Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

131–140 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#131

Earlier quoted context omitted.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

Really depends on your background doesn't it? You could have convictions, be sanctioned, have visa problems, or all kinds of things that are not easily solvable.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#132

Earlier quoted context omitted.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

Please let me know when finding a job in software engineering in 2026 is feasible for everyone with ‘computer skills’.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#133

Earlier quoted context omitted.

Fiasco? You mean where they voluntarily shut down rather than compromise themselves? Or are you referring to another matter?

Presumably when the authors of TrueCrypt declared “Using TrueCrypt is not secure” If I trust them to provide my FDE software, I certainly trust them when they say I shouldn’t use it.

This. I have no trust in TrueCrypt or it's derivatives. If TrueCrypt was compromised then it stands that VeraCrypt is as well.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#134
post #79
post #38

Earlier quoted context omitted.

If "things go catastrophic" your hard drive is not usable at all anymore. At the very least some files can't be recovered at all. So you need backups in any case. Once you have backups, you might as well encrypt your hard drives, especially if you store these in different locations (which you should). An advantage of encryption is that it makes it easier to give away or resell devices. With recent encryption schemes…

That’s not true. I’ve had many computers that refuse to turn on and I was able to recover the files by removing the drive and loading it into a USB hard drive reader and recover the files.

I sure envy you if this qualifies as "catastrophic", because hard drive can and do fail.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#135
post #118

Earlier quoted context omitted.

Better still: LUKS allows you to set up multiple entry keys, so use two, either of which will grant access to the drive. * Your preferred memorized passphrase and will never be written down anywhere. * A random key you can print and store in a box somewhere. Then if your backup paper gets lost, you can revoke/replace it without having to abandoned your memorized favorite.

Yep. You can also put your key on a usb drive that can be read on boot. Just choose a good quality one....

A few ideas for extra security:

* Split the recovery key in two, store each half with a different friend. (If you're feeling fancy, XOR the halves and store that with a third friend, then any two out of three will work.)

* Sneak the key into something you know friends/family won't throw away while you're still alive, like stuck to the back of a sentimental photo in a frame.

____

That said, I think I'm wandering from the original "accumulating dusty old drives in a box" scenario, which has a simpler solution: Keep a growing old_drives_keys.txt file on your current (encrypted) main device.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#136
post #132

Earlier quoted context omitted.

If you have those sorts of skills with a computer, you will have other options

Please let me know when finding a job in software engineering in 2026 is feasible for everyone with ‘computer skills’.

The guy doesn’t just have „computer skills“ if he found this.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#137
post #104

Earlier quoted context omitted.

This is one it those answers that seems on the surface like it contains insight but on closer inspection it’s vacuous. This could be rewritten as “because they aren’t you”, which is true but not a meaningful or educational answer.

Sure sounds like rhetorical questions or attacking the messenger. Someone can think the bounty industry is going to reward them for actually being exceptional and not look soon enough for other options then pivot to a stance that should give them some quick job offers. If I thought I found an intentional back door I would not engage with an embargo system from the same vendor but I am also not them.

> Someone can think the bounty industry is going to reward them for actually being exceptional and not look soon enough for other options then pivot to a stance that should give them some quick job offers

Sure. And that’s a meaningful answer to the question.

“people with values different from yours, presumably” is a condescending nonanswer.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#138

Earlier quoted context omitted.

Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.

You need a separate pin because windows lives on the encrypted disk so you need to decrypt it before you can boot completely.

macOS solved this (and a lot of other problems) by putting the OS on a separate read-only partition - technically an APFS volume - that doesn’t get encrypted. Microsoft’s backwards-compatibility obsession might not let them make that the default, but they could at least make it an option.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#139

Earlier quoted context omitted.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

We are, quite notably, in a huge hiring crisis where vast numbers of programmers and researchers can't even get interviews. It really is not that simple

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#140

The real problem with a Bitlocker backdoor or weakness is that when a laptop gets stolen or lost, in most regulated organizations, the criteria for legally declaring and disclosing a breach pivots on whether it was protected by disk encryption. If it's a backdoor, that's a serious fraud against their customers.

This doesn't make much sense. Almost every single organization using Bitlocker knows that it's backdoored. It's like Push Notifications or SMS, warrantless surveillance is the norm and you don't get to opt-out. Nobody's IT department is waking up in cold sweats at the idea of the Fed stealing their data, it's part and parcel with using Windows services.

If you really think this will be prosecuted as fraud, then you'll be shocked by how American courts handle these sorts of things.

Post reply on HN