General 15 min read

Encrypted Isn't Enough: Ask Who Can Hand Over the Key to Your Notes

MMNMNOTE
encryptionkey-custodykey-escrowprivacydata-ownershiplocal-first

"Encrypted" answers only half the question. The other half is custody: who else can produce the key. Microsoft, Apple and Google all publish that answer for their own systems, in their own documentation, and the answers differ by product and by setting. The second half is the one worth reading before you trust a tool with your notes.

Microsoft's own BitLocker documentation describes what happens on an ordinary consumer machine. "When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account, and a TPM protector is created." 1 Nothing in that sentence is a leak or a scandal — it is the published design, and it is the reason a drive can be recovered after a laptop dies or a password is forgotten.

The same page records that the population it applies to has grown: "Starting in Windows 11, version 24H2, the prerequisites of DMA and HSTI/Modern Standby are removed. As a result, more devices are eligible for automatic and manual device encryption." 1 More machines encrypt themselves by default now. The word on the box — encrypted — did not change to say where the key went.

What "encrypted" is taken to mean

Most people hear "encrypted" as a promise about readers: the data is scrambled, so nobody else can read it. That reading is reasonable, and the scrambling part is real. Microsoft's device encryption "uses the XTS-AES 128-bit encryption method, by default." 1 The cipher is almost never the weak link in the chain.

Evidence for that arrives from an unlikely direction. Forbes reported in January 2026 that an ICE Homeland Security Investigations forensic expert had written in a court document in early 2025 that his agency did "not possess the forensic tools to break into devices encrypted with Microsoft BitLocker, or any other style of encryption". 2 A federal forensic unit, in a filing, saying the math beat it.

So the interesting failures are not cryptographic ones. Whether a given implementation derives and stores its keys correctly is a hard question in its own right — the browser-side version of it is a post in itself 3. But a flawless cipher with a key in someone else's account is exactly the case worth thinking about here.

The cipher can be perfect and the honest answer to who can read your notes can still be: more than one party.

The half of the claim that never gets read

Every encryption claim has two parts. The first is the cipher: what scrambles the data. The second is custody: who derives the key, who keeps a copy, and who can be compelled to produce it. Consumer marketing describes the first part and almost never the second, though the vendors themselves document it plainly.

Microsoft states the custody arrangement for consumer device encryption in a single line: "Device encryption turns on BitLocker automatically on device encryption-qualifying devices, with the recovery key automatically backed up to Microsoft Entra ID, AD DS, or the user's Microsoft account." 1

Automatically. Backed up. To an account.

That is not a buried clause — it is the headline behaviour of the feature, published on the vendor's own documentation site. It also explains why "is it encrypted?" is a question with a satisfying yes that settles very little. A companion audit of which note apps actually encrypt your notes end-to-end 4 can tell you whether the claim exists. It cannot tell you where the recovery key sleeps.

A documented case: a warrant, three laptops, and a key

In January 2026, Forbes reported that in early 2025 the FBI had "served Microsoft with a search warrant, asking it to provide recovery keys to unlock encrypted data stored on three laptops" in a Guam fraud investigation, and that this was "the first known instance where the Redmond, Washington company has provided any encryption key to law enforcement". 2

Microsoft confirmed the practice on the record. Its spokesperson, Charles Chamberlayne, told Forbes that "While key recovery offers convenience, it also carries a risk of unwanted access, so Microsoft believes customers are in the best position to decide... how to manage their keys" 2.

Microsoft also volunteered its own frequency figure — the company "receives around 20 requests for BitLocker keys per year and in many cases, the user has not stored their key in the cloud making it impossible for Microsoft to assist" 2.

Twenty a year is a small number, and it deserves to be read as one. This is not a dragnet.

Matt Green, the Johns Hopkins cryptographer, made the structural point rather than the volume one: "The lesson here is that if you have access to keys, eventually law enforcement is going to come." 2 He framed the arrangement as a decision rather than an accident: "This is private data on a private computer and they made the architectural choice to hold access to that data. They absolutely should be treating it like something that belongs to the user" 2.

