• audaxdreik@pawb.social
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    20 hours ago

    The protection of FDE is the carrot they give to get you to enable TPM 2.0. The stick is the remote attestation which can be used for nefarious purposes like DRM and other types of denial/system lockdown at Microsoft’s discretion.

    It’s true it’s hard to motivate people into taking a better security posture for themselves but forcing them like this doesn’t come from a good and sincere place.

    • 鳳凰院 凶真 (Hououin Kyouma)@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      14 hours ago

      “Protection” that require you to create an account and have the key auto-uploaded to their servers before the encryption is active. Not even a secret, they literall tell you they will upload your key. Lol

      • Romkslrqusz@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        14 hours ago

        This 49 minute video ends with the presenter saying that fixes for what they demonstrated were shipped in July’s patch Tuesday

        The recommended mitigation is the use of TPM and a PIN, which is going to apply to any machine where the user went “with the flow” during Windows 11’s OOBE

      • mierdabird@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        4
        ·
        15 hours ago

        Thanks for this, I accidentally locked my wife’s tablet when I was testing if Linux would run on it from USB drive. Came back to win 11 and it was bitlocked, with no codes in her Microsoft account and no idea where else to find them. Hopefully I can study this and figure out a way to bypass it