Microsoft has now delayed the feature multiple times to address those concerns, and it outlined multiple security-focused additions to Recall in a blog post in September. Among other changes, the feature is now opt-in by default and is protected by additional encryption. Users must also re-authenticate with Windows Hello each time they access the database. Turning on the feature requires Secure Boot, BitLocker disk encryption, and Windows Hello to be enabled. In addition to the manual exclusion lists for sites and apps, the new Recall also attempts to mask sensitive data like passwords and credit card numbers so they aren’t stored in the Recall database.
The new version of Recall can also be completely uninstalled for users who have no interest in it, or by IT administrators who don’t want to risk it exposing sensitive data.
Testers will need to kick the tires on all of these changes to make sure that they meaningfully address all the risks and issues that the original version of Recall had, and this Windows Insider preview is their chance to do it.
“Do security”
Part of the original Recall controversy was that Microsoft wasn’t going to run it through the usual Windows Insider process—it was intended to be launched directly to users of the new Copilot+ PCs via a day-one software update. This in itself was a big red flag; usually, even features as small as spellcheck for the Notepad app go through multiple weeks of Windows Insider testing before Microsoft releases them to the public. This gives the company a chance to fix bugs, collect and address user feedback, and even scrub new features altogether.
Microsoft is supposedly re-orienting itself to put security over all other initiatives and features. CEO Satya Nadella recently urged employees to “do security” when presented with the option to either launch something quickly or launch something securely. In Recall’s case, the company’s rush to embrace generative AI features almost won out over that “do security” mandate. If future AI features go through the typical Windows Insider testing process first, that will be a sign that Microsoft is taking its commitment to security seriously.
Other Humane charging accessories, like the Charge Pad, are said to be unaffected because Humane doesn’t use the same unnamed vendor for any parts besides the Charge Case Accessory’s battery.
Humane’s statement puts the blame on this anonymous third-party vendor. The company said it realized there was a problem when a user reported a “charging issue while using a third-party USB-C cable and third-party power source.” The company added:
Our investigation determined that the battery supplier was no longer meeting our quality standards and that certain battery cells supplied by this vendor may pose a fire safety risk. As a result, we immediately disqualified this battery vendor while we work to identify a new vendor to avoid such issues and maintain our high quality standards.
Impacted customers can get a refund for the accessory (up to $149) or a replacement via an online form. While refunds will go through within 14 business days, users seeking a replacement Charge Case Accessory have to wait until Humane makes one. That could take three to six months, the San Francisco firm estimates.
In the meantime, Humane is telling customers to properly dispose of their Charge Case Accessories (which means not throwing them in a trash can or the used battery recycling boxes found at some stores).
Another obstacle for Humane
A well-executed recall in the name of user safety isn’t automatically a death knell for a product, but Humane has already been struggling to maintain a positive reputation, and its ability to sell AI Pins in the long term was already in question before this mishap.
The AI Pin’s launch was marred by a myriad of complaints, including the pin’s inability to properly clip to some clothing, slow voice responses, short battery life, limitations with the laser projector working outside of dark rooms, and overall limited functionality. Soon after the product was released, The New York Times reported that the company’s founders, two former Apple executives, ignored negative internal reviews and even let go of an engineer who questioned the product. Humane spokesperson Zoz Cuccias admitted to The Verge in August that upon releasing the wearable, Humane “knew we were at the starting line, not the finish line.”
Software fixes are now responsible for more than 1 in 5 automotive recalls. That’s the key finding from a decade’s worth of National Highway Traffic Safety Administration recall data, according to an analysis from the law firm DeMayo Law. While that’s a sign of growing inconvenience for drivers, the silver lining is that a software patch is usually a much quicker fix than something requiring hardware replacement.
“Our analysis suggests we’re witnessing a shift in how automotive recalls are handled. The growing number of software-related recalls, coupled with the ability to address issues remotely, could revolutionize the recall process for both manufacturers and vehicle owners,” said a spokesperson for DeMayo Law.
