Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

331–340 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#331

Earlier quoted context omitted.

If your security requirements are such that you need to worry about legally-issued search warrants, you should not connect your computer to the internet. Especially if it's running Windows.

Because all cops are honest, all warrants are lawful and nothing worrying happens in the land of freedom right now.

And what's more, that perfect situation could never change in the future.

Me-30-years-ago would have called today's government crimes and corruption an implausible fever dream.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#332

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

It's a good start, but FDE alone is still fairly easy to compromise in many cases. If you ever type the password under a camera, it may be leaked. If the device ever leaves your possession and you don't have secure boot, your bootloader can be trivially altered to leak the password. Then there are keyloggers. And cold boot attacks can often be done if your system is running.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#333

What was the point of mandatory TPM then? I thought they were storing the keys securely there!

Keys are stored securely in a TPM in the sense that a random program has no access to it. They are not stored safely there in the sense that they couldn’t possibly get destroyed. TPM hardware, or the motherboard that hosts it, occasionally fails. Or you might want to migrate your physical hard drive to a different PC. That’s the purpose of backing up the keys to the cloud. Alternatively, you can write down a recovery key and put it in your safe. Personally, I put it in my password vault that also happens to be backed up to the cloud (though not Microsoft’s).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#334

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

The resistance is to switch to Linux.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#335
post #315

Earlier quoted context omitted.

Good PINs are ones you're not allowed to brute force. You can easily configure an iPhone to wipe itself after too many wrong guesses. There's a single checkbox labeled "Erase Data", saying "Erase all data on this iPhone after 10 failed passcode attempts." You bet I have that enabled.

My toddler would wipe my phone with that on

We each have our own threat models. Toddlers are high on that list, to be sure.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#336

Earlier quoted context omitted.

> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. The fully security conscious option is to not link a Microsoft account at all. I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.

> it was really easy to set up without a Microsoft account. By "really easy" do you mean you had a checkbox? Or "really easy" in that there's a secret sequence of key presses at one point during setup? Or was it the domain join method? Googling around, I'm not sure any of the methods could be described as "really easy" since it takes a lot of knowledge to do it.

I recently had to install Windows for the first time in ages because reasons, and it really wasn’t very hard. The setup really just presents two options at a time: the cloudy option, and the other option. If in doubt, the flashy one is the cloudy one. I kept selecting the non cloudy option and got to the desktop without signing up for anything. Sure it took more clicking than last time I went through this, but really wasn’t nearly as bad as people say and didn’t take any windows know-how or googling. Might be very different between editions and regions though…

Edit: ofc we all agree local accounts needs to be a supported option, but perhaps we should be more careful about yelling from the rooftops that it’s practically impossible. I’ve been told for years now that it’s really hard or impossible, and it really was not that hard (yet…)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#337

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Too many tech workers decided to rollover for the government and that's why we are in this mess now.

It isn't really about the government. It's about a bunch of people trying to convince you that the locked-down proprietary closed source corporate crap that they use isn't in and of itself a security risk, no matter what the quality of the code that you've never seen is. Apple, Microsoft, Google etc. aren't your friends; no matter how brand loyal you are, they'll never care whether you're alive or dead.

FOSS isn't your friend either, but they're not asking you to trust them. Any exposure to these world spanning juggernaut military and intelligence contractor companies is a security hole. It's insane that people (thinking of Europeans now) get fired up to switch from this stuff because Trump but not because of course you should. Instead they're busy calling being suspicious of Microsoft old and hatred of Apple's customer corral stuck up and the desire to own your own machine fanatical and judgemental. Have you ever considered that you've been programmed to say and encourage dumb stuff that is completely against your own interests and supports the interests of the people who sell things to you?

You're convinced by the argument that people dumber than you have to be protected from their own machines (by corporations who have no interest in or obligation to protect them) - have you ever thought that people are saying the same thing about you? That you have to be protected from writing things you shouldn't write or talking to people you shouldn't be talking to? And the world isn't a meritocracy: the people on the top are inbred creeps. You've given up your freedom to dummies with marketing departments.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#338
post #6

Earlier quoted context omitted.

It's not like companies have a choice. If they have a key in their possession and law enforcement gets an order for it, they have to provide it.

And even if they don't have the key. Case in point: https://medium.com/@tahirbalarabe2/the-encryption-dilemma-wh...

Thanks for the link, interesting article. The UK is among the worst in this regard.

Regarding the article's Apple example:

> The FBI eventually found a third party to break into the phone, but the tension between privacy and security remains unresolved.

This is actually quite resolved.

- Tech companies in the US are free to write secure encryption technologies without backdoors.

- Government is free to try to break it when they have valid legal authority.

- Tech companies are obligated to turn over information in their possession when given a legal warrant signed by a judge based on probable cause that a crime has occurred.

- Tech companies are not required to help hack into systems on the government's behalf.

As far as I'm concerned, in the US things are perfectly resolved, and quite well I think. It's the government and fear-mongers who constantly try to "unresolve" things.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#339
I'm certain I should encrypt my data, backup all LUKS headers, and backup all data.

But what about unsophisticated users? In aggregate it might be true data exfiltration is worse than data loss? I don't know if that's true.

But what is true is enabling encryption by default without automated backup and escrow will lead to some data loss.

It's difficult for me to separate the aggregate scenarios from individual scenarios. The individual penalty of data loss can be severe. Permanent.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#340

Earlier quoted context omitted.

It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the governmen…

For laptops sure, but then those are not reasons for it to be default on desktops too. Are most Windows users on laptops? I highly doubt that. So it is not a sensible default.

Most pc users are using laptops, yes. Above 60%.

Even offices usually give people laptops over desktops so that they can bring it to meetings.

Post reply on HN