[HN Gopher] Skip Microsoft Acct. Sign-In in Win 11 Home? It Skip...
___________________________________________________________________
Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting
Your Data Key
Author : g1a55er
Score : 37 points
Date : 2024-01-27 21:25 UTC (1 hours ago)
(HTM) web link (www.g1a55er.net)
(TXT) w3m dump (www.g1a55er.net)
| vdaea wrote:
| From reading the article, it seems the author assumed that disk
| encryption is on by default, which is not the case in Windows.
| You have to, for example, open the "Manage BitLocker" control
| panel applet to set up disk encryption.
| g1a55er wrote:
| It is on by default in Windows 11 Home if you go through the
| normal setup experience completely according to the Microsoft
| documentation. As part of the setup, you sign in to a Microsoft
| account, which then creates a TPM protector.
|
| "Unlike a standard BitLocker implementation, device encryption
| is enabled automatically so that the device is always
| protected... When the administrator uses a Microsoft account to
| sign in, the clear key is removed, a recovery key is uploaded
| to the online Microsoft account, and a TPM protector is
| created. Should a device require the recovery key, the user is
| guided to use an alternate device and navigate to a recovery
| key access URL to retrieve the recovery key by using their
| Microsoft account credentials."
|
| From https://learn.microsoft.com/en-
| us/windows/security/operating...
|
| This is also how it's reported in the press:
|
| "In fact, the mechanisms to do exactly that are already in
| place. Windows 11 Home and Windows 11 Pro both support
| automatic device encryption, with the Home version a more
| streamlined experience. You just have to sign into the machine
| with a Microsoft account, which nearly all people do during
| setup."
|
| From https://www.pcworld.com/article/624593/is-your-
| windows-11-pc...
|
| My main point is just that if you skip this, like a lot of
| privacy conscious people do, you might end up inadvertently not
| having encryption fully enabled.
| vdaea wrote:
| You left out the part where it says "If a device uses only
| local accounts, then it remains unprotected even though the
| data is encrypted"
|
| I think you are confusing "device encryption" with "disk
| encryption" (BitLocker)
| g1a55er wrote:
| I quote that exact part of the documentation in the post. I
| also talk about the difference between "Device encryption"
| and "BitLocker Device Encryption"
|
| My argument isn't that this isn't documented. It's that it
| is a bit counterintuitive.
|
| My points are:
|
| 1) It would be best if Microsoft just asked if you wanted
| encryption if you create a local account. This is what
| Apple does in this situation. I imagine a large portion of
| the people who are creating local accounts on Windows 11
| Home are the sort that want to manage their own keys.
|
| 2) If you are in that set of people, you should double
| check your setting if you never thought about it before,
| because it's easy to miss.
| internet2000 wrote:
| This seems like a reasonable default. Encrypting data without
| having a reasonable recovery method (such as uploading the key to
| the cloud), would cause more harm than it would help. And if the
| user is already straying from the happy path in set up, it's
| probably a good idea to avoid encrypting and assume they know
| what they're doing.
|
| Note that this is the same on Mac OS: all drives are encrypted by
| default, but turning on FileVault gives you the option of either
| uploading the key to iCloud, or have a recovery key printed out,
| which you are expected to keep safe:
| https://support.apple.com/guide/mac-help/protect-data-on-you...
| ddtaylor wrote:
| It seems pretty scummy since it convinces and uses language that
| would lead users to believe they are getting an OOTB disk
| encrypted system even if they opt to not become a part of
| Microsoft's data silo.
| sys42590 wrote:
| Recently I wiped the contents of the Trusted Platform Module of a
| laptop. Now the laptop failed to boot as the Bitlocker key was
| not stored in the TPM anymore.
|
| To my surprise it was possible to get a code from Microsoft to
| access the laptop's disk again, as one of the admin accounts was
| a Microsoft account.
|
| I strongly suspect, Microsoft does only activate Bitlocker during
| the OOBE if it can set-up this kind of Bitlocker recovery
| mechanism, storing an (indirect) decryption key at Microsoft.
| gnabgib wrote:
| This is literally documented[0] and reported to you when
| setting up bitlocker[1]/creating a user account[2].
|
| [0]: https://support.microsoft.com/en-us/windows/finding-your-
| bit... [1]:
| https://www.windowspro.de/sites/windowspro.de/files/imagepic...
| [2]: https://www.anoopcnair.com/wp-
| content/uploads/2019/11/switch...
| londons_explore wrote:
| Do I read between the lines here that the default setup for home
| users (who have a Microsoft account) is to have an encrypted
| drive, but Microsoft gets sent a copy of the key...?
|
| I really wonder how many times the Microsoft legal department
| gets asked to hand over keys to law enforcement...
| g1a55er wrote:
| This is explicitly the case according to Microsoft
| documentation[1].
|
| "When the administrator uses a Microsoft account to sign in,
| the clear key is removed, a recovery key is uploaded to the
| online Microsoft account..."
|
| Microsoft does not break down requests by key disclosure, but
| they do say in their most recent report for 2022 H2 that they
| released account content for 522 requests to US criminal
| authorities in that half. It does not note how many accounts
| were included in those 522 requests.[2]
|
| [1] https://learn.microsoft.com/en-
| us/windows/security/operating...
|
| [2] https://www.microsoft.com/en-us/corporate-
| responsibility/law...
| slowmovintarget wrote:
| To quote the character from _The Matrix_ "Mmmm... all the
| time."
| drewcoo wrote:
| > I used one of the unofficial, unsupported, yet well known and
| commonly used tricks to get through the setup process without
| having to sign in with a Microsoft account
|
| > It turns out that if you skip the Microsoft account sign-in
| step and only create a "local account", your data is encrypted
| but the encryption key is stored on the drive unprotected
|
| So . . . unsupported behavior gets unexpected results?
|
| [cue sad trombone]
| Ajay-p wrote:
| I have made a claim before which I shall make again: Windows 11
| should be considered malware, it is the worst product Microsoft
| has ever produced. I hope the experience gets even worse so that
| more people will abandon Windows for better OS's.
___________________________________________________________________
(page generated 2024-01-27 23:02 UTC)