Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: Reports | TechCrunch

7 months ago by commander to c/technology

The FBI served Microsoft a warrant requesting encryption recovery keys to decrypt the hard drives of people involved in an alleged fraud case in Guam.
empireOfLove2 449 points 7 months ago

So, this means Microsoft has copies of every single bitlocker key, meaning that a bad actor could obtain them... Thereby making bitlocker less than worthless, it's an active threat.
MS really speedrunning worst possible software timeline

path: 0 21725902, hotness: undefined, score: 449, children: 66
dual_sport_dork 222 points 7 months ago

They don't have a copy of every single Bitlocker key. They do have a copy of your Bitlocker key if you are dumb enough to allow it to sync with your Microsoft account, you know, "for convenience."

Don't use a Microsoft account with Windows, even if you are forced to use Windows.

path: 0 21725902 21725974, hotness: undefined, score: 222, children: 47
tabular 149 points 7 months ago

To use Windows without a Microsoft account requires tech literacy these days, I thought. I would not be suprised if users didn't choose to sync with a MS account but it's doing it anyway, if that's what MS want.

path: 0 21725902 21725974 21726207, hotness: undefined, score: 149, children: 17
dual_sport_dork 53 points 7 months ago

If you sign in with a Microsoft account at all I don't believe there's the capability to opt out.

I only use local accounts. I have never had a Microsoft account. I never will.

path: 0 21725902 21725974 21726207 21726266, hotness: undefined, score: 53, children: 13
suicidaleggroll 58 points 7 months ago

You can't do that anymore, at least not with a normal Windows installation. All of the tricks of forcing it offline, clicking cancel 10 times and jumping up and down don't work anymore, they've disabled them all, the only way to install Windows 11 now (using the normal Microsoft installer) is by linking it to a Microsoft account.

path: 0 21725902 21725974 21726207 21726266 21726793, hotness: undefined, score: 58, children: 12
Feyd 16 points 7 months ago

I'm not even sure if you can install without an MS account if you don't use Rufus anymore. Rufus requires literacy for sure, and even if you can still do it without it is designed to make it impossible to know you can from within the installer itself.

path: 0 21725902 21725974 21726207 21726465, hotness: undefined, score: 16, children: 2
conorab 2 points 7 months ago

Main issue with Rufus is secure boot unfortunately, otherwise Rufus is easy enough that I gave a couple “click here, then here, then here and here are some screenshots” to a friend they were able to navigate it just fine. At this point I swear Rufus is easier than using the official installer provided Secure Boot is off.

path: 0 21725902 21725974 21726207 21726465 21730144, hotness: undefined, score: 2, children: 1
DeathByBigSad 47 points 7 months ago

Encryption doesn't actually complete until you log in with a Microsoft account for Home Edition.

Anyways: Use Veracrypt.

Or just Linux + LUKS

path: 0 21725902 21725974 21726358, hotness: undefined, score: 47, children: 0
lemmyout 45 points 7 months ago

It's a bit harsh and unfair to say "you are dumb enough to allow it". Microsoft makes it damn near impossible to avoid this unless you are extremely particular and savvy about it, and never have an off day where you make a mistake while using your PC.

path: 0 21725902 21725974 21726841, hotness: undefined, score: 45, children: 0
realitaetsverlust 21 points 7 months ago

Don't use a Microsoft account with Windows

Ftfy

path: 0 21725902 21725974 21729672, hotness: undefined, score: 21, children: 10
3laws 13 points 7 months ago

Don't use a Microsoft account with Windows

FFTFY.

Bethesda anything, Azure, Outlook, GitHub, Visual Studio, Office, Bing, XBox, LinkedIn, SharePoint (so disgusting this is a given), fuck it not even Skype (lmao what year is it?)

path: 0 21725902 21725974 21729672 21730361, hotness: undefined, score: 13, children: 3
realitaetsverlust 6 points 7 months ago

Still kinda hurts they own Bethesda now, but considering that company has only produced garbage since FO4 which only was kinda mid, I don't even mind skipping them.

path: 0 21725902 21725974 21729672 21730361 21731445, hotness: undefined, score: 6, children: 2
quips 1 point 7 months ago

Literally fix the anticheat problem and I’ll uninstall.

path: 0 21725902 21725974 21729672 21732421, hotness: undefined, score: 1, children: 5
realitaetsverlust 4 points 7 months ago

The anticheat problem already is fixed. It's called "don't play games that don't support your choices". These days, no game is worth being put through all that AI bullshit.

path: 0 21725902 21725974 21729672 21732421 21737273, hotness: undefined, score: 4, children: 2
DeathByBigSad 1 point 7 months ago

Dualboot, don't store sensitive files in windows?

(Although I'm having a bit of trouble trying to do dualboot myself so... idk lol)

path: 0 21725902 21725974 21729672 21732421 21733800, hotness: undefined, score: 1, children: 1
goferking0 9 points 7 months ago

But, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud, allowing the tech giant — and by extension law enforcement — to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes.

I mean it's dumb to sync but at same time it's not like MS isn't great at either making it almost impossible to not sync it re-enable syncing for a bit after updates.

You can constantly tell it not to sync but all it takes is MS saying we want it now and they'll get it

path: 0 21725902 21725974 21731153, hotness: undefined, score: 9, children: 1
Pika 1 point 7 months ago

Whats dumb is this issue is very easily resolved by encrypting the users security pin or password against the bitlocker keys and then only storing that.

or better yet have the pin/password an isolated thing from the microsoft system, so when a key gets uploaded, it requests the recovery pin, and if the pin matches it uploads, otherwise it states invalid pin and offers to change it while warning that it will remove existing keys, then optionally next time a system whom contains a drive with an identifier (which wouldn't need to be encrypted only the key) goes online, it can prompt the user "note: due to recovery pin, drive X recovery key needs to be backed up again, would you like to do so?"

This type of system would make it so the only data MS has stored is the already encrypted recovery key, and as such would mean that the data they gave law enforcement would be worthless.

path: 0 21725902 21725974 21731153 21746393, hotness: undefined, score: 1, children: 0
empireOfLove2 7 points 7 months ago

They do have a copy of your Bitlocker key if you are dumb enough to allow it to sync with your Microsoft account, you know, “for convenience.”

Which I don't believe is the only way it can leak. It's well known Microsoft can access anything and everything on an internet connected Windows PC whether there's a Microsoft account or not. If the nazi's push for the device of someone on a local account only, you know they'll magically find a way.

path: 0 21725902 21725974 21726060, hotness: undefined, score: 7, children: 0
iterable 7 points 7 months ago

Save a copy of your bitlocker keys to a Veracrypt drive with a password no shorter then 15 mixed characters. Then upload that encrypted container to any free service. They wont be able to open it and now you have a remote backup copy.

path: 0 21725902 21725974 21728351, hotness: undefined, score: 7, children: 9
dual_sport_dork 14 points 7 months ago

I employed the super secure expedient of never exporting my keys. I have no idea what they are, I never did, and I never will.

