6 ms·
Uploading your encryption keys up to someone else's machine is not a sensible default
by ChromaticPanic 8mo ago
Uploading your encryption keys up to someone else's machine is not a sensible default
- crazygringo 8mo agoIt generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the government, you're generally not using default options.
- ChromaticPanic 8mo agoFor laptops sure, but then those are not reasons for it to be default on desktops too. Are most Windows users on laptops? I highly doubt that. So it is not a sensible default.
- Xss3 8mo agoMost pc users are using laptops, yes. Above 60%. Even offices usually give people laptops over desktops so that they can bring it to meetings.
- dijit 8mo ago> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyou. Yet for some unknown reason everyone should send their disk encryption keys to one of the largest companies in the world (largely outside of legal jurisdiction), because they themselves can't be trusted. Bear in mind that with a(ny) TPM chip, you don't need to remember anything. Come off it mate. You're having a laugh aren't you?
- mcmcmc 8mo agoSo what happens if your motherboard gets fried and you don’t have backups of your recovery key or your data? TPMs do fail on occasion. A bank PIN you can call and reset, they can already verify your identity through other means.
- dijit 8mo ago> So what happens if your motherboard gets fried and you don't have backups of your recovery key or your data? If you don't have backups of your data, you've already lost regardless of where your recovery key lives. That's not an encryption problem, that's a "you didn't do backups" problem, which, I'll agree is a common issue. I wonder if the largest software company on the planet (with an operating system in practically every home) can help with making that better. Seems like Apple can, weird. > TPMs do fail on occasion. So do Microsoft's servers. Except Microsoft's servers are a target worth attacking, whereas your TPM isn't. When was the last time you heard about a targeted nation-state attack on someone's motherboard TPM versus a data breach at a cloud provider? > A bank PIN you can call and reset, they can already verify your identity through other means. Banks can do that because they're regulated financial institutions with actual legal obligations and consequences for getting it wrong. They also verified your identity when you opened the account, using government ID and proof of address. Microsoft is not your bank, not your government, and has no such obligations. When they hand your keys to law enforcement, which they're legally compelled to do, you don't get a phone call asking if that's alright. The solution to TPM failure is a local backup of your recovery key, stored securely. Not uploading it to someone else's computer and hoping for the best.
- LtWorf 8mo agoThen don't enable encryption? Basically I cannot rescue the files on my own disk but the police can?
- crazygringo 8mo ago> Basically I cannot rescue the files on my own disk but the police can? I think you're misunderstanding. You can rescue the files on your own disk when you place the key in your MS account. There's no scenario where you can't but the police can.
- deleted 8mo ago[deleted]