"YellowKey" only impaced Windows 11 (24H2, 25H2 and 26H1) and Server 2025 because the vulnerable code path only exists in the new WinRE/Bitlocker trust chain. Windows 10 and older recovery environments does not have the same code that YellowKey exploited.
Sure. You want it truly secure, don't even give the end user access to a recovery key period. they lose the password, they are 100% done. But we don't do that either.
Risk also exists that somebodies private data at home is also exposed and at risk. The risks have gone up and will always continue to go up. But we also saw what happened in the old XP days when Microsoft made everybody administrator on their box too.....adware, spyware, malware, viruses...all ran absolutely rampant. Because so many people don't have any idea how to keep themselves safe.
I do agree that Microsoft is a much bigger target and hackers and the like will exploit that like crazy to steal everything versus coming just for my machine. But just because I stored it and didn't put it on the cloud, doesn't guarantee it's safety.
Correct. And also reason why I don't put everything in the cloud. If my grocery list gets out, or pictures from the concert that I went to, or my screenshots for setting up OneDrive get out, it probably won't be a catastrophe.
You can use a yubikey, passkey or a long complicated password you can store in a password manager. With hardware keys like yubico then your backup plan is to have two register to the same service as hardware do break over time. Passkeys and complicated passwords is easier and its not accessable externally.
But yes.. if you loose the key, the data should be toasted as that is what the meaning of encryption should mean.
Yes.. malware on computers is well known.. Windows is the biggest target of all OS's do to its market-share.. as smaller, the smaller risk it is..
Linux is not so much more secure then windows if you harden windows.. But as its so few desktop users on Linux, then hackers dont spend time developing malware to target 3% of the world population.. when 2% of those 3% is nerds with security in mind.. so only 1% is a good target.
With windows then its a 98% good target as only 2% of windows users are nerds like we are in here that knows to not download bad things and not to click on bad links that makes a bad target to go after.
Hackers only target interesting targets.. you are rich, famous, an CEO, an politician or you have a job so they see you as the steppingstone in to a interesting company.
((The exception of this rule is if you are a security researcher, then they see you as a challenge to hack.. or you have pissed of a hacker or someone that know how to hire an hacker and has the money to pay that bill.))
But 99% of all hacks/intrusions is self inflicted hacks.. users clicking on links, or downloads a cracked game or cracked software etc.
So i agree... real sensitive data should be kept offline when not actively using the data.. and encrypted is also good thing if its really-really sensitive as someone can break in to your home and get physical access.
Sometimes you might have to get sensitive data from one place to another, then a zero-knowledge encrypted cloud service can be usable.
Say you work as a journalist in a hostile country and you need to get the data out and you know you will be search at the border and they will confiscate your devices if they cant read the data .. or you work with human rights in hostile countries and need to get data out to another countries.
If you then have a open cloud provider that can access the data,, that hostile country government can then send in a legal warrant to the cloud provider to hand out the data... and that is bad.