Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

151–160 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#151
post #140

Earlier quoted context omitted.

The "reasonable default" is to force the user to actually make the choice, probably after forcing the user to prove they understand the implications.

I don't think there's a good answer here. Users absolutely 100% will lose their password and recovery key and not understand that even if the bytes are on a desk physically next to you, they are gone. Gone baby gone. In university, I helped a friend set up encryption on a drive w/ his work after a pen drive with work on it was stolen. He insisted he would not lose the password. We went through the discussion of "this…

Apple gives users the choice during set up assistant, no reason Microsoft can't.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#152
post #123

Earlier quoted context omitted.

Correct me if I'm wrong, but isn't forcing you to divulge your encryption password compelled speech? So the police can crack my phone but they can't force me to tell them my PIN.

Warrants are a mechanism by which speech is legally compelled. The 5th Amendment gives you the right to refuse speech that might implicate you in a crime. It doesn’t protect Microsoft from being compelled to provide information that may implicate one of its customers in a crime.

Indeed. Third Party Doctrine has undermined 4th/5th Amendment protections due to the hair brained power grab that was "if you share info with a third party as art of the only way of doing business, you waive 4th Amendment protections. I ironically, Boomers basically knee-capped Constitutional protections for the very data most critically in need of protection in a network state.

Only fix is apparently waiting until enough for to cram through an Amendment/set a precedent to fix it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#153

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

"Good" companies in the old days would ensure they don't have your data, so they don't have to give it to the police.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#154
post #59

Earlier quoted context omitted.

>A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. This is absurd, because it's basically a generic argument about any sort of feature that vaguely reduces privacy. Sorry guys, we can't have automated backups in windows (even opt in!), because if the feature exists, a random bitflip can cause everything to…

Uploading your encryption keys is not just "any sort of feature".

You're right, it's less intrusive than uploading your files directly, like a backup does.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#156

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> This isn't an argument about law, it's about designing secure systems False. You can design truly end-to-end encrypted secure system and then the state comes at you and says that this is not allowed, period. [1] [1] https://medium.com/@tahirbalarabe2/the-encryption-dilemma-wh...

Another one: https://www.theguardian.com/australia-news/2024/nov/05/sessi...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#157

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

It’s not about engineers being lazy, it’s about money. Trying to resist building ethically questionable software usually means quitting or being fired from a job.

I agree with you, but also think this is only true because we as an industry have been so completely corrupted by money at this point.

In the 90s and 00s people overwhelmingly built stuff in tech because they cared about what they were building. The money wasn't bad, but no one started coding for the money. And that mindset was so obvious when you looked at the products and cultures of companies like Google and Microsoft.

Today however people largely come into this industry and stay in it for the money. And increasingly tech products are reflecting the attitudes of those people.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#158

Earlier quoted context omitted.

That is a strange viewpoint. Are we calling everyone who wants some control over their computers enemies of the state?

It's holistic philosophy. You're not going to save yourself from FBI surveillance by avoiding Windows, I guarantee that to you.

You're not going to avoid any state surveillance if the state is really interested in you specifically.

But you can still help prevent abuses of mass surveillance without probable cause by making such surveillance as expensive and difficult as possible for the state

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#159

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

If you design it so you don't have access to the data, what can they do? I'm sure there's some cryptographic way to avoid Microsoft having direct access to the keys here.

If you design it so you don't have access to the data, how do you make money?

Microsoft (and every other corporation) wants your data. They don't want to be a responsible custodian of your data, they want to sell it and use it for advertising and maintaining good relationships with governments around the world.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#160
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

To be fair, if they didn't have BitLocker enabled at all, the FBI would have just scanned the hard-drive as-is. The only usefulness of BitLocker is if a stranger steals your laptop, assuming Microsoft doesn't hand out the keys to just anybody, your files should be safe, in theory.
Post reply on HN