Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

261–270 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#261

Earlier quoted context omitted.

There are many things you can't prove or disprove in this world. That's where trust and reputation comes in - to fill the uncertainty gap.

You mean, trust and reputation of Apple? They're not exactly high: https://news.ycombinator.com/item?id=46252114 https://news.ycombinator.com/item?id=45520407 https://news.ycombinator.com/item?id=42014588 https://news.ycombinator.com/item?id=26644216

At the end of the day, it's all about how you weigh the evidence. If those examples are sufficient to tip the scales for you, that's your choice. However, Apple's overall trustworthiness--particular when it comes to protecting people's sensitive data--remains high for in the market. Even the examples you posted aren't especially pertinent to that (except for iCloud Keychain, where the complaint isn't whether Apple is securely storing it, but the fact that it got transmitted to them in the first place, and there exists some unresolved ambiguity about whether it is appropriately deleted on demand).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#262
post #219

Earlier quoted context omitted.

Yeah and Microsoft could insert code to upload the bitlocker keys. What's your point? Even linux could do that if they were compelled to.

> Even linux could do that if they were compelled to. An open source project absolutely cannot do that without your consent if you build your client from the source. That's my point.

Wait I'm sorry do you build linux from source and review all code changes?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#263

I have opted out of all cloud services in my windows installation; I use a passphrase, too (it is even before booting the computer). I feel like this is pretty safe

except MS could easily turn something on without you knowing and be uploading your files to their cloud. Yes, I believe they would stoop that low and even lower.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#264
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Also, this essay by Mickens at USENIX over a decade ago - https://www.usenix.org/system/files/1401_08-12_mickens.pdf

Tl;dr - "Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT" (Mickens, 2014)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#265

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

That's not the point. Microsoft shouldn't be silently taking your encryption key in the first place. The law doesn't compel them to do that.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#266
post #159

Earlier quoted context omitted.

If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

If you design it so you don't have access to the data, how do you make money? Microsoft (and every other corporation) wants your data. They don't want to be a responsible custodian of your data, they want to sell it and use it for advertising and maintaining good relationships with governments around the world.

> If you design it so you don't have access to the data, how do you make money?

The same way companies used to make money, before they started bulk harvesting of data and forcing ads into products that we're _already_ _paying_ _for_?

I wish people would have integrity instead of squeezing out every little bit of profit from us they can.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#267
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Hacker News defending corporate key escrow. Wow.

> It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive.

It allows /anyone/ to recover their data later. You don't have to be a "purist" to hate this.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#268

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

I wish there was more people like you and me. Privacy is not a crime.

I wish people didn't have to be like us to have privacy.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#269
I consider myself pretty pro-privacy, but there is so much dragnet surveillance and legitimate breaches of the fourth amendment that I have a hard time getting up in arms over a company complying with a valid search warrant that is scoped to three hard drives (and which required law enforcement to have physical possession of the drives to begin with).

This is so much more reasonable than (for example) all the EU chat control efforts that would let law enforcement ctrl+f on any so-called private message in the EU.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#270

Earlier quoted context omitted.

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

> actively hostile

That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

Post reply on HN