Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

201–210 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#201
post #172

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

Nonsense. there are way more accommodations for people who wouldn't have had a place 20 years ago... those accommodations have changed what a "standard IC" is. There never was a place for run-of-the-mill geniuses who couldn't be bothered to spend a few hours researching P2P (Person to Person) protocols. They were always pushed off to small companies where the risk was much lower. This hasn't, won't, and shouldn't change. If that makes you salty, I got some things I'd recommend you research.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#202
post #32

"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…

Or use something like veracrypt which is opensource

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#203

This doesn't sound bitlocker specific, sounds more like a login bypass. If you rely on TPM without PIN then it gets decrypted automatically. This should be fine normally as attackers shouldn't be able to get past login screen. But this exploit shows a way allegedly to get a unrestricted shell in the recovery environment. The researcher claims a way to bypass PIN too but hasn't revealed it.

Probably since disclosure didn't result in a bounty may as well sell it to someone who would pay.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#204
post #172

Earlier quoted context omitted.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you.

You might be a 100x rockstar developer. You might even be the best software engineer in the world.

But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others.

I'd rather have a team of "merely" good engineers than one "rockstar" creating a toxic work culture. Fuck that noise.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#206

Earlier quoted context omitted.

Someone who doesn't have better options?

If you have those sorts of skills with a computer, you will have other options

Oh hell, no. Does anyone remember Sandboxescaper/Polarbear? Very skilled researcher, but also crashouts and mental problems.

Had a job at MSFT once, but is now struggling to earn money at all and is posting heart breaking stuff on Twitter. https://x.com/WeirdQuadratic

Hope she finds a way out and a more stable and fun job in the future.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#207
post #32

"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…

Or use something like veracrypt which is opensource

Don't be so sure. Veracrypt is a fork of Truecrypt, which was famously shuttered after security rumours started spreading - all the way to NSA interventions aimed at the developers. One rumour even said they intentionally shut it down to prevent a possible backdoor compromise. Popular encryption tools for public use will always be priority targets for three letter agencies. And there's more than enough legal leeway here to compromise anyone and anything. If it is popular enough for you to see it mentioned outside of dedicated nerd forums, you can bet these agencies already target it.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#208

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

Why is 'conspiratorial' posed as a prime facie _bad thing_ to posit?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#210

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly. And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with…

> we shouldn't be against the person who expected an organization with more money than God to uphold a deal for relative peanuts, right?

You're assuming that there was a deal that wasn't upheld. I don't think we have enough information to assess that. This person's blog posts do read as being somewhat unstable. There's even someone in the comments seemingly genuinely trying to be helpful: "Just wondering if you’re BiPolar (like me) and see a different reality than what is real. Been there."

Post reply on HN