Microsoft AI Can Access and Store WhatsApp and Signal Messages Without User Knowledge
Microsoft’s Recall feature, launched on Windows PCs, has raised significant privacy concerns. This AI tool secretly takes screenshots of users’ screens, including any messages sent through secure platforms like WhatsApp and Signal. The system utilizes optical character recognition (OCR) to process and save all content, including sensitive information like photos, passwords, medical conditions, and encrypted messages. Even if the sender hasn’t enabled Recall, messages they send to users with Recall activated are still captured and stored. The process occurs silently, with no notification or opt-out option for the sender. Security experts have pointed out that the system’s reliance on basic PIN protection is insufficient, making it vulnerable to hacking. Additionally, these screenshots are stored locally, which raises concerns about data security. The risk extends to messages that have been deleted or set to disappear, as Recall retains even these. Furthermore, WhatsApp’s own integration of AI, designed to summarize messages and offer writing suggestions, has only added to the confusion, with assurances of privacy being called into question. Given these issues, experts recommend avoiding sending sensitive information to users with Recall enabled.
