Earlier quoted context omitted.
Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.
> I've told them over and over I'm not capable of that I can relate and empathize. And also provide this suggestion based on my own similar experience: if you can't provide evidence (e.g. doctor's diagnosis) that you are "special" or "not capable of that", then they don't have to care and will take steps to force you out. I wish you all the best.
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
241–250 of 280 posts
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#242Anyone remember “Using TrueCrypt is not secure as it may contain unfixed security issues”? ;)
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#243I just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if…
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#244Earlier quoted context omitted.
> not with even with your computer would I run VeraCrypt This has got to be the most surprising encryption-related comment I've ever read from you. Please tell us what you're thinking about VeraCrypt. What would you say about TrueCrypt v7.1a, the last known good release?
I would also love to hear specific opinions about VeraCrypt because I need to get some Windows users to encrypt some of their seldom-used sensitive files, like HR for example. They can't use age or any other "right answer" tools. I'm talking about people who don't know their own username, people who don't know that their Windows password is the one they use to log into Windows. "Is that for my email?" Just getting th…
Generally I’d say this is what Sharepoint or Box or a more workflow-specific platform is for. You generally don’t want sensitive data living on individual people’s workstations in an enterprise context, you want it somewhere that you can enforce security settings.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#245Earlier quoted context omitted.
> The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM! Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). In the default TPM-only mode of BitLocker, the secret is in fact in the TPM, which will (as instructed by Windows upon key creation) release it to the correct OS running on the correct computer. Notably not in the picture…
> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). Yes this is the one I'm referring to. I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.
In TPM-only mode, I only see the screen—which asks for an recovery key that serves an alternative to the TPM-borne secret, not for whatever you are calling the “TPM PIN” here—whenever I update the firmware or the bootloader (the latter from the other side of the dual-boot setup). Otherwise it boots straight to the login screen, which meshes with the measured-boot-only theory of operation I’ve described above. There’s nothing nefarious in this part, even if I think it exposes an unwisely large attack surface (e.g. the USB stack). I suspect you simply reboot so rarely you’re never hitting the happy path.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#246Earlier quoted context omitted.
My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)
Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#247Earlier quoted context omitted.
Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.
You need a separate pin because windows lives on the encrypted disk so you need to decrypt it before you can boot completely.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#248Earlier quoted context omitted.
How would one cite a personal belief?
For example pointing to the research confirming that Veracrypt is not secure somehow (if such belief has any justification in facts).
Sorry, I just hate how overused that meme is as it's rarely helpful and doesn't add to the conversation.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#249Earlier quoted context omitted.
Many brilliant people have serious mental health issues that preclude their ability to regulate their emotions and act maturely in serious situations e.g. responsible vulnerability disclosure. I've watched genius-level IQ people get fired time and again because they don't know how to work with others at a basic kindergarten level.
To be honest if I got fired in a mean or unfair way I'd definitely hit back at my employer in such a manner if I'd have the ability to. I'm unlikely to have that though as I'm not aware of any saucy company secrets. But if this is what happened I think it's pretty justified. The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM! That's a pretty big revelatio…
I knew a contractor that developed a habit of not paying his workers for a short time. After people started walking off job sites with his tools and showing up at his house demanding to get paid, he magically found the money to pay them.
It’s pretty unsurprising how vindictive regular people rapidly become when they’ve been ripped off.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#250Earlier quoted context omitted.
This doesn't make much sense. Almost every single organization using Bitlocker knows that it's backdoored. It's like Push Notifications or SMS, warrantless surveillance is the norm and you don't get to opt-out. Nobody's IT department is waking up in cold sweats at the idea of the Fed stealing their data, it's part and parcel with using Windows services. If you really think this will be prosecuted as fraud, then you'l…
if you have ever dealt with a regulated institution, they have an obligation to publicly report lost and stolen devices that contain PII/PHI as a breach, and the people whose data was on the device must be notified. It's a huge deal that has board level involvement when it occurs. The ONLY control that mitigates this risk is disk encryption, and it is perniciously misleading to ship a sabotaged product on which these…
So remind me how Microsoft was reprimanded for merging Dual_EC_DRBG support into Windows Vista? Or how they were punished for turning over Bitlocker keys to US law enforcement? It never happens. The regulation isn't worth the paper it's written on, and it hasn't been for well over a decade now: https://en.wikipedia.org/wiki/NOBUS