Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

381–390 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#381
post #279
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

The same is true for Apple laptops! Take a look in your Passwords app and you will see it automatically saves and syncs your laptop decryption key into the cloud. So all the state needs to get into your laptop is to get access from Apple to your iCloud account.

The iCloud Keychain is end-to-end encrypted.[0] Apple can't decrypt it.

That said, when setting up FileVault, you have the option to escrow your recovery key with Apple. If you enable that, Apple can get the recovery key.

[0] https://support.apple.com/en-us/102651

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#382
post #61
post #32

Earlier quoted context omitted.

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Are you referring to Microsoft Recall? My understanding is that is opt-in and only stored locally.

1) for now

2) according to Microsoft

So, trust is not zero. It's deeply negative.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#383
post #308

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

You can turn it off without resorting to a local account, although it's non-obvious. GPEdit -> Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Operating System Drives → “Choose how BitLocker-protected operating system drives can be recovered” Repeat for other drives.

I imagine you have to re-encrypt the drive after that, though, for it to have some real effect

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#384
post #140

Earlier quoted context omitted.

The "reasonable default" is to force the user to actually make the choice, probably after forcing the user to prove they understand the implications.

I don't think there's a good answer here. Users absolutely 100% will lose their password and recovery key and not understand that even if the bytes are on a desk physically next to you, they are gone. Gone baby gone. In university, I helped a friend set up encryption on a drive w/ his work after a pen drive with work on it was stolen. He insisted he would not lose the password. We went through the discussion of "this…

Then you don't want encrypt by default and anyone who goes out of their way knows what they're doing

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#385

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

The median user's threat model doesn't include the government, but does include data loss, forgetting the password, or a thief stealing your laptop. Microsoft struck the right balance. I'm glad the knee-jerk absolutists are marginal, for one. A world run by you people would be much worse for anyone who isn't you.

A world one by "those" people would lead to a less abusive and exploitive world, our current world is one based on suffering if you aren't extremely wealthy. I think I know which world I would rather join.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#386

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Too many tech workers decided to rollover for the government and that's why we are in this mess now. It has nothing to do with the state and has to do with getting the RSUs to pay the down payment for a house in a HCOL area in order to maybe have children before 40 and make the KPIs so you don't get stack-ranked into the bottom 30% and fired at big tech, or grinding 996 to make your investors richest and you rich-i…

To be fair, house prices have a lot to do with the state.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#387
post #313

Earlier quoted context omitted.

> I take it you've never worked at a company when law enforcement comes knocking for data? The solution to that is to not have the data in the first place. You can't avoid the warrants for data if you collect it, so the next best thing is to not collect it in the first place.

"But I forgot my password! You need to fix this!" The technology exists to trivially encrypt your data if you want to. That's not a product most people want, because the vast majority of people (1) will forget their password and don't want to lose their data, and (2) aren't particularly worried about the feds barging in and taking their laptop during a criminal investigation. That's not what the idealists want, but t…

Apple approaches it different with iCloud. You have a clear option to not hand these keys over.

It shows that your idea of how the market works clearly is not representative of the actual market.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#388

> The case involved several people suspected of fraud related to the Pandemic Unemployment Assistance program If it were preventing a mass murder I might feel differently... But this is protecting the money supply (and indirectly the governments control). Not a reason to violate privacy IMO, especially when at the time this was done these people were only suspected of fraud, not convicted.

They had a warrant. That's enough. Nobody at Microsoft is going to be willing to go to jail for contempt to protect fraudsters grifting off of the public taxpayer. Would you?

Yes. Businesses have a moral responsibility to honor their agreements with their stakeholders above the government.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#389

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Too many tech workers decided to rollover for the government s/workers/Corporations/

A Corporation can't do anything without a worker's consent.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#390
post #140

Earlier quoted context omitted.

The "reasonable default" is to force the user to actually make the choice, probably after forcing the user to prove they understand the implications.

I don't think there's a good answer here. Users absolutely 100% will lose their password and recovery key and not understand that even if the bytes are on a desk physically next to you, they are gone. Gone baby gone. In university, I helped a friend set up encryption on a drive w/ his work after a pen drive with work on it was stolen. He insisted he would not lose the password. We went through the discussion of "this…

Some people will hurt themselves if given dangerous tools, but if you take all the dangerous items out of the tool shop, there won't be any tools left.

Microsoft seems to feel constant pressure to dumb Windows down, but if you look at the reasons people state when switching to Linux, control is a frequent theme. People want the dangerous power tools.

Post reply on HN