There's really no irreplaceable data on my Windows machine. If I have to reformat it some day A) that's no big deal, and B) it's Windows, what else is new.

path: 0 21725902 21725974 21728351 21728421, hotness: undefined, score: 14, children: 0
wischi 10 points 7 months ago

Why not save a step, fuck bitlocker, and use veracrypt to encrypt your drive in the first place?

path: 0 21725902 21725974 21728351 21730264, hotness: undefined, score: 10, children: 5
Nyx0r 7 points 7 months ago

Why not save a step and don't install Windows in the first place.

path: 0 21725902 21725974 21728351 21730264 21730347, hotness: undefined, score: 7, children: 3
iterable 0 points 7 months ago

That is a option but it's performance is bad and you need at least fifteen mix character password every time you boot. If you game you need to use bitlocker sadly or load times dive hard. Having a second drive in full Veracrypt is fine for things like basic documents but not to game on.

path: 0 21725902 21725974 21728351 21730264 21732220, hotness: undefined, score: 0, children: 0
Wispy2891 1 point 7 months ago

If the password is long 15 characters that means you use a password manager. At that point just put the bitlocker password in the password manager

path: 0 21725902 21725974 21728351 21733913, hotness: undefined, score: 1, children: 1
iterable 1 point 7 months ago

nope use password sentences easy when you make it a sentence you can remember

path: 0 21725902 21725974 21728351 21733913 21751085, hotness: undefined, score: 1, children: 0
JustEnoughDucks 5 points 7 months ago

Are you naive enough to believe the surveillance OS that uploads literally all of your activity along with screenshots of your desktop doesn't automatically upload you keys no matter what little box you tick on the installer?? 😂 there is absolutely not one single 3rd party auditing that they actually follow any of the options at all that they give.

path: 0 21725902 21725974 21735114, hotness: undefined, score: 5, children: 0
obinice 1 point 7 months ago

Why is that dumb?

I encrypt my drive to protect my data from burglars and thieves who might steal my laptop, how would they obtain the recovery key from Microsoft? O_o

path: 0 21725902 21725974 21745074, hotness: undefined, score: 1, children: 0
Tollana1234567 1 point 7 months ago

i heard win11 its automatically used online for home.

path: 0 21725902 21725974 21734140, hotness: undefined, score: 1, children: 0
bw42 48 points 7 months ago

No they do not have copies of every Bitlocker key.

Bitlocker by default creates a 48-bit recovery code that can be used to unlock an encrypted drive. If you run Windows with a personal Microsoft account it offers to backup that code into your Microsoft account in case your system needs recovered. The FBI submitted a supoena to request the code for a person's encrypted drive. Microsoft provided it, as required by law.

Bitlocker does not require that key be created, and you don't have to save it to Microsoft's cloud.

This is just a case of people not knowing how things work and getting surprised when the data they save in someone else's computer is accessed using the legal processes.

path: 0 21725902 21726041, hotness: undefined, score: 48, children: 7
user28282912 46 points 7 months ago

Except that Microsoft basically puts a gun to every users head to login with a Microsoft account which can/does backup the recovery keys.

path: 0 21725902 21726041 21726367, hotness: undefined, score: 46, children: 4
Agent641 -2 points 7 months ago

This is why we Jason Bourne style snatch the gun out of their holster before they can draw it and beat them unconcious with it, I mean oobe\bypassnro

path: 0 21725902 21726041 21726367 21728060, hotness: undefined, score: -2, children: 2
felsiq 6 points 7 months ago

Iirc bypassnro no longer works on recent builds of windows

path: 0 21725902 21726041 21726367 21728060 21728787, hotness: undefined, score: 6, children: 1
SalamenceFury -3 points 7 months ago

Rufus: "Am I a joke to you?"

path: 0 21725902 21726041 21726367 21730464, hotness: undefined, score: -3, children: 0
greybeard 13 points 7 months ago

If you sign into a Microsoft account during setup, Microsoft automatically turns on bitlocker and sends the key off to Microsoft for safe keeping. You are right, there are other ways to handle bitlocker, but that's way beyond most people, and I don't think Microsoft even tells you this during setup. It's honestly a lifesaver for when bitlocker breaks(and it does), but it comes at a cost. In the business world, this is seen as a huge benefit, as we aren't trying to protect from the US government, mostly petty theft and maybe some corporate espionage.

As is often the case, the real solution is Linux, but that, too, is far beyond most people until manufacturers start shipping Linux machines to big box stores and even then they'd probably not enable any encryption.

path: 0 21725902 21726041 21729480, hotness: undefined, score: 13, children: 1
SkyeStarfall 4 points 7 months ago

I question whether we are rapidly approaching the point where Linux is simply easier to use in a safe, secure, and practical way for the average user, because it doesn't try to actively fuck you over like Microsoft does

It's easier when you don't need to jump through hoops to make a local account. It's easier when you don't need to turn off a dozen settings you might not know about regarding data collection or advertisements. It's easier when you don't have an antagonistic system that treats you like the product, not a user, not pushing you towards confusing things you don't want

path: 0 21725902 21726041 21729480 21730492, hotness: undefined, score: 4, children: 0
NatakuNox 19 points 7 months ago

Hey copilot, give me the bitlocker key to the nuclear football!

path: 0 21725902 21730085, hotness: undefined, score: 19, children: 0
x0x7 13 points 7 months ago

Microsoft is already a bad actor and they have them. Or a bad actor could threaten microsoft physically and microsoft will hand them over. Wait, that already happened.

path: 0 21725902 21726415, hotness: undefined, score: 13, children: 0
Kongar 3 points 7 months ago

And people make fun of me for turning off secure boot and tpm. They just cause grief for no benefit.

path: 0 21725902 21727070, hotness: undefined, score: 3, children: 3
partial_accumen 7 points 7 months ago

As long as you're doing your own whole disk encryption, you have a valid path to still be secure. However, if you're running an unencrypted disk, you're much more likely to lose your data to a non-state actor.

path: 0 21725902 21727070 21727488, hotness: undefined, score: 7, children: 0
frongt 6 points 7 months ago

Well this isn't directly related to those, so maybe some derision is warranted.

path: 0 21725902 21727070 21729005, hotness: undefined, score: 6, children: 0
cley_faye 3 points 7 months ago

Both are completely unrelated to the discussion. TPM sometimes have issues regarding their security, but you can certainly use Secure Boot with your own signing keys to ensure the kernel you run is one you installed, which improves security. And you can use TPM to either keep your FDE keys, or only part of them combined with a PIN if you don't fully trust them to be secure, so you keep strong encryption but with a bit of convenience.

