It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
91–100 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#92FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#93Earlier quoted context omitted.
>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?
Given enough computers, anything will happen. Apparently enough bit flips happen in domains (or their DNS resolution) that registering domains one bit away from the most popular ones (e.g. something like gnogle.com for google.com) might be worth it for bad actors. There was a story a few years ago, but I can't find it right now; perhaps someone will link it.
Was in DEFCON19.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#94FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Any power users should avoid Windows entirely.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#95FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. At this point, the only thing that can restore trust in Microsoft is open sourcing Windows.
The fully security conscious option is to not link a Microsoft account at all.
I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#96Earlier quoted context omitted.
Why take the drastic step of switching to linux (a difficult endeavor) when you can simply turn off key uploading.
Why continue to use an operating system that’s adversarial towards you?
The only explanation that makes sense to me is that there's an element of irrationality to it. Apple has a well known cult, but Microsoft might have one that's more subtle? Or maybe it's a reverse thing where they hate Linux for some equally irrational reasons? That one is harder to understand because Linux is just a kernel, not a corporation with a specific identity or spokesperson (except maybe Torvalds, but afaik he's well-regarded by everyone)
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#97Earlier quoted context omitted.
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…
>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?
More on the topic: Single-event upset[1]
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#98Earlier quoted context omitted.
Given enough computers, anything will happen. Apparently enough bit flips happen in domains (or their DNS resolution) that registering domains one bit away from the most popular ones (e.g. something like gnogle.com for google.com) might be worth it for bad actors. There was a story a few years ago, but I can't find it right now; perhaps someone will link it.
https://www.youtube.com/watch?v=aT7mnSstKGs Was in DEFCON19.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#99Earlier quoted context omitted.
I'm not sure how to do this on Windows, but to disable FileVault cloud key backup on Mac, go to `Settings > Users & Groups > click on the (i) tooltip next to your account` and uncheck "Allow user to reset password using Apple Account". This is a part of Settings that you will never see at a passing glance, so it's easy to forget that you may have it on. I'd also like to gently push back against the cynicism expressed…
Or use a local account to login ?
There are two ways to log into macOS: a local user account or an LDAP (e.g. OpenDirectory, Active Directory) account. Either of these types of accounts may be associated with an iCloud account. macOS doesn’t work like Windows where your Microsoft account is your login credential for the local machine.
FileVault key escrow is something you can enable when enabling FileVault, usually during initial machine setup. You must be logged into iCloud (which happens in a previous step of the Setup Assistant) and have iCloud Keychain enabled. The key that wraps the FileVault volume encryption key will be stored in your iCloud Keychain, which is end-to-end encrypted with a key that Apple does not have access to.
If you are locked out of your FileVault-encrypted laptop (e.g. your local user account has been deleted or its password has been changed, and therefore you cannot provide the key to decrypt the volume encryption key), you can instead provide your iCloud credentials, which will use the wrapping key stored in escrow to decrypt the volume encryption key. This will get you access to the drive so you can copy data off or restore your local account credentials.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#100FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Correct me if I'm wrong, but isn't forcing you to divulge your encryption password compelled speech? So the police can crack my phone but they can't force me to tell them my PIN.
But this is irrelevant to the argument made above, right?