Last time Microsoft talked about the possibility of uninstalling its controversial Recall feature, stating that it was a simple bug, which would be fixed shortly. In Redmond they seem obsessed with its launch, and spent the last months optimizing the security profile. The most relevant news, however, is this: it will be a completely opt-in experience, requires all Windows 11 security parameters … and we can remove it from the system.
The initial version of Windows Recall only turned the nightmares of many security experts into reality: its database was not encrypted, and anything (read: “malware”) could have accessed its content. Faced with the wave of negative reactions, Redmond's decision was to reshuffle and deal again, incorporating details that are important to the company... but that should have been there from the beginning. David Weston, vice president of “Enterprise and OS Security” at Microsoft, recently spoke with The Verge and explained some of the changes:
Windows Recall: Opt-in, Encryption, and Uninstallable
The first thing Weston highlights (and Microsoft on its official blog) is that Recall will be an opt-in experience. The initial version of Recall came enabled by default, but now it must be manually selected during OOBE setup.
Another essential change for Recall is encryption: The keys will be tied to the TPM module (which Windows 11 “requires” for installation in the first place), and it will also demand a “proof of presence”. What does that mean exactly? The user must log in via Windows Hello, configuring their face or a fingerprint before being able to enable PIN support (which Hello sees as a fallback mode).
Third, the possibility of uninstalling Recall appears. That's right, the bug became a feature, and Weston confirmed that if the user decides to remove Recall from their system, the action will “remove the bits”. This extends to all the artificial intelligence models that Recall uses.
Recall works on what Microsoft calls “VBS Enclave”, essentially a virtual machine that keeps everything isolated. The user will also be able to filter specific apps and web pages, set retention times, and allocate a fixed amount of space for snapshots. Sensitive content (passwords, card numbers, other forms of ID) is filtered by default, and an icon in the system tray will report the status of the snapshots, as well as serve as a shortcut to pause them.
Finally, Recall will verify all security measures in Windows 11 (along with the aforementioned TPM), and it won't work if any of them is missing. In other words, it will be restricted to “Copilot Plus” PCs, and its preview will continue during the month of October in Insider.
Sources: The Verge, Microsoft