongly implies a dire financial situation, you don't need to see their literal search results to make inferences about a person's behavior, and I think people often forget this.
 
Microsoft wonders why the masses are giving them the middle finger where Recall and CoPilot is concerned?
 
"April 14, 2016: Microsoft filed a lawsuit with the U.S. District Court for the Western District of Washington in Seattle challenging the U.S. government’s use of indefinite and overly broad secrecy orders that prevent us from telling customers when the government accesses their data...."

"Sep 6: 2016: Long list of groups backs Microsoft in case involving digital-data privacy

Scores of technology companies, media enterprises, corporations, organizations and former law-enforcement officials filed briefs Friday in support of Microsoft’s lawsuit against the U.S. government that contends a procedure used by federal investigators to collect digital data is unconstitutional...."

It's margin. Too many cases where MS simply handed over data upon request. All your stuff gets stored in your online account. Even your bitlocker key, lol.
 
No competent government would have allowed recall to be implemented in an OS.

This just goes to prove that we don't have any competent, or people serving, government and politicians.
 
Back