Jennifer Granick, surveillance and cybersecurity counsel at the ACLU, described what a key opens: "The keys give the government access to information well beyond the time frame of most crimes, everything on the hard drive" 2. "Remote storage of decryption keys can be quite dangerous", she told Forbes 2.

The case was reported as ongoing, and none of this is legal advice. The durable part is architectural — a party that holds a key is a party that can be asked for it.

Apple's own table has a row for Notes

Apple publishes a table of which iCloud data categories are end-to-end encrypted, and it has a row for Notes. Under Standard data protection — the default — Notes are listed as "In transit & on server" with key storage "Apple". Under Advanced Data Protection, the same row reads "End-to-end", key storage "Trusted devices". 5

Same vendor, same data, same device. One opt-in setting moves the key from Apple's data centres to your trusted devices. Apple states the default plainly: "Standard data protection is the default setting for your account." 5 And it says what the default means: "the encryption keys are secured in Apple data centers so we can help you with data recovery, and only certain data is end-to-end encrypted" 5.

The count of categories that change is Apple's own. On that page, with Advanced Data Protection on, "the number of data categories that use end-to-end encryption rises to 25" 5. Read that as a figure from one dated Apple page rather than an industry constant — Apple's Platform Security guide describes the same change as a rise "from 14 to 23" 6. The number moves. The structure does not.

Google states its own version with one load-bearing word. Its Android backup help page says: "Your backups are uploaded to Google. Some of your data is end to end encrypted with your device’s screen lock PIN, pattern, or password." 7

Some. Not all. That single adjective carries the whole custody answer for a phone's backup, and it is sitting in the help centre, unhidden.

Escrow is a feature, and it cuts both ways

Key escrow is not a betrayal — it is why consumer encryption turns on at all. Microsoft's documentation names the alternative directly: "If a device uses only local accounts, then it remains unprotected even though the data is encrypted." 1 Remove the escrow and, for a great many machines, you remove the encryption.

The trade-off runs in both directions, and Apple states its side of it as clearly as Microsoft does. Advanced Data Protection, in Apple's words, "is an optional setting that offers our highest level of cloud data security." 5 Turning it on has a consequence the same page names: "If you enable Advanced Data Protection and then lose access to your account, Apple will not have the encryption keys to help you recover it" 5.

Both sentences are true at the same time. That is the whole difficulty.

So the honest version of the argument is not that escrow is wrong. It is that escrow is a decision someone made about your data, and that in most products it was made for you, once, by default, in a setting you never opened. The question is not whether the vendor is trustworthy. The question is whether you know which arrangement you are in.

The three questions to ask any tool you use

Replace the yes/no question with three. Who derives the key? Who else can produce a copy of it? And what does the vendor say happens when a third party is legally compelled? All three are answerable from public documentation for the major platforms, which is the most useful thing about them.

  1. Who derives the key? Your passphrase, your device, or the service. If the service derives it, the service has had it.
  2. Who holds a recoverable copy? Search the vendor's own docs for "recovery key" and read where it goes. Microsoft's answer runs one sentence and names an account. 1
  3. What happens if you lose it? A vendor that can restore your data is a vendor that can produce your key. Apple says the opposite case out loud for Advanced Data Protection: it cannot help you recover. 5
  4. Which data, exactly? Read the table, not the adjective. Apple publishes a per-category table; Google's help page says "Some", one word doing all the work. 5 7
  5. What has the vendor said about legal process? Some publish transparency reports; some answer journalists on the record, as Microsoft did in January 2026. 2

None of this asks you to become a cryptographer. It asks you to open a documentation page and read one column.

Frequently Asked Questions

These are the questions people actually type once the word "encrypted" stops feeling like an answer. Each one has a published, checkable response for the platforms named here — and the same method works on any tool you use, because the answer always lives in the vendor's own documentation rather than in its marketing.

Who has my BitLocker recovery key?

