4 ms·
>Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument
by wfjackson 12y ago
>Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument doesn't stack up with the fact that OneDrive/SkyDrive is enrolled in PRISM.
The encryption is automatic, hence it makes sense that the backup is forced. Given that many Windows user get confused when their icons are moved, it would be hard to expect them to manage decryption keys. A significant percentage could lose their data. This is still better than earlier versions of personal use Windows where the data wasn't encrypted at all and all one had to do is to connect the hard drive on a different computer. On Professional and Enterprise versions, when you choose to encrypt, the dialog box with the choice does appear, I just tried.
- xnull2guest 12y agoIt does not matter whether a dialog box appears. Have you confirmed that the keys are not pushed into OneDrive? (That's the thing to check.) So what you are saying is that bitlocker keys are automatically uploaded to OneDrive and OneDrive is PRISM, but this isn't key escrow for government. The backup can both be for Grandma and Federal Law Enforcement. They are not mutually exclusive. My original point stands. Modern Windows Bitlocker keys are automatically placed into a location where TLAs can request them.
- wfjackson 12y agoBitLocker is not the same as Device Encryption. Please stop confusing the two. Also you have been unable to say what you want Microsoft to do in grandma's case.
- xnull2guest 12y ago"BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices." http://technet.microsoft.com/en-us/library/dn306081.aspx http://technet.microsoft.com/en-us/library/dn306081.aspx They are not the same. Agreed. Sorry about the confusion. Anyway, it's true that modern Windows Operating Systems, even on non-RT devices, upload bitlocker keys automatically and transparently to the cloud, where the data is indexed for the PRISM program. They do this with Device Encryption, which is supported by Bitlocker on x86 and x64-based computers with a TPM that supports connected stand-by. Edit: Regarding Grandma. Keys can be stored on a non-boot internal drive. Keys can be shown on the screen as a QR code (and the screen can tell Grandma to take a picture). Grandma's keys can be printed out on a small detachable USB or SD/MicroSD device with a kilobyte of space. The machine can provide provisional encryption until Grandma's computer can connect to a printer (where it gets printed). Grandma's computer could send the key over USB/Bluetooth/Wifi to a trusted computer friend after pairing (such as a 'tech savvy' niece/nephew). There are plenty of options. The 'grandma clause' is not mutually exclusive with key escrow. OneDrive is a nice place for grandma AND a nice place for the FBI.
- higherpurpose 12y agoNo it doesn't. The key could be automatically saved in the TPM - locally. Yet Microsoft chooses to save it in its own cloud. And you could make the same argument against Android 5 and iOS 8 encryption, too. That users won't be able to "recover" their data. Tough luck. Google and Apple did it anyway, and it seems to be a successful move. Microsoft is now the only one of the three major platforms who doesn't provide secure automatic encryption with locally stored keys.
- wfjackson 12y ago>No it doesn't. The key could be automatically saved in the TPM - locally. And how does grandma retrieve it if she forgets her password? Also, does Apple do this for OS X or just iOS?
- xnull2guest 12y agoGrandma recieves it from the same place law enforcement does. We get it. Key escrow can be key escrow for everyone. Grandma gets her copy and so does Big Brother.