Live data from Hacker News

Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

g1a55er.net

1–10 of 28 posts

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#4
post #2

From reading the article, it seems the author assumed that disk encryption is on by default, which is not the case in Windows. You have to, for example, open the "Manage BitLocker" control panel applet to set up disk encryption.

It is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector.

"Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account, and a TPM protector is created. Should a device require the recovery key, the user is guided to use an alternate device and navigate to a recovery key access URL to retrieve the recovery key by using their Microsoft account credentials."

From https://learn.microsoft.com/en-us/windows/security/operating...

This is also how it's reported in the press:

"In fact, the mechanisms to do exactly that are already in place. Windows 11 Home and Windows 11 Pro both support automatic device encryption, with the Home version a more streamlined experience. You just have to sign into the machine with a Microsoft account, which nearly all people do during setup."

From https://www.pcworld.com/article/624593/is-your-windows-11-pc...

My main point is just that if you skip this, like a lot of privacy conscious people do, you might end up inadvertently not having encryption fully enabled.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#6
This seems like a reasonable default. Encrypting data without having a reasonable recovery method (such as uploading the key to the cloud), would cause more harm than it would help. And if the user is already straying from the happy path in set up, it's probably a good idea to avoid encrypting and assume they know what they're doing.

Note that this is the same on Mac OS: all drives are encrypted by default, but turning on FileVault gives you the option of either uploading the key to iCloud, or have a recovery key printed out, which you are expected to keep safe: https://support.apple.com/guide/mac-help/protect-data-on-you...

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#8
post #4
post #2

From reading the article, it seems the author assumed that disk encryption is on by default, which is not the case in Windows. You have to, for example, open the "Manage BitLocker" control panel applet to set up disk encryption.

It is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in…

You left out the part where it says "If a device uses only local accounts, then it remains unprotected even though the data is encrypted"

I think you are confusing "device encryption" with "disk encryption" (BitLocker)

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#9
Recently I wiped the contents of the Trusted Platform Module of a laptop. Now the laptop failed to boot as the Bitlocker key was not stored in the TPM anymore.

To my surprise it was possible to get a code from Microsoft to access the laptop's disk again, as one of the admin accounts was a Microsoft account.

I strongly suspect, Microsoft does only activate Bitlocker during the OOBE if it can set-up this kind of Bitlocker recovery mechanism, storing an (indirect) decryption key at Microsoft.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#10
post #8
post #4

Earlier quoted context omitted.

It is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in…

You left out the part where it says "If a device uses only local accounts, then it remains unprotected even though the data is encrypted" I think you are confusing "device encryption" with "disk encryption" (BitLocker)

I quote that exact part of the documentation in the post. I also talk about the difference between "Device encryption" and "BitLocker Device Encryption"

My argument isn't that this isn't documented. It's that it is a bit counterintuitive.

My points are:

1) It would be best if Microsoft just asked if you wanted encryption if you create a local account. This is what Apple does in this situation. I imagine a large portion of the people who are creating local accounts on Windows 11 Home are the sort that want to manage their own keys.

2) If you are in that set of people, you should double check your setting if you never thought about it before, because it's easy to miss.

Post reply on HN