7 ms·
From that link: >There are several locations in which your BitLocker recovery key might have been saved. Keyword: might.
by wfjackson 12y ago
From that link:
>There are several locations in which your BitLocker recovery key might have been saved.
Keyword: might.
- xnull2guest 12y agoFor personal use this is most certainly the case. Here are quotes and links from both Microsoft Technet and tech media coverage. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected. The following list outlines the way this is accomplished: * When a clean install of Windows 8.1 is completed the computer is prepared for first use. As part of this preparation, device encryption is initialized on the operating system drive and fixed data drives on the computer with a clear key (this is the equivalent of standard BitLocker suspended state). * If the device is not domain-joined a Microsoft Account that has been granted administrative privileges on the device is required. When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to online Microsoft account and TPM protector is created. Should a device require the recovery key, the user will be guided to use an alternate device and navigate to a recovery key access URL to retrieve the recovery key using their Microsoft Account credentials." http://technet.microsoft.com/en-us/library/dn306081.aspx http://technet.microsoft.com/en-us/library/dn306081.aspx "... because the recovery key is automatically stored in SkyDrive for you." http://www.zdnet.com/surface-bitlocker-and-the-future-of-encryption-7000024613/ http://www.zdnet.com/surface-bitlocker-and-the-future-of-enc... "BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices." http://technet.microsoft.com/en-us/library/dn306081.aspx#BKMK_Encryption http://technet.microsoft.com/en-us/library/dn306081.aspx#BKM... Device Encryption is supported by Bitlocker for all major skews including Windows Server 2012 R2.
- wfjackson 12y agoThat isn't Bit Locker, it's device encryption which is supported in 8.1 (Home) and Windows RT where naive users are more likely to forget to backup the key and hence lose data. BitLocker is only available in the professional,enterprise and ultimate versions of Windows 8.1 and it does not automatically backup the key to an MS account.
- xnull2guest 12y ago"BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices." http://technet.microsoft.com/en-us/library/dn306081.aspx http://technet.microsoft.com/en-us/library/dn306081.aspx Device Encryption is supported by Bitlocker for all major skews including Windows Server 2012 R2. They have also backported Device Encryption to 8. Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument doesn't stack up with the fact that OneDrive/SkyDrive is enrolled in PRISM.
- wfjackson 12y agoThe big difference is that it's automatic on RT, Phone and 8.1 if the hardware supports it. Think Grandma's PC. Do you really want her to see the option window about where to store a recovery key? For the other SKUs, an option window pops up when you enable BitLocker asking about backup location.
- wfjackson 12y ago>Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument doesn't stack up with the fact that OneDrive/SkyDrive is enrolled in PRISM. The encryption is automatic, hence it makes sense that the backup is forced. Given that many Windows user get confused when their icons are moved, it would be hard to expect them to manage decryption keys. A significant percentage could lose their data. This is still better than earlier versions of personal use Windows where the data wasn't encrypted at all and all one had to do is to connect the hard drive on a different computer. On Professional and Enterprise versions, when you choose to encrypt, the dialog box with the choice does appear, I just tried.
- xnull2guest 12y agoIt does not matter whether a dialog box appears. Have you confirmed that the keys are not pushed into OneDrive? (That's the thing to check.) So what you are saying is that bitlocker keys are automatically uploaded to OneDrive and OneDrive is PRISM, but this isn't key escrow for government. The backup can both be for Grandma and Federal Law Enforcement. They are not mutually exclusive. My original point stands. Modern Windows Bitlocker keys are automatically placed into a location where TLAs can request them.