The data that I didn’t know I didn’t have to back up to Microsoft’s cloud

I spent more time than I’d planned Friday afternoon poking around the security settings of my Windows laptop, then undoing one setting that I am somewhat embarrassed to admit I had scarcely thought about over the previous two and a half years of using this HP.

The FBI gets some credit for that for making me rethink my own device security after some of its agents raided Washington Post reporter Hannah Natanson’s home two weeks ago and seized several of her devices–an obvious move to intimidate journalists– leaving the storage encryption on that hardware as the last line of defense for her data.

Forbes security writer Thomas Brewster gets the rest of the credit for a strong post Friday morning unpacking how Microsoft’s approach to device encryption via its BitLocker software can leave Windows computers open to law enforcement investigators who bring a valid legal order to the company requesting a particular user’s encryption recovery key.

“It’s possible for users to store those keys on a device they own, but Microsoft also recommends BitLocker users store their keys on its servers for convenience,” Brewster wrote. “While that means someone can access their data if they forget their password, or if repeated failed attempts to login lock the device, it also makes them vulnerable to law enforcement subpoenas and warrants.”

He reported that Microsoft gets about 20 requests a year for BitLocker keys but cannot respond to many of them because the customers involved didn’t back up those keys to its cloud.

Windows 11 Home’s Device Encryption isn’t branded as BitLocker in the Settings app, but it runs on the same framework. And as in the Pro, Enterprise and Education editions of Windows 11, it allows a choice of key-backup locations–which I did not realize until eyeballing Microsoft’s documentation after I’d read Brewster’s post.

I had gone unthinkingly with the default of having the recovery key backed up to my Microsoft 365 cloud storage; I don’t remember even being presented with a choice when I set up the computer in August of 2023. But since the key is only a string of 48 numbers periodically separated by dashes, there was no point in keeping it there.

Instead, I saved it in my end-to-end-encrypted password manager 1Password, where the security design does not expose backdoors that can be opened with a court order. Then I deleted the backed-up recovery key from my M365 storage after clicking a checkbox to confirm that I’d saved the key elsewhere–along with seven older ones I found saved there, going back to a Surface laptop I reviewed a decade or so ago.

(I don’t know how long it will take for this data to be gone from my online storage, although there is the option of decrypting and re-encrypting the laptop to ensure the old key is useless.)

I never should have taken Microsoft up on this offer. But Microsoft should not be leaving users in this position–as Johns Hopkins University cryptography professor Matthew Green told Brewster in that article. Apple’s FileVault device encryption now automatically encrypts recovery keys backed up to the company’s iCloud service (see this explainer from my friend Glenn Fleishman at Six Colors), leaving nothing for a third party to inspect with a warrant.

There are many areas where Microsoft can’t readily catch up with Apple, starting with having a mobile platform to complement its desktop operating system. But this should not be one of them.

#BitLocker #diskEncryption #encryption #FBI #HannahNatanson #keyEscrow #M365 #Microsoft365 #MicrosoftBackup #Windows11Home #WindowsDeviceEncryption

Windows 11 Nedir? Microsoft’un En Modern İşletim Sistemi

Microsoft’un efsanevi işletim sistemi ailesinin en yeni üyesi olan Windows 11, modern tasarımı, performans geliştirmeleri ve kullanıcı deneyimini ön planda tutan yapısıyla dikkat çekiyor.Görsel açıdan sadeleşmiş, performans olarak optimize edilmiş olan bu sürüm, sadece bir işletim sistemi değil; üretkenliği artıran yeni nesil bir çalışma ortamı sunuyor. 🌟 Windows 11 Nedir? Windows 11, Microsoft’un 2021 yılında

Systém Domácí Samojeb 11 na novém kaptopu, cca 3 měsíce starém.

#windows11home #bsod #newhardware

@mrgrumpymonkey depends...

Next logical step is some #PowerShell script that downloads a #Linux distro image, repartition the system drive, add some unallocated space at the end, put a #CloudInit config in it and then do an #UnattendedInstall of said system with bcd by calling up #bcdedit to #chainload said partition.

  • I jist have neither the time nor spoons to do that shit myself, but in theory a #NetInstaller image of ~ 100MB should suffice...
COMPUTEX 2025: MSI erweitert Gaming-Handheld-Portfolio um Claw A8 und Claw 8 AI+ Polar Tempest Edition
MSI hat auf der COMPUTEX 2025 in Taipeh zwei neue Modelle seiner Claw-Serie vorgestellt.
https://xboxdev.com/computex-2025-msi-erweitert-gaming-handheld-portfolio-um-claw-a8-und-claw-8-ai-polar-tempest-edition/
#COMPUTEX2025 #Event #Hardware #120HzVRR #AMDRyzenZ2Extreme #Claw8AIPolarTempestEdition #ClawA8 #COMPUTEX2025 #GamingHandheld #IntelCoreUltra7258V #NVMeSSD #Windows11Home
COMPUTEX 2025: MSI erweitert Gaming-Handheld-Portfolio um Claw A8 und Claw 8 AI+ Polar Tempest Edition - XboxDev

MSI hat auf der COMPUTEX 2025 in Taipeh zwei neue Modelle seiner Claw-Serie vorgestellt.

XboxDev

Découvrez l’ASUS ROG Strix G17 G713 – AMD Ryzen 7 6800H, GeForce RTX 3060 6 Go, 16 Go DDR5, SSD 1 To, écran 17,3″ WUXGA 360 Hz et Windows 11 Home. Performance et réactivité ultime pour gamers et créateurs ➡️

https://setupmedia.ma/produit/asus-rog-strix-g17-g713-ryzen-7-16go-1to-rtx-3060/

#ROGStrixG17 #Ryzen76800H #RTX3060 #GamingLaptop #Setupmedia #PCGamer #DDR5 #SSD1To #360Hz #Windows11Home

ASUS ROG Strix G17 G713 / Ryzen 7 6800H / RTX 3060 / 16 Go DDR5 / 1 To SSD / 17,3″ WUXGA 360 Hz / Windows 11 Home

Découvrez le Asus ROG Strix G17 G713 : PC portable gaming 17″ avec Ryzen 7 6800H, RTX 3060, 16 Go DDR5, SSD 1 To et écran 360 Hz pour une expérience ultime.

Setup Media
How to install Windows 11 Home without internet - GTech Booster

This is useful for users who prefer to create a local account instead of using a Microsoft account or for those who simply do not have internet access during installation.

GTech Booster

🇬🇧 𝗨𝗽𝗴𝗿𝗮𝗱𝗲 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝟭𝟭 𝗛𝗼𝗺𝗲 𝘁𝗼 𝗣𝗿𝗼

https://dariusz.wieckiewicz.org/en/upgrade-windows-11-home-to-pro/

#Windows
#Windows11Home
#Windows11Pro
#Windows11Enterprise
#upgrade

Upgrade Windows 11 Home to Pro

A simple way to upgrade Windows 11 from Home to Pro while keeping your data and apps.

Got my SO a refurbished laptop for her birthday. First thing I did was tear out #Windows11Home and install #Fedora #linux. Last go-around with this, she loved the #GNOME desktop. (That one had a hardware failure and I gave her an old #MacBook for a while).