Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

131–140 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#131

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

It makes sense if you consider the possibility of a secret deal between the government and a giant corporation. The deal is that people's data is never secure.

It's a nightmare actually.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#132
post #21

Earlier quoted context omitted.

They've only done more since 2016. Lockdown mode: https://support.apple.com/en-us/105120 Advanced Data Protection for iCloud: https://support.apple.com/en-us/108756

Sure, but these are all mere statements. You don't know if they fully back that until there's a public standoff with law enforcement/administration and there weren't any in recent years. Yet at the same time it's hard to believe there were no attempts from that government to decrypt some devices they needed. So the fact we hear nothing about it is also an information to me. Sure, this is all speculation, but all thin…

iCloud Keychain is end-to-end encrypted, even without the Advanced Data Protection setting. https://support.apple.com/en-us/102651 Not something they can turn over to the feds.

And if you don't want iCloud Keychain, you are still given the choice to encrypt and print the backup key.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#133
post #69

Earlier quoted context omitted.

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

While you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think abou…

I really doubt those motives are "evil." They're in the business of selling and supporting an OS. Most people couldn't safeguard a 10-byte password on their own, they're not going to have a solution for saving their encryption key that keeps it safer than it'd be with Microsoft, and that goes for both criminals (or people otherwise facing law enforcement scrutiny) and normal grandmas who just want to not have all their pictures and recipes lost.

Before recently, normal people who get arrested and have their computer seized were 100% guaranteed that the cops could read their hard drive and society didn't fall apart. Today, the chances the cops can figure out how to read a given hard drive is probably a bit less. If someone needs better security against the actual government (and I'm hoping that person is a super cool brave journalist and not a terrorist), they should be handling their own encryption at the application layer and keeping their keys safe on their own, and probably using Linux.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#134
post #69

Earlier quoted context omitted.

While you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think abou…

You can just ... not select the option to upload your keys to MS? During the setup you get to choose where to store your bitlocker recovery key.

The last time I've installed windows, bitlocker was enabled automatically and the key was uploaded without my consent.

Yes, you can opt out of it while manually activating bitlocker, but I find it infuriating that there's no such choice at the system installation process. It's stupid that after system installation a user supposed to renecrypt their system drive if they don't want this.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#135
post #69

Earlier quoted context omitted.

While you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think abou…

Maybe three letter agencies prevented them from giving that option.

Surely that's not legal is it? Can the government force companies to include spyware?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#136
post #30

Earlier quoted context omitted.

Yes, I know this sounds conspiratorial, but I think the whole Liquid Ass thing was a rush to put some other software in Apple products to appease the Trump admin. For example, it is new in Tahoe that they store your filevault encryption key in your icloud keychain without telling you. https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...

But iCloud Keychain is end-to-end encrypted using device-specific keys, so Apple cannot read items in your iCloud Keychain (modulo adding their own key as a device key, rolling out a backdoor, etc. but that applies to all proprietary software).

How is the data recovered if device is lost?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#137
post #21

Earlier quoted context omitted.

They've only done more since 2016. Lockdown mode: https://support.apple.com/en-us/105120 Advanced Data Protection for iCloud: https://support.apple.com/en-us/108756

Sure, but these are all mere statements. You don't know if they fully back that until there's a public standoff with law enforcement/administration and there weren't any in recent years. Yet at the same time it's hard to believe there were no attempts from that government to decrypt some devices they needed. So the fact we hear nothing about it is also an information to me. Sure, this is all speculation, but all thin…

They fully comply with Chinese requirements if you subscribe to iCloud in China, and they do this quite transparently. They do not, notably, say they don't share anything with China and then go ahead and do it anyway.

Unless Apple is straight up lying about their technology and encryption methods used to secure iCloud and their hardware, the issue of a public standoff is moot, because Apple couldn't help them if they wanted to. And while perhaps it's possible that Apple would lie to consumers to please US law enforcement, it's a bit of a stretch to say that because there haven't been any high-profile cases where law enforcement tries to force Apple to give up what they don't have, that this must be evidence that they're in cahoots.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#138

Earlier quoted context omitted.

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

This is a consent issue, and visibility thereof, not "crypto architecture"

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#139

Earlier quoted context omitted.

But iCloud Keychain is end-to-end encrypted using device-specific keys, so Apple cannot read items in your iCloud Keychain (modulo adding their own key as a device key, rolling out a backdoor, etc. but that applies to all proprietary software).

How is the data recovered if device is lost?

If you lose access to all devices in the circle of trust, the data is lost. If you're curious: https://support.apple.com/guide/security/secure-keychain-syn...

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#140
The headline is misleading. It says that Microsoft will provide the key if asked, but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order.

These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order.

It does illustrate a significant vulnerability in that Microsoft has access to user keys by default. The public cannot be sure that Microsoft employees or criminals are unable to access those keys.

Post reply on HN