Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

441–450 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#441

Earlier quoted context omitted.

> Too many tech workers decided to rollover for the government and that's why we are in this mess now. It has nothing to do with the state and has to do with getting the RSUs to pay the down payment for a house in a HCOL area in order to maybe have children before 40 and make the KPIs so you don't get stack-ranked into the bottom 30% and fired at big tech, or grinding 996 to make your investors richest and you rich-i…

To be fair, house prices have a lot to do with the state.

My point was that it is not "[rolling over] for the government".

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#442
post #137

Earlier quoted context omitted.

What part of "We can't have nice things" do you not understand?

The part where you're asking me about the phrase when it's not been used anywhere in this thread prior to your comment.

>This is absurd, because it's basically a generic argument about any sort of feature that vaguely reduces privacy. Sorry guys, we can't have automated backups in windows (even opt in!), because if the feature exists, a random bitflip can cause everything to be uploaded to microsoft against the user's will.

This is a dismissal of an objection to a software system implemented such that it performs in a discrete manner by default(no info leaves until I explicitly tell it to; this would be a nice thing, if you hadn't noticed). You repudiate the challenge on the basis of "we want to implement $system that escrows keys by default; a bad thing, but great for the company and host government in which said thing is widely adopted).

You may not have used the exact words; but the constellation of factors is still there. We can't have nice things (machines that don't narc, do what we tell them, etc.) because there are other forces at work in our society making these things an impossibility.

It is regrettable you do not see the pattern, but then again, that may be for the better for you. I wouldn't wish the experience of seeing things the way I do on anyone else. Definitely not a fun time. But it is certainly there.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#443

Earlier quoted context omitted.

If by "power user" you mean "enemy of the state", there's a lot of software you'd be better-off avoiding.

"enemy of the state" depends a lot on the current state of the state. Eg in England you're already an enemy of the state when you protest against Israel's actions in Gaza. In America if you don't like civilians being executed by ICE. This is really a bad time to throw "enemy of the state" around as if this only applies to the worst people. Current developments are the ideal time to show that these powers can be abuse…

No you aren't,why are you lying. You can protest all you want,the only time people got in trouble was because of the Nazi flags the protestors were using and extreme Islamists trying to recruit terrorists.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#444

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

Obligatory XKCD https://xkcd.com/538

alternatively, being held in contempt for a decade for refusing to give passwords

the only real defense of privacy these days is to literally not write anything down or store it in any way

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#445
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works.

Companies know that putting themselves in a position where they can betray their users, means they will be forced to do so. Famously demonstrated when Apple had to ban the Hong Kong protest app [1]. Yet they continue to do it, don't inform their users, and in the rare occasion that they offer an alternative, it is made unclear and complicated and easy to get wrong [2].

They deserve every ounce of blame.

[1] https://www.bbc.com/news/technology-49919459

[2] https://news.ycombinator.com/item?id=46736345

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#446
post #362
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

Remember when the original dev of TrueCrypt (the VeraCrypt predecessor) suddenly abandoned the project and wrote that people should use BitLocker instead? [1] [2] We now know that BitLocker is not secure, and an intelligent open source dev saying that was probably knowingly not saying the truth. The best explanation to me is that this was said under duress, because somebody wanted people to move away from the good Tr…

alternatively, they knew truecrypt/veracrypt to be irrepairably compromised, and while bitlocker may be backdoored in the same way, it is at least maintained

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#447
post #444

Earlier quoted context omitted.

Obligatory XKCD https://xkcd.com/538

alternatively, being held in contempt for a decade for refusing to give passwords the only real defense of privacy these days is to literally not write anything down or store it in any way

You should also have several large random blobs with incriminating filenames on your hard drive. Attackers won't know which one is encrypted and which one is random. If you like, you can have an encrypted blob of decoy data next to your random blobs and your actually incriminating encrypted blob, and if you're duressed, you reveal that one as the real one.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#448
post #313

Earlier quoted context omitted.

"But I forgot my password! You need to fix this!" The technology exists to trivially encrypt your data if you want to. That's not a product most people want, because the vast majority of people (1) will forget their password and don't want to lose their data, and (2) aren't particularly worried about the feds barging in and taking their laptop during a criminal investigation. That's not what the idealists want, but t…

Apple approaches it different with iCloud. You have a clear option to not hand these keys over. It shows that your idea of how the market works clearly is not representative of the actual market.

You realize the famous case of Apple pushing back against the govt ended because their encryption was breakable by a third party, right?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#449

Earlier quoted context omitted.

> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. You can encrypt secrets end-to-end - just look at how password managers work - and it means the cops can only su…

> Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. Apple does this too. So does Google. This is nothing new. It's a commonly used feature by the average user who loses their password or their last device. During set up, they even explicitly inform the user that their bitlocker ke…

Nah, Apple doesn't do this.

If the user's MacOS FileVault disk encryption key is "stored in iCloud" it resides in the users iCloud Keychain which is end-to-end encrypted. This creates a situation similar to the iPhone, where Apple does not have the ability to access the user's data and therefore cannot comply with a warrant for access (which really annoys organizations like the FBI and Interpol)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#450

Earlier quoted context omitted.

It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?
Post reply on HN