ISSUE 18.20 • 2021-05-31 LANGALIST By Fred Langa Does it feel like rolling the security dice when you save your files to a cloud-based service? When t
[See the full post at: Securing sensitive files in OneDrive’s cloud]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Securing sensitive files in OneDrive’s cloud
Home » Forums » Newsletter and Homepage topics » Securing sensitive files in OneDrive’s cloud
- This topic has 9 replies, 9 voices, and was last updated 3 years, 11 months ago.
AuthorTopicFred Langa
AskWoody MVPMay 31, 2021 at 1:04 am #2368136Viewing 7 reply threadsAuthorReplies-
bmeacham
AskWoody PlusMay 31, 2021 at 7:49 am #2368189What about Personal Vault? Per Microsoft, Personal Vault is “a protected area in OneDrive that you can only access with a strong authentication method or a second step of identity verification, such as your fingerprint, face, PIN, or a code sent to you via email or SMS.”
To get access to sensitive files placed in Personal Vault, a hacker would have to not only get into your Microsoft account, but would also have to know the authentication method for your Personal Vault.
Sounds secure to me. Why not mention it in your article?
-
Fred Langa
AskWoody MVPMay 31, 2021 at 8:57 am #2368217The Personal Vault’s secure folder is very limited in what it can do. It will not, for example, allow for automatic syncing of general files from the Documents folder; you have to more or less manually add things.
In fact, Microsoft does *not* recommend Personal Vault for general storage, instead suggesting it for longer-term storage of limited types of mostly-unchanging documents such as scans of your license, passport, tax records, property deeds, etc. — not the daily churn of files in the Documents folder. (MS info: https://www.microsoft.com/en-us/microsoft-365/blog/2019/06/25/onedrive-personal-vault-added-security-onedrive-additional-storage/ )
Personal Vault is simply not well-suited for workaday, general-purpose, automated file syncing and storage of files that change regularly or rapidly.
-
WSFloridaBill
AskWoody PlusMay 31, 2021 at 8:02 am #2368196Another alternative for securing your “cloud” storage is to use Boxcryptor (www,boxcryptor.com). It locally encrypts files and folders and is available across virtually all computing platforms and works with most, if not all, commercially available cloud storage systems.
There is a free ( with limitations) and paid versions. I have been using it for years and found it to be a robust and reliable solution.
Perhaps this would be a good topic for the newsletter.1 user thanked author for this post.
Dan in St. Louis
AskWoody PlusMay 31, 2021 at 9:27 am #2368229I just cannot get it to work the way you describe. In File Explorer I see two “Documents” folders: one under “OneDrive” and one under “This PC.” I have checked all of the boxes under OneDrive’s “Settings > Account > Choose folders” to enable “You can get to these items even when you’re offline.”
But that means they are synched in both directions — if I delete a file from “This PC/Documents” it is also deleted from “OneDrive/Documents.” So “your working copy … will be kept local with a separate and still-encrypted copy tucked away in the Microsoft-protected cloud” is NOT protected from any loss of the local copy.
How else could it possibly work? The whole idea of OneDrive is that any changes to a file will be mirrored to the Cloud, and back again on demand, and OneDrive has no way to know whether those changes were intentional or accidental.
Unless there is another “don’t mess with these files” setting that I have not found……..
anonymous
GuestMay 31, 2021 at 9:32 am #2368228Why pay for a VPN when you may already have one. Check your router and see if it’s built in. When I’m using somebody else’s wireless I log in to my VPN and that way my traffic is encrypted all the way to my home Internet connection.
If you use KeePass then use a keyfile. The keyfile should only be on your home computer and your laptop / tablet / phone. My KeePass database file is publicly exposed but I’m not worried about it because without my password and the keyfile you are never going to be able to unencrypt it.
windbg
AskWoody PlusJune 1, 2021 at 7:15 am #2368396Another way to secure sensitive files in any cloud:
1. Place your most private files in a virtual encrypted disk.
2. Dismount/close the virtual disk.
3. Copy the single virtual encrypted disk file to the cloud directory.If you need to restore the backup or update/read a file from a different device, copy the encrypted disk file back out of the cloud to your local only copy. Open the virtual disk to read or edit. Close it. If edited, copy the virtual disk file back to cloud directory.
Your password manager’s encrypted database file ends up encrypted three times by three different encryption systems from three different vendors: the password manager vendor, the encrypted virtual disk vendor, and hopefully the cloud provider.
Note: A virtual encrypted disk is different from whole disk encryption and the virtual disk resolves down to a single file that is mounted as a new drive letter or directory when open and when closed the drive letter or directory is not available and the contents are encrypted regardless of the login status of your device.
Windows 10 22H2 desktops & laptops on Dell, HP, ASUS; No servers, no domain.
