4 ms·
Why would you need to create a local account? You can just not choose to store the keys in your Microsoft account during BitLocker setup: https://www.diskpart.c
by shawnz 8mo ago
Why would you need to create a local account? You can just not choose to store the keys in your Microsoft account during BitLocker setup: https://www.diskpart.com/screenshot/en/others/windows-11/windows-11-bitlocker/bitlocker-save-microsoft-account.png https://www.diskpart.com/screenshot/en/others/windows-11/win...
Admittedly, the risks of choosing this option are not clearly laid out, but the way you are framing it also isn't accurate
- shakna 8mo agoAll "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9f1544c258161ad93cb4641f100d952a https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...
- crazygringo 8mo agoThey're Microsoft and it's Windows. They always have the ability to fetch the key. The question is do they ever fetch and transmit it if you opt out? The expected answer would be no. Has anyone shown otherwise? Because hypotheticals that they could are not useful.
- lazide 8mo agoConsidering all the shenanigans Microsoft has been up to with windows 11 and various privacy, advertising, etc. stuff? Hell, all the times they keep enabling one drive despite it being really clear I don’t want it, and then uploading stuff to the cloud that I don’t want? I have zero trust for Microsoft now, and not much better for them in the past either.
- nativeit 8mo agoThis 100% happens, they’ve done it to at least one of my clients in pretty explicit violations of HIPAA (they are a very small health insurance broker), even though OneDrive had never been engaged with, and indeed we had previously uninstalled OneDrive entirely. One day they came in and found an icon on their desktop labeled “Where are my files?” that explained they had all been moved in OneDrive following an update. This prompted my clients to go into full meltdown mode, as they knew exactly what this meant. We ultimately got a BAA from Microsoft just because we don’t trust them not to violate federal laws again.
- brianxq3 8mo ago> Because hypotheticals that they could are not useful. Why? They are useful to me and I appreciate the hypotheticals because it highlights the gaps between "they can access my data and I trust them to do the right thing" and "they literally can't access my data so trust doesn't matter."
- cyberax 8mo agoThis is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.
- riskable 8mo ago> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.
- g-b-r 8mo agoPeople really pay too little attention to this attack avenue. It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account. I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways. Please check theupdateframework.io if you have a say in an update system.
- g-b-r 8mo agoI actually misremembered what theupdateframework.io is, I thought it provided more protections...
- theragra 8mo agoIsn't it the same with many Linux distros? Updates are using root to run?
- g-b-r 8mo agoIt's largely the same for all automatic updating systems that don't protect against personalized updates. I don't know the status of the updating systems of the various distributions; if some use server-delivered scripts run as root, that's potentially a further powerful attack avenue. But I was assuming that the update process itself is safe; the problem is that you usually don't have guarantees that the updates you get are genuine. So if you update a component run as root, yes, the update could include malicious code that can do anything. But even an update to a very constrained application could be very damaging: for example, if it is for a E2EE messaging application, it could modify it to have it send each encryption key to a law enforcement agency.
- vel0city 8mo agoThey could also just push an update to change it anyways to grab it. If you really don't trust Microsoft at all then don't use Windows.
- jasomill 8mo agoWhat do Entra role permissions have to do with Microsoft's ability to turn over data in its possession to law enforcement in response to a court order?
- smileybarry 8mo agoThat's for Entra/AD, aka a workplace domain. Personal accounts are completely separate from this. (Microsoft don't have a AD relationship with your account; if anything, personal MS accounts reside in their own empty Entra forest)