you are viewing a single comment's thread
view the rest of the comments
[–] 88 points 7 months ago (2 children)

Yes. But this completely invalidates the encryption. If anyone can decrypt your data without you giving the keys to them, it is not really encrypted.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 22 points 7 months ago (2 children)

    The encryption key is data, don't give it to ANYONE. "Two people can keep a secret if one of them is dead."

  • source
  • parent
  • hideshow 4 child comments
  • [–] 1 point 7 months ago (1 child)

    You’re confusing two different things here, in a really weirdly obtuse way.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 7 months ago (1 child)

    It may seem that way but I'm really not. An encryption key is just data. It's critical security data to be sure but it's still data and like other data you shouldn't share anything that you wouldn't want made public.

    Don't want MS to cough up your data when asked? Then don't give it to them. In regards to your BL key that means storing it another way, such as on a jump drive or printing it out.

    In the end if you have data of any type that you absolutely DO NOT want made public then you need to retain that data locally. If that means leaving the Microsoft or any other ecosystem then that's the price that needs paid for keeping your data under your control.

    This is the foundation of the entire privacy movement.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 7 months ago*

    No, you really are. If you’re in control of an encryption key, then it’s perfectly fine to “give Microsoft your data” that’s encrypted by that key. An encryption key isn’t “just data”, it’s data that’s used to encrypt other data.

    The problem here is not that Microsoft has access to your data, it’s that Microsoft has access to your encryption key.

  • source
  • parent
  • [–] 3 points 7 months ago (5 children)

    Its not anyone though. Not anyone can get a warrant and demand the keys

  • source
  • parent
  • hideshow 10 child comments
  • [–] 30 points 7 months ago (2 children)

    if Microsoft has the power to give the keys to the feds what happens when Microsoft gets hacked?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 12 points 7 months ago

    Sure. It's not anyone. It's anyone that can get a warrant. Or anyone that have enough power/underhanded influence to ask them nicely. Or any admin that have access to cloud storage at MS (remember they where caught with some exec having full access to that a while ago). Or any big leak that could exfiltrate these data. And probably a handful of other people, like, someone getting access to your MS account for whatever reason (which kinda happen, seeing how people lose their mail account to phishing/scams all the time) suddenly having access to your keys from there.

    If your keys are in a DB somewhere, there's a lot of way they could get out. Would these ways coincide with someone actually having your drive at hand? Probably not. Still, the key not existing in plaintext in some third party storage close all these holes.

  • source
  • parent
  • [–] 5 points 7 months ago* (2 children)

    what happens when fydor monikov the sleeper agent from the kgb working at the fbi gets a copy of these master keys

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 7 months ago (1 child)

    Are they really sleepers any more?

  • source
  • parent
  • hideshow 2 child comments