The Galaxy S24 Ultra is a hell of a phone. As always, Samsung has jammed it full of more high-end hardware than you can shake an S Pen at, and this year it’s also packed with cutting-edge AI features. But it’s expensive, and most of my favorite things about it have very little to do with the AI parts, which aren’t even exclusive to the Ultra.
Technology
Samsung Galaxy S24 Ultra review: all that and AI
It comes with a display that’s so easy to use outside in bright light that I want every other manufacturer to copy it. Its camera system is one of the best in the game and comes with a fantastic portrait mode. The built-in stylus remains one of the nicest and fanciest ways to make a grocery list.
Some of the AI features really are impressive: live translation for phone calls could be really helpful for someone who makes a lot of calls in an unfamiliar language. Voice recording summaries are surprisingly good and give my beloved Pixel Recorder a real run for its money. And turning any video into slow motion is just plain fun. Are the results always great? No, but they’re usually delightful.
But battery performance is just okay, and while I appreciate the new flat-screen design, it leaves some sharp corners that can be uncomfortable in your hand. Above all, the Ultra is expensive — now starting at $1,299, a $100 increase from last year’s model. Samsung’s everything-but-the-kitchen-sink device is still the most feature-packed phone money can buy, but I’m just not seeing an extra $100 worth of improvements, especially considering that the AI features will all be ported to the S23 series in a future software update.
Ever try to use your phone in direct sunlight and find it turns into a mirror? Reflections bounce right off the glass, and whatever you were trying to look at is suddenly invisible. It’s a real pain in the buns, although it’s been less of a problem as OLED screens have gotten brighter over the past few years. The S24 Ultra goes an extra step and introduces a new anti-glare coating that does a fantastic job of cutting those reflections down.
The 6.8-inch screen peaks at 2,600 nits in bright light, which makes a real difference when you use your phone outside. I prepared myself to squint at the display when I used it in some bright sunshine, so it was a real treat to realize I could see the screen almost as well as I could indoors. There’s a new Gorilla Glass Armor protecting the screen, and it purports to be much more scratch-resistant than previous versions of Gorilla Glass. It’s hard to judge that in just over a week of testing, but so far, so good.
Samsung followed Apple’s lead on another screen feature: dimming the wallpaper on the always-on display. You can also add a handful of widgets that will continue to display on the AOD even with the phone locked. It’s a straight-up Apple clone, and I have zero problems with that because I crave information and love widgets. Answering “What’s next on my calendar?” is as simple as glancing at my phone screen.
The always-on display is handy, but it does seem to take a significant toll on battery performance. At the end of each day I tested it, diagnostics reported that it was responsible for about 7 percent of my battery use throughout the day. Overall, battery life on the S24 Ultra isn’t great, but it’s not a disaster by any means — on days of light use, I got to bedtime with around 50 percent in the tank. Heavier days with closer to five hours of screen-on time pushed my review unit’s battery down to 30 percent. Honestly, that’s about average for a flagship phone these days, and I wish performance were a little better across the board.
In any case, plenty of people will get through a full day on the S24 Ultra just fine, though it’s worth remembering your mileage will dwindle over time as the battery ages. If you’re a power user — as I suspect a lot of people interested in this phone are — you might need an afternoon recharge to avoid late-day battery anxiety.
There’s 45W wired and 15W wireless Qi charging available but no Qi2, which is a real disappointment. If you want to live the MagSafe life with the S24 Ultra, you’ll need to pick up a third-party magnet case — just don’t use the stylus with a magnetic accessory attached — and a MagSafe-compatible (not MagSafe or Qi2) charger.
The S24 Ultra comes equipped with the Snapdragon 8 Gen 3 chipset no matter where you buy it — not true of the standard S24 and S24 Plus, which come with Exynos chips outside of the US. I can’t find anything wrong with performance on the Ultra. It didn’t get excessively hot in my testing, and with 12GB of RAM, it handled everything I threw at it without a problem.
The S24 Ultra is the first Ultra with a flat screen, and I appreciate it — no longer do I fear running the S Pen over the curved edge. The titanium exterior finish is lovely, but this remains an unapologetically big, heavy phone. After the first few times it slipped out of the pocket of my joggers and onto the wood floor with a thud heard ’round the house, I quit carrying it around with me and left it on the dining room table.
