• frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 hours ago

    Yeah, just don’t enable key upload and this can’t happen. Don’t link your account either if you want to be more sure.

    If your account has already been linked, unlink it and change the bitlocker keys, both regular and recovery. (Easiest way is to entirely decrypt and reencrypt the drive.)

    • Home edition has this “please sign in to microsoft account to ‘finish encryption’” text with a exclamation mark which implies the key is available on the drive unencrypted if you don’t sign in, meaning anyone could just access your drive with physical access.

      There is no “turning off” the key upload, once you sign in, the upload happens immediately, you can “delete” it later, but like nobody really knows if they ever delete it once they have it.