Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

421–430 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#421
post #403

Earlier quoted context omitted.

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…

Eh, not for laptops - I say as someone who switched to Linux from windows in past year.

I have spent a decent few days to get long battery life on Linux (fedora), with sleep hibernate + encryption. And I am still thinking that the Linux scheduler is not correctly using Intel's pcore/ecore on 13th gen correctly.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#422

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

Obligatory XKCD https://xkcd.com/538

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#423

Earlier quoted context omitted.

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Apple has the number 1 marketing team in the world. They got away with PRISM and terrible security. They are immune to reputation damage. Teens and moms don't care.

Terrible security... compared to what? Some ideal state that exists in your head, or a real-world benchmark? Do you expect them to ignore lawful orders from governments as well?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#424
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

This is a great reminder: if your device doesn't ask you for a pin/passphrase every time it turns on, it's not actually encrypted.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#425

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

> I take it you've never worked at a company when law enforcement comes knocking for data? The solution to that is to not have the data in the first place. You can't avoid the warrants for data if you collect it, so the next best thing is to not collect it in the first place.

Yes, just hand over the encrypted data that you have no way of retrieving the keys for. "Have fun, officer."

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#426
post #198

Earlier quoted context omitted.

Correct me if I'm wrong, but isn't forcing you to divulge your encryption password compelled speech? So the police can crack my phone but they can't force me to tell them my PIN.

In the UK they can jail you just for not providing an encryption key

yeah but it's the UK ...prison is a joke there

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#427

Earlier quoted context omitted.

> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. You can encrypt secrets end-to-end - just look at how password managers work - and it means the cops can only su…

Where did you get that they are stored in plaintext?

It doesn't matter how it's stored. So long as it isn't E2EE, they (and anyone who can ask for it) will be able to access the drives

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#428
post #4

> Microsoft told Forbes that the company sometimes provides BitLocker recovery keys to authorities, having received an average of 20 such requests per year. At least they are honest about it, but a good reason to switch over to linux. Particularly if you travel. If microsoft is giving these keys out to the US government, they are almost certainly giving them to all other governments that request them.

Why take the drastic step of switching to linux (a difficult endeavor) when you can simply turn off key uploading.

Microsoft is known for regularly altering the deal. Just because you configure the OS to not upload keys today, does not mean that setting will be respected in the future.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#429
post #407

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

> What happens if I forget my keys? … restore contents from backups. What happens if you forget your backup keys?

Redownload everything from OneDrive and Outlook.com.. shit!! ;D

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#430
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works. If your company has data that the police want and they can get a warrant, you have no choice but to give it to them.

I’m not sure how you’re criticizing the “gave” framing when you’re describing and stating Microsoft literally giving the keys to the FBI.

Post reply on HN