Earlier quoted context omitted.
[flagged]
Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
121–130 of 280 posts
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#122I just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if…
>If there is a stick you can boot from and drop into an emergency shell This won't work because the TPM will only give you the keys if you're booting an "approved" OS, specifically the PCR states that the encryption keys are bound to. >or if you have to buy a $5 microcontroller and solder it to certain pins on the main board to sniff the TPM keys. That only works with dTPMs. fTPMs aren't vulnerable to this, and are f…
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#123At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!
"now"?
Shall we have a discussion about the excuse Microsoft gave as to why keys they claimed, back then, were "secondary keys" belonging to Microsoft, were called ..._NSAKEY when a version of Windows NT shipped, by mistake, with debug symbols on?
One time, just freaking one time, a version of Windows shipped with debug symbols on and, by chance, there had to be cryptographic keys named "NSAKEY" in there.
Yeah.
Now that people constantly turning a blind eye on the wrongdoings of the state are of course going to say that it's totally normal and just repeat the, carefully crafted, excuses from Microsoft from back, that it was totally not a backdoor etc.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#124Earlier quoted context omitted.
Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.
Someone who doesn't have better options?
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#125Earlier quoted context omitted.
[flagged]
But nothing has changed. It's fair to say it's silly, jeuvenile, but it's also fair to say MS deserve absolutely no normal respect you would pay a turd. Maybe the poster actually is 12 and we all have a right to be 12 for a while. There's always a new generation discovering today what we discovered 30 years ago.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#126Earlier quoted context omitted.
Print it on a piece of paper and put it in a lock box.
Better still: LUKS allows you to set up multiple entry keys, so use two, either of which will grant access to the drive. * Your preferred memorized passphrase and will never be written down anywhere. * A random key you can print and store in a box somewhere. Then if your backup paper gets lost, you can revoke/replace it without having to abandoned your memorized favorite.
Just choose a good quality one....
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#127Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#128Earlier quoted context omitted.
>so they had to make a seemingly ridiculous statement (because who in their right mind would trust bitlocker) to call attention that "something is very wrong" Alternately, they don't want people to rely on abandonware for security. Also, despite the conspiracy theories of backdoors I'm not aware of any bitlocker exploits that work on TPM + pin, which is the intended "secure" configuration[1]. All exploits rely on TPM…
Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#129At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!
You are confused. They are not "security" roles, they are compliance roles. That's all most enterprise customers really care about. They satisfied all of the compliance rules, and are following "best practices" (influenced by MS), anything that happens is not their fault.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#130Earlier quoted context omitted.
people with values different from yours, presumably
This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous. This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.