In 2014, 34 of 277 automotive recalls were software fixes. The percentage of software recalls floated around 12–13 percent (apart from a spike in 2015) before growing steadily from 2020. In 2021, 16 percent of automotive recalls (61 out of 380) were for software. In 2022, almost 22 percent of recalls were software fixes (76 out of 348), and last year topped 23 percent (82 out of 356).
Leading the way was Chrysler, with 82 different software recalls since 2014. Ford (66 recalls) and Mercedes-Benz (60) are the two runner-ups. Meanwhile, Tesla ranks only eighth, with 26 software recalls since 2014, which puts it on par with Hyundai (25) and Kia (25).
Electrical systems were the most common problem area, which makes sense—this is also the second-most common hardware fix recall and would probably be the top if it were not for the massive Takata airbag recall, which has affected more than 100 million cars worldwide.
The other common systems affected by recalls requiring software remedies were related to backover prevention—whether that be reversing cameras, collision warnings, or automatic emergency braking—airbags, powertrains, and exterior lighting.
It should be noted that not all recalls involving a software fix are to solve a software problem. Take the recent Jaguar I-Pace recall, which was triggered by battery fires caused by battery cells damaged during assembly. Jaguar’s fix? A software update that sets a new, lower limit to the storage capacity of the battery pack, preventing it from fully charging to 100 percent.
While many older vehicles from legacy OEMs require a trip to the dealer to be patched, more and more new models can be updated over the air, meaning that owners can have the recall performed from the comfort of their own parking space, provided they have connectivity. Even this isn’t hassle-free, though, as some Rivian owners found out to their dismay late last year when an update broke some infotainment screens.
Expect this to become more common
To hear carmakers tell it, customers see their smartphone and games console and want that kind of entertainment built into their next car. (Whether that’s true is up for debate, however.) Software competency is a new battleground between global automakers, and the fear of Chinese brands is strong despite an impending ban on Chinese-connected car software, which looks likely to be put into effect in a couple of years.
So, it’s highly likely the trend of fixing product flaws with software will only escalate, particularly with the introduction of software-defined vehicles. This represents a clean-sheet approach to designing a car, with a handful of powerful computers replacing tens of dozens of black boxes, each with a single function. Which is great when it all works, but it’s a headache when there are problems.
Anker is recalling three models of MagSafe iPhone batteries due to a fire risk, it said yesterday.
The models being recalled are the Anker 334 MagGo Battery (PowerCore 10K, model number A1642), Anker Power Bank (model number A1647), and Anker 334 MagGo Battery (model number A1652). In its recall notice, Anker said that some of the lithium-ion batteries in the devices “may pose a fire risk due to a manufacturing defect.”
“The lithium-ion battery in the affected power banks can overheat, potentially causing melting of plastic components, smoke, and fire hazards,” the notice reads.
Anker claims that only products made from January 3 to September 17 are affected but says it’s recalling all units “out of an abundance of caution.”
Anker says that people who own one of these products should “immediately stop using” it. Owners should store the affected products “in a safe location” and use Anker’s website to verify their device’s serial number before filling out a recall form and getting a replacement.
Anker’s recall notice also included tips for safely disposing of power banks, reminding people not to toss them in the trash.
If you own an Anker battery pack and want to check if it’s being recalled, you can look at the bottom of the device for the aforementioned product names and model numbers (A1642, A1647, and A1652) as shown below:
To date, 57 people across 18 states have been sickened, all of whom required hospitalization. A total of eight have died. The latest tally makes this the largest listeriosis outbreak in the US since 2011, when cantaloupe processed in an unsanitary facility led to 147 Listeria infections in 28 states, causing 33 deaths, the CDC notes.
The new cases and deaths come after a massive recall of more than 7 million pounds of Boar’s Head meat products, which encompassed 71 of the company’s products. That recall was announced on July 30, which itself was an expansion of a July 26 recall of an additional 207,528 pounds of Boar’s Head products. By August 8, when the CDC last provided an update on the outbreak, the number of cases had hit 43, with 43 hospitalizations and three deaths.
