This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
391–400 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#392What was the point of mandatory TPM then? I thought they were storing the keys securely there!
Keys are stored securely in a TPM in the sense that a random program has no access to it. They are not stored safely there in the sense that they couldn’t possibly get destroyed. TPM hardware, or the motherboard that hosts it, occasionally fails. Or you might want to migrate your physical hard drive to a different PC. That’s the purpose of backing up the keys to the cloud. Alternatively, you can write down a recovery…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#393Earlier quoted context omitted.
If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.
If you design it so you don't have access to the data, how do you make money? Microsoft (and every other corporation) wants your data. They don't want to be a responsible custodian of your data, they want to sell it and use it for advertising and maintaining good relationships with governments around the world.
Microsoft does not sell / use for advertising data from your Bitlocked laptop.
They do use the following for advertising:
Name / contact data Demographic data Subscription data Interactions
This seems like what a conspiracy theorist would imagine a giant evil corporation does.
https://www.microsoft.com/en-us/privacy/usstateprivacynotice
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#394Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#395Earlier quoted context omitted.
>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?
At google "more than 8% of DIMM memory modules were affected by errors per year" [0] More on the topic: Single-event upset[1] [0] https://en.wikipedia.org/wiki/ECC_memory [1] https://en.wikipedia.org/wiki/Single-event_upset
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#396Earlier quoted context omitted.
This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.
> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.
It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account.
I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways.
Please check theupdateframework.io if you have a say in an update system.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#397Similarly, your TPM is protected by keys Intel or AMD can give anyone.
If you want to extrapolate, your Yubikey was supplied by an American company with big contracts to supply government with their products. Since it's closed source and you can't verify what it runs, a similar thing could possibly happen with your smartcard/GPG/pass keys.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#398FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Often it is the case that companies hand over private data to law enforcement just by being asked for it nicely, no warrant needed.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#399Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#400Earlier quoted context omitted.
> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.
It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.