Paul T
AskWoody MVPJune 1, 2021 at 2:05 pm #2368476Your password manager’s encrypted database file ends up encrypted three times by three different encryption systems from three different vendors
And then when your system breaks and you need to access your cloud to restore the backup, you don’t have the password because it’s in the cloud.
Keep at least one copy of your password database local and away from your PC. And test that you can open it without using anything already installed on your PC.
cheers, Paul
1 user thanked author for this post.
Mick Mickle
AskWoody PlusJune 1, 2021 at 2:29 pm #2368485There is also an option to store and use sensitive files in a third-party virtual local drive (using full disk encryption) that is integrated with OneDrive or another cloud provider. Stablebit CloudDrive (https://stablebit.com/CloudDrive) seamlessly joins the local encrypted storage with the cloud encrypted storage, caching most frequently used files locally. (By the developer of Stablebit Scanner and Stablebit DrivePool.)
[Moderator edit] CloudDrive is a commercial product costing $40. Please ensure you mention this when posting (advertising without prior approval is against Da rules)
Edit: Sorry about the “advertising” aspect. Yeah, it’s got a price tag as described by moderator. Fred Langa’s article was very fine and informative (as usual), but I wanted to point out that there’s at least one exception to his note cautioning against relying on “whole-disk encryption” in connection with storing sensitive files on OneDrive.
Thormod Stordalen
AskWoody LoungerJune 1, 2021 at 3:10 pm #2368494Very informative and good article, but I do not see the full value of using VPN, as long as it is not a cloud provider that offers VPN. If you use VPN you get an extra layer of security but it is only to VPN provider, from there you need to trust HTTPS up to cloud provider. The fact that you want to disguise your location is probably of less interest since cloud provider already knows who you are.
1 user thanked author for this post.
Viewing 7 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Common Dental Problems and How to Prevent Them (Awaiting moderation)
by
Lyric Gutmann
17 minutes ago -
Multiple Partitions?
by
CWBillow
5 hours, 12 minutes ago -
World Passkey Day 2025
by
Alex5723
4 hours, 36 minutes ago -
Add serial device in Windows 11
by
Theodore Dawson
19 hours, 50 minutes ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
7 hours, 27 minutes ago -
Cached credentials is not a new bug
by
Susan Bradley
1 day ago -
Win11 24H4 Slow!
by
Bob Bible
1 day ago -
Microsoft hiking XBox prices starting today due to Trump’s tariffs
by
Alex5723
21 hours, 45 minutes ago -
Asus adds “movement sensor” to their Graphics cards
by
n0ads
1 day, 2 hours ago -
‘Minority Report’ coming to NYC
by
Alex5723
23 hours, 4 minutes ago -
Apple notifies new victims of spyware attacks across the world
by
Alex5723
1 day, 11 hours ago -
Tracking content block list GONE in Firefox 138
by
Bob99
1 day, 10 hours ago -
How do I migrate Password Managers
by
Rush2112
18 hours, 40 minutes ago -
Orb : how fast is my Internet connection
by
Alex5723
20 hours, 29 minutes ago -
Solid color background slows Windows 7 login
by
Alex5723
1 day, 23 hours ago -
Windows 11, version 24H2 might not download via Windows Server Updates Services
by
Alex5723
1 day, 21 hours ago -
Security fixes for Firefox
by
Susan Bradley
22 hours, 4 minutes ago -
Notice on termination of services of LG Mobile Phone Software Updates
by
Alex5723
2 days, 9 hours ago -
Update your Apple Devices Wormable Zero-Click Remote Code Execution in AirPlay..
by
Alex5723
2 days, 18 hours ago -
Amazon denies it had plans to be clear about consumer tariff costs
by
Alex5723
2 days, 9 hours ago -
Return of the brain dead FF sidebar
by
EricB
1 day, 21 hours ago -
Windows Settings Managed by your Organization
by
WSDavidO61
1 day ago -
Securing Laptop for Trustee Administrattor
by
PeachesP
2 hours, 7 minutes ago -
The local account tax
by
Susan Bradley
1 day, 22 hours ago -
Recall is back with KB5055627(OS Build 26100.3915) Preview
by
Alex5723
3 days, 7 hours ago -
Digital TV Antenna Recommendation
by
Win7and10
3 days ago -
Server 2019 Domain Controllers broken by updates
by
MP Support
3 days, 19 hours ago -
Google won’t remove 3rd party cookies in Chrome as promised
by
Alex5723
3 days, 21 hours ago -
Microsoft Manager Says macOS Is Better Than Windows 11
by
Alex5723
4 days ago -
Outlook (NEW) Getting really Pushy
by
RetiredGeek
3 days, 3 hours ago
Recent blog posts
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | ||||
4 | 5 | 6 | 7 | 8 | 9 | 10 |
11 | 12 | 13 | 14 | 15 | 16 | 17 |
18 | 19 | 20 | 21 | 22 | 23 | 24 |
25 | 26 | 27 | 28 | 29 | 30 | 31 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.