In a media statement Wednesday, the CDC says the updated toll of cases and deaths is a “reminder to avoid recalled products.” The agency noted that the outbreak bacteria, Listeria monocytogenes, is a “hardy germ that can remain on surfaces, like meat slicers, and foods, even at refrigerated temperatures. It can also take up to 10 weeks for some people to have symptoms of listeriosis.” The agency recommends that people look through their fridges for any recalled Boar’s Head products, which have sell-by dates into October.
If you find any recalled meats, do not eat them, the agency warns. Throw them away or return them to the store where they were purchased for a refund. The CDC and the US Department of Agriculture also recommend that you disinfect your fridge, given the germs’ ability to linger.
L. monocytogenes is most dangerous to people who are pregnant, people age 65 years or older, and people who have weakened immune systems. In these groups, the bacteria are more likely to move beyond the gastrointestinal system to cause an invasive listeriosis infection. In older and immunocompromised people, listeriosis usually causes fever, muscle aches, and tiredness but may also cause headache, stiff neck, confusion, loss of balance, or seizures. These cases almost always require hospitalization, and 1 in 6 die. In pregnant people, listeriosis also causes fever, muscle aches, and tiredness but can also lead to miscarriage, stillbirth, premature delivery, or a life-threatening infection in their newborns.
The Food and Drug Administration has been warning for years that some tattoo inks are brimming with bacteria—a large assortment that, when injected into your skin, can cause inflammatory reactions, allergic hypersensitivity, toxic responses, and, of course, straight-up infections. And, worse yet, the labels that say the inks are sterile are not reliable.
But, a recent recall of three tattoo pigments from the same manufacturer does a good job of illustrating the FDA’s concerns. The water-based inks, all from Sierra Stain, had a bizarre array of bacteria, which were found at high levels, according to FDA testing.
One ink product—described as “Carolina Blue”—offered a microbial menagerie, with six odd species identified. They included a bacterium that often dwells in the gastrointestinal system and can inflame the mucosal lining of the intestines (Citrobacter braakii), a water-borne bacterium (Cupriavidus pauculus), and several that cause opportunistic infections (Citrobacter farmer, Achromobacter xylosoxidans, Ochrobactrum anthropi, and Pseudomonas fluorescens). These are bacteria that don’t typically go about attacking humans but will if the conditions are right, including when they find themselves inside a human with a compromised immune system.
An ink called “UV China Pink” contained an unusual soil bacterium (Curtobacterium citreum/pusillum). And an “All Purpose Black” ink puzzlingly contained Acetobacter senegalensis, a bacterium first isolated from mangos in Senegal and used for industrial vinegar production in low-income countries.
The three inks were sold nationwide through Amazon. To date, there have been no reported infections or adverse reactions linked to these inks. But the FDA notes that reactions to contaminated inks can be difficult to accurately diagnose. The infections and skin responses can look like generic rashes and allergic responses, sometimes including lesions with red papules in areas where the ink was injected, the FDA notes. However, infections from tattoo ink can leave permanent scarring.
In a study published in July in Applied and Environmental Microbiology, FDA researchers tested 75 samples of tattoo and permanent makeup inks from 14 manufacturers. Of the 75 inks, 26 (35 percent) were contaminated with a total of 34 types of bacteria, many that were possibly disease-causing. Some of the bacteria were anaerobic, meaning they don’t need oxygen to grow, suggesting they could thrive in the low-oxygen environment of skin layers. Of the 40 tattoo inks specifically, nine (22 percent) were contaminated. Among all the ink samples, 49 were labeled “sterile” and, of those, 16 (33 percent) were contaminated.
The recall announcement noted that Sierra Stain is no longer in business. While the company lists a remaining email address, it did not immediately respond to a comment request from Ars on the bacteria found in their inks.
The FDA recommends that consumers be vigilant about the quality and safety of tattoo supplies and techniques. It also encourages tattoo artists to work in professional environments that can reduce the risk of contamination.
Microsoft will begin sending a revised version of its controversial Recall feature to Windows Insider PCs beginning in October, according to an update published today to the company’s original blog post about the Recall controversy. The company didn’t elaborate further on specific changes it’s making to Recall beyond what it already announced in June.
