Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

391–400 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#391
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

Sadly VeraCrypt is not optimized for SSDs and has a massive performance impact compared to Bitlocker for full disk encryption because the SSD doesn't know what space is used/free with VeraCrypt.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#392
post #333

What was the point of mandatory TPM then? I thought they were storing the keys securely there!

Keys are stored securely in a TPM in the sense that a random program has no access to it. They are not stored safely there in the sense that they couldn’t possibly get destroyed. TPM hardware, or the motherboard that hosts it, occasionally fails. Or you might want to migrate your physical hard drive to a different PC. That’s the purpose of backing up the keys to the cloud. Alternatively, you can write down a recovery…

There's also no security in the communication between the CPU and the TPM, so you can plug in a chip that intercepts it and copies all the keys, or plug the TPM into a chip that pretends to be the CPU and derives identical keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#393
post #159

Earlier quoted context omitted.

If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

If you design it so you don't have access to the data, how do you make money? Microsoft (and every other corporation) wants your data. They don't want to be a responsible custodian of your data, they want to sell it and use it for advertising and maintaining good relationships with governments around the world.

I think you’re conflating lots of different types of data into one giant “data.”

Microsoft does not sell / use for advertising data from your Bitlocked laptop.

They do use the following for advertising:

Name / contact data Demographic data Subscription data Interactions

This seems like what a conspiracy theorist would imagine a giant evil corporation does.

https://www.microsoft.com/en-us/privacy/usstateprivacynotice

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#394

This is why local account setup is so important on windows, and why microsoft makes it harder and harder each update.

or not use microsoft products for encryption

or not use microsoft products

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#395
post #97

Earlier quoted context omitted.

>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?

At google "more than 8% of DIMM memory modules were affected by errors per year" [0] More on the topic: Single-event upset[1] [0] https://en.wikipedia.org/wiki/ECC_memory [1] https://en.wikipedia.org/wiki/Single-event_upset

At the time Google was taking RAM that had failed manufacturer QA that they had gotten for cheap and sticking it on DIMMs themselves and trying to self certify them.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#396

Earlier quoted context omitted.

This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.

> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.

People really pay too little attention to this attack avenue.

It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account.

I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways.

Please check theupdateframework.io if you have a say in an update system.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#397
Your firmware and UEFI likely accept MS keys even if you supplied your own for Secure Boot. Sometimes the keys are unable to be removed, or they'll appear "removed" but still present because losing the keys could break firmware updates/option ROMs/etc.

Similarly, your TPM is protected by keys Intel or AMD can give anyone.

If you want to extrapolate, your Yubikey was supplied by an American company with big contracts to supply government with their products. Since it's closed source and you can't verify what it runs, a similar thing could possibly happen with your smartcard/GPG/pass keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#398
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works. If your company has data that the police want and they can get a warrant, you have no choice but to give it to them.

Often it is the case that companies hand over private data to law enforcement just by being asked for it nicely, no warrant needed.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#400

Earlier quoted context omitted.

> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.

Buy a laptop with less problems on Linux if that's your intention.
Post reply on HN