This kind of "vulnerability" has been a constant topic of his blog in the past:
https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31... https://devblogs.microsoft.com/oldnewthing/20181219-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20121207-00/?p=58... https://devblogs.microsoft.com/oldnewthing/20180227-00/?p=98... https://devblogs.microsoft.com/oldnewthing/20240404-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20240102-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20070807-00/?p=25... https://devblogs.microsoft.com/oldnewthing/20230206-00/?p=10...
> "That could make it trivial for an attacker" (emphasis mine)
It _is_ trivial, right? The attack _is_ trivial. It's the solution that isn't. OP isn't claiming that. Seems reasonable to me.
I went back and reread https://doublepulsar.com/recall-stealing-everything-youve-ev... which is the first link in OP. Again, it doesn't have much to say about encryption at all except to point out that hey, the protections Microsoft is claiming are underwhelming. Without those protections the cost/benefit balance is way out of whack.