For those unfamiliar, Recall is a Windows service that runs in the background on compatible PCs, continuously taking screenshots of user activity, scanning those screenshots with optical character recognition (OCR), and saving the OCR text and the screenshots to a giant searchable database on your PC. The goal, according to Microsoft, is to help users retrace their steps and dig up information about things they had used their PCs to find or do in the past.
The problem was that other users on the same PC, or attackers with physical or remote access to your PC, could easily access, view, and export those screenshots and the OCR database since none of the information was encrypted at rest or protected in any substantive way.
Microsoft had planned to launch Recall as one of the flagship features of its Copilot+ PC launch in July, along with the new Qualcomm Snapdragon-powered Surface devices, but its rollout was bumped back and then paused entirely so that Recall could be reworked and then sent out to Windows Insiders for testing like most other Windows features are.
Among the changes Microsoft has said it will make: The database will be encrypted at rest and will require authentication (and periodic reauthentication) with Windows Hello before users will be allowed to access it. The feature will also be off by default, whereas the original plan was to turn it on by default and make users go into Settings to turn it off.
“Security continues to be our top priority and when Recall is available for Windows Insiders in October we will publish a blog with more details,” reads today’s update to Microsoft Windows and Devices Corporate Vice President Pavan Davuluri’s blog post.
When the preview is released, Windows Insiders who want to test the Recall preview will need to do it on a PC that meets Microsoft’s Copilot+ system requirements. Those include a processor with a neural processing unit (NPU) capable of at least 40 trillion operations per second (TOPS), 16GB of RAM, and 256GB of storage. The x86 builds of Windows for Intel and AMD processors don’t currently support any Copilot+ features regardless of whether the PC meets those requirements, but that should change later this year.
That said, security researchers and reporters who found the holes in the original version of Recall could only find them because it was possible to enable them on unsupported PCs, just as it’s possible to run Windows 11 on PCs that don’t meet the system requirements. It’s possible that users will figure out how to get Recall and other Copilot+ features running on unsupported PCs at some point, too.
Over 7 million pounds of Boar’s Head brand deli meats are being recalled amid a bacterial outbreak that has killed two people. The outbreak, which began in late May, has sickened a total of 34 people across 13 states, leading to 33 hospitalizations, according to the US Department of Agriculture.
On June 26, Boar’s Head recalled 207,528 pounds of products, including liverwurst, beef bologna, ham, salami, and “heat and eat” bacon. On Tuesday, the Jarratt, Virginia-based company expanded the recall to include about 7 million additional pounds of meat, including 71 different products sold on the Boar’s Head and Old Country brand labels. The products were sold nationwide.
The meats may be contaminated with Listeria monocytogenes, a foodborne pathogen that is particularly dangerous to pregnant people, people over the age of 65, and people with compromised immune systems. Infections during pregnancy can cause miscarriage, stillbirth, premature delivery, or a life-threatening infection in newborns. For others who develop invasive illness, the fatality rate is nearly 16 percent. Symptoms of listeriosis can include fever, muscle aches, headache, stiff neck, confusion, loss of balance, and convulsions that are sometimes preceded by diarrhea or other gastrointestinal symptoms.
The problem was discovered when the Maryland Department of Health—working with the Baltimore City Health Department—collected an unopened liverwurst product from a retail store and found that it was positive for L. monocytogenes. In later testing, the strain in the liverwurst was linked to those isolated from people sickened in the outbreak.
According to the Centers for Disease Control and Prevention, six of the 34 known cases were identified in Maryland, and 12 were identified in New York. The other 11 states have only reported one or two cases each. However, the CDC expects the true number of infections to be much higher, given that many people recover without medical care and, even if people did seek care, health care providers do not routinely test for L. monocytogenes in people with mild gastrointestinal illnesses.
In the outbreak so far, there has been one case in a pregnant person, who recovered and remained pregnant. The two deaths occurred in New Jersey and Illinois.