Without a (properly configured) Secure Boot startup, anyone could just put a malware between the actual boot and your first kernel. If the first thing that happens when you boot is something asking for a password to be able to decrypt your storage, then an attacker can just put something here, grab your password, and let you proceed while storing in a a place it can be retrieved.

Is this scenario a concern for most people? That's unlikely. But every computer sold these last five years (at least!) can be setup to reduce this risk, so why not take advantage of it.

path: 0 21725902 21727070 21731371, hotness: undefined, score: 3, children: 0
Kissaki 3 points 7 months ago

So, this means Microsoft has copies of every single bitlocker key

But, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud

Not everyone follows the default. So no, it doesn't mean Microsoft has copies of every single BitLocker key.

path: 0 21725902 21738549, hotness: undefined, score: 3, children: 0
Arcane2077 2 points 7 months ago

Could be worse. Could have skeleton keys

path: 0 21725902 21726330, hotness: undefined, score: 2, children: 1
corsicanguppy 9 points 7 months ago

You're assuming there isn't a master pubkey baked into the software.

path: 0 21725902 21726330 21726673, hotness: undefined, score: 9, children: 0
Appoxo 0 points 7 months ago

More likely stupid users storing their bitlocker key in the microsoft account instead of printing it out or storing it somewhere not owned by MS lol

path: 0 21725902 21729269, hotness: undefined, score: 0, children: 0
JoMiran 131 points 7 months ago

path: 0 21726072, hotness: undefined, score: 131, children: 5
bdonvr 6 points 7 months ago

bonjour!

path: 0 21726072 21730698, hotness: undefined, score: 6, children: 0
brooke592 2 points 7 months ago

Can't stop winning.

path: 0 21726072 21737178, hotness: undefined, score: 2, children: 0
PabloSexcrowbar 2 points 7 months ago

I wouldn't be naive enough to believe there's not a backdoor somewhere in LUKS.

path: 0 21726072 21734098, hotness: undefined, score: 2, children: 2
pemptago 9 points 7 months ago

"Naive" doesn't sit right with me. Anyone can scrutinize LUKS, or BitLocker for that matter (via cryptsetup). Backdoors aren't the issue here, even for MS Bitlocker. The issue, as stated in the article, is:

by default, BitLocker recovery keys are uploaded to Microsoft’s cloud

No need for a backdoor if you know you can get keys to the front door.

path: 0 21726072 21734098 21734982, hotness: undefined, score: 9, children: 0
thethunderwolf 1 point 7 months ago

This is not a backdoor

This is the house rental company having a key to the front door

path: 0 21726072 21734098 21742463, hotness: undefined, score: 1, children: 0
Buelldozer 126 points 7 months ago

The word "Gave" is really doing some heavy lifting in that title. Microsoft produced the keys in response to a warrant as required by law.

If you don't want a company, any company, to produce your data when given a warrant then you can't give the company that data. At all. Ever.

Not fast food joints, not Uber, not YouTube, not even the grocery store.

path: 0 21730448, hotness: undefined, score: 126, children: 40
kokesh 88 points 7 months ago

Yes. But this completely invalidates the encryption. If anyone can decrypt your data without you giving the keys to them, it is not really encrypted.

path: 0 21730448 21730551, hotness: undefined, score: 88, children: 18
Buelldozer 22 points 7 months ago

The encryption key is data, don't give it to ANYONE. "Two people can keep a secret if one of them is dead."

path: 0 21730448 21730551 21730796, hotness: undefined, score: 22, children: 4
goferking0 24 points 7 months ago

Which means it's useless if always uploaded to MS

path: 0 21730448 21730551 21730796 21731092, hotness: undefined, score: 24, children: 0
EncryptKeeper 1 point 7 months ago

You’re confusing two different things here, in a really weirdly obtuse way.

path: 0 21730448 21730551 21730796 21735625, hotness: undefined, score: 1, children: 2
Buelldozer 0 points 7 months ago

It may seem that way but I'm really not. An encryption key is just data. It's critical security data to be sure but it's still data and like other data you shouldn't share anything that you wouldn't want made public.

Don't want MS to cough up your data when asked? Then don't give it to them. In regards to your BL key that means storing it another way, such as on a jump drive or printing it out.

In the end if you have data of any type that you absolutely DO NOT want made public then you need to retain that data locally. If that means leaving the Microsoft or any other ecosystem then that's the price that needs paid for keeping your data under your control.

This is the foundation of the entire privacy movement.

path: 0 21730448 21730551 21730796 21735625 21744149, hotness: undefined, score: 0, children: 1
MrScottyTay 3 points 7 months ago

Its not anyone though. Not anyone can get a warrant and demand the keys

path: 0 21730448 21730551 21730707, hotness: undefined, score: 3, children: 12
jumping_redditor 30 points 7 months ago

if Microsoft has the power to give the keys to the feds what happens when Microsoft gets hacked?

path: 0 21730448 21730551 21730707 21731468, hotness: undefined, score: 30, children: 3
Tollana1234567 6 points 7 months ago

or they give the keys or whatever data willingly, and then say they are hacked as an excuse.

path: 0 21730448 21730551 21730707 21731468 21734231, hotness: undefined, score: 6, children: 0
Corporal_Punishment 2 points 7 months ago

Wouldn't the hacker then need to track down your physical computer...steal it....use the bitlocker key....look to see if you actually have any data worth taking etc....?

path: 0 21730448 21730551 21730707 21731468 21735034, hotness: undefined, score: 2, children: 1
ech 16 points 7 months ago

Anyone as in "a single person". They don't mean everyone has access.

path: 0 21730448 21730551 21730707 21730736, hotness: undefined, score: 16, children: 0
cley_faye 12 points 7 months ago

Sure. It's not anyone. It's anyone that can get a warrant. Or anyone that have enough power/underhanded influence to ask them nicely. Or any admin that have access to cloud storage at MS (remember they where caught with some exec having full access to that a while ago). Or any big leak that could exfiltrate these data. And probably a handful of other people, like, someone getting access to your MS account for whatever reason (which kinda happen, seeing how people lose their mail account to phishing/scams all the time) suddenly having access to your keys from there.

