Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

351–360 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#351

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

I use macOS most of the time, but switch to a Windows VM for Excel. Without the same keyboard shortcuts, the macOS version ends up having a fraction of the power available to experienced users of the Windows version. For people who use Excel extensively, LibreOffice or Google Sheets would have to offer some remarkable new killer features to make it worth the switch. I don’t think feature parity alone would make the benefits of Linux outweigh the significant transition costs.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#352

Based on the comments in the thread, I sense I will be in the minority, but for most consumers this is a reasonable default. Broadly speaking, the threat model most users are concerned with doesn't account for their government. The previous default is no encryption at rest, which doesn't protect from the most common threats, like theft or tampering. With BitLocker on, a new risk for users is created: loss of access t…

It's certainly a reasonable default. People lose or have their laptops stolen much more often than they get targeted by their governments.

Though that doesn't mean Microsoft couldn't implement a way of storing these keys so that they can't be accessed by Microsoft. Still better than nothing though.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#353
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

And the only reason windows uploads the keys is that Microsoft wants to help the government while fucking you.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#354
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

So long as Microsoft also "give customer set of BitLocker encryption keys to unlock their own laptop" in the right set of conditions.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#355

Earlier quoted context omitted.

Uploading your encryption keys up to someone else's machine is not a sensible default

It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the governmen…

> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data.

What's the equivalent of thinking users are this stupid?

I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff.

I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyou.

Yet for some unknown reason everyone should send their disk encryption keys to one of the largest companies in the world (largely outside of legal jurisdiction), because they themselves can't be trusted.

Bear in mind that with a(ny) TPM chip, you don't need to remember anything.

Come off it mate. You're having a laugh aren't you?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#356

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

The median user's threat model doesn't include the government, but does include data loss, forgetting the password, or a thief stealing your laptop. Microsoft struck the right balance.

I'm glad the knee-jerk absolutists are marginal, for one. A world run by you people would be much worse for anyone who isn't you.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#357

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

Is your last name Segurakreischer? Have them try - leave the Windows computer online and accessible, give your parents a linux box and have them use it exclusively unless they absolutely 100% need to get back on the Windows machine for some reason, and talk with you about it. Set up a NAS with an external HD and a shared folder on both the windows and linux box, so if they actually do need to go back to Windows, they aren't leaving anything stuck on the Linux box.

That's a 100% easy peasy safe mode, the worst they're likely to encounter is a brief 2 minute call with you, and in the worst case scenario, they get to go back to Windows without having to be scared of losing anything.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#358
post #300

Earlier quoted context omitted.

Of course. But I suppose you run Teams on a company provided/managed, or at least paid for by the company, device? Just don’t use that machine for anything private. Is anyone using their private devices for work? (Also there is teams for Linux and on the web, if that is not prevented by the policy of your org.)

In the startup world, BYOD is/was exceedingly common. All but two jobs of my career were happy to allow me to use my own Linux laptop and eschew whatever they were otherwise going to give me. Obviously enterprises aren’t commonly BYOD shops, but SMBs and startups certainly can be. … whether the people who would do such BYOD things are at all likely to be Windows users who care about this Bitlocker issue, is a differe…

Then the founders do something really stupid, and the law decides that your equipment may be evidence.

Unless you're a founder, you should always use company provided equipment.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#359

Earlier quoted context omitted.

> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.

I switched from Windows to Mac 15 years ago. It was a revelation when the terrible habits of verbally abusing my computer and anxiety saving files every 22 seconds just evaporated.

Those old habits have been creeping back lately through all the various *OS 26 updates. I too now have Linux on Framework. Not perfect, but so much better for my wellbeing.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#360
post #221

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

>Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using your local account and make sure not to sign into your Microsoft account or link it to Windows again. 1. Is there any indication it forcibly uploads your r…

[deleted]
Post reply on HN