Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

241–250 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#241
post #214
post #193

Earlier quoted context omitted.

You’ve overly simplified the degree to which a company must accept a court order without pushback. First they are capable of fulfilling the request in the first place which means their approach or encryption is inherently flawed. Second companies can very much push back on such requests with many examples of such working, but they need to make the attempt.

I don't think it's reasonable to expect businesses to spend money fighting court orders for customer data, especially if the orders are more or less reasonable. They do seem to be reasonable in the case that brought about this reporting, with substantial evidence that the suspects committed fraud and that evidence is on the devices in question.

Heh, I subpoena'd Microsoft once in part of some FOIA litigation I did against the White House OMB back in 2017. They, in no unclear terms, denied it. We were seeking documentation.

I realize it's not a court order, but just want to add to the stack that there are examples of them being requested to provide something within the public's interest in a legal context (a FOIA lawsuit) where their counsel pushed back by saying no.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#242
post #231
post #227

Earlier quoted context omitted.

Never means the specifics are irrelevant, you’re making the sad argument on the worst possible case and the best one. So why should customers entrust their data to the company? It’s a transactional relationship and the less you do the less reason someone has to pay you. Further, our legal system is adversarial it assumes someone is going to defend you. Without that there’s effectively zero protection for individuals.

People shouldn't entrust highly sensitive data to third parties who aren't highly motivated to protect it. That means different things in different situations, but if you're likely to be investigated by the FBI, don't give Microsoft the encryption keys to your laptop.

As many, many people have pointed out -- many people don't know that their drives are encrypted or know that these protections exist. You're also assuming that the FBI doesn't investigate just random people. "I'm not doing anything bad, why should I worry?"

You're making a lot of assumptions about how people use their computers, their understanding of their own devices, and the banality of building argumentation around what someone should have done or should not have done in the face of how reality works.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#243
post #177
post #149

Earlier quoted context omitted.

Is it meaningfully misleading? How often is this an obstacle for the FBI?

I would guess that the FBI never asks Microsoft for encryption keys without a valid legal order because it knows Microsoft will demand one, and because the FBI rarely has possession of suspect devices without a warrant to search for them and obtain their contents. It could be a bigger obstacle for other agencies. CBP can hold a device carried by someone crossing the border without judicial oversight. ICE is in the mi…

Great comment.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#245
post #177
post #149

Earlier quoted context omitted.

Is it meaningfully misleading? How often is this an obstacle for the FBI?

I would guess that the FBI never asks Microsoft for encryption keys without a valid legal order because it knows Microsoft will demand one, and because the FBI rarely has possession of suspect devices without a warrant to search for them and obtain their contents. It could be a bigger obstacle for other agencies. CBP can hold a device carried by someone crossing the border without judicial oversight. ICE is in the mi…

>I would guess that the FBI never asks Microsoft for encryption keys without a valid legal order

I keep seeing mentions in the news of FBI agents resigning suddenly.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#246

Earlier quoted context omitted.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

Google Authenticator used to be disconnected from reality like this. Users were asking how to copy the codes to another phone, and they said "you can't, WAI, should add the other phone as a second auth method on every site." Like how people say you shouldn't copy SSH privkeys. I figured out an undocumented way to do it on iPhone by taking an encrypted iTunes backup though. Eventually they yielded on this, but their l…

> should add the other phone as a second auth method on every site.

That's the problem right there. Migrating my phone recently (without having broken/bricked the previous one, which is somehow even worse wrt. transferring 2FA these days than getting new phone after old one breaks!), I discovered that most sites I used did not allow more than one authenticator app. If I try to add new phone as second-factor auth method, the website deletes the entry for the old phone.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#247
post #33
post #29

Earlier quoted context omitted.

Thanks, that's good to know. I suspect WhatsApp's "we're fully E2E encrypted" would be similar too.

It's most software. Cryptography is user-unfriendly. The mechanisms used to make it user friendly sacrifice security. There's a saying that goes "not your keys not your crypto" but this really extends to everything. If you don't control the keys something else does behind the scenes. A six digit PIN you use to unlock your phone or messaging app doesn't have enough entropy to be secure, even to derive a key-encryption…

> A six digit PIN you use to unlock your phone or messaging app doesn't have enough entropy to be secure

The PIN is not usually used for cryptography, it's used to authorize the TEE (secure enclave) to do it for you. It's usually difficult or impractical to get the keys from the TEE.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#248
post #11

Earlier quoted context omitted.

Exactly. Being again and again surprised that corporations will defend you for literally no reason is kinda delusional.

That's a reductionist view. Apple, at least, based a big portion of their image on privacy and encryption. If a company does that and is then proven otherwise, it does a tremendous damage to the brand and stock value and is something shareholders would absolutely sue the board and CEO for. Things like these happened many times in the past. This isn't that simple.

Nobody today cares about their encryption, their main sales pich now is convenience and luxury. They still need to comply with law which they do. In US or China. Nothing reductionist about stating a fact.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#249
post #159

Earlier quoted context omitted.

That's why full disk encryption was always a no-go for approximately all computer users, and recommending it to someone not highly versed in technology was borderline malicious. "Tough luck, should have made a backup" is higher responsibility than securing anything in meatspace, including your passport or government ID. In the real world, there is always a recovery path. Security aficionados pushing non-recoverable t…

I had hoped the average person would have a baseline understanding of how computers work by now. Baseline includes things like the difference between a web browser and a search engine, "the cloud" is someone else's computer, and encrypted means gone if you lose the password/key. I am sad that this now appears unlikely. I suspect it may even be lower for people in their 20s today than a decade ago.

> Baseline includes things like the difference between a web browser and a search engine, "the cloud" is someone else's computer, and encrypted means gone if you lose the password/key.

One of these things is not like the other...

That's why I'm stressing the comparison to e.g. government documents: nothing in meatspace requires regular people to show anywhere near as much conscientiousness as handling encryption keys.

Or: many people probably know, in the abstract, that "encrypted means gone if you lose the key", much like many people know slipping up while working on a HV line will kill you. Doesn't mean we should require everyone to play with them.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#250
post #4

Veracrypt https://veracrypt.io/en/Home.html

Let us not forget that the predecessor to VeraCrypt, TrueCrypt, was suddenly discontinued and users were told they should migrate to BitLocker.

There were questions about their motivation at the time. There still are questions.

Post reply on HN