If your keys are in a DB somewhere, there's a lot of way they could get out. Would these ways coincide with someone actually having your drive at hand? Probably not. Still, the key not existing in plaintext in some third party storage close all these holes.

path: 0 21730448 21730551 21730707 21731268, hotness: undefined, score: 12, children: 0
EncryptKeeper 6 points 7 months ago

Anyone included Microsoft. You’re thinking of the word “everyone”

path: 0 21730448 21730551 21730707 21735635, hotness: undefined, score: 6, children: 0
nutsack 5 points 7 months ago

what happens when fydor monikov the sleeper agent from the kgb working at the fbi gets a copy of these master keys

path: 0 21730448 21730551 21730707 21731566, hotness: undefined, score: 5, children: 4
DeathByBigSad 4 points 7 months ago

KGB is inside the oval office 💀

(I mean they literally deported a Russian dissident back to russia... need say more?)

path: 0 21730448 21730551 21730707 21731566 21734463, hotness: undefined, score: 4, children: 0
French75 3 points 7 months ago

Are they really sleepers any more?

path: 0 21730448 21730551 21730707 21731566 21734018, hotness: undefined, score: 3, children: 2
ColeSloth 62 points 7 months ago

If you can't possess the keys, you can't give them when there's a warrant. Microsoft designed a system that could obtain and decrypt those keys on purpose.

path: 0 21730448 21732682, hotness: undefined, score: 62, children: 3
korazail 8 points 7 months ago

I'm certainly not a microslop supporter, but....

They designed a system that recommended that the average user use full disk encryption as part of device setup, and then provided a way that Grandma could easily recover her family photos when she set it up with their cloud.

This was built by an engineer trying to prevent a foreseeable issue. The intent was not malicious. The intent was to get more people more secure by default, since random hacker couldn't compell ms to give them keys, while still allowing low tech literacy people to not get fucked.

It's been a while since I installed a new Windows OS, but I'm pretty sure it prompts you to allow uploading your bitlocker key. It probably defaults to yes, but I doubt you can't say no, or reset the key post onboarding if you want the privacy, and now it's on you to record your key. You do have to have some technical understanding of the process, though, which is true of just about everything.

That all said, if a company has your data, it can be demanded by the government. This is a cautionary tale about keeping your secrets secret. Don't put them in GitHub, don't put them in Chrome, don't put them online anywhere because the Internet never forgets.

path: 0 21730448 21732682 21738230, hotness: undefined, score: 8, children: 0
Miaou 2 points 7 months ago

They're doing this because there's demand (with actually, non malicious genuine needs), and the feature is clearly advertised AFAIK.

It's not some evil conspiracy. Microsoft does enough shitty things without us needing to blame them for their users' shitty OpSec.

path: 0 21730448 21732682 21742742, hotness: undefined, score: 2, children: 1
ColeSloth 1 point 7 months ago path: 0 21730448 21732682 21742742 21744982, hotness: undefined, score: 1, children: 0
deczzz 10 points 7 months ago

I'm stupid. How do thet even produce the keys?

path: 0 21730448 21731010, hotness: undefined, score: 10, children: 12
cley_faye 23 points 7 months ago

Your computer generate a random key using (hopefully) a trusted PRNG with good enough sources. This key is then used to encrypt your data. This key is stored in your computer's TPM module, and provided to the OS only if the chip approves all the checks in places. In addition, you get that key displayed to you, so you can write it down (or alternatively save the key file somewhere of your convenience). This is relatively good as far as security goes (unless the TPM is broken, which can happen).

And then, unless you jumped through hoops to disable it, your PC sends the key to Microsoft so they can just keep it linked to your account. That's the part that sucks, because then, they have the key, can unlock your drive on your behalf, and have to produce it if asked by a judge or something.

Note that there are relatively safe way to protect these keys even if they are backed up in "the cloud", by encrypting them beforehand using your actual password. It's not absolutely perfect, but can make it very hard/costly/impossible to retrieve, depending on the resources of the attacker/government agency. But MS didn't chose this way. I don't know if it's because of sheer incompetence, inattention, or because this feature is claimed to be here to "help" people that lose their key, and as such are likely to lose their password too, but it is what it is.

path: 0 21730448 21731010 21731201, hotness: undefined, score: 23, children: 6
DeathByBigSad 12 points 7 months ago

“help” people that lose their key

Funny enough, people have lost access to their bitlocker encrypted drive because of some weird issues that triggered the windows intallation to revert to asking for the full bitlocker encryption key (I think if you disable secure boot or mess with CPU upgrades or the TPM, or some weird update broke, that can happen), which they didn't have and forgot the microsoft account. But microsoft can't help because they forgot about their acount credentials.

They should've asked the FBI for help lolz

path: 0 21730448 21731010 21731201 21731933, hotness: undefined, score: 12, children: 1
Wispy2891 6 points 7 months ago

It happened TWICE on my Lenovo laptop, when it automatically installed a firmware update from windows update

path: 0 21730448 21731010 21731201 21731933 21733835, hotness: undefined, score: 6, children: 0
jnod4 4 points 7 months ago

I'm pretty sure all tpms can be read with an electric interference reader when they're probed, as an intended loophole

path: 0 21730448 21731010 21731201 21731620, hotness: undefined, score: 4, children: 1
French75 1 point 7 months ago

I don't know about intentionally designing that. It would violate contracts and have to be a hidden, but broadly conspiratorial activity. I have some professional experience in consumer electronics, and I remember when TPMs started becoming a required component for CE. It took several years to become commonplace; a slow transition from security by obscurity to sensible practices when devices started to be internet connected.

Nevertheless, from my experience, I'd say the TPMs aren't there for user security, they are there to keep Hollywood movies safe.

path: 0 21730448 21731010 21731201 21731620 21742839, hotness: undefined, score: 1, children: 0
French75 3 points 7 months ago

And then, unless you jumped through hoops to disable it, your PC sends the key to Microsoft so they can just keep it linked to your account.

You'd probably also have to jump through the hoops to disable windows recall too.

path: 0 21730448 21731010 21731201 21734043, hotness: undefined, score: 3, children: 0
NauticalNoodle 0 points 7 months ago
path: 0 21730448 21731010 21731201 21731631, hotness: undefined, score: 0, children: 0
Wispy2891 12 points 7 months ago

In Windows 11, if the main user logs in with a Microsoft account (which is mandatory unless you do some hacks during the install), it automatically encrypts the main drive by default without asking the user consent and uploads the decryption key to Microsoft servers (again, without user consent, but usually this is appreciated because sometimes automatic BIOS updates via windows update wipe the tpm and keep all your data at ransom.)

path: 0 21730448 21731010 21733822, hotness: undefined, score: 12, children: 0
Dlayknee 0 points 7 months ago

Microsoft built the encryption in Windows so know how to get around it. In theory that remains a closely guarded secret but there are the warrants and the NSA and...

path: 0 21730448 21731010 21731135, hotness: undefined, score: 0, children: 3
DeathByBigSad 9 points 7 months ago

Nope, this isn't even a "backdoor". The key itself was automatically uploaded to your microsoft account, so they can just take the key from the microsoft servers and walk right in. This isn't some secret, a quick online search will reveal this as public information. They literally tell you the key will get uploaded.

path: 0 21730448 21731010 21731135 21731900, hotness: undefined, score: 9, children: 2
ChogChog 1 point 7 months ago

I’d go as far as to say it’s similar to a landlord requiring a key to access the apartment your renting from them. Sure, they probably won’t abuse that power, most don’t, but the doesn’t mean they can’t.

