13 ms·
> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft a
by dgrunwald 8mo ago
> make sure not to sign into your Microsoft account or link it to Windows again
That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams.
In the past I also had Edge importing Firefox data (including stored passwords) without me agreeing to do so, and then uploading those into the Cloud.
Nowadays you just need to assume that all data on Windows computers is available to Microsoft; even if you temporarily find a way to keep your data out of their hands, an update will certainly change that.
- LtdJorge 8mo agoTeams inside a VM it is, then.
- dvfjsdhgfv 8mo agoIt's not just Teams. You need to be constantly vigilant not to make any change that would let them link your MS account to Windows. And they make it more and more difficult not only to install but also use Windows without a Microsoft account. I think they'll also enforce it on everybody eventually.
- prmoustache 8mo agoYou need to just stop using windows and that's it. The only windows I am using is the one my company makes me use but I don't do anything personal on it. I have my personal computer next to it in my office running on linux.
- ssl-3 8mo agoOr: Put all of Windows inside of a VM, within a host that uses disk encryption -- and let it run amok inside of its sandbox. I did this myself for about 8 years, from 2016-2024. During that time my desktop system at home was running Linux with ZFS and libvirt, with Windows in a VM. That Windows VM was my usual day-to-day interface for the entire system. It was rocky at first, but things did get substantially better as time moved on. I'll do it again if I have a compelling reason to.
- SV_BubbleTime 8mo agoIf you’re doing your work inside the windows machine, what protection does Linux as a host get you?
- ssl-3 8mo agoThe topic is bitlocker, and Microsoft, and keys. With a VM running on an encrypted file system, whatever a warrant for a bitlocker key might normally provide will be hidden behind an additional layer that Microsoft does not hold the keys to. (Determining whether that is useful or not is an exercise for the person who believes that they have something to hide.)
- nativeit 8mo agoIsn’t it a pretty well-established fallacy that privacy only benefits those with something to hide?
- JasonADrury 8mo agoWouldn't it be easier to just use bitlocker and not back up your keys with microsoft?
- ssl-3 8mo agoSure, the plan you outline does sound very simple. And in an ideal world, that'd be perfectly fine. Except we don't live in an ideal world. See, for example, the fuckery alluded to above. Therein: Linking a Microsoft account to a Windows login is something that appears to happen automatically under some circumstances, and then bitlocker keys are also automatically leaked to the mothership... The machine is quite clearly designed with the intent that it behaves as a trap. Do you trust it?
- JasonADrury 8mo agoIf you distrust Windows that much, isn't the only real option to just not use it?
- smileybarry 8mo agoJust Teams in a browser tab instead. Does it actively require running as a full app to do anything?
- LtdJorge 8mo agoNo, but you have to use a Chromium browser on Windows, otherwise your life will be miserable.
- theLiminator 8mo agoYes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.
- J_Shelby_J 8mo ago> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.
- deleted 8mo ago[deleted]
- josephg 8mo agoIt’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.
- seemaze 8mo agoI switched from Windows to Mac 15 years ago. It was a revelation when the terrible habits of verbally abusing my computer and anxiety saving files every 22 seconds just evaporated. Those old habits have been creeping back lately through all the various *OS 26 updates. I too now have Linux on Framework. Not perfect, but so much better for my wellbeing.
- eimrine 8mo agoThe 7 did not behave like that.
- heavyset_go 8mo ago
- xp84 8mo agoDo we have confirmation that it’s a must to upload the key if you use an MS account with Windows? Is it proven that it's not possible to configure Windows to have an MS account linked, maybe even to use OneDrive, while not uploading the BitLocker key? Btw - my definition of “possible” would include anything possible in the UI - but if you have to edit the registry or do shenanigans in the filesystem to disable the upload from happening, I would admit that it’s basically mandatory.
- ls612 8mo agoI just checked on my personal desktop, which has Windows 11 installed using a local user account and is signed into my MS account for OneDrive and my account is listed as having no recovery codes in the cloud. I don’t recall editing anything in the registry to accomplish this it was the default behavior for having a local user account. I copied my recovery codes when I built the machine and pasted them into an E2EE iPhone note which should allow me to recover my machine if disaster strikes (also everything is backed up to Backblaze using their client side encryption).
- replyifuagree 8mo ago> logging into MS Teams I mean, this is one application nobody should ever log into!
- IAmBroom 8mo agoThat's nice. I, however, like getting my paycheck, and so I have no choice.
- spockz 8mo agoOf course. But I suppose you run Teams on a company provided/managed, or at least paid for by the company, device? Just don’t use that machine for anything private. Is anyone using their private devices for work? (Also there is teams for Linux and on the web, if that is not prevented by the policy of your org.)
- klardotsh 8mo agoIn the startup world, BYOD is/was exceedingly common. All but two jobs of my career were happy to allow me to use my own Linux laptop and eschew whatever they were otherwise going to give me. Obviously enterprises aren’t commonly BYOD shops, but SMBs and startups certainly can be. … whether the people who would do such BYOD things are at all likely to be Windows users who care about this Bitlocker issue, is a different debate entirely.
- elzbardico 8mo agoThen the founders do something really stupid, and the law decides that your equipment may be evidence. Unless you're a founder, you should always use company provided equipment.
- lll-o-lll 8mo agoI’ve been diving down the BYOD rabbit hole recently. At enterprise scale it’s not “hook in with your vpn, job done”, it’s got to be managed. Remote wipe on exit, prove the security settings, disk encryption, EDR. What this means for the user is your personal device is rather invasively managed. If you want Linux, your distro choice may be heavily restricted. What you can do with that personal device might be restricted (all the EDR monitoring), and you’ll probably take a performance and reliability hit. Not better than just a second laptop for most people.
- deleted 8mo ago[deleted]
- SV_BubbleTime 8mo ago>Nowadays you just need to assume that all data on Windows computers is available to Microsoft; even if you temporarily find a way to keep your data out of their hands, an update will certainly change that. I get why the US would not, but I really wish the rest of the world looked at this like the security and sovereignty issue that it is.
- redeeman 8mo agodoing things like that which is completely unrelated should be considered data theft, and microsoft should be punished so severely they wish they never had the idea to begin with
- arikrahman 8mo agoIt's exceptionally more straightforward than people think and is listed as one command on AtlasOS's guide.