Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

21–30 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account.

Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the security properties of the system have changed without any visible indication that it happened.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#22

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

Both Microsoft and Apple (I think Apple does) have the option to encrypt those keys with the user's password where they are storing them.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#23

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

It is the default setting on windows 11 to share your key with microsoft.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#24
post #17
post #6

Earlier quoted context omitted.

It's not like companies have a choice. If they have a key in their possession and law enforcement gets an order for it, they have to provide it.

> It's not like companies have a choice. > If they have a key in their possession [...] So they do have a choice.

People/users have an option to keep the key themselves. Most wouldn’t bother to manage encryption keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#25

Earlier quoted context omitted.

Any power users should avoid Windows entirely.

If by "power user" you mean "enemy of the state", there's a lot of software you'd be better-off avoiding.

That is a strange viewpoint. Are we calling everyone who wants some control over their computers enemies of the state?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#26

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

> Don't think Apple wouldn't do the same.

Of course Apple offers a similar feature. I know lots of people here are going to argue you should never share the key with a third party, but if Apple and Microsoft didn't offer key escrow they would be inundated with requests from ordinary users to unlock computers they have lost the key for. The average user does not understand the security model and is rarely going to store a recovery key at all, let alone safely.

> https://support.apple.com/en-om/guide/mac-help/mh35881/mac

Apple will escrow the key to allow decryption of the drive with your iCloud account if you want, much like Microsoft will optionally escrow your BitLocker drive encryption key with the equivalent Microsoft account feature. If I recall correctly it's the default option for FileVault on a new Mac too.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#27
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

It would make me a lot less angry if Microsoft didn't go out of their way to force people to use a Microsoft account of course.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#28
post #21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

>even a cosmic ray flipping the "do not upload" bit in memory

Stats on this very likely scenario?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#29
post #26

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

> Don't think Apple wouldn't do the same. Of course Apple offers a similar feature. I know lots of people here are going to argue you should never share the key with a third party, but if Apple and Microsoft didn't offer key escrow they would be inundated with requests from ordinary users to unlock computers they have lost the key for. The average user does not understand the security model and is rarely going to sto…

That's what I said. I admit the double-negative grammar is a bit confusing.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#30
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

I'm not sure how to do this on Windows, but to disable FileVault cloud key backup on Mac, go to `Settings > Users & Groups > click on the (i) tooltip next to your account` and uncheck "Allow user to reset password using Apple Account".

This is a part of Settings that you will never see at a passing glance, so it's easy to forget that you may have it on.

I'd also like to gently push back against the cynicism expressed about having a feature like this. There are more people who benefit from a feature like this than not. They're more likely thinking "I forgot my password and I want to get the pictures of my family back" than fully internalizing the principles and practices of self custody - one of which is that if you lose your keys, you lose everything.

Post reply on HN