Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

201–210 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#201
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

That's a distinction without a difference. Microsoft should structure Windows such that they're unable to comply with such an order, however legal. There are practical cryptographic ways to do it: Microsoft just doesn't want to. Shame on them.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#202
post #25

Earlier quoted context omitted.

If you have advanced data protection enabled, Apple claims: “No one else can access your end-to-end encrypted data — not even Apple — and this data remains secure even in the case of a data breach in the cloud.” https://support.apple.com/en-us/102651

Please read this section of Apple's own document before you talk about their "advanced data protection". The following information may be available from iCloud if a user has enabled Advanced Data Protection for iCloud: https://www.apple.com/legal/privacy/law-enforcement-guidelin... Do you think Tim Cook gave that gold bar to Trump for nothing?

> For users that have enabled Advanced Data Protection, iCloud stores content for email, contacts, and calendars that the customer has elected to maintain in the account while the customer’s account remains active. This data may be provided, as it exists in the customer’s account, in response to a search warrant issued upon a showing of probable cause, or customer consent.

> Apple does not receive or retain encryption keys for customer’s end-to-end encrypted data. Advanced Data Protection uses end-to-end encryption, and Apple cannot decrypt certain iCloud content, including Photos, iCloud Drive, Backup, Notes, and Safari Bookmarks

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#203
post #151

Earlier quoted context omitted.

> tradeoff between security and convenience they'd certainly have far fewer customers What? Most people, thinking through the tradeoff, would 100% not choose to be in charge of safeguarding their own key, because they're more worried about losing everything on their PC, than they are about going to jail. Because most people aren't planning on doing crime. Yes, I know people can be wrongly accused and stuff, but overa…

That's exactly what I mean. If you tell people, "I'll take care of safeguarding your key for you," it sounds like you're just doing them a favor. It would be more honest to say, "I can hold on to a copy of your key and automatically unlock your data when we think you need it opened," but that would make it too obvious that they might do so without your permission.

I think most people would be ok with your second formulation too.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#204
Title should read "Microsoft confirms it will give the FBI your Windows PC data encryption key if court-ordered to do so".

Just because the article is click bait doesn't mean the HN entry needs to be, too.

Sure, the fact that MS has your keys at all is no less problematic for it, but the article clearly explains that MS will do this if legally ordered to do so. Not "when the FBI asks for it".

Which is how things work: when the courts order you to do something, you either do that thing, or you are yourself violating the law.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#205

Earlier quoted context omitted.

https://linuxmint.com/ https://ubuntu.com/download/desktop https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.

And MacOS, which I suspect may be the more obvious choice for many users.

macOS and iOS both send Push Notification data directly to the US federal government, according to Senator Ron Wyden: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#207
post #21

Earlier quoted context omitted.

Sure, but these are all mere statements. You don't know if they fully back that until there's a public standoff with law enforcement/administration and there weren't any in recent years. Yet at the same time it's hard to believe there were no attempts from that government to decrypt some devices they needed. So the fact we hear nothing about it is also an information to me. Sure, this is all speculation, but all thin…

They fully comply with Chinese requirements if you subscribe to iCloud in China, and they do this quite transparently. They do not, notably, say they don't share anything with China and then go ahead and do it anyway. Unless Apple is straight up lying about their technology and encryption methods used to secure iCloud and their hardware, the issue of a public standoff is moot, because Apple couldn't help them if they…

> Unless Apple is straight up lying about their technology and encryption methods

Which, to be clear, is perfectly possible. Apple has denied the existence of a deliberately backdoored system at least once before: https://arstechnica.com/tech-policy/2023/12/apple-admits-to-...

  Apple has since confirmed in a statement provided to Ars that the US federal government “prohibited” the company “from sharing any information,” but now that Wyden has outed the feds, Apple has updated its transparency reporting and will “detail these kinds of requests” in a separate section on push notifications in its next report.
Who knows what else they're hiding, if we only found out about this scheme in 2023.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#209
post #140

The headline is misleading. It says that Microsoft will provide the key if asked , but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order . These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Mi…

Microsoft is legally entitled to refuse absent a warrant, but generally all it takes is a phone call from the FBI to get big tech to cough up any authenticating info they actually have.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#210

Earlier quoted context omitted.

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

For something as widely adopted as Windows, the only sensible alternative is to not encrypt the disk by default. The default behavior will never ever be to "encrypt the disk by a key and encrypt the key with the user's password." It just doesn't work in real life. You'll have thousands of users who lost access to their disks every week.

It works for macOS. Filevault key is encrypted by user password. User login screen is shown early in boot process, so that Filevault is able to decrypt data and continue boot process. It sure works fine for a about a decade. No TPM nonsense required. Imo, the TPM based key only makes sense for unattended systems such as servers.
Post reply on HN