7 ms·
You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every
by vik0 8mo ago
You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)
- ryandrake 8mo ago[flagged]
- walletdrainer 8mo agoThis is ridiculous. There are a lot of people here criticising MSFT for implementing a perfectly reasonable encryption scheme. This isn’t some secret backdoor, but a huge security improvement for end-users. This mechanism is what allows FDE to be on by default, just like (unencrypted) iCloud backups do for Apple users. Calling bs on people trying to paint this as something it’s not is not “whiteknighting”.
- patja 8mo agoAre you referring to Microsoft Recall? My understanding is that is opt-in and only stored locally.
- parliament32 8mo agoStored locally.. until it's uploaded by OneDrive or Windows Backup?
- deleted 8mo ago[deleted]
- egorfine 8mo ago1) for now 2) according to Microsoft So, trust is not zero. It's deeply negative.
- Aurornis 8mo agoSorry to interrupt the daily rage session with some neutral facts about how Windows and the law work. > that just so happens to take a screenshot of your screen every few seconds Recall is off by default. You have to go turn it on if you want it.
- dns_snek 8mo agoIt only became off by default after those "daily rage sessions" created sufficient public pressure to turn them off. Microsoft also happens to own LinkedIn which conveniently "forgets" all of my privacy settings every time I decide to review them (about once a year) and discover that they had been toggled back to the privacy-invasive value without my knowledge. This has happened several times over the years.
- lpcvoid 8mo agoDaily rage is exactly what technology affine people need to direct at Microslop, while helping their loved ones and ideally businesses transition away from the vendor lockin onto free software.
- LoganDark 8mo agoMicrosoft doesn't take the screenshot; their operating system does if Recall is enabled, and although the screenshots themselves are stored in an insecure format and location, Microsoft doesn't get them by default.
- pohuing 8mo agoIs that last part even still true? When I played around with it they asked me to store a recovery pass phrase off device in case windows hello breaks
- gruez 8mo agoYes, because object level facts matter, and it's intellectually dishonest to ignore the facts and go straight into analyzing which side is the most righteous, like: >Microsoft is an evil corporation, so we must take all bad stories about them at face value. You're not some corpo bootlicker, now, are you? Now, in unrelated news, I heard Pfizer, another evil corporation with a dodgy history[1] is insisting their vaccines are safe... [1] https://en.wikipedia.org/wiki/Pfizer#Legal_issues https://en.wikipedia.org/wiki/Pfizer#Legal_issues
- yoyohello13 8mo agoI big demographic of HN users are people who want to be the multi-trillion dollar corporation so it’s not too surprising. In this case though I think they are right. And I’m a big time Microsoft hater.
- dijit 8mo agoThe defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you also lose the data. We have trained users about this for a decade, there have been countless dialogues explaining this, even if we were dumber than we were (we're not, despite what we're being told: users just have fatigue from over stimulation due to shitty UX everywhere); then it's still a bad default.
- MoltenMan 8mo agoJust to be clear: bitlocker is NOT encrypting with your login password! I could be a little fuzzy on the details but I believe how it works is that your TPM (Trusted Platform Module) is able to decrypt your laptop, but will only do so if there is a fully signed and trusted boot chain, so if somebody gains access to your laptop and attempts to boot into anything other than Windows, it will ask for the bitlocker key because the TPM won't play ball. The important bit here is that ~*nobody* who is using Windows cares about encryption or even knows what it is! This is all on by default, which is a good thing, but also means that yes, of course Microsoft has to store the keys, because otherwise a regular user will happen to mess around with their bios one day and accidentally lock themselves permanently out of their computer. If you want regular FDE without giving Microsoft the key you can go ahead and do it fairly easily! But realistically if the people in these cases were using Linux or something instead the police wouldn't have needed an encryption key because they would never have encrypted their laptop in the first place.
- 8mo ago
- zer00eyz 8mo agohttps://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A ... Then, years later every one acts like Snowden had some big reveal. There is the old password for candy bar study: https://blog.tmb.co.uk/passwords-for-chocolate https://blog.tmb.co.uk/passwords-for-chocolate Do users care? I would posit that the bulk of them do not, because they just dont see how it applies to them, till they run into some type of problem.
- mcmcmc 8mo agoAI enshittification is irrelevant here. Why is someone pointing out that sensible secure defaults are a good thing suddenly defending the entire company?
- ChromaticPanic 8mo agoUploading your encryption keys up to someone else's machine is not a sensible default
- crazygringo 8mo agoIt generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the government, you're generally not using default options.
- ChromaticPanic 8mo agoFor laptops sure, but then those are not reasons for it to be default on desktops too. Are most Windows users on laptops? I highly doubt that. So it is not a sensible default.
- Xss3 8mo agoMost pc users are using laptops, yes. Above 60%. Even offices usually give people laptops over desktops so that they can bring it to meetings.
- dijit 8mo ago> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyou. Yet for some unknown reason everyone should send their disk encryption keys to one of the largest companies in the world (largely outside of legal jurisdiction), because they themselves can't be trusted. Bear in mind that with a(ny) TPM chip, you don't need to remember anything. Come off it mate. You're having a laugh aren't you?