https://arstechnica.com/gadgets/2025/04/in-depth-with-windows-11-recall-and-what-microsoft-has-and-hasnt-fixed/

I'm noticing that recall's auth methods via Microsoft Hello are all things you can be compelled to give up.

  • biometrics
  • PIN
In depth with Windows 11 Recall—and what Microsoft has (and hasn’t) fixed

Original botched launch still haunts new version of data-scraping AI feature.

Ars Technica

I'm not keen about biometrics at all. Like, MS says Recall data stays on-device, but what happens when there's a patch where it suddenly doesn't stay on the device anymore? Windows hello can be used for both local and web auth. What data about our biometrics is being stored out there?

Because once that data is out there, YOU CAN'T FUCKIN' CHANGE IT

@da_667 (Similar stance on the use of biometrics (it's generally a bad idea as the primary/only factor), just clarifying how "windows hello" hardware uses them)

With the design of windows hello, the biometrics themselves stay entirely on-device inside the fingerprint reader (much like apple's fingerprint stuff in the secure enclave) even for online auth. Think "a yubikey with a fingerprint reader instead of a button" for a mostly-accurate model of modern fingerprint readers. And at least in theory, modern ones don't even expose the biometric data to the OS, only a pass/fail or "detected known finger" with all the matching in-device (vs the old ones that did all the matching in a userland driver)

Of course, that doesn't mean that the fingerprint readers can't or don't expose that data to the OS, just that they shouldn't per the published specs, hence why biometric authentication is still sketchy as hell unless you seriously trust the reader vendor to not include secret 'debug commands'...

@becomethewaifu alright, that's fair. thanks for the primer.

@da_667 I think about this a lot, but lack the expertise to really drill into it and haven't yet.

I really don't like the idea of my fingerprints being exposed, or the data extrapolated from them being exposed.

I know my shit is likely already out there in the hands of AT LEAST the Chinese, because lol former Army, but still...

@da_667 I try not to take pictures of my hands, seriously, because I'm somewhat paranoid of this particular risk.
@da_667 inb4 they decide to "conveniently" back up all your recall data to onedrive "for your own good" and make it opt-out