Microsoft Likely Has Your Windows 10 Recovery Key, and That's Bad: Report

Advertisement
By Manish Singh | Updated: 29 December 2015 19:33 IST

Microsoft may be putting the privacy of millions of users at risk. The built-in disk encryption feature in Windows 10, the latest desktop operating system from the company, is set to automatically upload your recovery key to Microsoft's servers, making it vulnerable in an event of a security breach.

Windows 10 ships with a device encryption feature that is enabled by default. While this has its own benefits such as ensuring your data is protected on the computer, for those who use a Microsoft account (Outlook/Live email) as a method of signing in, this also means that Microsoft has a stored your disk encryption key, reports The Intercept.

Advertisement

The issue, as you can imagine, is that if a person hacks into your Microsoft account, they can access this recovery key. Also, if a fraudster hacks into Microsoft's server, in that event too your privacy is pretty much compromised. There are many more scenarios in which an unauthorised personnel can glean access to your computer's recovery key.

Now in Microsoft's defence, this feature is genuinely useful. At times, you would want your recovery key to be available at a secure place, making it easier for you to log in with your Microsoft account. However, the potential privacy risk it imposes on the account perhaps makes it less worthy. Many Windows Insider participants are likely vulnerable as they are required to use Microsoft account and are likely using it to sign in to their system as well. As of early July of this year, more than 5 million users were signed up as a Windows Insider participant.

Advertisement

The report adds that users who utilise their organisation's email address to sign in, their keys aren't stored in Microsoft's server. So what needs to be done for the rest? You can check if your key is stored in the cloud by visiting this website . You can delete your key from your account to avoid any risk, and Microsoft says all copies will be wiped from its servers and backup drives. Those who don't see any key associated with their Microsoft account probably didn't use their Microsoft account to sign in, or they don't have device encryption enabled. Users who don't have the encryption option visible in Settings need not worry as they are probably using older machines without the Trusted Platform Module (TPM) required for device encryption.

Windows Pro and Windows Enterprise users can use the premium disk encryption service like BitLocker or a third-party tool to generate a new key. Users are recommended to store their new key by either printing it on a piece of paper or on a USB disk, and keeping it some place safe.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. How Instagram's Edits App Evolved Over the Past Year and What's Next
  2. Oppo Find X9s With Triple 50-Megapixel Cameras Launched at This Price
  3. Microsoft Cuts Xbox Game Pass Prices in India, Global Markets
  4. Sennheiser CX 80U, HD 400U With USB Type-C Connectivity Launched in India
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.