Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

121–130 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#121
post #62

Earlier quoted context omitted.

[flagged]

Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles

Positive HN-appropriate angle: they're very financially successful and have been for 40 years.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#122
post #84

I just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if…

>If there is a stick you can boot from and drop into an emergency shell This won't work because the TPM will only give you the keys if you're booting an "approved" OS, specifically the PCR states that the encryption keys are bound to. >or if you have to buy a $5 microcontroller and solder it to certain pins on the main board to sniff the TPM keys. That only works with dTPMs. fTPMs aren't vulnerable to this, and are f…

fTPMs also have similar issues. The real takeaway is that if your threat model includes actors capable of executing attacks against BitLocker you need to put a password/pin on it in addition to the TPM.

https://arxiv.org/pdf/2304.14717

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#123
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

> And now backdoors!

"now"?

Shall we have a discussion about the excuse Microsoft gave as to why keys they claimed, back then, were "secondary keys" belonging to Microsoft, were called ..._NSAKEY when a version of Windows NT shipped, by mistake, with debug symbols on?

One time, just freaking one time, a version of Windows shipped with debug symbols on and, by chance, there had to be cryptographic keys named "NSAKEY" in there.

Yeah.

Now that people constantly turning a blind eye on the wrongdoings of the state are of course going to say that it's totally normal and just repeat the, carefully crafted, excuses from Microsoft from back, that it was totally not a backdoor etc.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#124
post #75

Earlier quoted context omitted.

Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#125

Earlier quoted context omitted.

[flagged]

But nothing has changed. It's fair to say it's silly, jeuvenile, but it's also fair to say MS deserve absolutely no normal respect you would pay a turd. Maybe the poster actually is 12 and we all have a right to be 12 for a while. There's always a new generation discovering today what we discovered 30 years ago.

Nothing has changed? Microsoft is a huge open source contributor now, produced one of the largest open source ecosystems in use (.NET) and provides free access to the biggest open source software repositories (GitHub). Sorry to say, but believing nothing with MS has changed is deranged.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#126
post #118

Earlier quoted context omitted.

Print it on a piece of paper and put it in a lock box.

Better still: LUKS allows you to set up multiple entry keys, so use two, either of which will grant access to the drive. * Your preferred memorized passphrase and will never be written down anywhere. * A random key you can print and store in a box somewhere. Then if your backup paper gets lost, you can revoke/replace it without having to abandoned your memorized favorite.

Yep. You can also put your key on a usb drive that can be read on boot.

Just choose a good quality one....

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#127
post #88

Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.

Assuming that the PIN version claim is true, it's interesting to think why they would've released a nerfed useless version rather than the PIN version. I have some ideas but they're completely baseless.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#128
post #100

Earlier quoted context omitted.

>so they had to make a seemingly ridiculous statement (because who in their right mind would trust bitlocker) to call attention that "something is very wrong" Alternately, they don't want people to rely on abandonware for security. Also, despite the conspiracy theories of backdoors I'm not aware of any bitlocker exploits that work on TPM + pin, which is the intended "secure" configuration[1]. All exploits rely on TPM…

Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.

You need a separate pin because windows lives on the encrypted disk so you need to decrypt it before you can boot completely.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#129
post #80
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

You are confused. They are not "security" roles, they are compliance roles. That's all most enterprise customers really care about. They satisfied all of the compliance rules, and are following "best practices" (influenced by MS), anything that happens is not their fault.

And having more busywork to do is actually a good thing. Having people employed to do said busywork shows how serious they are about "security", without requiring any skills that are difficult to hire

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#130
post #104
post #96

Earlier quoted context omitted.

people with values different from yours, presumably

This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous. This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.

Sure sounds like rhetorical questions or attacking the messenger. Someone can think the bounty industry is going to reward them for actually being exceptional and not look soon enough for other options then pivot to a stance that should give them some quick job offers. If I thought I found an intentional back door I would not engage with an embargo system from the same vendor but I am also not them.
Post reply on HN