Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

171–180 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#171

Earlier quoted context omitted.

Presumably when the authors of TrueCrypt declared “Using TrueCrypt is not secure” If I trust them to provide my FDE software, I certainly trust them when they say I shouldn’t use it.

This. I have no trust in TrueCrypt or it's derivatives. If TrueCrypt was compromised then it stands that VeraCrypt is as well.

How so? Veracrypt was independently audited, even by German BSI [1] and no serious problems were found. [1] https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publicat...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#172
post #54

Earlier quoted context omitted.

How would that leave them homeless?

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#173
post #88

Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.

Does your company require the pin? Or more importantly, does the company that your company pays for Cyber insurance require the pin?

I have never seen a company where they require the pin for bitlocker.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#174

Earlier quoted context omitted.

If you have those sorts of skills with a computer, you will have other options

Then you pay him since you see the value he’s creating so clearly.

This is a strange argument. I don't have the capital, desire, or skills to employee this guy, or anyone really.

Me not hiring someone doesn't mean the skills aren't valuable.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#175
post #172

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

Emotionally immature people tend to be a liability, not an asset. Therapy can help, but they first need a willingness to do better.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#176
post #54

Earlier quoted context omitted.

How would that leave them homeless?

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly.

And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with more money than God to uphold a deal for relative peanuts, right?

Like yes we all get that large orgs make spending $5 very hard, many claps for being the in-group, but their frustration would be understandable.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#177

Earlier quoted context omitted.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

King Terry was living proof this is not true.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#178

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly. And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with…

I'm supposed to feel bad that Microsoft didn't immediately wire him an advance on the bounty before validating anything? Have you ever tried to get anything corrected with a corporate payroll department? Try three months minimum.

It's like suggesting someone was relying on a lottery ticket to payout to survive.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#179
post #88

Better writeup: https://infosec.exchange/@wdormann/116565129854382214 The published exploit doesn’t affect Bitlocker with a PIN, without which Bitlocker isn’t secure anyway. The original author claims they have an exploit that also works with a PIN, but hasn’t provided any proof of that.

Does your company require the pin? Or more importantly, does the company that your company pays for Cyber insurance require the pin? I have never seen a company where they require the pin for bitlocker.

[deleted]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#180
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

As opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were…

Not in the UK sadly, ADP is disabled.
Post reply on HN