Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

271–280 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#271
post #235

Earlier quoted context omitted.

All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...

This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.

Furthermore it seems like it's specific to Azure AD, and I'm guessing it probably only has effect if you enable to option to back up the keys to AD in the first place, which is not mandatory

I'd be curious to see a conclusive piece of documentation about this, though

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#272
post #235

Earlier quoted context omitted.

All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...

They're Microsoft and it's Windows. They always have the ability to fetch the key. The question is do they ever fetch and transmit it if you opt out? The expected answer would be no. Has anyone shown otherwise? Because hypotheticals that they could are not useful.

Considering all the shenanigans Microsoft has been up to with windows 11 and various privacy, advertising, etc. stuff?

Hell, all the times they keep enabling one drive despite it being really clear I don’t want it, and then uploading stuff to the cloud that I don’t want?

I have zero trust for Microsoft now, and not much better for them in the past either.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#273

Earlier quoted context omitted.

Power users should stop bothering with Windows nonsense and install Linux instead so that they can actually have control over their system. It's 2026. The abuses of corporations are well documented. Anyone who still chooses Windows of their own volition is quite literally asking for it and they deserve everything that happens to them.

I’ll bite. What Linux distro currently has the nicest desktop experience? I work on a MacBook but my desktop is a windows PC that I use for gaming and personal projects. I hear Proton has made the former pretty good now, and the latter is mostly in WSL for me anyway. Maybe a good time to try. What do you suggest? I’ll try it in a VM or live usb.

If you want maximum commodity and as many things to "just work" as possible out of the box, go for good old plain Ubuntu.

If you care a little more about your privacy and is willing to sacrifice some commodity, go for Fedora. It's community run and fairly robust. You may have issues with media codecs, nvidia drivers and few other wrinkles though. The "workstation" flavor is the most mature, but you may want to give the KDE version a try.

If you want an adventure, try everything else people are recommending here :)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#274

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

> logging into MS Teams

I mean, this is one application nobody should ever log into!

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#275
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

20 requests per year also doesn't sound like a privacy problem. These are people where the police got a search warrant for the hard drives.

I'd be more concerned about access to cloud data (emails, photos, files.)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#276

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

That's not the point. Microsoft shouldn't be silently taking your encryption key in the first place. The law doesn't compel them to do that.

It's not silent. It tells you when you set up BitLocker and it also allows you to recover the drive.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#277

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

Unfortunately there's a loud contingent of incredibly proud idiots that post here as well that really like to pretend they know what they're doing.

The people going 'well of course' or 'this is for the user' drive me insane here because as said, there are secure ways you can build a key escrow system so that your data and systems are actually secure. From a secure design standpoint it feels more and more like we're living in Idiocracy as people argue insecure solutions are secure actually and perfectly acceptable.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#278
post #262

Earlier quoted context omitted.

> Even linux could do that if they were compelled to. An open source project absolutely cannot do that without your consent if you build your client from the source. That's my point.

Wait I'm sorry do you build linux from source and review all code changes?

You missed the important part:

> For this threat model

We're talking about a hypothetical scenario where a state actor getting the information encrypted by the E2E encryption puts your life or freedom in danger.

If that's you, yes, you absolutely shouldn't trust US corporations, and you should absolutely be auditing the source code. I seriously doubt that's you though, and it's certainly not me.

The sub-title from the original forbes article (linked in the first paragraph of TFA):

> But companies like Apple and Meta set up their systems so such a privacy violation isn’t possible.

...is completely utterly false. The journalist swallowed the marketing whole.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#279
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

The same is true for Apple laptops! Take a look in your Passwords app and you will see it automatically saves and syncs your laptop decryption key into the cloud.

So all the state needs to get into your laptop is to get access from Apple to your iCloud account.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#280
post #32

Earlier quoted context omitted.

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

I big demographic of HN users are people who want to be the multi-trillion dollar corporation so it’s not too surprising. In this case though I think they are right. And I’m a big time Microsoft hater.

The defenders of Microsoft are right?

How?

There is no point locking your laptop with a passphrase if that passphrase is thrown around.

Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key.

Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you.

The cost of this is that if you lose your key: you also lose the data.

We have trained users about this for a decade, there have been countless dialogues explaining this, even if we were dumber than we were (we're not, despite what we're being told: users just have fatigue from over stimulation due to shitty UX everywhere); then it's still a bad default.

Post reply on HN