Also, this phone is kind of sharp? The corners where the flat parts of the phone meet the curved edges are pointy, and if you don’t get it situated in your hand just right, they’re pretty uncomfortable. I’m not a case person, but I might consider one with the S24 Ultra for this reason.
The S24 series ships with One UI 6.1, which is Samsung’s take on Android 14. Like Android 14 itself, One UI 6.1 is a relatively light update, and the things that irritate me about Samsung software persist: a push notification urging me to check out the new Galaxy S24 (lol); lots of proprietary apps and features that I don’t have a use for (I refuse to believe Global Goals has inspired anyone to do anything except uninstall Global Goals); and clickbait links stuffed at the bottom of the weather app (“Tourist Finds Large Diamond at State Park,” really?).
You can de-Samsung a lot of this stuff and live a peaceful existence with One UI, and there’s some good news this year: the company is promising seven years of OS upgrades, including seven years of security updates. That’s a great proposition for ROI and anyone who wants to get the absolute most years out of their phone.
That’s the gist of the regular phone stuff — a massive screen, okay battery life, and performance fitting of a 2024 flagship. So how about the marquee feature: Galaxy AI? Settle in, because there’s a lot to cover.
The short version is this: the S24 Ultra has an impressive collection of AI features. But it’s just that — a collection. It doesn’t feel like a unified set of tools with a collective purpose; it feels like a handful of capabilities scattered throughout the system that are excellent at times and baffling at others.
Take live translation: it happens on-device, and it can act as a real-time interpreter on phone calls. I tried it with my colleague Victoria Song, a fluent speaker of Japanese, and she thought it did an adequate job translating our exchange. It’s best suited for short transactional conversations because it gets impatient with pauses. It doesn’t quite get things right when talking more casually, either — I asked how Vee’s cats were doing, and the translator somehow interpreted her Japanese for “Petey is eating my chair” as “I am eating my chair.” Hilarious, but not ideal!
But if you need to call and ask for some information or make a reservation, it would serve the purpose. And that’s kind of amazing — if you live in a country where you don’t speak the language, I can see this being a hugely useful tool. It’s the kind of situation where AI that’s good enough is better than nothing.
Automatic note and voice transcript summaries are in the same category. I put the S24 Ultra’s new voice recorder features up against my beloved Pixel Recorder by reading them both a passage from the closest book I had on hand, Precious Little Sleep, aka the baby sleep Bible. Overall, I was surprised by how well Samsung kept up with the Pixel. It doesn’t transcribe in real time like the Pixel does, but it’s on-device, and it’s relatively quick after the fact; a six-minute recording took about 90 seconds to transcribe in my testing.
Once you have your transcript, you can generate a detailed summary in just a few seconds, complete with subheads and timestamps. It’s not something I’d trust without double-checking the source material, but like call translation, it gives you a starting point — something useful when you’d otherwise have nothing. Samsung’s translation summaries happen in the cloud, not on-device, so they do require an internet connection. Summarization seems like it’s too much to ask of a phone processor: the Pixel 8 Pro I tested at the same time tried to summarize its recording of the same text, produced one bullet point, and then gave up after chugging for a few minutes.
Then there’s Circle to Search, which is only really an AI feature by association, but spiritually, it feels at home in a discussion about the S24 Ultra’s AI features. It’s a Google feature that’s debuting on the Galaxy S24 and Pixel 8 series and will reportedly come to more high-end Android phones in the future. Basically, it’s Google Lens but everywhere on your phone — any app, anytime. You long-press the home button or navigation handle to engage it, and then a prompt appears to circle the thing you want to know more about. A page of Google results will follow, and you can tap around to learn more or dismiss the whole thing and go about your business. It’s simple, but it kind of feels like how our phones should have been working all along.
Google’s improvements to multisearch really make this feature stand out. After you’ve circled something to search for it, you can clarify your search with additional questions using the image as a starting point. Previously, multisearch could only work with basic modifiers, like “blue” to search for a pair of shoes in a particular color. Now, you can ask more complicated questions, and the search results will offer up an answer using generative AI. And that’s where I found the answer I was after most often.
