I'm not Richard Stallman, but...

After ensuring I didn’t misunderstand what I read, when I learned about Microsoft’s Co-Pilot Recall thing, I couldn’t help but ask myself the obvious question: ‘Just how the hell could anyone possibly believe it’s a smart idea?’. But I sort of know the answer: It’s because the obsession among corporations with pleasing investors by forcing ‘AI’ onto everything and everyone, whether we like it or not, and regardless of the ramifications.

Essentially Recall screenshots a Windows device every few seconds, and stores the images in a database or directory. It’s essentially a continuous screengrabber, recording everything one sees and does on their device. Co-Pilot then does some data harvesting ‘AI’ things with those screenshots. Wouldn’t it be great, Microsoft says, if Co-Pilot gave us a searchable timeline of everything we saw and did on our laptops over the last three months, and could show us exactly what we were browsing and/or typing at a specific point in time?

I’m certainly not alone in thinking the terms ‘infostealer’, ‘malware’ and ‘spyware’ are pretty descriptive of Recall. One MalwareBytes post describes it as Microsoft making the choice to develop an ‘AI-powered threat to security, privacy and identity’. These aren’t exaggerations, when we think about it.

Recall stores the screenshots locally, but that part of it could be disabled (and quietly re-enabled later, potentially). The bit that does the screengrabbing, however, cannot be disabled or uninstalled, and would still be running in the background. Microsoft claims the images are protected by encryption, but, since the user doesn’t have exclusive control of it, it’s not encryption I’d trust. Anyone and everything with access to the user’s account (including Microsoft) would also have access to the data.

As it stands, the obvious problem is that Recall’s database would store screenshots of everything by default: Every Web page visited, every displayed password, every email and chat message, all online banking information, the content of sensitive documents and, obviously, all the pornography that one watches. It should be apparent that everyone has something to hide. Moreso the large percentage of (non-technical!) people in executive positions with highly compromising data on their devices relating to pornography of the less ‘vanilla’ sort, gambling/debt problems and extra-marital affairs. Recall would be a massive security liability for organisations.

It wouldn’t matter if we use encrypted storage for backing up sensitive information, or if we use the best password managers for protecting our bank account details, or if we do everything possible to honour some NDA or the Official Secrets Act. All that information would be screengrabbed and potentially copied, potentially without our knowledge, to a database that’s considerably less protected. That database would be a prize target for adversaries and malware. Microsoft’s encryption doesn’t actually protect against this, or against adversaries that gain access to the user’s account, because it’s not designed to in the way some third-party encryption products would.

Unless Recall is canned (the idea is getting a lot of pushback), it would eventually be on every Windows 11 device, and it’s reasonable to assume that, in future, everything Co-Pilot harvests from the screenshots would be uploaded to Microsoft’s data centres. Indeed, simply because Recall exists, governments will sooner or later demand it becomes a means to arbitrarily access everything on anyone’s device under the pretext of law enforcement and fighting terrorism. This time, Microsoft would be in a position to readily provide that access (because Microsoft, not the user, controls the encryption), or, alternatively, modify Copilot to report users to the authorities.

But, Emma, sensitive data is already written to all kinds of obscure places in the filesystem, and it’s already possible to construct a detailed timeline of what someone did on their device.’, some might point out.

Well, yes, but the first difference is that obscurity does provide some level of security. Malware is generally not sophisticated enough to aggregate all that data, and there are several practical reasons malware authors wouldn’t want to - limited benefits, increased risk of discovery, etc. It’s much easier to write malware that’s taking screenshots and exfiltrating them slowly from one directory - or better still, from the process in system memory that’s doing the screengrabbing - and it would be much harder to detect because of its relatively small footprint. Recall would do most the work already, even if it’s ‘disabled’ and not writing the images to disk.

The other huge difference is that data breaches and identity theft generally aren’t a big deal for organisations such as Microsoft, but they absolutely can be catastrophic for individuals. When we engage in activities that involve our bank account details, we’re essentially staking everything on security that’s explicitly designed to prevent the kind of bullshit Recall does. A good password manager, for example, prevents highly sensitive data ever being written to a storage device unencrypted, and has some memory protection.

So, is there anything we can do about all this? The answer is yes, sort of. Most of us don’t get to decide what laptops are issued to us in the workplace, or what’s installed on them, but we can and should draw the line when it comes to personal devices. Since upgrading to Windows 11 on my personal laptop, I’d been tempted to replace it with Linux, and use the latter as my primary operating system for the first time in a decade. I know that’s probably easier said than done for most people, but it’s doable, and it’s now a choice between that and eventually having no privacy.