Microsoft's latest operating system keeps showing behavior that goes against the user's interests. The latest line of devices with Windows 10 preinstalled comes with hard drive encryption enabled by default, and if you decide to sign in with a Microsoft account, it will automatically send a copy of the key to the company's servers. Microsoft argues that it's for security... but the problem is that it doesn't warn you, nor does it offer the option to avoid it.

Windows 10 sends encryption keys to Microsoft servers
Microsoft

Clearly, we have reached a point where every step taken by Windows 10 is examined from every angle. Microsoft has decided to implement a complex policy that in some cases seems contradictory and even harmful to the end user. Needless to say, at Redmond they are aware that they cannot satisfy everyone despite their best intentions, but that does not change the fact that they would have saved themselves a lot of grief by applying a different criterion. As an example, let's take the latest report published by the folks at The Intercept, in which they highlight a very important detail for owners of new computers (emphasis on "new") with Windows 10 preinstalled: disk encryption comes enabled by default, and if you sign in with a Microsoft account, a copy of the key is saved on their servers.

Windows 10 sends encryption keys to Microsoft servers
BitLocker allows backing up the key on local media. If Windows 10 asked this same question when setting up a new computer, the story would be different.

The Cloud Backup Issue

First of all, it is necessary to recognize the logical and coherent: Enabling factory encryption is a good decision. This increases the security of the data the user stores on their hard drive, and no one can object to the technical aspect. The problem is the backup of the key in the cloud, a decision derived from its current internal policy. We understand that Microsoft does it in case something goes wrong, or the user forgets or loses their key... but in reality, the user knows nothing about this. The operating system does not inform about the backup on the servers, does not offer the option to avoid it, nor does it allow a sort of local copy, something that does exist in BitLocker. Perhaps some of our readers think this can be avoided by using a local account instead of signing in with a Microsoft account. Technically that is true, but let's not forget that Windows 10 revolves around Microsoft services, and to get the most out of it, the idea is to have a company account.

Windows 10 sends encryption keys to Microsoft servers
Microsoft offers the option to delete the stored keys... but who has access to them?

What Can You Do?

The first option the user of a new computer (I insist, "new computer") with Windows 10 has is to visit this site and order Microsoft to delete all registered encryption keys (after all, a single account can cover multiple devices). However, there is always the possibility that something or someone makes a backup of that key before its deletion, or that it is delayed for several days, as happens with data from certain social networks. At this point, what follows is to decrypt and re-encrypt the hard drive to generate a new key using BitLocker and indicate a local key backup, assuming you have Windows 10 Pro or Enterprise, otherwise you will need an upgrade from Windows 10 Home to Pro. Now... I understand what's coming. I know that keys are only useful if you have physical access to the computer, and that everything carries an extra pinch of paranoia these days... but the paranoia works. Something changed in Microsoft with Windows 10, and the more the user knows, better.

The Intercept