There are some obvious situations where Circle to Search makes immediate sense — a friend texts the name of a restaurant, you highlight the name, and without ever leaving the messages app, you can check where it is. I had to sort of unlearn doing this the long way while using the S24 Ultra, and now that I’m used to Circle to Search, I don’t want to go back to the old way.
But when I was looking for more information about something, the first set of results didn’t always clear things up. Searching for a mural I photographed in San Jose brought up a page of similar-looking murals — helpful if you’re making a Pinterest mood board, less helpful if you want to know exactly what you’re looking at. But asking “Where is this?” in multisearch (shh, I knew where it was, I was just testing the computer) got me to the right answer quickly.
There are more AI features — naturally there are more — but I won’t go into depth about every one of them. You can have generative AI spice up your text messages with emoji or summarize webpages. They work reasonably well but don’t strike me as being quite as useful as the others. Of course, there’s one more place you’ll find AI at work: the Galaxy S24 Ultra’s camera.
First, the numbers. Per usual, there are a boatload of cameras on this phone:
- Main camera: 200-megapixel f/1.7 with OIS
- 3x telephoto: 10-megapixel f/2.4, OIS
- 5x telephoto: 50-megapixel f/3.4, OIS
- Ultrawide: 12-megapixel f/2.2
- Selfie: 12-megapixel f/2.2
They’re the same cameras that are on the S23 Ultra except for one notable substitution — the 10x lens is gone, swapped for a 5x lens coupled with a bigger, higher-res sensor. This is terrible news for me personally because I love that ridiculous 10x lens. You can take pictures of planes! In the sky! It’s such a great party trick.
The new version uses crop zoom to get to 10x, and Samsung insists that the image quality is just as good as the 10x optical zoom on the previous version. As far as I can tell, that’s mostly true — detail rendering looks about the same. And the S24 Ultra definitely looks better at 5x since the S23 Ultra was using digital zoom at that focal length. I do see more chromatic aberration on some of the S24 Ultra’s 10x images compared to the S23 Ultra’s, which can make certain subjects appear a little fuzzier — this seems to be less of a problem with distant subjects, like the top of a skyscraper. The switch to a 5x zoom hasn’t been a completely victimless crime. But overall, it’s a move that makes sense. The 5x focal length has a lot more practical uses, and Samsung claims it’s used more often than 10x. Fair.
Otherwise, there aren’t any drastic changes year over year. Samsung is still leaning on the saturation slider, embracing those vivid reds and blues it’s known for. It usually looks nice and occasionally looks bananas. The company made a few tweaks to the tech behind its portrait mode, which is still excellent. Expert RAW now produces 24-megapixel images with data from 50- and 12-megapixel captures. More data, more better, as they say.
And I’m thrilled to see Samsung fully embrace Ultra HDR — that’s the high dynamic range image format supported in Android 14. You’ll see the Ultra HDR tone mapping in the live image preview as you take your photo, and the S24 series are the first devices that let you upload Ultra HDR photos to Instagram. These are true HDR photos that look more vibrant than the washed-out “HDR” photos we’re used to seeing, which are really just attempts at showing a wider dynamic range on an SDR display. I’m already impatient for third-party app support to come to more phones.
Samsung is the company that gave us AI Moon, so naturally, there are a few AI photo and video editing features here. Generative AI edits are available behind a star icon in the native gallery editing interface. You can select objects to move around the frame or erase entirely, and you can adjust the horizon using generative fill to pad out the image rather than cropping in. The edits happen off-device, so you need an internet connection and a little patience.
This is very similar to the generative AI editing tools offered on the Pixel 8 Pro, which isn’t surprising — Samsung is using Google’s models to power just about every AI feature on these phones. But I actually find Samsung’s object selection much easier to use than the Pixel’s. On the S24, you just circle an object you want to select, and on-device AI makes the selection. It’s a little uncanny how good it is. Selecting objects on the Pixel feels a little more fiddly.
