Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

511–520 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#511

I think most people don't understand that 99% of people don't know what data encryption is and definitely don't care about it. If it weren't for Bitlocker, their laptops wouldn't be encrypted at all! And of course if your software (Windows) encrypts by default but you don't want to bother the average user with the details (because they don't know anything about this or care about it) you will need to store the key in…

> If it weren't for Bitlocker, their laptops wouldn't be encrypted at all!

And because of Bitlocker, their encryption is worth nothing in the end.

> if these people were using Linux, their laptops wouldn't be encrypted

Maybe, maybe not. Ubuntu and Fedora both have FDE options in the installer. That's objectively more honest and secure than forcing a flawed default in my opinion.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#512
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Microsoft did give them. Just because they have a warrant doesn't mean keys should be handed over in any usable form. As indicated in the Forbes [0] article - both Meta and Apple have the exact same convenience in place (cloud backup) with none of the direct risk.

So, yes. That is how it works: 1) Microsoft forces users to online accounts 2) Bitlocker keys are stored in an insecure manner allowing any US agency to ask for them. I intentionally say "ask for them" because the US government is a joke with respect to respecting its own citizens privacy [1] at this point.

This type of apologetic half-truth on behalf of a multi-billion dollar corporation is getting old fast.

[0] https://www.forbes.com/sites/thomasbrewster/2026/01/22/micro... [1] https://www.npr.org/2026/01/23/nx-s1-5684185/doge-data-socia...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#513
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Microsoft did give them. Just because they have a warrant doesn't mean keys should be handed over in any usable form. As indicated in the Forbes [0] article - both Meta and Apple have the exact same convenience in place (cloud backup) with none of the direct risk. So, yes. That is how it works: 1) Microsoft forces users to online accounts 2) Bitlocker keys are stored in an insecure manner allowing any US agency to as…

The difference is Microsoft has the keys to your front door, Apple only has an encrypted copy of your house (but no key).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#514
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

"They have no choice" because they're "just doing their job" and "following the law."

Which are both choices. Microsoft can for sure choose to block the government and so can individual workers. Let's not continue the fascism-enabling narratives of "no choice."

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#515

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance

Hackernews is a public forum, and the people here change constantly. "Back in the day" there were mostly posts about LISP and startup equity. It's obviously not the same people here now.

> Too many tech workers decided to rollover for the government

Again, not the same group of people. In the 2000s "tech workers" might have mostly been Californians. Now they're mostly in India. Differing perspectives on government, to be sure.

> lazy engineers build lazy key escrow

Hey you should know this one, because it's something that HAS stayed constant since "back in the day": The engineers have absolutely no say in this whatsoever.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#516
post #81

Earlier quoted context omitted.

AI enshittification is irrelevant here. Why is someone pointing out that sensible secure defaults are a good thing suddenly defending the entire company?

Uploading your encryption keys up to someone else's machine is not a sensible default

[deleted]

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#517
post #280

Earlier quoted context omitted.

I big demographic of HN users are people who want to be the multi-trillion dollar corporation so it’s not too surprising. In this case though I think they are right. And I’m a big time Microsoft hater.

The defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you als…

The vast, vast majority of Windows users don't know their laptops are encrypted, don't understand encryption, and don't know what bitlocker is. If their keys weren't stored in the cloud, these users could easily lose access to their data without understanding how or why. So for these users, which again is probably >99% of all windows users, storing their keys in the cloud makes sense and is a reasonable default. Not doing it would cause far more problems than it solves.

And the passphrase they log in to windows with is not the key, Microsoft is not storing their plain text passphrase in the cloud, just to be clear.

The only thing I would really fault Microsoft for here is making it overly difficult to disable the cloud storage for users who do understand all the implications.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#518
post #355

Earlier quoted context omitted.

It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the governmen…

> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyo…

So what happens if your motherboard gets fried and you don’t have backups of your recovery key or your data? TPMs do fail on occasion. A bank PIN you can call and reset, they can already verify your identity through other means.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#519
post #467

Earlier quoted context omitted.

It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the governmen…

Then don't enable encryption? Basically I cannot rescue the files on my own disk but the police can?

> Basically I cannot rescue the files on my own disk but the police can?

I think you're misunderstanding. You can rescue the files on your own disk when you place the key in your MS account.

There's no scenario where you can't but the police can.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#520

Earlier quoted context omitted.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

Get whatever is most popular on amazon at your price point. All the most popular hardware should work fine with any of the most popular distros.
Post reply on HN