Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

251–260 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#251

Earlier quoted context omitted.

Absent the source code, it's incredibly difficult to disprove when the only proof you have is good vibes.

There are many things you can't prove or disprove in this world. That's where trust and reputation comes in - to fill the uncertainty gap.

You mean, trust and reputation of Apple? They're not exactly high:

https://news.ycombinator.com/item?id=46252114

https://news.ycombinator.com/item?id=45520407

https://news.ycombinator.com/item?id=42014588

https://news.ycombinator.com/item?id=26644216

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#252
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

So you're saying Microsoft gave the FBI the key?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#253

Earlier quoted context omitted.

That only strengthens the parent point. Switch to an OS where this requirement doesn't come into play if you're worried about any governments having a backdoor into your own machine.

> Switch to an OS where this requirement doesn't come into play I use BitLocker on my Windows box without uploading the keys. I don't even have it connected to a Microsoft account. This isn't a requirement.

except Microsoft probably as a master key

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#254
post #4

> Microsoft told Forbes that the company sometimes provides BitLocker recovery keys to authorities, having received an average of 20 such requests per year. At least they are honest about it, but a good reason to switch over to linux. Particularly if you travel. If microsoft is giving these keys out to the US government, they are almost certainly giving them to all other governments that request them.

Why take the drastic step of switching to linux (a difficult endeavor) when you can simply turn off key uploading.

oh man, it's so difficult even teenagers can do it within an hour and all they have to do is click on a few buttons.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#255
post #71

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

You shouldn't include Apple in this. As of macOS Tahoe, the FileVault key you (optionally) escrow with Apple is stored in the iCloud Keychain, which is cryptographically secured by HSM-backed, rate-limited protections. You can (and should) watch https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for all the details about how iCloud is protected.

You can (and should) read Mr. Fart's Favorite Colors as a response, explaining how "perfect" security becomes the enemy of principled security: https://medium.com/@blakeross/mr-fart-s-favorite-colors-3177...

  Unbreakable phones are coming. We’ll have to decide who controls the cockpit: The captain? Or the cabin?
The security in iOS is not to designed make you safer, in the same way that cockpit security doesn't protect economy class from rogue pilots or business-class terrorists. Apple made this decision years ago, they're right there in Slide 5 of the Snowden PRISM disclosure. Today, Tim stands tall next to POTUS. Any preconceived principle that Apple might have once clung to is forfeit next to their financial reliance on American protectionism: https://www.cnbc.com/2025/09/05/trump-threatens-trade-probe-...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#257
post #182

If you use a local windows account does it still upload your bitlocker key to M$?

No, and by default the keys are stored on the disk so it's not actually secure. If you open the BitLocker control panel applet your drive(s) will be labelled as "Bitlocker waiting for activation".

Oh? Do tell how to retrieve those insecure keys. I have an old laptop I would love to get access to again.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#258
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

MacOS has this feature as well. It used to be called "Allow my iCloud account to unlock my disk," but it keeps getting renamed and moved around in new MacOS versions. I think it's now tied together with remote password resets into one option called "allow user to reset password using Apple Account."

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#259
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

The problem is they don't make this clear to the user or make it easy to opt out. Contrast with how Apple does it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#260
post #235

Earlier quoted context omitted.

All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...

This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.

> MS doesn't have a magic way to reach into your laptop and pluck the keys.

Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.

Post reply on HN