Live data from Hacker News

Windows 11 users are tired of MS account requirements creeping into everything

windowscentral.com

371–380 of 464 posts

Re: Windows 11 users are tired of MS account requirements creeping into everything

#371
post #299

Earlier quoted context omitted.

Not the parent, but have you heard of Snowden leaks? Also this from the old times: https://en.wikipedia.org/wiki/NSAKEY

Snowden says nothing about backdoor'ed Windows. And _NSAKEY... There is no evidence that it was ever part of a backdoor. But it is good for a laugh.

It's safe to assume that Windows is backdoored, as it's closed, not audiatable and is a part of PRISM. It's not a proof, but this is how good opsec works.

And yes, this is not equivalent to what the parent said, but your reaction should be similar.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#372
post #172

Earlier quoted context omitted.

You are not worried about 0-days and other malware?

The computer is not exposed to the WAN (behind a firewall), the main way it could get infected is via a vulnerability in a browser, but these do get updated. And OS updates don't really protect you from malware in executables you install anyway.

Thanks for telling! Very interesting way of thinking about the security.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#373

This stuff drives me nuts. Chrome on desktop is another abhorrent example of this. Every time I log in to a Google account within the browser, it nags me to link the account to the browser itself. One time my partner clicked the popup that asks to link the account by accident (this is very easy to do and probably Google's intention) and it hijacked all of my bookmarks. When I logged out of the account, everything was…

> Chrome on desktop is another abhorrent example of this.

Consider Chromium (the open source build) instead of Chrome when you migrate to Linux. It is in the main repo of most distributions. Chrome is literally spyware. Also Firefox (with the real uBlock Origin, not the watered down version for Chrome/Chromium) is excellent.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#374

Earlier quoted context omitted.

Agreed, specifically about the tax info concerns. All my drives are encrypted with either luks, veracrypt, or native zfs encryption if my server data. My primary concern is a robbery while I'm not home. It's trivial to break in, steal hard drives, and then go pop them into another machine on your own time to scan the files looking for tax or other sensitive docs. While encryption keys are a risk, you can always save…

Curious: Are you specifically worried about a robber who is targeting your tax information in particular? Home breakins are relatively rare, and when they do happen, for the vast majority of them, the robber grabs whatever cash, jewelry, and other small, easy-to-pawn valuables, and are probably not going to care about computers. And for those rare robbers who actually grab your computer, what percentage of them are r…

Maybe I am the fool. :) I think about crime in the way I would do it, which is to grab the valuables police are unlikely to care about (hard drives) that allow me to quickly clone and encrypt myself, so I can destroy the tangible evidence, and then I have unlimited time to crack and review the information, and then even more time to execute my malicious attack against identities or whatever other I information I do find.

Only slightly better than this would be to break in, install a root kit, and then leave everything else untouched so as to try and minimize the knowledge that I was there, but I'd still be concerned that my c2 server would eventually point to me.

Maybe I should read about these actual crimes or get meds. The first couple years of my first kid's life were full of anxiety that someone would break in and steal my kid while I was sleeping at night.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#375

I was in a hurry trying to log into my kid's Minecraft account, wound up clicking something to associate it with the Windows account... now the PC is in restricted mode and I'm having a hard time restoring the previously associated Microsoft account (among other things, have to ask permission to open the browser and approve the requests logging in on my phone)! Everything online says to use the option to switch to a…

I ran into similar MS account hell when trying to get my kid's Xbox account signed back in.

Absolutely hate it. Can't wait to ditch Xbox for PS.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#376
post #296

One thing I disagree with the article about is that drives should not be encrypted by default. For the vast majority of people an encrypted drive is just data loss lying in wait. I prefer to use non-encrypted drives so I have the option of popping out the disk and reading it from another system with ease, which also means that I can recover files from drives of otherwise dead systems just as easily. This is a trade o…

My solution for your concerns is twofold:

1. Use a password-based encryption method (not tied to hardware identity) if you prioritize moving the disk around. Then it is just as readable in a spare machine.

2. Use an easy to remember password/passphrase and write it down somewhere you keep paper documents, if you prioritize recovery.

This still provides meaningful protection when you need to discard the drive. The random downstream recipient of the hardware will not know your password, even if you skip the step where you "crypto-shred" the drive by setting a new random password.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#377
I think it is fair to encrypt the user hard drive since the majority of users are unaware that they're even leaking secrets and PII when e.g., they sell a laptop without wiping the disk first.

But I think it is also fair if the user was opening a CMD during install just to type `oobe /bypassnro` the user is advanced enough to understand the risks of not encrypting the hard drive (it is really easy to activate the BitLocker afterwards anyway, and for example in my case instead of storing the secret key in Microsoft I decided to store it in my password manager). So I really don't buy the excuses of this article.

Also WTH Microsoft, why it is so easy to reset the TPM key during e.g., a bios update and lose access to all your TPM keys (so you need to type your BitLocker key again). It should be a requirement from Microsoft laptops that the TPM contents are never lost unless the user explicitly asks for it.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#378

Earlier quoted context omitted.

It's an open secret that Windows is backdoored for the NSA to be fair and that isn't even including the truly dodgy stuff like Intel Management Engine being a backdoor on a BIOS level with remote access

Do you have a source for literally any of those allegations? I'm as big of a Windows and ME hater as they come, but I'm not aware of any proven backdoors in either. Especially ME, which has been thoroughly reverse-engineered by the security community by this point. The only 'backdoor' discovered was the undocumented killswitch command that disables it after initialization.

> Especially ME, which has been thoroughly reverse-engineered by the security community by this point.

Links? Activists say the opposite, https://en.wikipedia.org/wiki/Intel_Management_Engine#Assert...

Re: Windows 11 users are tired of MS account requirements creeping into everything

#379

Earlier quoted context omitted.

You can save your recovery key in different formats (printed, on a USB stick, etc). The online recovery is just automatic.

So the encryption of your personal computer is at the whims of the least competent employee at Microsoft?

I'm not exactly sure what your point is.

This has always been the case considering Microsoft made the encryption itself.

Re: Windows 11 users are tired of MS account requirements creeping into everything

#380
post #377

I think it is fair to encrypt the user hard drive since the majority of users are unaware that they're even leaking secrets and PII when e.g., they sell a laptop without wiping the disk first. But I think it is also fair if the user was opening a CMD during install just to type `oobe /bypassnro` the user is advanced enough to understand the risks of not encrypting the hard drive (it is really easy to activate the Bit…

You’ve forgotten the most important fact: users don’t provide enough of a revenue stream. Therefore they aren’t represented at the table when decisions are being made that effect their fate.

Similar to how there is no actual citizen representation in the Congress of the US.

Now stop whining and get back to work.

Post reply on HN