Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

101–110 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#101
post #21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

There's a lot of sibling comments to mine here that are reading this literally, but instead, I would suggest the following reading: "I never selected that option!" "Huh, must have been a cosmic ray that uploaded your keys ;) Modern OS updates never obliterate user-chosen configurations"

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#102

Earlier quoted context omitted.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Absent the source code, it's incredibly difficult to disprove when the only proof you have is good vibes.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#103
post #21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

This is correct, I also discovered while preparing several ThinkPads for a customer based on a Windows 11 image i made, that even if you have bitlocker disabled you may also need to check that hardware disk encryption is disabled as well (was enabled by default in my case). Although this is different from bitlocker in that the encryption key is stored in the TPM, it is something to be aware of as it may be unexpected.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#105
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

I think this is a fair position and believe you're making it in good faith, but I can't help but disagree.

I think the reasonable default here would be to not upload to MS severs without explicit consent about what that means in practise. I suspect if you actually asked the average person if they're okay with MS having access to all of the data on their device (including browser history, emails, photos) they'd probably say no if they could.

Maybe I'm wrong though... I admit I have a bad theory of mind when it comes to this stuff because I struggle to understand why people don't value privacy more.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#106

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#107

Earlier quoted context omitted.

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Absent the source code, it's incredibly difficult to disprove when the only proof you have is good vibes.

There are many things you can't prove or disprove in this world. That's where trust and reputation comes in - to fill the uncertainty gap.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#109
post #6

Earlier quoted context omitted.

It's not like companies have a choice. If they have a key in their possession and law enforcement gets an order for it, they have to provide it.

That only strengthens the parent point. Switch to an OS where this requirement doesn't come into play if you're worried about any governments having a backdoor into your own machine.

> Switch to an OS where this requirement doesn't come into play

I use BitLocker on my Windows box without uploading the keys. I don't even have it connected to a Microsoft account. This isn't a requirement.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#110
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them.

They can fight the warrant, if you don't at least object to it then "giving the keys away" is not an incorrect characterization.

Post reply on HN