It's straightforward to set Bitlocker up so that Microsoft doesn't hold a backup key.
Microsoft is doing what their userbase wants them to do. I'm not sure what's interesting about this story.
It's straightforward to set Bitlocker up so that Microsoft doesn't hold a backup key.
Microsoft is doing what their userbase wants them to do. I'm not sure what's interesting about this story.
Which he states on his own, and with a quote from an unnamed Microsoft representative, starting on the 7th paragraph:
> Of course, keeping a backup of your recovery key in your Microsoft account is genuinely useful for probably the majority of Windows users, which is why Microsoft designed the encryption scheme...
But, I agree with you. This is pretty much a non-story. One might have to jump through one more hoop to setup BitLocker without sending the key to any third party, but it's essentially the same as the default of sending your FileVault key to Apple for the easiest backup option.
Since Microsoft presumably doesn't have the data, they get little value from holding the key. However, I would never copy a key without telling anyone.
What you say here -- encryption keys are not like online account passwords (you can't reset them) -- is NOT the default for people coming from dmcrypt[1], for example, where I can have multiple pass phrases / files to the same vault, easily adding and removing them.
It feels odd to work with at rest encryptions systems, and I'm guessing Win10 has the same constraint out of the box?, that don't offer this feature.
[1] https://wiki.archlinux.org/index.php/Dm-crypt/Device_encrypt...
This is also how they implement recovery passwords (as 'numerical passwords') by default.
I have a lot of sympathy for Microsoft here, given some professional history with Chrome's Sync feature. Originally Sync data was always encrypted locally with either your Google password or a custom passphrase, and recovery wasn't possible (well, practical) absent that passphrase. The result was a bit of a support nightmare, as people would lose their sync data because they changed their account password and forgot the old one, or upgraded their machine and had forgotten the password years before, because it was being autofilled.
To solve the problem we ended up changing the way we managed the encryption, so we could recover the data for the default case, and kept the custom passphrase as an opt-in for local-only encryption. That's not to say I think we did everything we could to promote and support the use of a custom passphrase, but I am thoroughly convinced that it's not something the majority of users are concerned about or want to hassle with. If the average user forgets their password they still want to be able to get their data back (and there's no good way to forewarn or explain away why it won't work).
Device encryption tends to be terrible, and as Micah says you can't ever change the storage option for the recovery key. It's automatically tied to the Microsoft account.
If Windows Home had BitLocker, this wouldn't be a problem. But as with most of Microsoft'/Nadella's moves lately, they seem to believe they know best not for 99% of their users, but for 100% of them. That's how we got encryption keys that can only get stored in Microsoft/NSA's datacenters, telemetry services that you can never truly stop, and even if you do, they come back as zombies, and updates that you can at best delay, but also never stop. And that's on top of all the other privacy invasive "features" that are set by default, and Microsoft makes it hard for 99% of the users to know they can turn them off.
User: "What do you mean I can't access my emails because I lost my password?"
Admin: "For privacy, it's designed so that your password is only thing that unlocks the keys. If that's gone, then the email is gone. That's how it's supposed to work."
User: "Well, that's bullshit. Now, we might loose all kinds of money over this crap. And for what!? It's not like there's people snooping our traffic on the internal network."
Scenario plays out in so many situations. In business, it's availability first, integrity second, and confidentiality maybe. Almost always.
The only valid answer is to switch to Linux.
(And don't ask the average user to understand or do anything to prevent that. Default matter.)
Microsoft added drive encryption by default with easy recovery if you forget your password - which necessitates Microsoft keeping the recovery key by default.
Power users can change these settings.
There is no "excuse" here, Microsoft has improved the situation. (And unless things have changed recently, user action is required on virtually every popular Linux distribution except Android to get any drive encryption at all.)
What people need is education about the situation and a real solution. Not a "solution" that makes them feel secure, which is what Microsoft sells here.
You are correct:
http://www.cnet.com/news/best-buy-employee-accused-of-copyin...
http://consumerist.com/2007/07/05/video-consumerist-catches-...
http://consumerist.com/2007/05/02/the-10-page-geek-squad-con...
So Microsoft is charging more to not keep the key, which means they view it as a benefit for them to keep the key.
If it was just to help the user, why charge to not upload the key?
So get pro.
Or it means that Bitlocker has been a Pro or Ultimate feature in Windows Vista, Windows 7, Windows 8, and Windows 8.1, and PHBs decreed that Microsoft wasn't going to put the full-fledged feature in Home to continue to differentiate between Home and Pro and that the intended market of Home users did not need to be provided a way to lose their keys and brick their computers because nobody wants those support calls and the negative publicity about your data being inaccessible?
>the intended market of Home users did not need to be provided a way to lose their keys and brick their computers because nobody wants those support calls and the negative publicity about your data being inaccessible
So make the option a registry tweak, which is free, not an upgrade to Pro, which isn't.
I don't think freedom from corporate decryption abilities should be something charged for.
A basic version of Bitlocker has been provided since Windows 8 in the Home edition, as you point out.
There's nothing more I can write I didn't address in the above post. Device encryption and Bitlocker aren't separate entities. Device encryption is the consumer version of Bitlocker. Device encryption doesn't expose all the features of Bitlocker because then there's less that differentiates Home and Pro/Enterprise.
I agree it would be nice to have in Home, but the average Home user doesn't know what this is, doesn't want it, and probably shouldn't have it. If you are the kind of knowledgeable user that does know it and should have it, Pro isn't hard to get. Hell, Home doesn't even have freakin' Remote Desktop.
Microsoft has to have something to differentiate editions (if they're going to insist on doing so in the first place - life would be simpler if they didn't), this seems reasonable enough and a step in the right direction - more encrypted harddrives.
There is no "corporate decryption ability" unless Microsoft is in actual physical possession of your TPM and harddrive.