The bigger picture to me is it’s pretty clear then internally, Microsoft views you as a “tenant” of THEIR OS. Not a purchaser. This is why they use the words “This PC” in replace of “My PC”.

Yes, I think we can absolutely say that companies are pushing for consumers to use the cloud instead of their own hardware, but in this context, I’d say it’s more egregious showing their mindset that you’re just renting their software from them.

path: 0 21730448 21731010 21731135 21731900 21737101, hotness: undefined, score: 1, children: 1
quips -1 points 7 months ago

Not true with E2EE, they can’t give over shit when they don’t have the keys

path: 0 21730448 21732392, hotness: undefined, score: -1, children: 3
MSids 6 points 7 months ago

Bitlocker is computer drive encryption. On W11 it’s supposed to be tied to the motherboards TPM. End to end encryption is not really applicable in this scenario. That phrase is more applicable to cloud services or storage where a telecom or CSP hosts or transports your data but can’t see what the data is.

Microsoft should not have the keys to decrypt Bitlocker ever.

path: 0 21730448 21732392 21733133, hotness: undefined, score: 6, children: 2
quips 1 point 7 months ago

Ofc its not applicable in that one scenario

path: 0 21730448 21732392 21733133 21757643, hotness: undefined, score: 1, children: 0
Buelldozer 1 point 7 months ago

Microsoft should not have the keys to decrypt Bitlocker ever.

Windows is a closed source and proprietary commercial Operating System. Microsoft is going to do whatever they like with it. If enough people get angry about an issue they may change their mind but that doesn't change the nature of Microsoft's ownership over their products.

I've been participating in discussion about what Microsoft should and shouldn't do since the late 80s and it pretty much boils down to this: You need to select and use software that works the way you want it to. So if you don't want MS to have your disk encryption key then don't use Windows. If you don't want MS to have access to your documents then don't put them on any system that MS has control over.

It can be terrible inconvenient to protect your data in this way but this part and parcel of the privacy movement.

path: 0 21730448 21732392 21733133 21744344, hotness: undefined, score: 1, children: 0
db2 92 points 7 months ago

path: 0 21725675, hotness: undefined, score: 92, children: 0
x0x7 62 points 7 months ago

Linux. LUKS it yourself or it isn't really encrypted.

path: 0 21726403, hotness: undefined, score: 62, children: 0
socsa 48 points 7 months ago

What does Microsoft think the fucking point of encryption is? Do they think I am encrypting my data to protect it from my dog?

path: 0 21742295, hotness: undefined, score: 48, children: 8
FatVegan 13 points 7 months ago

As someone who used windows for way too long: they just simply don't give a shit. Like at all

path: 0 21742295 21743067, hotness: undefined, score: 13, children: 0
modus 7 points 7 months ago

If you're not the only one with the keys, is it really encrypted?

path: 0 21742295 21745590, hotness: undefined, score: 7, children: 0
wallabra 6 points 7 months ago

i saw your dog using arch linux

path: 0 21742295 21751200, hotness: undefined, score: 6, children: 3
ManicMambo 9 points 7 months ago

Don't be silly, the dog uses Puppy Linux.

path: 0 21742295 21751200 21758018, hotness: undefined, score: 9, children: 1
Verenos 2 points 7 months ago

Mines uses Yellow Dog Linux.

path: 0 21742295 21751200 21758018 21766768, hotness: undefined, score: 2, children: 0
Verenos 2 points 7 months ago

btw……

path: 0 21742295 21751200 21766763, hotness: undefined, score: 2, children: 0
Buddahriffic 3 points 7 months ago

Why do you think the encryption capabilities on your PC are there for your sake? They might have sold them to you on that, but they are really there to protect copyright data because TPM allows encryption/decryption that is completely hidden from the rest of your system. Like an encrypted handshake that then transfers an encrypted key to decrypt the video stream. But it doesn't save the decrypted data, it immediately re-encrypts it using your display's private key (or whatever device is next in the chain, maybe your GPU). They can make it so that the unencrypted stream never touches your RAM or travels on any wire, which means you can't pirate shows as you watch them unless you point a camera at your screen.

Obviously if they just said that was one of the main points, no one would want it and media companies couldn't benefit from it because they'd have to compromise to sell content.

The other point was so that they could build a system where they hold the encryption keys and get to choose whose data is actually private. Obviously that's an even harder sell.

So they did what marketers always do and lied by omission about what it was for and just outright lied if they ever said they'd never give the keys to law enforcement (did they ever even say that?).

Let go of the idea that someone selling something to you implies any kind of loyalty, especially when either party is a large corporation.

path: 0 21742295 21747375, hotness: undefined, score: 3, children: 0
TheTimeKnife 1 point 7 months ago
path: 0 21742295 21743973, hotness: undefined, score: 1, children: 0
cyberpunk007 48 points 7 months ago

Just use Linux.

path: 0 21732918, hotness: undefined, score: 48, children: 4
vacuumflower 12 points 7 months ago

I've read someone blabbering how BitLocker is better than FDE on Linux or BSDs just recently. I didn't do fact checking, but honestly just uploading keys to MS wasn't something I expected even from them.

path: 0 21732918 21733524, hotness: undefined, score: 12, children: 3
cyberpunk007 9 points 7 months ago

Not even from the company that tried to provide you with windows recall? 🤣

path: 0 21732918 21733524 21734414, hotness: undefined, score: 9, children: 2
vacuumflower 3 points 7 months ago

BitLocker is older.

path: 0 21732918 21733524 21734414 21735180, hotness: undefined, score: 3, children: 1
rob_t_firefly 3 points 7 months ago

It's a product of Vista-era Microsoft which is also current Windows-Recall-era Microsoft.

path: 0 21732918 21733524 21734414 21735180 21739038, hotness: undefined, score: 3, children: 0
moonshadow 36 points 7 months ago

A single bitter, crowing "hah!" at whoever thought there wasn't at least this much overlap between our corporate and government masters. Welcome to hell kid, shoutout to whatever's being trained on the last ~30 years of everything that touched the internet in the NSA's Utah data center. Rose coloured PRISM though, I dream of the day when someone makes those search tools public and I can reminisce through my preteen MSN Messenger convos

path: 0 21728070, hotness: undefined, score: 36, children: 0
FalschgeldFurkan 35 points 7 months ago

