Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

101–110 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#101

Earlier quoted context omitted.

I think my message wooshed. I was not comparing disk encryption and iCloud backups. My point is that insecure defaults are Apple and other's alternative to backdoors. They give plausible deniability ("how is someone able to recover their data if they lost their credentials and we used E2E?"), while at the same time satisfying law enforcement, because the vast majority of people is not aware of them. Another example i…

Signal won't let us download our own data and back it up using our own secure systems. Whatever its other merits it gets 0% for backup policy. Though I suppose then I have to give a negative % to all the systems that have insecure online backups. This whole area is a train wreck really.

> ‘Signal won't let us download our own data and back it up using our own secure systems.

Signal is slowly, very slowly, moving toward providing real backups and cross-device transfers

I understand why you’d believe Signal still can’t deliver that, because they had been ignoring the user demands for years.

But there is real progress now

https://support.signal.org/hc/en-us/articles/9708267671322-S...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#102
post #13

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

Cool. Everyone's threat model is different. As long as we're not writing passwords on sticky notes attached to the monitor, I don't think there's any need to be throwing stones.

> Everyone's threat model is different.

Everyone's threat model is different, but some are better than others, and maybe we shouldn't equate taking time to explain why with throwing stones.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#103
post #75
post #68

Earlier quoted context omitted.

Presumably, not paying out for these bugs which often take weeks of research to find.

Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.

> Who in their right mind bets on bug bounties to cover their basic needs?

Someone with a vulnerability worth as much as a two bedroom apartment?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#104
post #96
post #75

Earlier quoted context omitted.

Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.

people with values different from yours, presumably

This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous.

This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#105
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

Curious to see this take from you! I followed TrueCrypt for years, but always thought it was very strange that they were anonymous, and then the mysterious shutdown happened, and I have no idea what to make of VeraCrypt. It's been in my "possibly good, but too many weird flags around the whole project" bucket. Anything in particular that makes you wary? I'm aware of the 2016 and 2020 audits ( https://ostif.org/the-ve…

this crypto solution got their driver licence pulled afaik they cant update their program anymore / get new drivers loaded properly

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#106

Earlier quoted context omitted.

Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this

[flagged]

even Bill Gates bailed out of M$ https://finbold.com/bill-gates-foundation-fully-dumps-its-mi...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#107

Earlier quoted context omitted.

Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this

[flagged]

I hear you. But, I must also admit that reading "M$" in public discourse sure makes me nostalgic for better days on the internet.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#108

Earlier quoted context omitted.

Ever since the TrueCrypt fiasco years ago, I have no trust in that brand.

Fiasco? You mean where they voluntarily shut down rather than compromise themselves? Or are you referring to another matter?

Presumably when the authors of TrueCrypt declared “Using TrueCrypt is not secure”

If I trust them to provide my FDE software, I certainly trust them when they say I shouldn’t use it.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#109

Earlier quoted context omitted.

Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this

[flagged]

From my basement in Wyoming, I stab at thee!

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#110

Earlier quoted context omitted.

Signal won't let us download our own data and back it up using our own secure systems. Whatever its other merits it gets 0% for backup policy. Though I suppose then I have to give a negative % to all the systems that have insecure online backups. This whole area is a train wreck really.

> ‘Signal won't let us download our own data and back it up using our own secure systems. Signal is slowly, very slowly, moving toward providing real backups and cross-device transfers I understand why you’d believe Signal still can’t deliver that, because they had been ignoring the user demands for years. But there is real progress now https://support.signal.org/hc/en-us/articles/9708267671322-S...

It's not a matter of belief. Signal does not provide a way for me to download my own messages off my own devices and safely store them using my own secure backup facility.

Obviously Signal don't owe me anything. I'm not paying for the product and I appreciate what it does offer and makes available for free. But it would be much better if it also supported local backups under the user's control.

Post reply on HN