|
|
|
|
|
by jsmith99
1319 days ago
|
|
It's actually a really elegant solution as there is nil correlation of risk: the key is useless without physical access and physical access is useless without knowing the login. Your government might be able to get the key - if that's part of your threat model - but they probably have easier ways to force you to give it up. Anyway, FDE is often on by default. Do you really believe the average user is going to print out the backup key?! Do even tech savvy users have printouts of all their eg 2FA codes? Anyway, that would have worse correlation of risk as users would probably keep the printout next to their computer. |
|
That is assuming you somehow forget your encryption key but remember the login to your microsoft account... that you used once 2 years ago when you were installing the machine.
It also means anyone that does get the login for your MS stuff can decrypt your laptop