With an object selected, you can resize it, move it around the frame, or erase it completely. With a somewhat predictable background like grass or a gravel path, generative AI can fill in the blanks convincingly. Predictably, things get dicey with more complicated edits. I selected a lamp on a table and attempted to erase it from a photo; the AI replaced it with a different lamp.
It’s a similar story with slow-motion AI videos — impressive if you don’t challenge it too much or look too closely. The S24 Ultra can turn any video into a 120fps slow-motion video — essentially using frame interpolation but leaning on generative AI to fill in the gaps. With the right subject and background, it’s totally convincing. But if you start introducing some complexity, it kind of falls apart.
I slowed down the above 30fps video of my son on a swing, and you can see that the mulch on the playground and greenery in the background gave the AI some trouble. Is it still an adorable video? Yes. Will his grandparents be delighted by it despite its flaws? Also yes. It feels like a feature right on the edge between “good enough” and “too weird” to be fun.
It’s hard to describe why a device that does so much so well feels like it falls flat. The Galaxy S23 Ultra felt like something truly special — a refinement of a well-balanced formula. But with the S24 Ultra, the math feels a little off.
It’s $100 more expensive, but it’s hard to see an extra $100 worth of value, especially considering the new AI features are shared across the whole S24 series. To be clear, I think it’s a good thing that these features are available on all three phones. But if the Ultra really is the fastest, bestest phone in all the land, shouldn’t it be able to do a little more?
The new anti-glare screen coating is impressive and truly helpful on a bright day. The flat screen is an improvement, and the new titanium exterior looks and feels great. But that’s more or less the extent of this year’s Ultra-only improvements. The AI features, Ultra HDR support, seven years of OS upgrades, updated always-on display — they’re all available on the less pricey S24 and S24 Plus.
The feature-to-price ratio feels just a bit off-balance in a way that it didn’t in the S23 Ultra
That leaves the Ultra with a bigger screen, an S Pen, and a 5x zoom to distinguish it. They’re all great features and sure to please loyal Note / Ultra fans. But the feature-to-price ratio feels just a bit off-balance in a way that it didn’t in the S23 Ultra.
I wish Samsung had spent a little more time on the less-flashy stuff — improving battery life or making it lighter and more comfortable to use. Heck, I’d be thrilled if Samsung spent time on a little housekeeping on the features that have piled up over the years. Bixby Vision, Google Lens, and Circle to Search all exist on this phone. What are we doing here?
The Galaxy S24 Ultra remains the absolute most phone. Massive screen, S Pen, all of the cameras, performance out the wazoo — it really has no peer. I just wish that it felt a little more worthy of its price bump when the MSRP was already sky-high before. This is an Ultra phone, alright. I just wish it came with a little extra.
Photography by Allison Johnson / The Verge
Technology
Republicans attack ‘woke’ Netflix — and ignore YouTube
When Netflix co-CEO Ted Sarandos entered the Senate office building on Tuesday, he got thrown a curveball. What started as a standard antitrust hearing relating to the Warner Bros. merger quickly devolved into a performative Republican attack about the spread of “woke” ideology on the streaming service. At the same time, arguably a much more influential platform was completely ignored: YouTube.
After grilling Sarandos about residual payments, Sen. Josh Hawley (R-MO) launched into a completely different line of questioning: “Why is it that so much of Netflix content for children promotes a transgender ideology?” Hawley asked, making an unsubstantiated claim that “almost half” of the platform’s children’s content contains so-called “transgender ideology.” The statement harkened to a pressure campaign launched by Elon Musk months ago in which he called on X users to unsubscribe from Netflix for having a “transgender woke agenda,” citing its few shows with trans characters — shows that were canceled years ago.
“Our business intent is to entertain the world,” Sarandos replied. “It is not to have a political agenda.” Still, other Republican lawmakers, including Sens. Ashley Moody (R-FL) and Eric Schmitt (R-MO), piled on, bringing up a post Netflix made following the murder of George Floyd, and the French film Cuties, which sparked a right-wing firestorm years ago. Sen. Ted Cruz (R-TX) even asked Sarandos what he thought about Billie Eilish’s “no one is illegal on stolen land” comment at the Grammys. It seemed like they were grasping at straws to support their narrative that Netflix’s acquisition of Warner Bros. could somehow poison the well of content for viewers.
