Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

251–260 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#251
post #142

Earlier quoted context omitted.

Nothing has changed? Microsoft is a huge open source contributor now, produced one of the largest open source ecosystems in use (.NET) and provides free access to the biggest open source software repositories (GitHub). Sorry to say, but believing nothing with MS has changed is deranged.

I view it as new paint on same crappy house. They had to do the open-source thing for .NET because of external pressure - not because they've changed. They had to get GitHub because of the eyeballs. It's not some altruistic play. In both cases some VPs spun it around, juked the stats and got their bonus. The first E of EEE feels so good makes you forget the inevitable outcome. Like heroin.

> They had to do the open-source thing for .NET because of external pressure - not because they've changed.

Corporations don't have some innate "essence" that defines their nature, their behaviour is defined by internal and EXTERNAL factors, yes. So what?

The very fact that you recognize that external factors have influenced how they approach open source is a tacit acknowledgement that their behaviour has indeed changed.

> They had to get GitHub because of the eyeballs. It's not some altruistic play.

No corporation is completely altruistic, so what?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#252
post #145

Earlier quoted context omitted.

Nothing has changed? Microsoft is a huge open source contributor now, produced one of the largest open source ecosystems in use (.NET) and provides free access to the biggest open source software repositories (GitHub). Sorry to say, but believing nothing with MS has changed is deranged.

> produced one of the largest open source ecosystems in use (.NET) Are they going to ship an official cross platform UI library any time the next century? Decades after the Java lawsuit they still ship only a crippled copy of their scrapped Microsoft JVM for other platforms. > Microsoft is a huge open source contributor now Aren't almost all of their contributions for integration with their proprietary technology? >…

> Are they going to ship an official cross platform UI library any time the next century?

So because they haven't produced your pet project means they haven't changed?

> Aren't almost all of their contributions for integration with their proprietary technology?

No. They didn't have to make .NET cross platform and run equally well on Linux, they didn't have to join the Linux foundation and make contributions to the Linux kernel. There are hundreds if not thousands of examples like this that would have been unthinkable under Gates and Balmer Microsoft.

> Windows 11 meanwhile makes me wait for them to add a robotic arm with a knife as hardware requirement, to improve the backstabbing experience.

Microsoft is much, much larger than just Windows. You seem to have a very limited understanding of everything they do.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#253

Earlier quoted context omitted.

Nothing has changed? Microsoft is a huge open source contributor now, produced one of the largest open source ecosystems in use (.NET) and provides free access to the biggest open source software repositories (GitHub). Sorry to say, but believing nothing with MS has changed is deranged.

Nothing has changed except that it's even worse now than before, and the venue or arena changes every few years (os to developer tools to office to cloud etc). vscode or .net core or whatever you think is so valuable does not make MS your friend any more than giving you free IE did. Come the fuck on. It is beyond ignorant to try to make this argument. (or it's perfectly consistent with having a financial interest) I…

No real open source contributor thinks any corporation is "their friend", whatever that means. And yet, it is undeniably true that being a Linux foundation member and contributor, producing and maintaining one of the largest programming language ecosystem and runtimes currently in use, and running the largest open source friendly source code repositories for free, would have been unthinkable under Balmer or Gates' Microsoft, and if you think otherwise, you should look in the mirror for that ignorance you mentioned.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#254

Earlier quoted context omitted.

> The secret here seems to be that Microsoft caches the key somewhere even when it's supposed to be only in the TPM! Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). In the default TPM-only mode of BitLocker, the secret is in fact in the TPM, which will (as instructed by Windows upon key creation) release it to the correct OS running on the correct computer. Notably not in the picture…

> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). Yes this is the one I'm referring to. I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.

Bitlocker can be suspended, and will be unprotected until the next reboot. Then it will resume (and presumably re-lock to the current state)

A good or corporate BIOS/etc. updater will do this to avoid requiring a recovery at the next boot

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#255
post #145

Earlier quoted context omitted.

