Why is a padlock with the key stuck right into it secure? The encrypted data and the decryption key is on the same physical device.
Sure, memory isolation techniques may serve as a deterrent with extreme care. But if Microsoft increases the attack surface by sloppily integrating that feature everywhere in Windows, the yet-to-be-implemented-if-at-all encryption is going to be ineffective. And that’s going to happen more likely than not.
That's exactly the kind of thing I was referring to when I wrote "memory isolation techniques." Even if you gate access with an API, you can still retrieve data from it and that's the problem.
Also, it should be clear by now that government agencies are going to demand access to this data once this becomes widespread. VMs aren't going to protect against further assault on our civil liberties.
How does that work? Can authorities compell Microsoft to surreptitiously have only my computer randomly unencrypt and submit stuff? If so, couldn't the authorities just tell MS to activate a tool like recall anyway?
Authorities compel tech companies to hand over data and place backdoors. They typically abuse secrecy laws to avoid public backlash, but their public demands have gotten bolder since the Snowden disclosures.
Sure, memory isolation techniques may serve as a deterrent with extreme care. But if Microsoft increases the attack surface by sloppily integrating that feature everywhere in Windows, the yet-to-be-implemented-if-at-all encryption is going to be ineffective. And that’s going to happen more likely than not.