“My concern is that you don’t share my values or those of many other American parents, and you want the United States government to allow you to become one of the largest — if not the largest — streaming monopolist in the world,” Hawley said. “I think we ought to be concerned about what content you’re promoting.”
While it’s true that Netflix will control a substantial portion of the streaming market when — and or if — it acquires Warner Bros. and its streaming service HBO Max, it’s hard to criticize Netflix without bringing up YouTube.
“YouTube is not just cat videos anymore. YouTube is TV.”
For years now, Netflix has been trying to topple YouTube as the most-watched streaming service. Data from Nielsen says Netflix made up 9 percent of total TV and streaming viewing in the US in December 2025, while Warner Bros. Discovery’s services made up 1.4 percent. Combining the two doesn’t even stack up to YouTube, which held a 12.7 percent share of viewership during that time. “YouTube is not just cat videos anymore,” Sarandos told the subcommittee. “YouTube is TV.”
Unlike Netflix, YouTube is free and has an ever-growing library of user-created content that doesn’t require it to spend billions of dollars in production costs and licensing fees. YouTube doesn’t have to worry about maintaining subscribers, as anyone with access to a web browser or phone can open up and watch YouTube. The setup brings YouTube a constant stream of viewers that it can rope in with a slew of content it can recommend to watch next.
But not all creators on YouTube are striving for quality. As my colleague Mia Sato wrote, YouTube is home to creators who try to feed an algorithm that boosts inflammatory content and attempts to hook viewers, in addition to an array of videos that may be less than ideal for kids.
Like it or not, YouTube is the dominant streamer, with an endless supply of potentially offensive agendas for just about anyone. But for some reason, it’s not the target of this culture war. If these lawmakers actually cared about what their kids are watching, maybe they’d start looking more closely at how YouTube prioritizes content. Or, if they don’t like the shows and movies on Netflix, they could just do what Sarandos suggested during the hearing: unsubscribe.
Technology
Microsoft crosses privacy line few expected
NEWYou can now listen to Fox News articles!
For years, we’ve been told that encryption is the gold standard for digital privacy. If data is encrypted, it is supposed to be locked away from hackers, companies and governments alike. That assumption just took a hit.
In a federal investigation tied to alleged COVID-19 unemployment fraud in Guam, a U.S. territory where federal law applies, Microsoft confirmed it provided law enforcement with BitLocker recovery keys. Those keys allowed investigators to unlock encrypted data on multiple laptops.
This is one of the clearest public examples to date of Microsoft providing BitLocker recovery keys to authorities as part of a criminal investigation. While the warrant itself may have been lawful, the implications stretch far beyond one investigation. For everyday Americans, this is a clear signal that “encrypted” does not always mean “inaccessible.”
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
HACKERS ABUSE GOOGLE CLOUD TO SEND TRUSTED PHISHING EMAILS
In the Guam investigation, Microsoft provided BitLocker recovery keys that allowed law enforcement to unlock encrypted laptops. (David Paul Morris/Bloomberg via Getty Images)
What happened in the Guam BitLocker case?
Federal investigators believed three Windows laptops held evidence tied to an alleged scheme involving pandemic unemployment funds. The devices were protected with BitLocker, Microsoft’s built-in disk encryption tool enabled by default on many modern Windows PCs. BitLocker works by scrambling all data on a hard drive so it cannot be read without a recovery key.
Users can store that key themselves, but Microsoft also encourages backing it up to a Microsoft account for convenience. In this case, that convenience mattered. When served with a valid search warrant, Microsoft provided the recovery keys to investigators. That allowed full access to the data stored on the devices. Microsoft says it receives roughly 20 such requests per year and can only comply when users have chosen to store their keys in the cloud.
We reached out to Microsoft for comment, but did not hear back before our deadline.
How Microsoft was able to unlock encrypted data
According to John Ackerly, CEO and co-founder of Virtru and a former White House technology advisor, the problem is not encryption itself. The real issue is who controls the keys. He begins by explaining how convenience can quietly shift control. “Microsoft commonly recommends that users back up BitLocker recovery keys to a Microsoft account for convenience. That choice means Microsoft may retain the technical ability to unlock a customer’s device. When a third party holds both encrypted data and the keys required to decrypt it, control is no longer exclusive.”
