Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

261–270 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#261

Earlier quoted context omitted.

> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). Yes this is the one I'm referring to. I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.

Bitlocker can be suspended, and will be unprotected until the next reboot. Then it will resume (and presumably re-lock to the current state) A good or corporate BIOS/etc. updater will do this to avoid requiring a recovery at the next boot

> Bitlocker can be suspended

But the files on the disk must still be decrypted somehow. The key must be stored somewhere.

According to this: https://windowsforum.com/threads/pause-bitlocker-before-bios...

> BitLocker is now suspended, which means the drive remains encrypted, but Windows temporarily stores the unlock information so firmware changes won’t immediately trigger recovery.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#262

Earlier quoted context omitted.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

"Not being a team player" doesn't mean the person is a nuisance, but they can be an introvert who has a limited interaction budget and can work silently and efficiently otherwise. This generally means the person might not leave their cubicle much or give feedback frequent enough, but this doesn't mean they are not motivated to help others or share knowledge. One can approach and ask a question and get tons of help im…

I have worked with lots of introverts and my empirical observation is that the introversion/extraversion axis is completely orthogonal to whether or not someone can be a team player.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#263

Earlier quoted context omitted.

The author says he is able to use a similar vuln to bypass the PIN requirement. Most certainly a backdoor if true.

> Most certainly a backdoor if true If Microsoft wanted a backdoor they don't need to put it in the WinRE environment. They can sign payloads that will pass the TPM and unlock bitlocker, without needing to store anything on your disk.

Except with TPM+PIN, the TPM itself is verifying the PIN before unsealing any keys... so something else must be going on if they're telling the truth about a PIN exploit.

Maybe their alleged exploit doesn't work on a cold boot or has some other non-standard situation.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#264

Earlier quoted context omitted.

For example pointing to the research confirming that Veracrypt is not secure somehow (if such belief has any justification in facts).

Then say that. Sorry, I just hate how overused that meme is as it's rarely helpful and doesn't add to the conversation.

I would say being skeptical and calling out FUD is more helpful than being silent and letting people believe them.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#265
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

What? Why?

They don't know why because there isn't a good reason to distrust them.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#266
post #100

Earlier quoted context omitted.

>so they had to make a seemingly ridiculous statement (because who in their right mind would trust bitlocker) to call attention that "something is very wrong" Alternately, they don't want people to rely on abandonware for security. Also, despite the conspiracy theories of backdoors I'm not aware of any bitlocker exploits that work on TPM + pin, which is the intended "secure" configuration[1]. All exploits rely on TPM…

Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.

Whose/Which Windows password? The OS is inherently multi-user.

Plus if you ever needed to change or reset your password, that complicates the encryption.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#267
post #138

Earlier quoted context omitted.

You need a separate pin because windows lives on the encrypted disk so you need to decrypt it before you can boot completely.

macOS solved this (and a lot of other problems) by putting the OS on a separate read-only partition - technically an APFS volume - that doesn’t get encrypted. Microsoft’s backwards-compatibility obsession might not let them make that the default, but they could at least make it an option.

Not encrypting the OS means it's no longer considered FDE in my opinion.

But Windows doesn't need the OS to decrypt a BitLocker volume anyway because the bootloader can do it... otherwise how could a FDE disk ever boot in the first place?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#268

Earlier quoted context omitted.

You need a separate pin because windows lives on the encrypted disk so you need to decrypt it before you can boot completely.

Couldn't they just use the PIN also Windows password? Then the PIN screen would have to look like the Windows login screen.

what about systems with multiple users?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#269
post #82

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

My data is mundane and mostly my art projects and photography. I don’t believe I am important or interesting enough for someone to do anything with my data if they somehow managed to get it also I don’t have emails, saved passwords, banking info or that kind of sensitive info on my computers so meh I guess.

> I don’t have emails, saved passwords, banking info or that kind of sensitive info on my computers

Then where do you have it? Notes on a post-it? Or is this a very specific definition of "computers"?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#270
post #32

"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…

Nothing against VeraCrypt, but isn't it also a single encryption system?
Post reply on HN