Skip Microsoft Acct. Sign-In in Win 11 Home? It Skips Protecting Your Data Key
g1a55er.net
g1a55er.net
To my surprise it was possible to get a code from Microsoft to access the laptop's disk again, as one of the admin accounts was a Microsoft account.
I strongly suspect, Microsoft does only activate Bitlocker during the OOBE if it can set-up this kind of Bitlocker recovery mechanism, storing an (indirect) decryption key at Microsoft.
[0]: https://support.microsoft.com/en-us/windows/finding-your-bit... [1]: https://www.windowspro.de/sites/windowspro.de/files/imagepic... [2]: https://www.anoopcnair.com/wp-content/uploads/2019/11/switch...
One can easily obtain the recovery key on a system by doing "manage-bde -protectors -get c:" in an admin command prompt. This is not a vulnerability, it is by design.
Note that this is the same on Mac OS: all drives are encrypted by default, but turning on FileVault gives you the option of either uploading the key to iCloud, or have a recovery key printed out, which you are expected to keep safe: https://support.apple.com/guide/mac-help/protect-data-on-you...
Forced online account creation, page after page asking to enable data, ad preferences for what normally costs a lot of money, all of this seems crazy when I compare it with a recent Linux install which had zero things I had to agree to. The windows ULAs are so long you can't even read them if you wanted to.
At least I only paid USD 3 for the license because anything more than that IMO is insane at this point.
on win11 home edition, when inside an explorer folder , i can't even drag and drop another folder or file onto the address bar anymore (moving files up a directory). I swear i could do this in like windows xp and 2000, windows is for sure going backwards i hate it. i keep getting a blocked icon when i hover over parent directories.
i guess its motivation to become more proficient with the command line
also another hugely annoying thing is how windows has removed the labels for copy/paste and shortened the context menu. I recently went back to school and non tech savvy people have no clue about those icons and i swear i have to apologize to them everytime (since im the "tech guy") how bad microsoft is lmao
I really wonder how many times the Microsoft legal department gets asked to hand over keys to law enforcement...
"When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account..."
Microsoft does not break down requests by key disclosure, but they do say in their most recent report for 2022 H2 that they released account content for 522 requests to US criminal authorities in that half. It does not note how many accounts were included in those 522 requests.[2]
[1] https://learn.microsoft.com/en-us/windows/security/operating...
[2] https://www.microsoft.com/en-us/corporate-responsibility/law...
> It turns out that if you skip the Microsoft account sign-in step and only create a “local account”, your data is encrypted but the encryption key is stored on the drive unprotected
So . . . unsupported behavior gets unexpected results?
[cue sad trombone]
"Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account, and a TPM protector is created. Should a device require the recovery key, the user is guided to use an alternate device and navigate to a recovery key access URL to retrieve the recovery key by using their Microsoft account credentials."
From https://learn.microsoft.com/en-us/windows/security/operating...
This is also how it's reported in the press:
"In fact, the mechanisms to do exactly that are already in place. Windows 11 Home and Windows 11 Pro both support automatic device encryption, with the Home version a more streamlined experience. You just have to sign into the machine with a Microsoft account, which nearly all people do during setup."
From https://www.pcworld.com/article/624593/is-your-windows-11-pc...
My main point is just that if you skip this, like a lot of privacy conscious people do, you might end up inadvertently not having encryption fully enabled.
I think you are confusing "device encryption" with "disk encryption" (BitLocker)
My argument isn't that this isn't documented. It's that it is a bit counterintuitive.
My points are:
1) It would be best if Microsoft just asked if you wanted encryption if you create a local account. This is what Apple does in this situation. I imagine a large portion of the people who are creating local accounts on Windows 11 Home are the sort that want to manage their own keys.
2) If you are in that set of people, you should double check your setting if you never thought about it before, because it's easy to miss.
That screams anti-competitive behaviour to me-- how many people would stop their "let's try Linux" experiment if you can't mount your existing drive to access previous data?
...or they're trying to increase security against physical attacks. The year of the Linux desktop has been a running joke for decades. Microsoft doesn't need disk encryption to keep Linux from gaining traction. Linux is already doing a pretty good job for them.