Earlier quoted context omitted.
Ok, do you at least know what private means?
Not public.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
431–440 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#432Earlier quoted context omitted.
Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.
> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#433Earlier quoted context omitted.
No, and by default the keys are stored on the disk so it's not actually secure. If you open the BitLocker control panel applet your drive(s) will be labelled as "Bitlocker waiting for activation".
Oh? Do tell how to retrieve those insecure keys. I have an old laptop I would love to get access to again.
Microsoft themselves [1] say:
> If a device uses only local accounts, then it remains unprotected even though the data is encrypted.
There is a further condition: if you explicitly enable bitlocker then the key is no longer stored on the disk and it is secure.
When I run "manage-bde -status" on my laptop it says "Key Protectors: None found". If the TPM was being used that would be listed.
Have you tried plugging the disk or ssd from your old laptop into another computer?
[1]: https://learn.microsoft.com/en-us/windows/security/operating...
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#434FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works. If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. I’m not sure how you’re criticizing the “gave” framing when you’re describing and stating Microsoft literally giving the keys to the F…
Better, and more accurate wording, would be that "Microsoft surrendered keys" or "Microsoft ceded keys". Or "Microsoft legally compelled to give the keys". If Microsoft did so without a warrant, then "gave" would be more tonally accurate.
In addition, none of this is new. They've been turning over keys when legally compelled to, for many years.
Fun fact: Apple does this too. https://support.apple.com/en-us/108756
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#435Earlier quoted context omitted.
Sorry to interrupt the daily rage session with some neutral facts about how Windows and the law work. > that just so happens to take a screenshot of your screen every few seconds Recall is off by default. You have to go turn it on if you want it.
It only became off by default after those "daily rage sessions" created sufficient public pressure to turn them off. Microsoft also happens to own LinkedIn which conveniently "forgets" all of my privacy settings every time I decide to review them (about once a year) and discover that they had been toggled back to the privacy-invasive value without my knowledge. This has happened several times over the years.
99% of the daily rage sessions happened before it was even released
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#436FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. You can encrypt secrets end-to-end - just look at how password managers work - and it means the cops can only su…
Apple does this too. So does Google. This is nothing new.
It's a commonly used feature by the average user who loses their password or their last device.
During set up, they even explicitly inform the user that their bitlocker keys are being backed up to the cloud. And, you can still choose to use bitlocker without key escrow.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#437FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. They can fight the warrant, if you don't at least object to it then "giving the keys away" is not an incorrect characterization.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#438Earlier quoted context omitted.
Okay, so yes I grant your point that people where governments are the threat model should be auditing source code. I also grant that many things are possible (where the journalist says "isn't possible"). However, what remains true is that Microsoft appears to store this data in a manner that can be retrieved through "simple" warrants and legal processes, compared to Apple where these encryption keys are stored in a m…
> retrieved through "simple" warrants and legal processes The fact it requires an additional engineering step is not an impediment. The courts could not care less about the implementation details. > compared to Apple where these encryption keys are stored in a manner that would require code changes to accomplish. That code already exists at apple: the automated CSAM reporting apple does subverts their icloud E2E encr…
That's not really true in practice by all public evidence
> the automated CSAM reporting apple does
Apple does not have a CSAM reporting feature that scans photo libraries, it never rolled out. They only have a feature that can blur sexual content in Messages and warn the reader before viewing.
We can argue all day about this, but yeah - I guess it's true that your phone is closed source so literally everything you do is "under the complete and sole control of Apple."
That just sends you back to the first point and we can never win an argument if we disagree about the level the government might compel a company to produce data.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#439It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#440Hello there! Have you heard of our lord and savior, Linux?
> Yes, but Which version/fork? If I earn my living from a company that doesn't make Linux versions, should i still switch? Should my customers? It's a great idea, and my work does not touch the internet, but the confusing variations of linux do not a happy workfoce make. Your 'lord and saviour' can fuck off, with all the others, I prefer science.
Then test Omarchy.