2026-01-23 19:14 UTC
@dlakelan@mastodon.sdf.org
> Apparently, Microsoft exfiltrates a recovery key for your Bitlocker encryption and stores it in their cloud.
Well, not "apparently"… It's a known fact, and actually has been for a long time, that windows uploads "private" key for disk encryption de M$ servers.
Users have access to their not so-private keys by connecting to their M$ accounts on a web interface… M$ got Kerckhoffs principle backwards…
Unfortunately, Key escrow is a real thing…
Replies (1)
-
@wurzelmann@mastodon.wurzelmann.at 2026-01-24 11:47
@devnull@mamot.fr @dlakelan@mastodon.sdf.org yeah, they've been doing this by default for a while (automatic Bitlocker encryption without users knowing, uploading the key to their MS account [which they enforce 🤡 ]. Load of garbage.