'TotalRecall Reloaded' Tool Finds a Side Entrance To Windows 11 Recall Database (arstechnica.com)
- Reference: 0181733486
- News link: https://yro.slashdot.org/story/26/04/16/2052224/totalrecall-reloaded-tool-finds-a-side-entrance-to-windows-11-recall-database
- Source link: https://arstechnica.com/gadgets/2026/04/totalrecall-reloaded-tool-finds-a-side-entrance-to-windows-11s-recall-database/
> Two years ago, Microsoft launched its first wave of "Copilot+" Windows PCs with a handful of exclusive features that could take advantage of the neural processing unit (NPU) hardware being built into newer laptop processors. These NPUs could enable AI and machine learning features that could run locally rather than in someone's cloud, theoretically enhancing security and privacy. One of the first Copilot+ features was Recall, a feature that promised to track all your PC usage via screenshot to help you remember your past activity. But as originally implemented, Recall was [1]neither private nor secure ; the feature stored its screenshots plus a giant database of all user activity in totally unencrypted files on the user's disk, making it trivial for anyone with remote or local access to grab days, weeks, or even months of sensitive data, depending on the age of the user's Recall database.
>
> After journalists and security researchers discovered and detailed these flaws, Microsoft [2]delayed the Recall rollout by almost a year and substantially [3]overhauled its security . All locally stored data would now be encrypted and viewable only with Windows Hello authentication; the feature now did a better job detecting and excluding sensitive information, including financial information, from its database; and Recall would be turned off by default, rather than enabled on every PC that supported it. The reconstituted Recall was a big improvement, but having a feature that records the vast majority of your PC usage is still a security and privacy risk. Security researcher Alexander Hagenah was the author of the original "TotalRecall" tool that made it trivially simple to grab the Recall information on any Windows PC, and an updated "TotalRecall Reloaded" version exposes what Hagenah believes are additional vulnerabilities.
>
> The problem, as detailed by Hagenah on [4]the TotalRecall GitHub page , isn't with the security around the Recall database, which he calls "rock solid." The problem is that, once the user has authenticated, the system [5]passes Recall data to another system process called AIXHost.exe , and that process doesn't benefit from the same security protections as the rest of Recall. "The vault is solid," Hagenah writes. "The delivery truck is not." The TotalRecall Reloaded tool uses an executable file to inject a DLL file into AIXHost.exe, something that can be done without administrator privileges. It then waits in the background for the user to open Recall and authenticate using Windows Hello. Once this is done, the tool can intercept screenshots, OCR'd text, and other metadata that Recall sends to the AIXHost.exe process, which can continue even after the user closes their Recall session.
>
> "The VBS enclave won't decrypt anything without Windows Hello," Hagenah writes. "The tool doesn't bypass that. It makes the user do it, silently rides along when the user does it, or waits for the user to do it." A handful of tasks, including grabbing the most recent Recall screenshot, capturing select metadata about the Recall database, and deleting the user's entire Recall database, can be done with no Windows Hello authentication. Once authenticated, Hagenah [6]says the TotalRecall Reloaded tool can access both new information recorded to the Recall database as well as data Recall has previously recorded.
"We appreciate Alexander Hagenah for identifying and responsibly reporting this issue. After careful investigation, we determined that the access patterns demonstrated are consistent with intended protections and existing controls, and do not represent a bypass of a security boundary or unauthorized access to data," a Microsoft spokesperson told Ars. "The authorization period has a timeout and anti-hammering protection that limit the impact of malicious queries."
[1] https://it.slashdot.org/story/24/06/06/1626228/microsoft-has-lost-trust-with-its-users-and-windows-recall-is-the-straw-that-broke-the-camels-back
[2] https://it.slashdot.org/story/24/06/14/0318213/microsoft-postpones-windows-recall-after-major-backlash?sdsrc=rel
[3] https://it.slashdot.org/story/25/04/25/1830232/microsoft-launches-windows-recall-after-year-long-delay
[4] https://github.com/xaitax/TotalRecall
[5] https://arstechnica.com/gadgets/2026/04/totalrecall-reloaded-tool-finds-a-side-entrance-to-windows-11s-recall-database/
[6] https://www.linkedin.com/posts/alexhagenah_breaking-%F0%9D%90%96%F0%9D%90%A2%F0%9D%90%A7%F0%9D%90%9D%F0%9D%90%A8%F0%9D%90%B0%F0%9D%90%AC-%F0%9D%90%91%F0%9D%90%9E%F0%9D%90%9C%F0%9D%90%9A%F0%9D%90%A5%F0%9D%90%A5-again-ugcPost-7447864303682170880-lUih/
Recall wasn't there to help the user! (Score:3)
Recall is there to vacuum up all the sensitive data "on" the computer and make it available to Microsoft and their partners for their use.
TBH, I don't see how the Federal Government can use a Microsoft product and meet their government required security rules. CJIS for example and the handling of CHRI(Federal Criminal Records History Information) scanning and recording every background check that was opened and sending/saving/transmitting the info(somewhere Microsoft wants it?) seems like a huge no-no. Is Recall On/Off and it is managed by who?
Re: (Score:2)
> Recall is there to vacuum up all the sensitive data "on" the computer and make it available to Microsoft and their partners for their use.
I liken it to telemetry that can apply to all software / activities on a system - even third-party software - w/o having embed telemetry in any software. Simply screenshot things every few seconds and scan the images with OCR and/or "AI". Truly a horrible situation for the end-users.
Why? (Score:3)
> Recall, a feature that promised to track all your PC usage via screenshot to help you remember your past activity.
Who asked for this?
Re: (Score:1)
HR dept
Re: (Score:2)
>> Recall, a feature that promised to track all your PC usage via screenshot to help you remember your past activity.
> Who asked for this?
The people at Microsoft who wanted more universal telemetry and activity data, even for non-Microsoft software?
Well. (Score:3)
0.0 people saw that coming ;-D
Microsoft has managed to extend your threat... (Score:3)
Microsoft has managed to extend your cyber-attack surface into the 4th dimension. Cybersecurity threats are an inside job. Windows is malware and Microsoft is a threat to national security.
Get your ass to Mars (Score:2)
Because there is no Microsoft there ... yet.
Re: (Score:2)
Don't you watch For All Mankind? Everyone there uses a Zune instead of iThings.
Re: (Score:2)
Two Microsoft Outlooks open and not working - coming to a red planet soon.
Since NTSYNC is now implemented in the kernel (Score:3)
I've left Windows - and not looking back.....
shit like this....
and Bluehammer - that I don't think is getting talked about much.
[1]https://www.youtube.com/watch?... [youtube.com]
[1] https://www.youtube.com/watch?v=EDZMvSK1R28