Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

81–90 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#81
post #32
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

AI enshittification is irrelevant here. Why is someone pointing out that sensible secure defaults are a good thing suddenly defending the entire company?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#83
post #2

Quid pro quo.

What quid pro quo? Is there an allegation that the FBI gave Microsoft something in exchange?

As far as I can see this particular case is a straightforward search warrant. A court absolutely has the power to compel Microsoft to hand over the keys.

The bigger question is why Microsoft has the recovery feature at all. But honestly I believe Microsoft cares so little about privacy and security that they would do it just to end the "help customers who lose their key" support tickets, with no shady government deal required. I'd want to see something more than speculation to convince me otherwise.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#84
post #61
post #32

Earlier quoted context omitted.

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Are you referring to Microsoft Recall? My understanding is that is opt-in and only stored locally.

Stored locally.. until it's uploaded by OneDrive or Windows Backup?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#85

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

It’s not about engineers being lazy, it’s about money.

Trying to resist building ethically questionable software usually means quitting or being fired from a job.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#86
post #21

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?

Given enough computers, anything will happen. Apparently enough bit flips happen in domains (or their DNS resolution) that registering domains one bit away from the most popular ones (e.g. something like gnogle.com for google.com) might be worth it for bad actors. There was a story a few years ago, but I can't find it right now; perhaps someone will link it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#87
post #21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

If users are so paranoid that they worry about a cosmic ray bit flipping their computer into betraying them, they're probably not using a Microsoft account at all with their Windows PC.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#88

Earlier quoted context omitted.

It's "HN-likely" which translates to "almost never" in reality.

if cosmic ray bit flips were so rare then ecc ram wouldn't be a thing.

ECC protects against more events than cosmic rays. Those events are much more likely, for instance magnetic/electric interferences or chip issues.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#89

Earlier quoted context omitted.

Any power users should avoid Windows entirely.

If by "power user" you mean "enemy of the state", there's a lot of software you'd be better-off avoiding.

https://news.ycombinator.com/item?id=46700219

Criticizing the current administration? That sounds like something an enemy of the state would do!

Prepare yourself for the 3am FBI raid, evildoer! You're an enemy of the state, after all, that means you deserve it! /s

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#90
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive.

False. If you only put the keys on the Microsoft account, and Microsoft closes your account for whatever reason, you are done.

Post reply on HN