Once a provider has the ability to unlock data, that power rarely stays theoretical. “When systems are built so that providers can be compelled to unlock customer data, lawful access becomes a standing feature. It is important to remember that encryption does not distinguish between authorized and unauthorized access. Any system designed to be unlocked on demand will eventually be unlocked by unintended parties.”
Ackerly then points out that this outcome is not inevitable. Other companies have made different architectural choices. “Other large technology companies have demonstrated that a different approach is possible. Apple has designed systems that limit its own ability to access customer data, even when doing so would ease compliance with government demands. Google offers client-side encryption models that allow users to retain exclusive control of encryption keys. These companies still comply with the law, but when they do not hold the keys, they cannot unlock the data. That is not obstruction. It is a design choice.”
Finally, he argues that Microsoft still has room to change course. “Microsoft has an opportunity to address this by making customer-controlled keys the default and by designing recovery mechanisms that do not place decryption authority in Microsoft’s hands. True personal data sovereignty requires systems that make compelled access technically impossible, not merely contractually discouraged.”
In short, Microsoft could comply because it had the technical ability to do so. That single design decision is what turned encrypted data into accessible data.
“With BitLocker, customers can choose to store their encryption keys locally, in a location inaccessible to Microsoft, or in Microsoft’s consumer cloud services,” a Microsoft spokesperson told CyberGuy in a statement. “We recognize that some customers prefer Microsoft’s cloud storage, so we can help recover their encryption key if needed. While key recovery offers convenience, it also carries a risk of unwanted access, so Microsoft believes customers are in the best position to decide whether to use key escrow and how to manage their keys.”
WHY CLICKING THE WRONG COPILOT LINK COULD PUT YOUR DATA AT RISK
When companies hold encryption keys, lawful requests can unlock far more data than most people expect. (Kurt “CyberGuy” Knutsson)
Why this matters for data privacy
This case has reignited a long-running debate over lawful access versus systemic risk. Ackerly warns that centralized control has a long and troubling history. “We have seen the consequences of this design pattern for more than two decades. From the Equifax breach, which exposed the financial identities of nearly half the U.S. population, to repeated leaks of sensitive communications and health data during the COVID era, the pattern is consistent: centralized systems that retain control over customer data become systemic points of failure. These incidents are not anomalies. They reflect a persistent architectural flaw.”
When companies hold the keys, they become targets. That includes hackers, foreign governments and legal demands from agencies like the FBI. Once a capability exists, it rarely goes unused.
How other tech giants handle encryption differently
Apple has designed systems, such as Advanced Data Protection, where it cannot access certain encrypted user data even when served with government requests. Google offers client-side encryption for some services, primarily in enterprise environments, where encryption keys remain under the customer’s control. These companies still comply with the law, but in those cases, they do not possess the technical means to unlock the data. That distinction matters. As encryption experts often note, you cannot hand over what you do not have.
What we can do to protect our privacy
The good news is that personal privacy is not gone. The bad news is that it now requires intention. Small choices matter more than most people realize. Ackerly says the starting point is understanding control. “The main takeaway for everyday users is simple: if you don’t control your encryption keys, you don’t fully control your data.”
That control begins with knowing where your keys are stored. “The first step is understanding where your encryption keys live. If they’re stored in the cloud with your provider, your data can be accessed without your knowledge.”
Once keys live outside your control, access becomes possible without your consent. That is why the way data is encrypted matters just as much as whether it is encrypted. “Consumers should look for tools and services that encrypt data before it reaches the cloud — that way, it is impossible for your provider to hand over your data. They don’t have the keys.” Defaults are another hidden risk. Many people never change them. “Users should also look to avoid default settings designed for convenience. Default settings matter, and when convenience is the default, most individuals will unknowingly trade control for ease of use.”