> produced one of the largest open source ecosystems in use (.NET) Are they going to ship an official cross platform UI library any time the next century? Decades after the Java lawsuit they still ship only a crippled copy of their scrapped Microsoft JVM for other platforms. > Microsoft is a huge open source contributor now Aren't almost all of their contributions for integration with their proprietary technology? >…

> Are they going to ship an official cross platform UI library any time the next century? So because they haven't produced your pet project means they haven't changed? > Aren't almost all of their contributions for integration with their proprietary technology? No. They didn't have to make .NET cross platform and run equally well on Linux, they didn't have to join the Linux foundation and make contributions to the Li…

> So because they haven't produced your pet project means they haven't changed?

Good to know that their flagship cross platform framework not even having an UI component rates "pet project".

> No. They didn't have to make .NET cross platform and run equally well on Linux

Which they never did, instead they renamed .Net core, which to this day isn't a feature complete replacement for .Net.

> they didn't have to join the Linux foundation and make contributions to the Linux kernel.

Given that they sell cloud products with Linux integration, yes they did?

> Microsoft is much, much larger than just Windows.

And here I thought everything they do is compensation for being tiny, I mean it is literally in the name.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#256

Earlier quoted context omitted.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

You require both team players and "rockstar" individuals. It's not one or the other or a competition, because they do different things. Yes if you put a someone who can't work on a team on a team and expect team work then that will not work. But that's obvious, so then don't do that. Expecting a homogeneous workforce isn't realistic or optimal.

>You require both team players and "rockstar" individuals.

Hard disagree.

Some of the best, most successful, and most impactful projects I've ever been on had no "rockstars" at all.

People who refer to themselves as rockstars is a huge red flag.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#257

Earlier quoted context omitted.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

I'm not a software engineer at all. And I tend to take on projects nobody else wants because they are too complicated or esoteric. And I didn't say I'm not capable of being part of a team. Just that I need to have my own responsibilities within a team. I can't deal with micromanagement or excessive coordination like 'standups' every day.

[deleted]

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#258

Earlier quoted context omitted.

if you have ever dealt with a regulated institution, they have an obligation to publicly report lost and stolen devices that contain PII/PHI as a breach, and the people whose data was on the device must be notified. It's a huge deal that has board level involvement when it occurs. The ONLY control that mitigates this risk is disk encryption, and it is perniciously misleading to ship a sabotaged product on which these…

I commented because I've worked with regulated institutions where FDE was standard across the org. Bitlocker was laughed at whenever you mentioned it by name, there was not a single engineer I met that took it seriously (even the Windows daily drivers). Microsoft Windows is consistently identified as the weakest link for securing sensitive data, one job even had a no-fly policy for Windows laptops in case they were m…

we all know there are limits and vulnerabilities to manage in products. however, this backdoor appears to be a misrepresentation of the core function of the product. if you deployed something you believed to be a joke, you may be the sucker at that table, as thats culpable.

maybe the license language means they make no reps about security, but if this is as described they have compromised the compliance of their customer base.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#259

Does this mean every corporate windows laptop can basically be exploited to extract confidential information?

Only if:

- The device isn't PIN-protected (doesn't ask for a Bitlocker password on startup)

- It runs a vulnerable version of Windows (apparently anything after 10 and before whatever version Microsoft will probably patch it in)

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#260

Earlier quoted context omitted.

> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). Yes this is the one I'm referring to. I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.

> A normal reboot always [forces the TPM pin entry screen], even a 'hot' reboot. In TPM-only mode, I only see the screen—which asks for an recovery key that serves an alternative to the TPM-borne secret, not for whatever you are calling the “TPM PIN” here—whenever I update the firmware or the bootloader (the latter from the other side of the dual-boot setup). Otherwise it boots straight to the login screen, which mes…

No I have the explicit PIN turned on. That means it requires a Pin entry on each boot. It's not the recovery screen though it looks similar. It's also not a password that's then hashed. It unlocks the TPM with a short pin, the number of attempts is limited by the TPM itself so that it doesn't get brute forced.

This is not a standard option, I think it can only be set through a group policy.

Post reply on HN