3 ms·
depends on your counterfactual. for some commenters on this thread, that seems to be storing data in plaintext. for me, the more reasonable counterfactual is a
by justcommenting 12y ago
depends on your counterfactual. for some commenters on this thread, that seems to be storing data in plaintext. for me, the more reasonable counterfactual is a recovery key that i have sole control over, or perhaps an encrypted backup onto a disk i have sole control over.
i think we agree that encrypting data at rest isn't sufficient for keeping private data private, but it may be necessary and is probably beneficial.
for some users, keeping keys in microsoft's cloud may be a good option, but i think that hinges on whether they know and understand the implications of sending their recovery keys to microsoft.
for example, maybe you lose your phone and some pickpocket doesn't grab your data very easily, but maybe the local police force gets your recovery key from microsoft and finds nude photos of your significant other before returning your phone to you. i'd be pretty displeased in that case, even if it helped me get my device back.
i suspect many people storing recovery keys with microsoft don't know that this is happening, and might have made different choices if they knew that and understood some of the implications.
- amalcon 12y agoRight, I was trying to speak only to the possibility of getting data off the phone without physically obtaining the device. Those scenarios don't care if the storage is encrypted, and have nothing to do with scenarios where someone else has your phone.