What a slap to the faces of everyone who had been locked out of their data because they never knew about this crap and thus never saved their keys

path: 0 21747277, hotness: undefined, score: 35, children: 1
DeathByBigSad 19 points 7 months ago

Except their keys were saved but microsoft deemed that they cant "prove ownership" of the microsoft account, because they lack the credentials...

path: 0 21747277 21747957, hotness: undefined, score: 19, children: 0
funkyfarmington 34 points 7 months ago

People called me paranoid when I said this would happen someday...

path: 0 21745643, hotness: undefined, score: 34, children: 1
burstcomms 2 points 7 months ago

if theres money to be made it will happen one day

path: 0 21745643 21758885, hotness: undefined, score: 2, children: 0
kittenzrulz123 28 points 7 months ago

Daily reminder that verified boot is objectively superior to "secure boot", once again a common Linux W and another example of Google actually promoting some good security practices

path: 0 21734657, hotness: undefined, score: 28, children: 4
DeathByBigSad -1 points 7 months ago

Same thing?

You can add custom keys to secure boot.

path: 0 21734657 21735837, hotness: undefined, score: -1, children: 3
kittenzrulz123 4 points 7 months ago

That doesn't make it the same thing

path: 0 21734657 21735837 21738737, hotness: undefined, score: 4, children: 2
DeathByBigSad 1 point 7 months ago

Both are different names for a process that ensures the boot process is loading the correct non-malicious code.

path: 0 21734657 21735837 21738737 21745222, hotness: undefined, score: 1, children: 1
kittenzrulz123 2 points 7 months ago

Secure boot verifies the system is booting correct code, verified boot can ensure total system integrity and can protect against tampering. Furthermore the Linux implementation of secure boot is very often in the least secure method.

path: 0 21734657 21735837 21738737 21745222 21746945, hotness: undefined, score: 2, children: 0
melfie 28 points 7 months ago
path: 0 21728809, hotness: undefined, score: 28, children: 0
Wispy2891 26 points 7 months ago

Wasn't this by design? Otherwise why keeping the decryption keys on servers located in the united states'?

path: 0 21733782, hotness: undefined, score: 26, children: 2
Kissaki 6 points 7 months ago

It's a consequence of the design.

I certainly wouldn't want end users calling me because they lost their recovery keys and consequently all their data. So I can understand offering or even recommending fallbacks.

The real solution would be clear and obvious documented choice for an informed decision. Online backup for fallback but meaning possibility of court order compromise and other external management risks, or self-managed with no recovery in case of loss.

path: 0 21733782 21738479, hotness: undefined, score: 6, children: 1
SirHax 3 points 7 months ago

Indeed. I think that you have to remember that the vast majority of BitLocker users would go from no encryption to encryption with your key in the Cloud. Given the he risk of complete data loss this is imo a decent risk/reward in most cases. You need both the physical computer and the MS account login, and the US government also has the latter.

If you want to make an active and informed decision there is of course much better option s, but know that you would be responsible to keep the unlock key safe or risk total data loss.

path: 0 21733782 21738479 21741287, hotness: undefined, score: 3, children: 0
user28282912 23 points 7 months ago path: 0 21726342, hotness: undefined, score: 23, children: 0
jjlinux 19 points 7 months ago

Why is anyone surprised by this? And what kind of imbecile commits crimes and uses windows? 🤣

path: 0 21744360, hotness: undefined, score: 19, children: 6
v127 8 points 7 months ago

Not just that but also uploads a copy of the key to their Microsoft Account...

Many modern Windows computers rely on full-disk encryption, called BitLocker, which is enabled by default. This type of technology should prevent anyone except the device owner from accessing the data if the computer is locked and powered off. But, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud, allowing the tech giant — and by extension law enforcement — to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes.

path: 0 21744360 21747057, hotness: undefined, score: 8, children: 2
dan 8 points 7 months ago

uploads a copy of the key to their Microsoft Account

Microsoft added that feature because people kept losing their encryption keys and thus losing all their files if they need to have their computer replaced. They get complaints either way - privacy advocates complain when the key is backed up, and sysadmins/users complain when the key isn't backed up.

path: 0 21744360 21747057 21748046, hotness: undefined, score: 8, children: 1
wallabra 6 points 7 months ago

I think in cases like this, I'd rather the responsibility of burden be shifted towards individuals with autonomy than to large corporations. But I suppose in that case (reductionism warning) people might as well just use Linux.

path: 0 21744360 21747057 21748046 21751195, hotness: undefined, score: 6, children: 0
FalschgeldFurkan 5 points 7 months ago

Didn't Osama bin Laden use Windows? 😂

path: 0 21744360 21747292, hotness: undefined, score: 5, children: 2
jjlinux 2 points 7 months ago

Now I'm curious about that, haha!

path: 0 21744360 21747292 21755102, hotness: undefined, score: 2, children: 1
FalschgeldFurkan 3 points 7 months ago path: 0 21744360 21747292 21755102 21755468, hotness: undefined, score: 3, children: 0
myfunnyaccountname 18 points 7 months ago

Is anyone shocked by this? With everything that DHS, FBI, ICE, military, elected representatives, etc. are all doing without any concern or care for laws, civil rights, human rights, the Constitution, this should not be a shock to anyone. Corporations are bending over backwards to appease the talking orange and make more money. They do not care as long as profits are up and the shareholders are happy. A companies primary legal responsibility is to the shareholders, not the customers.

path: 0 21739455, hotness: undefined, score: 18, children: 3
French75 8 points 7 months ago

+100. People forget, or chose not to pay attention to the fact that Google sensor vault data was key evidence in convicting the January 6 insurrectionists (who were exonerated to become ICE). Surveillance capitalism doesn't care which side you are on.

path: 0 21739455 21742008, hotness: undefined, score: 8, children: 2
rustydomino 7 points 7 months ago

Small correction. They were not exonerated. They were pardoned. A pardon implicitly means guilt. Exonerated means their conviction was overturned.

path: 0 21739455 21742008 21743980, hotness: undefined, score: 7, children: 1
French75 6 points 7 months ago

Agreed. Wrong word choice. And its an important, major correction. Not a small one. :-)

path: 0 21739455 21742008 21743980 21744631, hotness: undefined, score: 6, children: 0
notannpc 18 points 7 months ago

Microslop is openly anti consumer. Why would you hand them your encryption keys?

path: 0 21727107, hotness: undefined, score: 18, children: 1
Tollana1234567 2 points 7 months ago

winds 11 home forces it apparently, when you have to use it.

path: 0 21727107 21734290, hotness: undefined, score: 2, children: 0
BlackLaZoR 18 points 7 months ago

Remember when Truecrypt got suspiciously terminated? That was the goal

path: 0 21726329, hotness: undefined, score: 18, children: 6
RamRabbit 24 points 7 months ago path: 0 21726329 21726557, hotness: undefined, score: 24, children: 2
Scrollone 4 points 7 months ago

I wonder if it's actually safe or if it's just a CIA honeypot.

path: 0 21726329 21726557 21726655, hotness: undefined, score: 4, children: 1
RustySharp 21 points 7 months ago path: 0 21726329 21726557 21726655 21727374, hotness: undefined, score: 21, children: 0
tekato 2 points 7 months ago

Microsoft only has your key if you give it to them for convenience (by syncing to your Microsoft account), and they’re required by law to give anything stored in their servers if asked. There’s no conspiracy here.

path: 0 21726329 21732743, hotness: undefined, score: 2, children: 2
RamRabbit 6 points 7 months ago

Microsoft railroads you into this. Your Bitlocker key will get exfiltrated unless you do a bunch of bullshit to make sure it isn't.