In a statement on the company’s website, Boar’s Head said that it learned from the USDA on Monday night that L. monocytogenes strain in the liverwurst linked to the multistate outbreak. “Out of an abundance of caution, we decided to immediately and voluntarily expand our recall to include all items produced at the Jarratt facility. We have also decided to pause ready-to-eat operations at this facility until further notice. As a company that prioritizes safety and quality, we believe it is the right thing to do.”
The USDA said it is “concerned that some product may be in consumers’ refrigerators and in retail deli cases.” The USDA, the company, and CDC warn people not to eat the recalled products. Instead, they should either be thrown away or returned to the store where they were purchased for a full refund. And if you’ve purchased one of the recalled products, the USDA also advises you to thoroughly clean your fridge to prevent cross-contamination.
After weeks of reports of severe illnesses across the country, the maker of Diamond Shruumz microdosing chocolates, gummies, and candy cones has finally issued a recall. It covers all lots and all flavors of all the brand’s products.
The illnesses have been marked by several severe symptoms, which notably include seizures, loss of consciousness, and the need for intubation and intensive care. To date, there have been 39 people sickened, including 23 hospitalizations across 20 states, according to the Food and Drug Administration and the Centers for Disease Control and Prevention. The FDA first issued a warning on the brand’s chocolate bars on June 7, when there were reports of eight cases, including six hospitalizations, in four states.
Diamond Shruumz’s parent company, Prophet Premium Blends, said in the recall notice that it had received only two complaints about the products to date and, upon receiving those complaints, reviewed recent laboratory analyses (Certificates of Analysis) of its products. According to the company, those CoAs noted “higher than normal amounts of muscimol,” which is one of two key compounds found in hallucinogenic Amanita mushrooms. Muscimol “could be a potential cause of symptoms consistent with those observed in persons who became ill after eating Diamond Shruumz products,” the company said in the recall notice.
In a statement posted on Diamond Shruumz’s website, Prophet Premium Blends announced the recall and added that it has also ceased production and distribution of all of the brand’s products.
“Due to consumers becoming ill after consuming the entire chocolate bar and some products containing higher levels of Muscimol than normal, it is crucial that all of our consumers refrain from ingesting this product while we, alongside the FDA, continue our investigation as to what is the cause of the serious adverse effects,” Prophet Premium Blends wrote on its website.
Diamond Shruumz has not responded to multiple requests for comment from Ars. Prophet Premium Blends did not respond to a request for comment and a list of questions.
What’s normal?
It’s unclear what amounts of muscimol were found in the company’s products and which products were affected. While the company reported only “higher than normal” amounts, it’s also unclear what the “normal” amount is. Diamond Shruumz posts third-party lab reports on its website, most of which indicate that the products are tested for muscimol. For instance, the reports show muscimol testing for all flavors of Cones and Extreme Gummies. For the brand’s chocolate bars, which the FDA first linked to the illnesses, all the bars except for the dark chocolate flavor showed muscimol results. For the gummies, only the report for the Hawaiian Punch flavor shows muscimol results. Of all the reports that include results for muscimol, all indicate that the amounts are lower than the limit of quantitation, which suggests that they are not supposed to contain any amount of muscimol. All of the reports reviewed by Ars were dated at various times throughout 2023.
Muscimol, along with related ibotenic acid, are both key psychoactive components of some Amanita mushrooms. That includes the hallucinogenic toadstool mushroom A. muscaria var. muscaria, which is notable for its unique bright red-orange caps with white warts. Both muscimol and ibotenic acid resemble neurotransmitters, namely GABA and glutamate, respectively. Muscimol is associated with depression of the central nervous system, while Ibotenic acid is associated with excitation of the central nervous system.
Fuzzy findings
According to the recall notice, it’s possible that the muscimol could cause some of the symptoms in people sickened, which included seizures, agitation, involuntary muscle contractions, loss of consciousness, confusion, sleepiness, nausea and vomiting, abnormal heart rates, and hyper/hypotension. The FDA said in its own update that it was “evaluating this information.”