When encryption is designed so that even the provider cannot access the data, the balance shifts back to the individual. “When data is encrypted in a way that even the provider can’t access, it stays private — even if a third party comes asking. By holding your own encryption keys, you’re eliminating the possibility of the provider sharing your data.” Ackerly says the lesson is simple but often ignored. “The lesson is straightforward: you cannot outsource responsibility for your sensitive data and assume that third parties will always act in your best interest. Encryption only fulfills its purpose when the data owner is the sole party capable of unlocking it.” Privacy still exists. It just no longer comes by default.
700CREDIT DATA BREACH EXPOSES SSNS OF 5.8M CONSUMERS
Reviewing default security and backup settings can help you keep control of your private data. (Kurt “CyberGuy” Knutsson)
Practical steps you can take today
You do not need to be a security expert to protect your data. A few practical checks can go a long way.
1) Start by checking where your encryption keys live
Many people do not realize that their devices quietly back up recovery keys to the cloud. On a Windows PC, sign in to your Microsoft account and look under device security or recovery key settings. Seeing a BitLocker recovery key listed online means it is stored with Microsoft.
For other encrypted services, such as Apple iCloud backups or Google Drive, open your account security dashboard and review encryption or recovery options. Focus on settings tied to recovery keys, backup encryption, or account-based access. When those keys are linked to an online account, your provider may be able to access them. The goal is simple. Know whether your keys live with you or with a company.
2) Avoid cloud-based key backups unless you truly need them
Cloud backups are designed for convenience, not privacy. If possible, store recovery keys offline. That can mean saving them to a USB drive, printing them and storing them in a safe place, or using encrypted hardware you control. The exact method matters less than who has access. If a company does not have your keys, it cannot be forced to turn them over.
3) Choose services that encrypt data before it reaches the cloud
Not all encryption works the same way, even if companies use similar language. Look for services that advertise end-to-end or client-side encryption, such as Signal for messages, or Apple’s Advanced Data Protection option for iCloud backups. These services encrypt your data on your device before it is uploaded, which means the provider cannot read it or unlock it later. Here is a simple rule of thumb. If a service can reset your password and restore all your data without your involvement, it likely holds the encryption keys. That also means it could be forced to hand over access. When encryption happens on your device first, providers cannot unlock your data because they never had the keys to begin with. That design choice blocks third-party access by default.
4) Review default security settings on every new device
Default settings usually favor convenience. That can mean easier recovery, faster syncing and weaker privacy. Take five minutes after setup and lock down the basics.
iPhone: tighten iCloud and account recovery
Turn on Advanced Data Protection for iCloud (strongest iCloud protection)
- Open Settings
- Tap your name
- Tap iCloud
- Scroll down and tap Advanced Data Protection
- Tap Turn On Advanced Data Protection
- Follow the prompts to set up Account Recovery options, like a Recovery Contact or Recovery Key
Review iCloud Backup
- Open Settings
- Tap your name
- Tap iCloud
- Tap iCloud Backup
- Decide if you want it on or off, based on your privacy comfort level
Strengthen your Apple ID security
- Open Settings
- Tap your name
- Tap Sign-In & Security
- Make sure Two-Factor Authentication (2FA) is turned on and review trusted phone numbers and devices
- Review trusted phone numbers and devices
Android: lock your Google account and backups
Review and control device backup
Settings may vary depending on your Android phone’s manufacturer.
- Open Settings
- Tap Google
- Tap Backup (or All services then Backup)
- Tap Manage backup
- Choose what backs up and confirm which Google account stores it
NEW ANDROID MALWARE CAN EMPTY YOUR BANK ACCOUNT IN SECONDS
Strengthen your screen lock, since it protects the device itself
Settings may vary depending on your Android phone’s manufacturer.
- Open Settings
- Tap Security or Security & privacy
- Set a strong PIN or password
- Turn on biometrics if you want, but keep the PIN strong either way
Secure your Google account
Settings may vary depending on your Android phone’s manufacturer.
