Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

141–150 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#141

Earlier quoted context omitted.

Maybe three letter agencies prevented them from giving that option.

Surely that's not legal is it? Can the government force companies to include spyware?

No, but they can tie it to the consideration of software and services contracts which has the same effect.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#142

Earlier quoted context omitted.

The alternative is just not having FDE on by default, it really isn't "require utterly clueless non-technical users to go through complicated opt-in procedure for backups to avoid losing all their data when they forget their password". And AFAICT, they do ask, even if the flow is clearly designed to get the user to back up their keys online.

No, encryption keys should never be uploaded to someone else's computer unencrypted. The OOBE should give users a choice between no FDE or FDE with a warning that they should not forget their password or FDE and Microsoft has their key and will be able to recover their disk and would be compelled to share the key with law enforcement. By giving the user the three options with consequences you empower the user to addr…

Always on FDE with online backups is a perfectly reasonable default. The OOBE does offer the users the choice to not back up their key online, even if it's displayed less prominently.

>By giving the user the three options with consequences you empower the user to address their threat model how they see fit.

Making it too easy for uneducated users to make poor choices is terrible software design.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#143
> ... if asked

This is blurring of fact drives click bait.

The origin of this is a Forbes article[0] where the quote is: "Microsoft confirmed to Forbes that it does provide BitLocker recovery keys if it receives a valid legal order."

[0] https://www.forbes.com/sites/thomasbrewster/2026/01/22/micro...

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#144
post #48

Pretty sure the same applies to all the passwords/passkeys/2FA codes stored in the Authenticator app with cloud backup on.

Only if that authenticator/password manager app is not end-to-end encrypted.

That's right, and Microsoft Authenticator isn't.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#145
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

The same way you cannot be sure that FBI is not criminals

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#146

Earlier quoted context omitted.

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

For something as widely adopted as Windows, the only sensible alternative is to not encrypt the disk by default. The default behavior will never ever be to "encrypt the disk by a key and encrypt the key with the user's password." It just doesn't work in real life. You'll have thousands of users who lost access to their disks every week.

While this is true, why even bother turning on encryption and making it harder on disk data recovery services in that case?

Inform, and Empower with real choices. Make it easy for end users to select an alternate key backup method. Some potential alternatives: Allow their bank to offer such a service. Allow friends and family to self host such a service. Etc.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#147

Earlier quoted context omitted.

Any American company will hand over data stored on their server (that they have access to) in response to a warrant. Apple provides an optional encryption level (ADP) where they don't have a copy of your encryption key. When Apple doesn't have the encryption key, they can't decrypt your data, so they can't provide a copy of the decrypted data in response to a warrant. They explain the trade off during device setup: I…

Any company in any country will hand over data in response to a warrant. There is no country with a higher standard of protection than a warrant.

Sure, but every company doesn't make it as difficult as possible to set up a new encrypted computer without uploading a copy of your your encryption key to their servers.

That's a Microsoft thing.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#148
I don't understand this, it's actually baffling. Why was the question being asked to begin with let along a whole post being made about this? If they have a legal request from a law enforcement agency of any country they operate in, they either comply or see executives in prison.

Is how bitlocker works not well known perhaps? I don't think it's a secret. The whole schtick is that you get to manage windows computers in a corporate fleet remotely, that includes being able to lock-out or unlock volumes. The only other way to do that would be for the person using the device to store the keys somewhere locally, but the whole point is you don't trust the people using the computers, they're employees. If they get fired, or if they lose the laptop, them being the only people who can unlock the bitlocker volume is a very bad situation. Even that aside, the logistics of people switching laptops, help desk getting a laptop and needing to access the volume and similar scenarios have to be addressed. Nothing about this and how bitlocker works is new.

Even in the safer political climates of pre-2025, you're still looking at prosecution if you resist a lawful order. You can fight gag-orders, or the legality of a request, but without a court order to countermand the feds request, you have to comply.

Microsoft would do the same in China, Europe, middle east,etc.. the FBI isn't special.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#149
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

Is it meaningfully misleading? How often is this an obstacle for the FBI?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#150
post #69

Earlier quoted context omitted.

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

While you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think abou…

The OOBE (out of box experience) uploads the key by default (it tells you it’s doing it, but it’s a bit challenging to figure out how to avoid it) but any other setup method specifically asks where to back up your key, and you can choose not to. The way to avoid enrollment is to enable Bitlocker later than OOBE.

I really think that enabling BitLocker with an escrowed key during OOBE is the right choice, the protection to risk balance for a “normal” user is good. Power users who are worried about government compulsion can still set up their system to be more hardened.

Post reply on HN