And that's the thing with Microsoft, they just keep doing this everywhere in Windows. There is and endless torrent of shit to turn off. No reasonable person will keep on top of it. And if you fuck up a singular time, they just vacuum everything.

path: 0 21726329 21732743 21733930, hotness: undefined, score: 6, children: 1
tekato 4 points 7 months ago

Well, you obviously have never used BitLocker. The first thing they ask you when you activate BitLocker is to pick one of 3 options:

  1. Link to Microsoft Account.

  2. Save to a File

  3. Print Recovery Key (so you can write it down on a piece of paper or whatever)

There’s no “railroading”. There’s plenty of real things to not like Microsoft. No need to make them up.

path: 0 21726329 21732743 21733930 21736433, hotness: undefined, score: 4, children: 0
brooke592 17 points 7 months ago

Federal investigators in Guam believed the devices held evidence that would help prove individuals handling the island’s Covid unemployment assistance program were part of a plot to steal funds.

Damn, they weren't even doing this to go after pedos.

I'm curious where in the economic ladder this person fell. Rich enough to get a significant amount of money from the system, but still too poor to make the government look the other way.

path: 0 21737159, hotness: undefined, score: 17, children: 0
Mwa 14 points 7 months ago

IIRC am pretty sure they have been doing this for years(since Windows 8).

path: 0 21729501, hotness: undefined, score: 14, children: 2
Ugurcan 2 points 7 months ago

There was an MS tool named COFEE for forensic of Windows machines that’s exclusive to national security agencies, which eventually leaked to What.CD like back in 2009. So I’m pretty sure this predates even Windows 8.

path: 0 21729501 21733055, hotness: undefined, score: 2, children: 1
Mwa 2 points 7 months ago

So Windows 7/Vista era they have been doing it

path: 0 21729501 21733055 21736270, hotness: undefined, score: 2, children: 0
A_Random_Idiot 12 points 7 months ago

Amazing how every time you think they've finally stopped digging.. they whip out the steam shovel and go "Hey y'all, watch this!"

path: 0 21742316, hotness: undefined, score: 12, children: 0
termaxima 12 points 7 months ago

Not your keys ? Not your data !

path: 0 21736512, hotness: undefined, score: 12, children: 0
oliver 11 points 7 months ago

Well, storing the key in the specific provider‘s cloud isn‘t a good idea anyway - the same counts for iCloud as well. There are things that should be separated from each other because of reasons, this one is just another proof for the need to do so.

path: 0 21738405, hotness: undefined, score: 11, children: 0
thethunderwolf 10 points 7 months ago

Microslop's OS is evidently untrustworthy and should not be used. I recommend replacing it with a Linux distribution.

path: 0 21742291, hotness: undefined, score: 10, children: 1
ipkpjersi 2 points 7 months ago

People will still use it all the same though lol

People are creatures of habit, whereas fortune favors the bold.

path: 0 21742291 21758800, hotness: undefined, score: 2, children: 0
wuffah 10 points 7 months ago

Even if you don’t care that MS and the federal government can decrypt your data, when Bitlocker is enabled your MS account becomes cryptographically linked to your identity and machine, making it a powerful tool for surveillance, identification, and DRM.

path: 0 21727597, hotness: undefined, score: 10, children: 0
xorollo 8 points 7 months ago

So how did Microsoft have the keys in the first place? The article says they are automatically uploaded to the cloud. What does that mean? They're uploaded to the user's on drive or something else? Because whatever that user account is shouldn't be accessible by Microsoft, even if they run the service. I'm not saying aim surprised they do have it, but would be nice to be a little clearer about what features of Bitlocker to avoid. Is it the Microsoft account associated with the windows key? Probably.

path: 0 21731762, hotness: undefined, score: 8, children: 2
Wispy2891 11 points 7 months ago

Did you read the news about how nowadays is almost impossible to use Windows 11 without a Microsoft account?

When/if any user uses the computer with a Microsoft account, then the bitlocker decryption key is silently and automatically uploaded to Microsoft servers as a "safe backup" 😉

path: 0 21731762 21733865, hotness: undefined, score: 11, children: 1
xorollo 1 point 7 months ago

Yep, this tracks. I wish the article was clearer about it, because to me it seems like they were indicating there was some permission involved in the choice. Which is not really the case in any meaningful sense.

path: 0 21731762 21733865 21746445, hotness: undefined, score: 1, children: 0
homesweethomeMrL 7 points 7 months ago

I was summoned to help eject a CD today.

I’m out.

path: 0 21726771, hotness: undefined, score: 7, children: 1
user224 8 points 7 months ago

cupholder.exe

path: 0 21726771 21729653, hotness: undefined, score: 8, children: 0
the_riviera_kid 7 points 7 months ago

This is why I don't use bit locker, nothing microslop controls secure in any way.

path: 0 21727090, hotness: undefined, score: 7, children: 0
theuniqueone 7 points 7 months ago

Expect nothing else from any corporation for your own safety.

path: 0 21730301, hotness: undefined, score: 7, children: 0
blanketswithsmallpox 6 points 7 months ago

Regular old ZIP with AES-256 should do the trick for anything truly important you want to keep locked down.

