Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

181–190 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#181

Earlier quoted context omitted.

This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly. And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with…

I'm supposed to feel bad that Microsoft didn't immediately wire him an advance on the bounty before validating anything? Have you ever tried to get anything corrected with a corporate payroll department? Try three months minimum. It's like suggesting someone was relying on a lottery ticket to payout to survive.

I tried to be as coddling with my language as possible.

Acknowledged how orgs work, separated blaming the org from sympathizing with their reaction, tried to separate the prudence of their actions from the sticky situation they'd still be left in by the orgs actions...

But it was for naught: people are really ingrained in a weird "might-makes-right" model of corporate operations. "Larry Ellison is a lawnmower" was supposed to be a jeremiad but now it's more like a guiding principle that we browbeat anyone for questioning.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#182
You should always assume that US/european corporate protections are backdoored, now MS, a couple days ago we knew about whatsapp, and I would also include all corporate “secure or encrypted” promises, so I would warn against signal, proton, and the likes. This is the work of NSA, providing a “secure” platforms and push it everywhere to get adopted, providing false sense of security, while depreciating the none bugged ones, few weeks ago verascript developer -Mounir Idrassi- complained about having their account blocked, same with wireguard facing similar issues, and if you find it hard to believe, GPG author -Zimmerman- was harassed by the gov because he wrote the encryption and encryption was considered munition, so he was exporting munition!

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#183
post #14

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.

I would. It doesn't even require theft. The naive burglary mitigation is just a happy accident.

I want the crypto-shredding retirement of each storage device. I don't assume I can delete/scrub/overwrite at the time a device goes out of service. I have a box of older HDDs that I still have to get around to destroying properly, because they exist from before the days of practical FDE.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#184
post #151

Earlier quoted context omitted.

Previously discussed numerous times on HN, like: https://news.ycombinator.com/item?id=48130519 Whether this is a backdoor or not boils down to whatever your usual proclivities about "bug or backdoor" are; it's not like "if microsoft = 1 hack bitlocker" like the tech press seem to love to report. This is a bug in the NTFS transaction log replay functionality in the Windows Recovery Environment WinRE, where it will rea…

It's very strange that the same component exists in Windows without the issue, though. Like the author, I'm finding it difficult to come up with reasons why they'd be different.

WinRE ending up with a different version of fstx.dll in it seems like a pretty standard Microsoft (or any other big company) thing to have happen? Again, it all comes down to whether you think the drift was a malicious internal fork or a simple mistake. I will say that the functionality being different makes it an inferior backdoor in many ways; especially in Windows land vulnerability researchers are obsessed with binary diffing, and any delta internally would be more likely to be discovered as a backdoor in review too (ie - “hey maybe we should update fstx in winrt finally, let’s review the drift to make sure there’s not going to be a regression, wait a second why did xyz employee add this suspicious looking code”).

A fun next step would be to look at different fstx versions to see if it’s just something that was patched or refactored out at some point. At that point it could be a patch-door (ie an organic bug where the patch was held back by interference), but again, that would be a crappy setup due to the propensity for Windows vulnerability engineers to use binary diffing - if you had the exploit and the power to hold back the patch, it would be way better to hold it back everywhere.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#185

Earlier quoted context omitted.

If you have those sorts of skills with a computer, you will have other options

We are, quite notably, in a huge hiring crisis where vast numbers of programmers and researchers can't even get interviews. It really is not that simple

[deleted]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#186
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

> not with even with your computer would I run VeraCrypt This has got to be the most surprising encryption-related comment I've ever read from you. Please tell us what you're thinking about VeraCrypt. What would you say about TrueCrypt v7.1a, the last known good release?

I would also love to hear specific opinions about VeraCrypt because I need to get some Windows users to encrypt some of their seldom-used sensitive files, like HR for example.

They can't use age or any other "right answer" tools. I'm talking about people who don't know their own username, people who don't know that their Windows password is the one they use to log into Windows. "Is that for my email?" Just getting them to use a password manager is like arm wrestling an aligator. If VeraCrypt isn't the best option for them, then what is?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#187
Lots and lots of smattering around here. If anything, this is a secure boot flaw (and partially TPM), but that is a separate conversation. Also, it's been known for years that TPM based encryption should always be protected with a PIN for truly sensitive data: https://learn.microsoft.com/en-us/windows/security/operating...

The author claims to be able to bypass TPM + PIN protection, but I seriously doubt it because that would require breaking or exploiting the TPM itself. Perhaps the author was referring to existing fTPM flaws but even then, brute-forcing the PIN would still be required because on BitLocker, the wrapped VMEK depends on the PIN, which brings me to the "backdoor" topic. As I have already mentioned, exploits have been found in AMD fTPMs in the past (https://arxiv.org/abs/2304.14717). This flaw is particularly severe on Linux/cryptenroll because the TPM returns the actual FVEK, unlike BitLocker, where the VMEK itself depends on the PIN. This cryptenroll flaw has been known for years and remains unfixed on cryptenroll (https://github.com/systemd/systemd/pull/27502). Yet, I see no one yelling and crying "backdoor", or accusing Lennart of being compromised. Cryptography, especially when combined with hardware security, is inherently not easy — and people make mistakes.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#188
post #87
post #81

Earlier quoted context omitted.

Ubuntu also released TPM based FDE a few versions ago. I had these thoughts then and decided against using it. Typing my passphrase on boot is muscle memory and gives me simple security I can trust. Also can recover data without my mainboard. Maybe a hybrid (secureboot-TPM+phrase) slot for day to day to also prevent against evil maid attacks, and another slot with a backup passphrase would be acceptable.

>Typing my passphrase on boot is muscle memory and gives me simple security I can trust. It's not an either-or. You can combine TPM with passwords which makes it far more secure than password alone. A TPM can enforce password guessing limits, otherwise a password needs to be absurdly long to be secure against GPU bruteforcing attacks. It also prevents someone from swapping out the bootloader with a backdoored version…

> It's not an either-or. You can combine TPM with passwords which makes it far more secure than password alone.

No. I have already explained it here: https://news.ycombinator.com/item?id=48133491

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#189
post #54

Earlier quoted context omitted.

How would that leave them homeless?

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

To be honest if I got fired in a mean or unfair way I'd definitely hit back at my employer in such a manner if I'd have the ability to. I'm unlikely to have that though as I'm not aware of any saucy company secrets. But if this is what happened I think it's pretty justified.

The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM! That's a pretty big revelation IMO.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#190
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

[citation needed]

How would one cite a personal belief?
Post reply on HN