[HN Gopher] Skip Microsoft Acct. Sign-In in Win 11 Home? It Skip...
       ___________________________________________________________________
        
       Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting
       Your Data Key
        
       Author : g1a55er
       Score  : 37 points
       Date   : 2024-01-27 21:25 UTC (1 hours ago)
        
 (HTM) web link (www.g1a55er.net)
 (TXT) w3m dump (www.g1a55er.net)
        
       | vdaea wrote:
       | From reading the article, it seems the author assumed that disk
       | encryption is on by default, which is not the case in Windows.
       | You have to, for example, open the "Manage BitLocker" control
       | panel applet to set up disk encryption.
        
         | g1a55er wrote:
         | It is on by default in Windows 11 Home if you go through the
         | normal setup experience completely according to the Microsoft
         | documentation. As part of the setup, you sign in to a Microsoft
         | account, which then creates a TPM protector.
         | 
         | "Unlike a standard BitLocker implementation, device encryption
         | is enabled automatically so that the device is always
         | protected... When the administrator uses a Microsoft account to
         | sign in, the clear key is removed, a recovery key is uploaded
         | to the online Microsoft account, and a TPM protector is
         | created. Should a device require the recovery key, the user is
         | guided to use an alternate device and navigate to a recovery
         | key access URL to retrieve the recovery key by using their
         | Microsoft account credentials."
         | 
         | From https://learn.microsoft.com/en-
         | us/windows/security/operating...
         | 
         | This is also how it's reported in the press:
         | 
         | "In fact, the mechanisms to do exactly that are already in
         | place. Windows 11 Home and Windows 11 Pro both support
         | automatic device encryption, with the Home version a more
         | streamlined experience. You just have to sign into the machine
         | with a Microsoft account, which nearly all people do during
         | setup."
         | 
         | From https://www.pcworld.com/article/624593/is-your-
         | windows-11-pc...
         | 
         | My main point is just that if you skip this, like a lot of
         | privacy conscious people do, you might end up inadvertently not
         | having encryption fully enabled.
        
           | vdaea wrote:
           | You left out the part where it says "If a device uses only
           | local accounts, then it remains unprotected even though the
           | data is encrypted"
           | 
           | I think you are confusing "device encryption" with "disk
           | encryption" (BitLocker)
        
             | g1a55er wrote:
             | I quote that exact part of the documentation in the post. I
             | also talk about the difference between "Device encryption"
             | and "BitLocker Device Encryption"
             | 
             | My argument isn't that this isn't documented. It's that it
             | is a bit counterintuitive.
             | 
             | My points are:
             | 
             | 1) It would be best if Microsoft just asked if you wanted
             | encryption if you create a local account. This is what
             | Apple does in this situation. I imagine a large portion of
             | the people who are creating local accounts on Windows 11
             | Home are the sort that want to manage their own keys.
             | 
             | 2) If you are in that set of people, you should double
             | check your setting if you never thought about it before,
             | because it's easy to miss.
        
       | internet2000 wrote:
       | This seems like a reasonable default. Encrypting data without
       | having a reasonable recovery method (such as uploading the key to
       | the cloud), would cause more harm than it would help. And if the
       | user is already straying from the happy path in set up, it's
       | probably a good idea to avoid encrypting and assume they know
       | what they're doing.
       | 
       | Note that this is the same on Mac OS: all drives are encrypted by
       | default, but turning on FileVault gives you the option of either
       | uploading the key to iCloud, or have a recovery key printed out,
       | which you are expected to keep safe:
       | https://support.apple.com/guide/mac-help/protect-data-on-you...
        
       | ddtaylor wrote:
       | It seems pretty scummy since it convinces and uses language that
       | would lead users to believe they are getting an OOTB disk
       | encrypted system even if they opt to not become a part of
       | Microsoft's data silo.
        
       | sys42590 wrote:
       | Recently I wiped the contents of the Trusted Platform Module of a
       | laptop. Now the laptop failed to boot as the Bitlocker key was
       | not stored in the TPM anymore.
       | 
       | To my surprise it was possible to get a code from Microsoft to
       | access the laptop's disk again, as one of the admin accounts was
       | a Microsoft account.
       | 
       | I strongly suspect, Microsoft does only activate Bitlocker during
       | the OOBE if it can set-up this kind of Bitlocker recovery
       | mechanism, storing an (indirect) decryption key at Microsoft.
        
         | gnabgib wrote:
         | This is literally documented[0] and reported to you when
         | setting up bitlocker[1]/creating a user account[2].
         | 
         | [0]: https://support.microsoft.com/en-us/windows/finding-your-
         | bit... [1]:
         | https://www.windowspro.de/sites/windowspro.de/files/imagepic...
         | [2]: https://www.anoopcnair.com/wp-
         | content/uploads/2019/11/switch...
        
       | londons_explore wrote:
       | Do I read between the lines here that the default setup for home
       | users (who have a Microsoft account) is to have an encrypted
       | drive, but Microsoft gets sent a copy of the key...?
       | 
       | I really wonder how many times the Microsoft legal department
       | gets asked to hand over keys to law enforcement...
        
         | g1a55er wrote:
         | This is explicitly the case according to Microsoft
         | documentation[1].
         | 
         | "When the administrator uses a Microsoft account to sign in,
         | the clear key is removed, a recovery key is uploaded to the
         | online Microsoft account..."
         | 
         | Microsoft does not break down requests by key disclosure, but
         | they do say in their most recent report for 2022 H2 that they
         | released account content for 522 requests to US criminal
         | authorities in that half. It does not note how many accounts
         | were included in those 522 requests.[2]
         | 
         | [1] https://learn.microsoft.com/en-
         | us/windows/security/operating...
         | 
         | [2] https://www.microsoft.com/en-us/corporate-
         | responsibility/law...
        
         | slowmovintarget wrote:
         | To quote the character from _The Matrix_ "Mmmm... all the
         | time."
        
       | drewcoo wrote:
       | > I used one of the unofficial, unsupported, yet well known and
       | commonly used tricks to get through the setup process without
       | having to sign in with a Microsoft account
       | 
       | > It turns out that if you skip the Microsoft account sign-in
       | step and only create a "local account", your data is encrypted
       | but the encryption key is stored on the drive unprotected
       | 
       | So . . . unsupported behavior gets unexpected results?
       | 
       | [cue sad trombone]
        
       | Ajay-p wrote:
       | I have made a claim before which I shall make again: Windows 11
       | should be considered malware, it is the worst product Microsoft
       | has ever produced. I hope the experience gets even worse so that
       | more people will abandon Windows for better OS's.
        
       ___________________________________________________________________
       (page generated 2024-01-27 23:02 UTC)