Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

321–330 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#321
post #300

Earlier quoted context omitted.

That's nice. I, however, like getting my paycheck, and so I have no choice.

Of course. But I suppose you run Teams on a company provided/managed, or at least paid for by the company, device? Just don’t use that machine for anything private. Is anyone using their private devices for work? (Also there is teams for Linux and on the web, if that is not prevented by the policy of your org.)

In the startup world, BYOD is/was exceedingly common. All but two jobs of my career were happy to allow me to use my own Linux laptop and eschew whatever they were otherwise going to give me.

Obviously enterprises aren’t commonly BYOD shops, but SMBs and startups certainly can be.

… whether the people who would do such BYOD things are at all likely to be Windows users who care about this Bitlocker issue, is a different debate entirely.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#322

Earlier quoted context omitted.

I can't believe it took this long. We have mandatory identification for all kinds of things that are illegal to purchase or engage in under a certain age. Nobody wants to prosecute 12 year old kids for lying when the clicked the "I am at least 13 years old" checkbox when registering an account. The only alternative is to do what we do with R-rated movies, alcohol, tobacco, firearms, risky physical activities (i.e. bu…

The problem is the implementation is hasty. When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. We can't trust every private company that now has to verify age to not store that information with whatever questionable security. If we aren't going to…

Depending on the gas station... I've been to at least a dozen in Texas where the clerk scanned the back of my DL for proof of age. I'm assuming that something is getting stored somewhere..

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#323

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

I used to be a principled freedom fighter. But others defected(thinking mostly about Apple users...). I promoted open source software, even dealing with the pains.

So now I just use whatever I want. Someone else can be a tech moralist.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#324
> The hackers would still need physical access to the hard drives to use the stolen recovery keys.

Or remote access to the computer. Or access to an encrypted backup drive. Or remote access to a cloud backup of the drive. So no, physical access to the original hard drive is not necessarily a requirement to use the stolen recovery keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#325

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

Just remember, never use or recommend Debian-family(Ubuntu/Mint) or you will be back to windows. Do not fall for the marketing term Stable, which means outdated and contains bugs that are fixed.

Fedora is my recommendation. I remind people Fedora is not Arch. Fedora is a consumer grade OS that is so good, I don't lump it in with the word Linux.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#326

This is almost certainly users who elect to store their BitLocker keys in OneDrive. Don't think Apple wouldn't do the same. If you don't want other people to have access to your keys, don't give your keys to other people.

I was going to say: "Well Apple historically is an easy target of Pegasus" but that can only be used a few times before Apple figures out the exploit and fixes it. Its more expensive than just asking the Apple.

But given PRISM, I'm sure Apple will just give it up.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#327
post #72

Earlier quoted context omitted.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

You should watch the whole BlackHat talk (from 2016!) from Apple's Head of Security Engineering and Architecture, but especially this part: https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s

Lot of trust in the words that cannot be verified.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#328

Earlier quoted context omitted.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Apple has the number 1 marketing team in the world. They got away with PRISM and terrible security.

They are immune to reputation damage. Teens and moms don't care.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#329

Earlier quoted context omitted.

> logging into MS Teams I mean, this is one application nobody should ever log into!

That's nice. I, however, like getting my paycheck, and so I have no choice.

teams works fine in website form for me because it IS a website (that uses an extra ~1gb of ram running as a desktop app because its also a separate browser)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#330
post #306

Earlier quoted context omitted.

You mean, trust and reputation of Apple? They're not exactly high: https://news.ycombinator.com/item?id=46252114 https://news.ycombinator.com/item?id=45520407 https://news.ycombinator.com/item?id=42014588 https://news.ycombinator.com/item?id=26644216

None of these really match the scenario we're discussing here. Some are typical big company stuff, some are technical edge cases, but none are "Apple lies about a fundamental security practice consistently and with malice"

Cognitive Dissonance. You already made up your mind, no evidence will change it. Any evidence you get is cast aside for one reason or another.
Post reply on HN