The totality of the ingredients in Diamond Shruumz’s products remains unclear. The company does not list the ingredients on its website, selling the products only with terms indicating they contain psychedelic compounds and the vague, buzzword-loaded description of having a “primo proprietary blend of nootropic and functional mushrooms.”
The CDC warns that such “edibles” are often sold as candies and snack food and might contain undisclosed ingredients, including illicit substances, adulterants, or potentially harmful contaminants. Common marketing terms to look out for include “microdosing,” “adaptogens,” “nootropics,” and “functional mushrooms,” the CDC warns.
Consumers should not eat, sell, or serve any Diamond Shruumz product. For those who have already purchased the products, they can be returned for a full refund to 1019 Arlington St., Orlando, Florida, 32805, according to Diamond Shruumz’s website.
Cases of illnesses linked to microdosing candies have more than doubled, with reports of seizures and the need for intubation, mechanical ventilation, and intensive care stays. But, there remains no recall of the products—microdosing chocolates, gummies, and candy cones by Diamond Shruumz—linked to the severe and life-threatening illnesses. In the latest update from the Food and Drug Administration late Tuesday, the agency said that it “has been in contact with the firm about a possible voluntary recall, but these discussions are still ongoing.”
In the update, the FDA reported 26 cases across 16 states, up from 12 cases in eight states last week. Of the 26 reported cases, 25 sought medical care and 16 were hospitalized. No deaths have been reported.
Last week, the Centers for Disease Control and Prevention released a health alert about the candies. The agency noted that as of June 11, the people sickened after eating Diamond Shruumz candies presented to health care providers with a host of severe symptoms. Those include: central nervous system depression with sedation, seizures, muscle rigidity, clonus (abnormal reflex responses), tremor, abnormal heart rate (bradycardia or tachycardia), abnormal blood pressure (hypotension or hypertension), gastrointestinal effects (nausea, vomiting, or abdominal pain), skin flushing, diaphoresis (excessive sweating), and metabolic acidosis with increased anion gap (an acid-based disorder linked to poisonings).
At the time of the CDC alert, 10 patients had been hospitalized, and “several required intubation, mechanical ventilation, and admission to an intensive care unit,” the agency reported.
It remains unclear what ingredient in the candies could be causing the poisonings. The FDA reports that it has worked with state partners to collect multiple samples of Diamond Shruumz products so they can be analyzed for potential toxic components. That analysis is still ongoing, the agency said.
Diamond Shruumz has not responded to multiple requests for comment from Ars.
Untold toxic ingredients
Diamond Shruumz does not list the ingredients of its products on its website. They are sold as “microdosing” candies, a term that typically suggests a small amount of a psychedelic compound is present. The company describes its chocolates, gummies, and cones as “trippy,” “psychedelic,” and “hallucinogenic,” and also claims they contain a “primo proprietary blend of nootropic and functional mushrooms.” But, it’s unclear what, if any, psychoactive compound is present in the candies.
The CDC notes that products like these “might contain undisclosed ingredients, including illicit substances, other adulterants, or potentially harmful contaminants that are not approved for use in food.”
Diamond Shruumz posted documents on its website from third-party laboratories claiming to indicate that the candies do not contain the most notable mushroom-derived psychedelic compound, psilocybin. The reports also indicate that some of the products do not contain cannabinoids or compounds from the hallucinogenic Amanita muscaria mushroom. Additionally, the company said in a blog post that its products contain a blend of Lion’s mane, Reishi, and Chaga mushrooms, but these are all non-hallucinogenic mushrooms used in herbal and traditional medicines and supplements.
In recent decades, hundreds of new synthetic psychoactive substances have hit the market in such products, including many new phenethylamines and tryptamines, which are chemically related to LSD and psilocybin. Some experts and members of the psychedelic community have speculated that Diamond Shruumz products could potentially contain one of the more popular tryptamines, 4-AcO-DMT, often pronounced “4-akko-DMT,” and also known as 4- acetoxy-N,N-dimethyltryptamine, O-acetylpsilocin, or psilacetin. According to a qualitative 2020 study, users describe 4-AcO-DMT as producing effects similar to psilocybin, but without some of the unpleasant side effects noted with natural mushrooms, such as nausea. Animal experiments have confirmed that 4-AcO-DMT appears to produce psilocybin-like effects.
