Skip to main content

Privacy advocates protest Microsoft’s backup of user encryption keys

An individual using a laptop that shows the logo for Microsoft OneDrive.
Pablo Calvog/Shutterstock
In the climate of government spying, and the ever present threat from nefarious hackers, encryption is a hot topic. Politicians don’t like it, privacy campaigners claim it’s a must, and end users are left worried about who to trust. Microsoft aimed to help make that decision easy with Windows 10 by having certain content, like corporate apps, emails and other sensitive data, encrypted by default.

You might know about this if you tuned in to some of Microsoft’s pre-release PR for the new operating system, but what you probably didn’t know is that Microsoft created a backup key (should you lose your password to decrypt the data), which it then stores remotely on its own servers.

This may well be a feature that was put in place to help protect those that might not otherwise have their decryption key stored safely. As ransomware victims no doubt can attest too, nothing much is worse than having your data encrypted and unrecoverable. However, some have suggested that this is a security risk in itself, and Microsoft hasn’t been very forthcoming.

With a remotely stored decryption key, there is always the danger of someone hacking the server where it’s stored or grabbing it during its transfer from your system to Microsoft’s servers. And as the Intercept points out, Microsoft has also been forced to give data on citizens to the NSA and other intelligence agencies in the past. If it stores customer decryption keys, it seems possible that it could be forced to hand those over to the authorities, too.

You can delete the back up key that Microsoft holds. To do so, simply login to your Microsoft account on the OneDrive page and you are quickly given access to all of the keys Microsoft stores for you. Deleting them there is just a few clicks away.

Privacy advocates still aren’t satisfied with this solution, though, because there’s no way to ensure the key was completely deleted. It may in fact still be available, but only to Microsoft. That’s a bit paranoid, but Microsoft didn’t volunteer the encryption key’s storage location in the first place, so trust is definitely an issue.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Best Apple deals: Save on AirPods, Apple Watch, iPad, MacBook
Apple MacBook Air M1 open, on a table.

Between some of the best wireless earbuds, the best smartwatches, the best laptops, and even the best tablets, Apple is one of the biggest tech companies in the world, and it's hard to argue with how popular it's become. Of course, being a premium brand with some of the best gear does mean that it's pretty expensive, and for those who love the Apple ecosystem, it can be hard to justify buying something within it, given the price. Luckily, there are a lot of excellent deals floating around from various online retailers, like Amazon or Best Buy, and that includes things like trade-in offers and special offers for Prime and My Best Buy members.

That's why we've gone out and searched through various big retailers to find you some of the best deals we can find. That includes everything from the MacBook deals, AirPods deals, Apple TV deals and Apple Watch deals to the AirTag, so hopefully, you can find the perfect deal that fits your needs and budget.
Apple AirTag (4-Pack) -- $79, was $99

Read more
Hacker group says it carried out Christie’s cyberattack
A digital depiction of a laptop being hacked by a hacker.

A hacker group has claimed responsibility for a cyberattack that targeted auction house Christie’s earlier this month, the New York Times reported on Monday.

The attack, which disrupted the auction house's website, took place just before the start of its high-profile spring sales event involving more than $850 million worth of art, forcing Christie's to suspend online bidding and accept offers only by phone or in person.

Read more
Chromebooks get new AI features and Gemini Advanced for free
Magic Editor being shown on a Chromebook.

Google has announced a new selection of Chromebook Plus devices that boast some new AI features and a free subscription to Gemini Advanced.

Google launched its Chromebook Plus initiative in October 2023 with a more premium brand of Chromebooks, and now Google is answering the recent push into AI by Microsoft with its own. Copilot+ PCs looks great, but Google says that AI should not be for just those who have over $1,000 to spend on a laptop. Chromebook Plus laptops start at $349 and range up to $649, but often come with better performance and features.

Read more