Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

181–190 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#182
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

Nah, you’re just not reading carefully. You must parse everything about this stuff carefully as the words are always crafted. It’s usually more productive to read with a goal to understand what isn’t said as opposed to what is said. They said “legal order”, which includes a variety of things ranging from administrative subpoenas to judicial warrants. Generally they say warrant if that was used. A “request” is “Hi Mic…

Hans George Gadamer over here with the advanced hermeneutic

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#183
post #126

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

This make little to no sense. This is being reported on because it seems newsworthy and a departure from the norm. Apple also categorically says they refuse such requests. It's a private device. With private data. Device and data owned by the owner. Using sleight of hand and words to coax a password into a shared cloud and beyond just seems to indicate the cloud is someone else's computer, and you are putting the key…

The Bernardino incident is a very different issue where Apple refused to use its own private key to sign a tool that would have unlocked any iPhone. There is absolutely no comparison between Apple's and MS conduct here because the architectures of the respective systems are so different (but of course, that's a choice each company made).

Should Apple find itself with a comparable decryption key in its possession, it would have little options but to comply and hand it over.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#184
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

The same way you cannot be sure that FBI is not criminals

[deleted]

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#185

Headline says “…if asked” Article and facts are “…if served with a valid legal order compelling it” ∴ Headline is clickbait.

I would prefer “it is impossible for Microsoft to give the keys because that’s not how their encryption works”.

That’s the case if you change a setting.

The default setting is a good mix of protecting people from the trouble they’re far more likely to run into (someone steals their laptop) while still allowing them back in if they forget their password. The previous default setting was no encryption at all which is worse in every case.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#186
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

> The headline is misleading. It says that Microsoft will provide the key if asked, but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order.

This is an odd thing to split hairs over IMO. Warrants or subpoenas or just asking nicely, whatever bar you want to set, is a secondary concern. The main issue is they can and will hand the keys to LEO’s at all.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#187
post #114

Earlier quoted context omitted.

https://linuxmint.com/ https://ubuntu.com/download/desktop https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.

To people on HN considering the switch, maybe. My family has zero interest or intention of trying any of these. It stops with me.

As my family's tech support department, i switched them over to linux long ago. For the last decade, my elderly parents used linux laptops and much prefered the stability.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#188
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

> The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . This is an odd thing to split hairs over IMO. Warrants or subpoenas or just asking nicely, whatever bar you want to set, is a secondary concern. The main issue is they can and will hand the keys to LEO’s at all.

The even-more-main-issue is that there is > 0 number of people who thought they wouldn’t

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#189
post #37
post #16

Apple will do this too. Your laptop encryption key is stored in your keychain (without telliing you!). All is needed is a warrant for your iCloud account and they also have access to your laptop. sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/

Wrong. You can (and should) watch all of https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for the details about how iCloud is protected by HSMs and rate limits to understand why you’re wrong, but especially the time-linked section… instead of spreading FUD about something you know nothing about.

You can say anything you want in a YouTube video or a whitepaper. It doesn't have to correspond to your security architecture.

Where's the source code? Who audits this system?

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#190
post #151

Earlier quoted context omitted.

Yes and they had to lie to sell that option. If they honestly informed customers about the tradeoff between security and convenience they'd certainly have far fewer customers. Instead they lead people to believe that they can get that convenience for free. The obvious better choice is transparancy.

> tradeoff between security and convenience they'd certainly have far fewer customers What? Most people, thinking through the tradeoff, would 100% not choose to be in charge of safeguarding their own key, because they're more worried about losing everything on their PC, than they are about going to jail. Because most people aren't planning on doing crime. Yes, I know people can be wrongly accused and stuff, but overa…

That's exactly what I mean.

If you tell people, "I'll take care of safeguarding your key for you," it sounds like you're just doing them a favor.

It would be more honest to say, "I can hold on to a copy of your key and automatically unlock your data when we think you need it opened," but that would make it too obvious that they might do so without your permission.

Post reply on HN