• yesman@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    5 hours ago

    I learned this week that Microsoft keeps a copy of your keys when you encrypt your hdd with their software. So you don’t need a black hat, all you need is a subpoena.

    • throwawayacc0430@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      To be fair, if microsoft didnt automatically backup the keys, a simple BIOS/UEFI setting change, or windows update could trip the Secure Boot settings, which would clear all the TPM keys from the system, which means the sysyem would prompt you for the recovery key. I think people value being able retain access to their data over encryption. And to Microsoft’s credit, its not exactly a secret, they literally tell you that the key will be uploaded.

      • jbk@discuss.tchncs.de
        link
        fedilink
        arrow-up
        1
        ·
        3 hours ago

        a simple BIOS/UEFI setting change, or windows update could trip the Secure Boot settings they could work around that though, but I still agree that backing up the passphrase to an arguably safe online system is good