Live data from Hacker News

Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

g1a55er.net

21–28 of 28 posts

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#21
post #9

Recently I wiped the contents of the Trusted Platform Module of a laptop. Now the laptop failed to boot as the Bitlocker key was not stored in the TPM anymore. To my surprise it was possible to get a code from Microsoft to access the laptop's disk again, as one of the admin accounts was a Microsoft account. I strongly suspect, Microsoft does only activate Bitlocker during the OOBE if it can set-up this kind of Bitloc…

It is the primary failsafe for Microsoft 365 accounts to store the BitLocker recovery key with your Microsoft account. The other failsafes are printing the key or storing it on an external device.

One can easily obtain the recovery key on a system by doing "manage-bde -protectors -get c:" in an admin command prompt. This is not a vulnerability, it is by design.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#22
post #15

I have made a claim before which I shall make again: Windows 11 should be considered malware, it is the worst product Microsoft has ever produced. I hope the experience gets even worse so that more people will abandon Windows for better OS's.

Agreed. My use of windows dies with Windows 10. My next gaming PC will be Linux and I will deal with not all games working. My steam deck proved this is 100% viable.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#23
post #15

I have made a claim before which I shall make again: Windows 11 should be considered malware, it is the worst product Microsoft has ever produced. I hope the experience gets even worse so that more people will abandon Windows for better OS's.

I installed Windows 11. A couple hours later, I was horrified to find that Windows 11 uploaded all files on my desktop to Microsoft. There's no warning or opt-in. OneDrive is set up by default to silently copy all your files. How is that legal?

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#24
post #15

I have made a claim before which I shall make again: Windows 11 should be considered malware, it is the worst product Microsoft has ever produced. I hope the experience gets even worse so that more people will abandon Windows for better OS's.

for sure enshittification going on

on win11 home edition, when inside an explorer folder , i can't even drag and drop another folder or file onto the address bar anymore (moving files up a directory). I swear i could do this in like windows xp and 2000, windows is for sure going backwards i hate it. i keep getting a blocked icon when i hover over parent directories.

i guess its motivation to become more proficient with the command line

also another hugely annoying thing is how windows has removed the labels for copy/paste and shortened the context menu. I recently went back to school and non tech savvy people have no clue about those icons and i swear i have to apologize to them everytime (since im the "tech guy") how bad microsoft is lmao

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#25
post #4
post #2

From reading the article, it seems the author assumed that disk encryption is on by default, which is not the case in Windows. You have to, for example, open the "Manage BitLocker" control panel applet to set up disk encryption.

It is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in…

I would think the other side of this is "if you try to boot another OS one day, surprise, you didn't know the disc was encrypted and can't access any of your files."

That screams anti-competitive behaviour to me-- how many people would stop their "let's try Linux" experiment if you can't mount your existing drive to access previous data?

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#26
post #25
post #4

Earlier quoted context omitted.

It is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in…

I would think the other side of this is "if you try to boot another OS one day, surprise, you didn't know the disc was encrypted and can't access any of your files." That screams anti-competitive behaviour to me-- how many people would stop their "let's try Linux" experiment if you can't mount your existing drive to access previous data?

>That screams anti-competitive behaviour to me

...or they're trying to increase security against physical attacks. The year of the Linux desktop has been a running joke for decades. Microsoft doesn't need disk encryption to keep Linux from gaining traction. Linux is already doing a pretty good job for them.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#27
post #26
post #25

Earlier quoted context omitted.

I would think the other side of this is "if you try to boot another OS one day, surprise, you didn't know the disc was encrypted and can't access any of your files." That screams anti-competitive behaviour to me-- how many people would stop their "let's try Linux" experiment if you can't mount your existing drive to access previous data?

>That screams anti-competitive behaviour to me ...or they're trying to increase security against physical attacks. The year of the Linux desktop has been a running joke for decades. Microsoft doesn't need disk encryption to keep Linux from gaining traction. Linux is already doing a pretty good job for them.

Well, I could see plenty of other use cases (i. e. "My machine is kaput, can you tether the hard disc and grab my data") but this one has a legitimate business edge if they intercept it.

Re: Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key

#28
post #23
post #15

I have made a claim before which I shall make again: Windows 11 should be considered malware, it is the worst product Microsoft has ever produced. I hope the experience gets even worse so that more people will abandon Windows for better OS's.

I installed Windows 11. A couple hours later, I was horrified to find that Windows 11 uploaded all files on my desktop to Microsoft. There's no warning or opt-in. OneDrive is set up by default to silently copy all your files. How is that legal?

Windows 10 had the same behavior. MacOS has also done this by default for years now. I don’t say this to excuse the behavior. On the contrary, I’ve seen many a small business owner run afoul of compliance requirements because they aren’t aware of the default behavior. Slurping data to consumer-grade cloud services ought to require informed consent.
Post reply on HN