If you signed into Windows with a Microsoft account, Microsoft does. Its documentation says the recovery key is "automatically backed up to Microsoft Entra ID, AD DS, or the user's Microsoft account" when device encryption turns on. 1 Local-account machines are the exception, and that exception has a downside of its own.

Can Microsoft decrypt my drive?

It cannot break the cipher — a federal forensic unit said in a 2025 court filing that it had no tools to do that. 2 It can hand over a recovery key it already holds, which Forbes reported in January 2026 that it did under a search warrant. 2 Those are two different capabilities.

Is my encrypted data private from the company?

That depends on custody, not on encryption. Apple's own table lists Notes with key storage "Apple" under the default setting and "Trusted devices" under Advanced Data Protection. 5 One toggle moves the key, and the answer moves with it.

Does end-to-end encryption mean the company can't read it?

For the data actually covered, yes. The word doing the work is "covered". Google's Android backup page says "Some of your data is end to end encrypted"; Apple's default protects only certain categories. 7 5 Check which categories are named, not whether the phrase appears.

Where is my recovery key stored?

In the vendor's documentation, that answer is usually one sentence long. Microsoft's says the key "is uploaded to the online Microsoft account". 1 Apple's says keys are "secured in Apple data centers" under the default setting. 5 Search your own tool's docs for "recovery key" and read the destination.

Has BitLocker been broken?

Not by the agency that said so on the record. An ICE Homeland Security Investigations forensic expert wrote in a court document that his agency did "not possess the forensic tools to break into devices encrypted with Microsoft BitLocker, or any other style of encryption". 2 The cipher held. Custody is the live question.

What is iCloud Advanced Data Protection, and should I turn it on?

It is an opt-in setting that moves key storage for more categories to your trusted devices — Apple calls it "an optional setting" and says the count of end-to-end encrypted categories "rises to 25". 5 The trade-off is recovery: with it on, Apple "will not have the encryption keys to help you recover" your account. 5

The question that replaces "is it encrypted?"

The question was never whether your notes are encrypted. It is who can be asked to hand over the key to them — and for almost every tool you use, that answer is already written down, by the vendor, on a page carrying a date.

Encryption is a claim about mathematics. Custody is a claim about people, and it is the one that decides who reads your notes.


MNMNOTE keeps notes as open Markdown on your own device and works offline, and the sharing it offers is end-to-end encrypted — mnmnote.com.

Footnotes

  1. Microsoft. "BitLocker overview." Microsoft Learn, document date 2025-07-29. https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/. Accessed 2026-08-02. 2 3 4 5 6 7 8

  2. Brewster, T. (2026, January 23). "Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw." Forbes. https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/. The ellipsis inside the Microsoft spokesperson's quotation is Forbes' own elision, reproduced as printed. Accessed 2026-08-02. 2 3 4 5 6 7 8 9 10 11 12

  3. MNMNOTE. "Encrypting Notes in the Browser: AES-GCM, Key Derivation, Nonce Pitfalls." https://blog.mnmnote.com/posts/encrypting-notes-in-the-browser-aes-gcm-key-derivation-nonce-pitfalls — whether the cipher is implemented correctly, which is the layer beneath this one. Accessed 2026-08-02.

  4. MNMNOTE. "Which Note Apps Actually Encrypt Your Notes End-to-End?" https://blog.mnmnote.com/posts/which-note-apps-actually-encrypt-your-notes-end-to-end — the companion audit of whether the end-to-end claim exists at all. Accessed 2026-08-02.

  5. Apple. "iCloud data security overview." Apple Support, published January 5, 2026. https://support.apple.com/en-us/102651. Accessed 2026-08-02. 2 3 4 5 6 7 8 9 10 11 12 13

  6. Apple. "Advanced Data Protection for iCloud." Apple Platform Security. https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f/web. Accessed 2026-08-02.

  7. Google. "Back up or restore data on your Android device." Android Help. The page carries no visible last-updated date. https://support.google.com/android/answer/2819582. Accessed 2026-08-02. 2 3