You could always do sly stuff like Hidden volumes with Veracrypt as well. Leave the crumb trail for the low key shit or old nudes of gfs you have permission to keep.

path: 0 21737245, hotness: undefined, score: 6, children: 7
waitmarks 11 points 7 months ago

Or don’t use an operating system that uploads your encryption keys to their corporate servers for “backup”.

path: 0 21737245 21738167, hotness: undefined, score: 11, children: 6
blanketswithsmallpox 1 point 7 months ago

Ya'll know Veracrypt isn't Bitlocker right?

path: 0 21737245 21738167 21750130, hotness: undefined, score: 1, children: 1
waitmarks 2 points 7 months ago

I understand what veracrypt is, i don’t understand willingly using an operating system that constantly violates your privacy at every given opportunity.

path: 0 21737245 21738167 21750130 21756645, hotness: undefined, score: 2, children: 0
Kissaki 1 point 7 months ago

Or decline the upload recommendation.

path: 0 21737245 21738167 21738427, hotness: undefined, score: 1, children: 3
uszo165 7 points 7 months ago

There is no recommendation that a user can decline. Windows uploads the keys without asking, without consent.

path: 0 21737245 21738167 21738427 21740568, hotness: undefined, score: 7, children: 2
Kissaki 2 points 7 months ago

Do you have a source for that?

This article said "by default". The article they link to on that talks about encryption on by default on new PCs. The article I read before this one said "Microsoft recommends".

BitLocker FAQ says

How can the recovery password and recovery key be stored?

The recovery password and recovery key for an operating system drive or a fixed data drive can be saved to a folder, saved to one or more USB devices, saved to a Microsoft Account, or printed.

/edit: fix quote

path: 0 21737245 21738167 21738427 21740568 21748221, hotness: undefined, score: 2, children: 1
Treczoks 5 points 7 months ago

Just as I expected how security in Microsoft products works.

path: 0 21747440, hotness: undefined, score: 5, children: 0
ItsMeForRealNow 4 points 7 months ago

Can I have those please? I think I need it to unlock an old hardrive.

path: 0 21733985, hotness: undefined, score: 4, children: 1
Kissaki 2 points 7 months ago

If you uploaded your recovery key to Microsoft, then recovery is probably available in the normal recovery workflow.

path: 0 21733985 21738514, hotness: undefined, score: 2, children: 0
teslasaur 4 points 7 months ago path: 0 21745236, hotness: undefined, score: 4, children: 1
Kazumara 2 points 7 months ago

I'm just wondering how many devices still use dedicated TPMs, instead of the ones integrated in the SoC by AMD and Intel. Sniffing a bus inside the SoC must be significantly harder or impossible.

path: 0 21745236 21755694, hotness: undefined, score: 2, children: 0
umbrella 4 points 7 months ago
path: 0 21742229, hotness: undefined, score: 4, children: 0
svullo56 3 points 7 months ago

Sooo... Is there an alternative to be secure other than switching to another OS? Not that I'm doing anything interesting but I would like to have at least a bit of privacy.

path: 0 21728067, hotness: undefined, score: 3, children: 5
DeathByBigSad 13 points 7 months ago

Veracrypt + LTSC

path: 0 21728067 21728425, hotness: undefined, score: 13, children: 0
frongt 6 points 7 months ago

Yeah, just don't enable key upload and this can't happen. Don't link your account either if you want to be more sure.

If your account has already been linked, unlink it and change the bitlocker keys, both regular and recovery. (Easiest way is to entirely decrypt and reencrypt the drive.)

path: 0 21728067 21729064, hotness: undefined, score: 6, children: 2
DeathByBigSad 5 points 7 months ago

Home edition has this "please sign in to microsoft account to 'finish encryption'" text with a exclamation mark which implies the key is available on the drive unencrypted if you don't sign in, meaning anyone could just access your drive with physical access.

There is no "turning off" the key upload, once you sign in, the upload happens immediately, you can "delete" it later, but like nobody really knows if they ever delete it once they have it.

path: 0 21728067 21729064 21729297, hotness: undefined, score: 5, children: 1
frongt 2 points 7 months ago

I doubt that that's actually required to finish encryption.

path: 0 21728067 21729064 21729297 21729535, hotness: undefined, score: 2, children: 0
Lfrith 2 points 7 months ago
path: 0 21728067 21735205, hotness: undefined, score: 2, children: 0
kobaltauge 3 points 7 months ago path: 0 21757219, hotness: undefined, score: 3, children: 0
SabinStargem 3 points 7 months ago

All the more reason to use Linux. I will be swapping to Cachy or SteamOS Desktop, depending on when and how things play out.

path: 0 21731703, hotness: undefined, score: 3, children: 0
goodboyjojo 1 point 7 months ago

Isn't this against the fourth admement or something?

path: 0 21745462, hotness: undefined, score: 1, children: 0
Appoxo -13 points 7 months ago

Everyone here (exceptions apply) being soo linux friendly and so tech literate that they don't know jack shit about both sides and jump to assumptions.

Microshit has no access to your key unless you upload it.

Well DUH!

path: 0 21729327, hotness: undefined, score: -13, children: 12
UltraBlack 10 points 7 months ago

A microsoft accpunt is now mandatory for windows. Your bitlocker keys are automatically uploaded to your account

path: 0 21729327 21730211, hotness: undefined, score: 10, children: 11
LifeInMultipleChoice 2 points 7 months ago

That has to be version specific. I did run into the issue that the Apple devices app that Apple makes is only made available through the Microsoft Store though. So you can't just run a standard install for it officially. Which sucks. Also their is no official Apple Devices app for Linux, so anyone who has an iPhone can't "safely" manage their device without having both an Apple Account and a Microsoft account, or a Mac.

path: 0 21729327 21730211 21730349, hotness: undefined, score: 2, children: 1
Appoxo 1 point 7 months ago

Couldnt you download the MSIX app bundle? That should be possible to install the app even without the account

path: 0 21729327 21730211 21730349 21735418, hotness: undefined, score: 1, children: 0
Appoxo 1 point 7 months ago

No, it is not.
At least not in the EU where I live.

path: 0 21729327 21730211 21735403, hotness: undefined, score: 1, children: 0
ultranaut -4 points 7 months ago

This is not correct. You can use Windows without a Microsoft account.

path: 0 21729327 21730211 21730795, hotness: undefined, score: -4, children: 7
kittenzrulz123 -1 points 7 months ago

Objectively untrue

path: 0 21729327 21730211 21730795 21734635, hotness: undefined, score: -1, children: 6
ultranaut 3 points 7 months ago

This is insane. I am using Windows without a Microsoft account regularly. It is 100% possible. I hate Microsoft too but it's completely ridiculous to go around spreading obvious bullshit like this.

path: 0 21729327 21730211 21730795 21734635 21739255, hotness: undefined, score: 3, children: 4
Appoxo 2 points 7 months ago

Objectively true.
We just did it this week with Windows 11 25H2 with the regular OOBE setup.

Not everywhere is a corporate hellscape like the US

And btw:
My PC right now with Win11 25H2 runs on a local account

path: 0 21729327 21730211 21730795 21734635 21735434, hotness: undefined, score: 2, children: 0
technology
technology

@lemmy.world

login for more options
87401
21272
15822

This is a most excellent place for technology news and articles.

Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


go to feed...