Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

101–110 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#101

Earlier quoted context omitted.

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

I thought this was what happened. Clearly not :( That’s the idea with services like 1Password (which I suppose is ultimately doing the same thing) - you need both the key held on the device and the password. I suppose this all falls apart when the PC unlock password is your MS account password, the MS account can reset the local password. In Mac OS / Linux, you reset the login password, you loose the keychain.

In case of 1password, I would think it would be challenging to do what you are saying, at least for shared password vaults.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#103

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

> How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"?

Perhaps in this case they should be required to get a warrant rather than a subpoena?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#106
post #16

Apple will do this too. Your laptop encryption key is stored in your keychain (without telliing you!). All is needed is a warrant for your iCloud account and they also have access to your laptop. sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/

> Your laptop encryption key is stored in your keychain

Probably not if one is not using Apple cloud on their laptops.

> stored in your keychain (without telliing you!)

How to verify that? Any commands/tools/guides?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#108

Earlier quoted context omitted.

https://linuxmint.com/ https://ubuntu.com/download/desktop https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.

> Every bad day for microsoft is yet another glorious day for linux. Nah. If that were the case, Linux would dominate personal computer statistics. The reality is that most mainstream users just don't care. But, of course, that won't stop us.

I bet most mainstream users thinks it good that FBI can access suspects data.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#109

Earlier quoted context omitted.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

"Disconnected from reality" ... tell that to the people who have had a lost or stolen device without encryotion. You'd need a backup and then some!

Apple manages a recovery path for users without storing the key in plain text. Must have something to do with those "security aficionados."

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#110

Earlier quoted context omitted.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

> Security aficionados pushing non-recoverable traps on people are plain disconnected from reality.

To be fair, if you inadvertently get locked out of your Google account "tough luck, should have used a different provider" and Gmail is a household name so ...

Less snarky, I think that there's absolutely nothing wrong with key escrow (either as a recovery avenue or otherwise) so long as it's opt in and the tradeoffs are made abundantly clear up front. Unfortunately that doesn't seem to be the route MS went.

Post reply on HN