Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

141–150 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#141
post #99

Earlier quoted context omitted.

Or use a local account to login ?

I’m not sure if you misunderstand how macOS accounts work or how FileVault works. There are two ways to log into macOS: a local user account or an LDAP (e.g. OpenDirectory, Active Directory) account. Either of these types of accounts may be associated with an iCloud account. macOS doesn’t work like Windows where your Microsoft account is your login credential for the local machine. FileVault key escrow is something y…

> There are two ways to log into macOS: a local user account or an LDAP (e.g. OpenDirectory, Active Directory) account.

And just in case it wasn't clear enough, I'd add: a local user account is standard. The only way you'd end up with an LDAP account is if you're in an organization that deliberately set your computer up for networked login; it's not a typical configuration, nor is it a component used by iCloud.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#143
post #88

Earlier quoted context omitted.

if cosmic ray bit flips were so rare then ecc ram wouldn't be a thing.

ECC protects against more events than cosmic rays. Those events are much more likely, for instance magnetic/electric interferences or chip issues.

Those random unexplainable events are also referred to casually as "cosmic rays"

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#144

Earlier quoted context omitted.

If users are so paranoid that they worry about a cosmic ray bit flipping their computer into betraying them, they're probably not using a Microsoft account at all with their Windows PC.

If your security requirements are such that you need to worry about legally-issued search warrants, you should not connect your computer to the internet. Especially if it's running Windows.

Because all cops are honest, all warrants are lawful and nothing worrying happens in the land of freedom right now.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#145
post #46

Earlier quoted context omitted.

Apple's solution is iCloud Keychain which is E2E encrypted, so would not be revealed with a court order.

> Apple's solution is iCloud Keychain which is E2E encrypted, so would not be revealed with a court order. Nope. For this threat model, E2E is a complete joke when both E's are controlled by the third party. Apple could be compelled by the government to insert code in the client to upload your decrypted data to another endpoint they control, and you'd never know.

That was tested in the San Bernardino shooter case. Apple stood up and the FBI backed down.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#146
post #77

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. At this point, the only thing that can restore trust in Microsoft is open sourcing Windows.

> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. The fully security conscious option is to not link a Microsoft account at all. I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.

> it was really easy to set up without a Microsoft account.

By "really easy" do you mean you had a checkbox? Or "really easy" in that there's a secret sequence of key presses at one point during setup? Or was it the domain join method?

Googling around, I'm not sure any of the methods could be described as "really easy" since it takes a lot of knowledge to do it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#147
post #64

Earlier quoted context omitted.

> IBM estimated in 1996 that one error per month per 256 MiB of RAM was expected for a desktop computer. From the wikipedia article on "Soft error", if anyone wants to extrapolate.

That makes it vanishingly unlikely. On a 16GB RAM computer with that rate, you can expect 64 random bit flips per month. So roughly you could expect this happen roughly once every two hundred million years. Assuming there are about 2 billion Windows computers in use, that’s about 10 computers a year that experience this bit flip.

> 10 computers a year experience this bit flip

That's wildly more than I would have naively expected to experience a specific bit-flip. Wow!

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#148
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Correct me if I'm wrong, but isn't forcing you to divulge your encryption password compelled speech? So the police can crack my phone but they can't force me to tell them my PIN.

They can't force you to tell them your PIN in some countries, but they can try all PINs, and they can search your desk drawer to find the post-it where you wrote your PIN.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#149
post #59
post #21

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

>A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. This is absurd, because it's basically a generic argument about any sort of feature that vaguely reduces privacy. Sorry guys, we can't have automated backups in windows (even opt in!), because if the feature exists, a random bitflip can cause everything to…

Uploading your encryption keys is not just "any sort of feature".

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#150
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Correct me if I'm wrong, but isn't forcing you to divulge your encryption password compelled speech? So the police can crack my phone but they can't force me to tell them my PIN.

Yes, you cannot be compelled to testify against yourself, but Microsoft is under no such obligation when served a warrant because of third party doctrine. Microsoft holding bitlocker recovery keys is considered you voluntarily giving the information to a third party, so the warrant isn't compelling you to do anything, so not a rights violation.

But, the 5th amendment is also why its important to not rely on biometrics. Generally (there are some gray areas) in the US you cannot be compelled to give up your password, but biometrics are viewed as physical evidence and not protected by the 5th.

Post reply on HN