Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

121–130 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#121

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

> don't really understand how could anyone imagine a world where MS could just refuse such a request

By simply not having the ability to do so.

Of course Microsoft should comply with the law, expecting anything else is ridiculous. But they themselves made sure that they had the ability to produce the requested information.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#123

Earlier quoted context omitted.

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

The alternative is just not having FDE on by default, it really isn't "require utterly clueless non-technical users to go through complicated opt-in procedure for backups to avoid losing all their data when they forget their password". And AFAICT, they do ask, even if the flow is clearly designed to get the user to back up their keys online.

No, encryption keys should never be uploaded to someone else's computer unencrypted. The OOBE should give users a choice between no FDE or FDE with a warning that they should not forget their password or FDE and Microsoft has their key and will be able to recover their disk and would be compelled to share the key with law enforcement. By giving the user the three options with consequences you empower the user to address their threat model how they see fit. There is no good default choice here. The trade offs are too varied.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#124

Earlier quoted context omitted.

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

Yes and they had to lie to sell that option.

If they honestly informed customers about the tradeoff between security and convenience they'd certainly have far fewer customers. Instead they lead people to believe that they can get that convenience for free.

The obvious better choice is transparancy.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#126

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

This make little to no sense.

This is being reported on because it seems newsworthy and a departure from the norm.

Apple also categorically says they refuse such requests.

It's a private device. With private data. Device and data owned by the owner.

Using sleight of hand and words to coax a password into a shared cloud and beyond just seems to indicate the cloud is someone else's computer, and you are putting the keys to your world and your data insecurely in someone else's computer.

Should windows users assume their computer is now a hostile and hacked device, or one that can be easily hacked and backdoored without their knowledge to their data?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#127

Headline says “…if asked” Article and facts are “…if served with a valid legal order compelling it” ∴ Headline is clickbait.

I would prefer “it is impossible for Microsoft to give the keys because that’s not how their encryption works”.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#128
post #41
post #32

Earlier quoted context omitted.

Well, for a consumer notebook or mobile device, the threat model typically envisions a thief grabbing it from a coffeehouse or hotel room. So your key needs to be safeguarded from the opportunist who possesses your hardware illegally. Linux can be fairly well-secured against state-level threat actors, but honestly, if your adversary is your own nation-state, then no amount of security is going to protect you! For Mic…

The problem is mass-surveillance and dragnets. Obviously if the state wants to go after you no laws will protect you. As we've seen they can even illegally collect evidence and then do a parallel construction to "launder" the evidence. But One-drive is essentially a mass-surveillance tool. It's a way to load the contents of every single person's computer into Palentir or similar tools and, say, for instance, "give me…

> But One-drive is essentially a mass-surveillance tool.

There are plenty of people that post clear positions on multiple social networks. I personally doubt that One-drive files will provide much more information for most of the people compared to what's already out there (including mobile phone location, credit card transactions, streaming services logs, etc.).

What I think the danger is for individual abuse. Someone "in power" wants one guy to have issues, they could check his One-drive for something.

Best is to make people aware of how it works and let them figure it out. There are so many options (local only, encrypted cloud storage, etc.) I doubt there is an ideal solution for everything.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#129

Pretty sure the same applies to all the passwords/passkeys/2FA codes stored in the Authenticator app with cloud backup on.

Use 1Password or similar instead. They’re keyed against a key they don’t have access to.

How do you avoid losing that key?
Post reply on HN