A new class of Windows PC
Microsoft defined Copilot+ PCs by a hardware floor: a neural processing unit capable of at least 40 trillion operations per second, run alongside the CPU and GPU so AI workloads execute on the device rather than in the cloud. The first machines to qualify used Qualcomm's Snapdragon X Elite and Snapdragon X Plus chips, with Microsoft saying it expected Intel and AMD parts, starting with Lunar Lake and Strix Point, to qualify later. Pre-orders opened the day of the announcement; devices from Microsoft's own Surface line and from Acer, Asus, Dell, HP, Lenovo and Samsung were set to ship June 18, 2024, starting at $999. [1]
Atlas interpretation: The NPU floor was the actual news. Microsoft was not describing a faster laptop; it was setting a hardware requirement that only a new generation of silicon met, which is why the launch lineup ran through three chipmakers rather than one. Everything the announcement built on top of that floor, Recall included, depended on local NPU capacity that older Windows PCs simply did not have. [1]
Recall as pitched
Recall was the flagship feature reserved for Copilot+ hardware: a searchable, scrollable timeline built from snapshots the PC took of the screen every few seconds, letting a user find something they had seen or done days earlier by describing it rather than remembering where it was. Microsoft said snapshots were saved and processed locally, never sent to the cloud, and that users could pause the feature, delete snapshots, or filter out specific apps and sites. Recall entered preview June 18, 2024, alongside the rest of the Copilot+ lineup. [1]
Atlas interpretation: "Photographic memory" for a PC is also, structurally, a standing record of everything a user has ever seen on it: banking sessions, medical portals, private messages, whatever crossed the screen. Microsoft's privacy answer was local processing and after-the-fact user controls, deletion, pausing, per-app filters, rather than limiting what got captured in the first place. That design choice is what security researchers tested within days of the announcement. [1]
The plaintext problem
Security researchers examining preview builds found that Recall's screenshots and the text extracted from them were stored in a local, unencrypted database, readable by any process with access to the machine. A proof-of-concept tool called TotalRecall demonstrated that the data could be pulled out and searched with no special privileges, and researchers noted the database captured whatever had been on screen, including passwords and financial account numbers, since Microsoft's own documentation stated Recall performs no content moderation and "will not hide information such as passwords or financial account numbers." That combination meant any malware already capable of running code on the machine, an info stealer, for instance, could harvest months of a user's on-screen activity in one file. [2]
Atlas interpretation: Local-only storage, the reassurance Microsoft led with, turned out to be the least important variable. What mattered was whether the local copy was encrypted and gated, and in the preview builds researchers tested, it was neither in any meaningful way. A feature marketed on privacy grounds shipped, in its first tested form, as a single searchable file an attacker with any foothold on the machine could read straight through. [2]
Microsoft pulls back, twice
On June 7, 2024, Microsoft said Recall would ship off by default rather than on, requiring a user to opt in, and that Windows Hello enrollment plus proof of presence would be required to enable it and to view or search the timeline afterward. That was not enough to hold the original date: on June 13, Microsoft announced it was pulling Recall from the general Copilot+ PC release entirely and would instead preview it first to Windows Insiders "in the coming weeks," language the company tied to "our commitment to providing a trusted, secure and robust experience." The Windows Insider preview slipped again, to October 2024 as of an August 21 update, and again to December 2024 as of an October 31 update, each time citing continued work on Recall's security and privacy architecture. [3][2]
On September 27, 2024, Microsoft detailed the rearchitected version: snapshots are encrypted at rest with keys protected by the Trusted Platform Module and tied to Windows Hello Enhanced Sign-in Security, snapshot processing and search run inside a Virtualization-based Security enclave isolated from the rest of the operating system, and viewing or searching the timeline requires re-authenticating with Windows Hello biometrics. Recall remained opt-in, off unless a user chose otherwise during setup, and Microsoft added the ability to uninstall it entirely through Windows' optional features settings. Sensitive-content filtering, on by default, was added to reduce capture of passwords, national ID numbers and credit card numbers. [4]
Atlas interpretation: The eventual design, encrypted at rest, processed in an isolated enclave, gated behind biometric re-authentication, uninstallable, is close to what a feature storing a record of everything on a user's screen arguably needed from the start. Microsoft did not arrive there through pre-launch design review; it arrived there over four months of delays that followed public demonstrations that the original scheme could be defeated by any malware already on the machine. The gap between the May 20 pitch and the September 27 architecture is the story: a feature announced as ready for a hardware launch, then rebuilt under outside scrutiny before it reached most of the users it was announced for. [3][4]
Sources
- Introducing Copilot+ PCs
Microsoft · May 20, 2024
- Microsoft Recall delayed after privacy and security concerns
Malwarebytes · Jun 17, 2024
- Update on the Recall preview feature for Copilot+ PCs
Windows Blog (Microsoft) · Jun 7, 2024
- Update on Recall security and privacy architecture
Windows Blog (Microsoft) · Sep 27, 2024