Earlier quoted context omitted.
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. At this point, the only thing that can restore trust in Microsoft is open sourcing Windows.
> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. The fully security conscious option is to not link a Microsoft account at all. I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
111–120 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#112https://cointelegraph.com/news/fbi-cant-be-blamed-for-wiping...
Perhaps next time, an agent will copy the data, wipe the drive, and say they couldn't decrypt it. 10 years ago agents were charged for diverting a suspect's Bitcoin, I feel like the current leadership will demand a cut.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#113FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#114Earlier quoted context omitted.
You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)
Sorry to interrupt the daily rage session with some neutral facts about how Windows and the law work. > that just so happens to take a screenshot of your screen every few seconds Recall is off by default. You have to go turn it on if you want it.
Microsoft also happens to own LinkedIn which conveniently "forgets" all of my privacy settings every time I decide to review them (about once a year) and discover that they had been toggled back to the privacy-invasive value without my knowledge. This has happened several times over the years.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#115FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#116It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
When you get high up in an org, choosing Microsoft is the equivalent of the old "nobody ever got fired for buying IBM". You are off-loading responsibility. If you ever get high up at a fortune 500 company, good luck trying to get off of behemoths like Microsoft.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#117It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
It’s not about engineers being lazy, it’s about money. Trying to resist building ethically questionable software usually means quitting or being fired from a job.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#118It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
False. You can design truly end-to-end encrypted secure system and then the state comes at you and says that this is not allowed, period. [1]
[1] https://medium.com/@tahirbalarabe2/the-encryption-dilemma-wh...
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#119Earlier quoted context omitted.
>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?
Given enough computers, anything will happen. Apparently enough bit flips happen in domains (or their DNS resolution) that registering domains one bit away from the most popular ones (e.g. something like gnogle.com for google.com) might be worth it for bad actors. There was a story a few years ago, but I can't find it right now; perhaps someone will link it.
Can't find an explanatory video though :(
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#120> Microsoft told Forbes that the company sometimes provides BitLocker recovery keys to authorities, having received an average of 20 such requests per year. At least they are honest about it, but a good reason to switch over to linux. Particularly if you travel. If microsoft is giving these keys out to the US government, they are almost certainly giving them to all other governments that request them.
It's not like companies have a choice. If they have a key in their possession and law enforcement gets an order for it, they have to provide it.