Still, it’s unclear if such ingredients could explain the symptoms seen in the current outbreak. Though clinical data on 4-AcO-DMT is scant, it has not been linked to such severe symptoms. On the other hand, some novel synthetic compounds, such as Dox and NBOMe, often misrepresented as LSD, are considered dangerous. For instance, NBOMe compounds (N-methoxybenzyl, also called N-bombs or 251), first discovered in 2003, have been linked to overdoses and deaths. In the scientific literature, they’ve been linked to “unpleasant hallucinations, panic, agitation, hypertension, seizures, acute psychosis, and/or excited delirium that can result in cardiac arrest,” according to the 2020 study.
Microsoft will be delaying its controversial Recall feature again, according to an updated blog post by Windows and Devices VP Pavan Davuluri. And when the feature does return “in the coming weeks,” Davuluri writes, it will be as a preview available to PCs in the Windows Insider Program, the same public testing and validation pipeline that all other Windows features usually go through before being released to the general populace.
Recall is a new Windows 11 AI feature that will be available on PCs that meet the company’s requirements for its “Copilot+ PC” program. Copilot+ PCs need at least 16GB of RAM, 256GB of storage, and a neural processing unit (NPU) capable of at least 40 trillion operations per second (TOPS). The first (and for a few months, only) PCs that will meet this requirement are all using Qualcomm’s Snapdragon X Plus and X Elite Arm chips, with compatible Intel and AMD processors following later this year. Copilot+ PCs ship with other generative AI features, too, but Recall’s widely publicized security problems have sucked most of the oxygen out of the room so far.
The Windows Insider preview of Recall will still require a PC that meets the Copilot+ requirements, though third-party scripts may be able to turn on Recall for PCs without the necessary hardware. We’ll know more when Recall makes its reappearance.
Why Recall was recalled
Recall works by periodically capturing screenshots of your PC and saving them to disk, and scanning those screenshots with OCR to make a big searchable text database that can help you find anything you had previously viewed on your PC.
The main problem, as we confirmed with our own testing, was that all of this was saved to disk with no additional encryption or other protection and was easily viewable and copyable by pretty much any user (or attacker) with access to the PC. Recall was also going to be enabled by default on Copilot+ PCs despite being a “preview,” meaning that users who didn’t touch the default settings were going to have all of this data recorded by default.
This was the version of Recall that was initially meant to ship out to reviewers this week on the first wave of Copilot+ PCs from Microsoft and other PC companies. After security researcher Kevin Beaumont publicized these security holes in that version of Recall, the company promised to add additional encryption and authentication protections and to disable Recall by default. These tweaks would have gone out as an update to the first shipments of Copilot+ PCs on June 18 (reviewers also wouldn’t get systems before June 18, a sign of how much Microsoft was rushing behind the scenes to implement these changes). Now Recall is being pushed back again.
A report from Windows Central claims that Recall was developed “in secret” and that it wasn’t even distributed widely within Microsoft before it was announced, which could explain why these security issues weren’t flagged and fixed before the feature showed up in a publicly available version of Windows.
Microsoft’s Recall delay follows Microsoft President Brad Smith’s testimony to Congress during a House Committee on Homeland Security hearing about the company’s “cascade of security failures” in recent months. Among other things, Smith said that Microsoft would commit to prioritizing security issues over new AI-powered features as part of the company’s recently announced Secure Future Initiative (SFI). Microsoft has also hired additional security personnel and tied executive pay to meeting security goals.
“If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security,” wrote Microsoft CEO Satya Nadella in an internal memo about the SFI announcement. “In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems.”
Recall has managed to tie together all the big Windows and Microsoft stories from the last year or two: the company’s all-consuming push to quickly release generative AI features, its security failures and subsequent promises to do better, and the general degradation of the Windows 11 user interface with unwanted apps, ads, reminders, account sign-in requirements, and other cruft.