Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

161–170 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#161
post #145

Earlier quoted context omitted.

> Apple's solution is iCloud Keychain which is E2E encrypted, so would not be revealed with a court order. Nope. For this threat model, E2E is a complete joke when both E's are controlled by the third party. Apple could be compelled by the government to insert code in the client to upload your decrypted data to another endpoint they control, and you'd never know.

That was tested in the San Bernardino shooter case. Apple stood up and the FBI backed down.

It's incredibly naive to believe apple will continue to be able to do that.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#162
Based on the comments in the thread, I sense I will be in the minority, but for most consumers this is a reasonable default. Broadly speaking, the threat model most users are concerned with doesn't account for their government. The previous default is no encryption at rest, which doesn't protect from the most common threats, like theft or tampering. With BitLocker on, a new risk for users is created: loss of access to their data because they don't have their recovery key. You are never forced to keep your recovery keys in Microsoft's servers and it's not a default for corporate users.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#163

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

> I take it you've never worked at a company when law enforcement comes knocking for data?

The solution to that is to not have the data in the first place. You can't avoid the warrants for data if you collect it, so the next best thing is to not collect it in the first place.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#164
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Power users should stop bothering with Windows nonsense and install Linux instead so that they can actually have control over their system.

It's 2026. The abuses of corporations are well documented. Anyone who still chooses Windows of their own volition is quite literally asking for it and they deserve everything that happens to them.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#165

Earlier quoted context omitted.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

The government would never prosecute a company for fraud where that fraud consists of cooperating with the government after promising to a suspected criminal that they wouldn't.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#166

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

What are you talking about?

> I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

FTA (3rd paragraph): don't default upload the keys to MSFT.

>If you design it so you don't have access to the data, what can they do?

You don't have access to your own data? If not, they can compel you to reveal testimony on who/what is the next step to accessing the data, and they chase that.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#167

Earlier quoted context omitted.

> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. The fully security conscious option is to not link a Microsoft account at all. I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.

And how do you know the keys are never uploaded if you don't have an account?

The same way you know that your browser session secrets, bank account information, crypto private keys, and other sensitive information is never uploaded. That is to say, you don't, really - you have to partially trust Microsoft and partially rely on folks that do black-box testing, network analysis, decompilation, and other investigative techniques on closed-source software.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#168
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> you have no choice but to give it to them

Will they shoot me in head?

What if I truly forgot the password to my encrypted drive? Will they also shoot me in the head?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#169
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Power users should stop bothering with Windows nonsense and install Linux instead so that they can actually have control over their system. It's 2026. The abuses of corporations are well documented. Anyone who still chooses Windows of their own volition is quite literally asking for it and they deserve everything that happens to them.

I’ll bite. What Linux distro currently has the nicest desktop experience? I work on a MacBook but my desktop is a windows PC that I use for gaming and personal projects. I hear Proton has made the former pretty good now, and the latter is mostly in WSL for me anyway. Maybe a good time to try.

What do you suggest? I’ll try it in a VM or live usb.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#170

Earlier quoted context omitted.

If by "power user" you mean "enemy of the state", there's a lot of software you'd be better-off avoiding.

"enemy of the state" depends a lot on the current state of the state. Eg in England you're already an enemy of the state when you protest against Israel's actions in Gaza. In America if you don't like civilians being executed by ICE. This is really a bad time to throw "enemy of the state" around as if this only applies to the worst people. Current developments are the ideal time to show that these powers can be abuse…

[deleted]
Post reply on HN