Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

61–70 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#61
post #32
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Are you referring to Microsoft Recall? My understanding is that is opt-in and only stored locally.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#62
post #32
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Sorry to interrupt the daily rage session with some neutral facts about how Windows and the law work.

> that just so happens to take a screenshot of your screen every few seconds

Recall is off by default. You have to go turn it on if you want it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#63
post #32
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Microsoft doesn't take the screenshot; their operating system does if Recall is enabled, and although the screenshots themselves are stored in an insecure format and location, Microsoft doesn't get them by default.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#64
post #21

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?

> IBM estimated in 1996 that one error per month per 256 MiB of RAM was expected for a desktop computer.

From the wikipedia article on "Soft error", if anyone wants to extrapolate.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#65
post #46

Earlier quoted context omitted.

Apple's solution is iCloud Keychain which is E2E encrypted, so would not be revealed with a court order.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#66
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

[flagged]

Microsoft shouldn't be uploading keys, but nor should they be turning bitlocker on without proper key backup. Therefore it should be left as an optional feature.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#67
post #32

Earlier quoted context omitted.

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

[flagged]

This is ridiculous.

There are a lot of people here criticising MSFT for implementing a perfectly reasonable encryption scheme.

This isn’t some secret backdoor, but a huge security improvement for end-users. This mechanism is what allows FDE to be on by default, just like (unencrypted) iCloud backups do for Apple users.

Calling bs on people trying to paint this as something it’s not is not “whiteknighting”.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#68

Earlier quoted context omitted.

>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?

It's "HN-likely" which translates to "almost never" in reality.

Especially since HN readers are more likely to be using ECC memory

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#70

Earlier quoted context omitted.

If by "power user" you mean "enemy of the state", there's a lot of software you'd be better-off avoiding.

That is a strange viewpoint. Are we calling everyone who wants some control over their computers enemies of the state?

> Are we calling everyone who wants some control over their computers enemies of the state?

As of today at 00:00 UTC, no.

    But there's an increasingly possible future
    where authoritarian governments will brand users
    who practice 'non-prescribed use' as enemies of the state.

    And when we have a government who's leader
    openly gifts deep, direct access to federal power
    to unethical tech leaders who've funded elections (ex:Thiel),
    that branding would be a powerful perk to have access to
    (even if indirectly).
Post reply on HN