- Open Settings
- Tap Google
- Tap Manage your Google Account
- Go to Security
- Turn on 2-Step Verification and review recent security activity
Mac: enable FileVault and review iCloud settings
Turn on FileVault disk encryption
- Click the Apple menu
- Select System Settings
- Click Privacy & Security
- Scroll down and click FileVault
- Click Turn On
- Save your recovery method securely
Review iCloud syncing
- Open System Settings
- Click your name
- Click iCloud
- Review what apps and data types sync
- Turn off anything you do not want stored in the cloud
Windows PC: check BitLocker and where the recovery key is stored
Confirm BitLocker status and settings
- Open Settings
- Go to Privacy & security
- Tap Device encryption or BitLocker (wording varies by device)
Check whether your BitLocker recovery key is stored in your Microsoft account
- Go to your Microsoft account page
- Open Devices
- Select your PC
- Look for Manage recovery keys or a BitLocker recovery key entry
- If you see a key listed online, it means the key is stored with Microsoft. That is why Microsoft was able to provide keys in the Guam case.
If your account can recover everything with a few clicks, a third party might be able to recover it too. Convenience can be helpful, but it can also widen access.
5) Treat convenience features as privacy tradeoffs
Every shortcut comes with a cost. Before enabling a feature that promises easy recovery or quick access, pause and ask one question. If I lose control of this account, who else gains access? If the answer includes a company or third party, decide whether the convenience is worth it.
These steps are not extreme or technical. They are everyday habits. In a world where lawful access can quietly become routine access, small choices now can protect your privacy later.
Strengthen protection beyond encryption
Encryption controls who can access your data, but it does not stop every real-world threat. Once data is exposed, different protections matter.
Strong antivirus software adds device-level protection
Strong antivirus software helps block malware, spyware and credential-stealing attacks that can bypass privacy settings altogether. Even encrypted devices are vulnerable if malicious software gains control before encryption comes into play.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com
An identity theft protection service helps when exposure turns into fraud
If personal data is accessed, sold, or misused, identity protection services can monitor for suspicious activity, alert you early and help lock down accounts before damage spreads. Identity Theft companies can monitor personal information like your Social Security Number (SSN), phone number and email address, and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com.
Kurt’s key takeaways
Microsoft’s decision to comply with the BitLocker warrant may have been legal. That doesn’t make it harmless. This case exposes a hard truth about modern encryption. Privacy depends less on the math and more on how systems are built. When companies hold the keys, the risk falls on the rest of us.
Do you trust tech companies to protect your encrypted data, or do you think that responsibility should fall entirely on you? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Substack data breach exposed users’ emails and phone numbers
Substack is notifying some users that the email addresses and phone numbers linked to their accounts were exposed in a “security incident” last year. In an email to account holders, Substack CEO Chris Best said that a hacker had accessed internal data without authorization in October 2025, but that passwords, credit card numbers, and other financial information remain secure.
“On February 3rd, we identified evidence of a problem with our systems that allowed an unauthorized third party to access limited user data without permission, including email addresses, phone numbers, and other internal metadata,” Best said in the email. “We do not have evidence that this information is being misused, but we encourage you to take extra caution with any emails or text messages you receive that may be suspicious.”
Substack says that it has since fixed the security problem, and is now conducting a full investigation alongside bolstering its systems “to prevent this type of issue from happening in the future.” The platform didn’t provide any details regarding what the security issue was, or how many users have been impacted — myself and several Verge colleagues who also use Substack did not receive the email. We have reached out to Substack for clarification.
“I’m incredibly sorry this happened,” Best said in the email to users. “We take our responsibility to protect your data and your privacy seriously, and we came up short here.”
-
Indiana4 days ago13-year-old rider dies following incident at northwest Indiana BMX park
-
Massachusetts5 days agoTV star fisherman, crew all presumed dead after boat sinks off Massachusetts coast
-
Tennessee6 days agoUPDATE: Ohio woman charged in shooting death of West TN deputy
-
Movie Reviews1 week agoVikram Prabhu’s Sirai Telugu Dubbed OTT Movie Review and Rating
-
Indiana4 days ago13-year-old boy dies in BMX accident, officials, Steel Wheels BMX says
-
Politics1 week agoVirginia Democrats seek dozens of new tax hikes, including on dog walking and dry cleaning
-
Austin, TX7 days ago
TEA is on board with almost all of Austin ISD’s turnaround plans
-
Texas5 days agoLive results: Texas state Senate runoff