Remix.run Logo
drnick1 3 hours ago

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account.

The real issue is that you can't be sure that the keys aren't uploaded even if you opt out.

At this point, the only thing that can restore trust in Microsoft is open sourcing Windows.

Aurornis 3 hours ago | parent [-]

> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out.

The fully security conscious option is to not link a Microsoft account at all.

I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.

MereInterest 2 hours ago | parent | next [-]

Last time I needed to install Windows 11, avoiding making a Microsoft account required (1) opening a command line to run `oobe/bypassnro`, and (2) skipping past the wifi config screen. While these are quick steps, neither of those are at all "easy", since they require a user to first know that it is an option in the first place.

And newer builds of Windows 11 are removing these methods, to force use of a Microsoft account. [0]

[0] https://www.windowslatest.com/2025/10/07/microsoft-confirms-...

zyx321 34 minutes ago | parent [-]

By selecting Domain Join, which is available on Professional edition and above.

epistasis 2 hours ago | parent | prev | next [-]

> it was really easy to set up without a Microsoft account.

By "really easy" do you mean you had a checkbox? Or "really easy" in that there's a secret sequence of key presses at one point during setup? Or was it the domain join method?

Googling around, I'm not sure any of the methods could be described as "really easy" since it takes a lot of knowledge to do it.

vanviegen 2 hours ago | parent | prev [-]

And how do you know the keys are never uploaded if you don't have an account?

jjnoakes 2 hours ago | parent | next [-]

The same way you know that your browser session secrets, bank account information, crypto private keys, and other sensitive information is never uploaded. That is to say, you don't, really - you have to partially trust Microsoft and partially rely on folks that do black-box testing, network analysis, decompilation, and other investigative techniques on closed-source software.

criddell 40 minutes ago | parent | prev [-]

Air gap the machine.