Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

221–230 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#221
post #184

Earlier quoted context omitted.

It's very strange that the same component exists in Windows without the issue, though. Like the author, I'm finding it difficult to come up with reasons why they'd be different.

WinRE ending up with a different version of fstx.dll in it seems like a pretty standard Microsoft (or any other big company) thing to have happen? Again, it all comes down to whether you think the drift was a malicious internal fork or a simple mistake. I will say that the functionality being different makes it an inferior backdoor in many ways; especially in Windows land vulnerability researchers are obsessed with b…

I'm not necessarily suggesting they intentionally made the dll different for RE. The possibility that RE was maliciously backdoored is certainly possible, but there are three plausible other possibilities I can see:

1. A bug was introduced that affects both, and the bug never make it back into the 11 branch

2. There's conditional logic in RE that triggers the issue

3. 11 introduced new behavior that never make it to RE, causing the bug

The fact that 10 is seemingly unaffected is telling. #2 seems very unlikely, because it suggests new conditional logic was added and not tested. #3 seems unlikely because I can't understand why the binaries would be different anyway. #1 seems unusual because it suggests there's no canonical source of truth for the code, which feels very unlikely for bitlocker of all things (where you want everything speaking the same language).

If there's any benign explanation, I suspect it's likely due to incompetence. This feels like such a strange problem to have. I suspect the follow-ups you suggest are going to happen very soon and we'll know more.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#222
post #213
post #172

Earlier quoted context omitted.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

IC = Independent contractor (I assume?)

https://www.indeed.com/career-advice/finding-a-job/what-is-a...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#223

Earlier quoted context omitted.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

"Not being a team player" doesn't mean the person is a nuisance, but they can be an introvert who has a limited interaction budget and can work silently and efficiently otherwise.

This generally means the person might not leave their cubicle much or give feedback frequent enough, but this doesn't mean they are not motivated to help others or share knowledge. One can approach and ask a question and get tons of help immediately.

How I know? That's me. I look like a cave dweller from a distance, but I'm not. The only difference I have is human interaction sometimes drains me a lot, so I just concentrate and work, yet everybody get their help immediately if they need them.

Also, no, I don't bite or belittle people. On the contrary.

Assuming the worst in others is bad. If I worked with you, I'd be looking for somewhere else the moment I found out how you think about me.

Remember. People don't leave bad jobs, but bad managers.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#224

Earlier quoted context omitted.

Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.

Reporting wrongdoing to the ones doing it doesn't work. Perhaps they relied on Microsoft a bit too much for their livelihood and are just beginning to reevaluate their decisions. It's not so rare for brilliant people to live a life of the mind and not pay enough attention to their material conditions. But defining that as "serious mental health issues" is such a cheap shot.

> Reporting wrongdoing to the ones doing it doesn't work.

Most large companies — including Microsoft [1] — have an internal affairs call center where you can anonymously report issues of malfeasance — assuming that's what happened here.

[1] https://www.microsoft.com/en-us/legal/compliance/sbc/report-...

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#225
post #213
post #172

Earlier quoted context omitted.

There is, sadly, no place for non-standard ICs in corpos nowadays. HR will enforce that.

IC = Independent contractor (I assume?)

individual contributor. Someone who has no one reporting to them.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#226

The real problem with a Bitlocker backdoor or weakness is that when a laptop gets stolen or lost, in most regulated organizations, the criteria for legally declaring and disclosing a breach pivots on whether it was protected by disk encryption. If it's a backdoor, that's a serious fraud against their customers.

This doesn't make much sense. Almost every single organization using Bitlocker knows that it's backdoored. It's like Push Notifications or SMS, warrantless surveillance is the norm and you don't get to opt-out. Nobody's IT department is waking up in cold sweats at the idea of the Fed stealing their data, it's part and parcel with using Windows services. If you really think this will be prosecuted as fraud, then you'l…

if you have ever dealt with a regulated institution, they have an obligation to publicly report lost and stolen devices that contain PII/PHI as a breach, and the people whose data was on the device must be notified. It's a huge deal that has board level involvement when it occurs.

The ONLY control that mitigates this risk is disk encryption, and it is perniciously misleading to ship a sabotaged product on which these legally consequential decisions get made around the world- based on the specific assurance the product is designed and marketed to provide.

If true, it is a specific outrage against the laws of several countries, medical and other research ethics, public health, and the social contracts people have with their institutions. If MS is given impunity for this, a lot of regulation is not worth the paper it is written on.

before arguing further, I recommend looking at the breach notification sections of the laws in these major economies: https://www.dlapiperdataprotection.com/

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#227

Earlier quoted context omitted.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

You require both team players and "rockstar" individuals. It's not one or the other or a competition, because they do different things.

Yes if you put a someone who can't work on a team on a team and expect team work then that will not work. But that's obvious, so then don't do that. Expecting a homogeneous workforce isn't realistic or optimal.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#228

Earlier quoted context omitted.

This is an oddly passive-aggressive comment when a much more likely read is they were relying on the funding and the large tech company did what large tech companies do and started moving slowly. And I can see others already blaming them for relying on the vulnerability for living expenses, but if we can hold the hyper-rationalization for a second, we shouldn't be against the person who expected an organization with…

I'm supposed to feel bad that Microsoft didn't immediately wire him an advance on the bounty before validating anything? Have you ever tried to get anything corrected with a corporate payroll department? Try three months minimum. It's like suggesting someone was relying on a lottery ticket to payout to survive.

Yes and that's bad. Saying it's bad doesn't make it not-bad, it just makes it still bad but now we know it's bad.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#229

Earlier quoted context omitted.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

Yeah you've completely misread this. The phrase "not being a team player" is a euphemism for someone not willing to do dubiously unethical or illegal (or things that go against internal company policy) things in support of a low level supervisor or manager's wishes. Or more favourably, someone who's unwilling to do things outside of what he's actually paid for or to do things unpaid (or outside working hours etc.). Also known as wage theft.

The guy saying that he has been accused of "not being a team player" isn't literally quoting his management here. He's summarizing that his immediate supervisors don't like him because he's unwilling to enter in some patronage like relationship with them.

The fact that you gave the benefit of the doubt to some faceless employer here instead of an actual person recounting his experiences is really sad and maybe ought to be reason for you to rethink your biases to jump to the conclusion that this guy is a toxic loner. Sounds like you're projecting hard here from some other experience.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#230

Earlier quoted context omitted.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

I'm not a software engineer at all. And I tend to take on projects nobody else wants because they are too complicated or esoteric.

And I didn't say I'm not capable of being part of a team. Just that I need to have my own responsibilities within a team. I can't deal with micromanagement or excessive coordination like 'standups' every day.

Post reply on HN