Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

151–160 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#151

Earlier quoted context omitted.

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

Yes and they had to lie to sell that option. If they honestly informed customers about the tradeoff between security and convenience they'd certainly have far fewer customers. Instead they lead people to believe that they can get that convenience for free. The obvious better choice is transparancy.

> tradeoff between security and convenience they'd certainly have far fewer customers

What? Most people, thinking through the tradeoff, would 100% not choose to be in charge of safeguarding their own key, because they're more worried about losing everything on their PC, than they are about going to jail. Because most people aren't planning on doing crime. Yes, I know people can be wrongly accused and stuff, but overall most people aren't thinking of that as their main worry.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#152

I don't understand this, it's actually baffling. Why was the question being asked to begin with let along a whole post being made about this? If they have a legal request from a law enforcement agency of any country they operate in, they either comply or see executives in prison. Is how bitlocker works not well known perhaps? I don't think it's a secret. The whole schtick is that you get to manage windows computers i…

>Microsoft would do the same in China, Europe, middle east,etc.. the FBI isn't special.

One would presume US agencies has leverage to access global data.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#153

Earlier quoted context omitted.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

> Security aficionados pushing non-recoverable traps on people are plain disconnected from reality. To be fair, if you inadvertently get locked out of your Google account "tough luck, should have used a different provider" and Gmail is a household name so ... Less snarky, I think that there's absolutely nothing wrong with key escrow (either as a recovery avenue or otherwise) so long as it's opt in and the tradeoffs a…

Google has a pretty robust recovery process. Of course if you've given them absolutely nothing about them then forgotten your password, it's tough.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#155

Earlier quoted context omitted.

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

The alternative is just not having FDE on by default, it really isn't "require utterly clueless non-technical users to go through complicated opt-in procedure for backups to avoid losing all their data when they forget their password". And AFAICT, they do ask, even if the flow is clearly designed to get the user to back up their keys online.

> The alternative is just not having FDE on by default

yes, it would be. So, the current way, 99% of people are benefitting from knowing their data is secure when very common thefts occur, and 1% of people have the same outcome as if their disk was unencrypted: When they're arrested and their computers seized, the cops have their crime secrets. What's wrong?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#156

Earlier quoted context omitted.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

Google Authenticator used to be disconnected from reality like this. Users were asking how to copy the codes to another phone, and they said "you can't, WAI, should add the other phone as a second auth method on every site." Like how people say you shouldn't copy SSH privkeys. I figured out an undocumented way to do it on iPhone by taking an encrypted iTunes backup though.

Eventually they yielded on this, but their later updates had other usability traps. Because Google Auth was the household name for TOTP apps, this maybe ruined TOTP's reputation early-on.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#157

Earlier quoted context omitted.

Maybe three letter agencies prevented them from giving that option.

Surely that's not legal is it? Can the government force companies to include spyware?

That's one of the ideas the British government had a few months back...

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#159

Earlier quoted context omitted.

For a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

I had hoped the average person would have a baseline understanding of how computers work by now. Baseline includes things like the difference between a web browser and a search engine, "the cloud" is someone else's computer, and encrypted means gone if you lose the password/key.

I am sad that this now appears unlikely. I suspect it may even be lower for people in their 20s today than a decade ago.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#160
post #149
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

Is it meaningfully misleading? How often is this an obstacle for the FBI?

Broader context isWindows defaults to making their access to your data legally accessible. Their entire windows platform and one drive defaults to this insecurity

Inlight of fascism coming to Democratic cities and anyone documenting it being a registered domestic terrorist...well thats pretty f'n insecure by default.

Post reply on HN