> Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt. What does this even mean? Nobody is using multiple encryption schemes on top of each other, are they?
I've heard this before, so what I think it means is this: If you want to encrypt some data that gets stored persistently somewhere on your machine, rather than invent an application-specific encryption scheme for that data alone, instead use a mainstream full-partition encryption mechanism, then store the data as plaintext within said partition.
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
271–280 of 280 posts
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#272Well I doubt anyone would be surprised with a backdoor in MS product, there have been many of them already, I frankly doubt anyone with "disk encryption" on Windows would think that it's NSA-proof (or script-kiddy clever, as shown in this article :))
source: trust me bro
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#273Earlier quoted context omitted.
Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.
Whose/Which Windows password? The OS is inherently multi-user. Plus if you ever needed to change or reset your password, that complicates the encryption.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#274Earlier quoted context omitted.
Don't be so sure. Veracrypt is a fork of Truecrypt, which was famously shuttered after security rumours started spreading - all the way to NSA interventions aimed at the developers. One rumour even said they intentionally shut it down to prevent a possible backdoor compromise. Popular encryption tools for public use will always be priority targets for three letter agencies. And there's more than enough legal leeway h…
In my humble opinion US TLAs don't need to touch Veracrypt at all. They are already in Windows, so keymaterial exfiltration is probably a child's play for them.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#275Earlier quoted context omitted.
macOS solved this (and a lot of other problems) by putting the OS on a separate read-only partition - technically an APFS volume - that doesn’t get encrypted. Microsoft’s backwards-compatibility obsession might not let them make that the default, but they could at least make it an option.
Not encrypting the OS means it's no longer considered FDE in my opinion. But Windows doesn't need the OS to decrypt a BitLocker volume anyway because the bootloader can do it... otherwise how could a FDE disk ever boot in the first place?
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#276Earlier quoted context omitted.
Not encrypting the OS means it's no longer considered FDE in my opinion. But Windows doesn't need the OS to decrypt a BitLocker volume anyway because the bootloader can do it... otherwise how could a FDE disk ever boot in the first place?
Why not? The macOS OS partition is signed and read-only. Unless you disable SIP (which you shouldn't), your OS partition is bit-for-bit identical to everyone else's.
Unless I want to change it... or have multiple OSes/partitions where I need the entire disk encrypted.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#277Earlier quoted context omitted.
Simple hypothetical: "A disaster hits and the workstation owner is unable to return to the location the workstation is stored. During that time period the workstation is stolen by a gang of looters."
Ah yes a typical Tuesday for me
The good thing though: the effort is low. You think through it once and you have your encryption and backup strategy for a long time.
I have a NAS System which only runs when i need it, i scrub every month and that basic setup is the same for the last 12 years.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#278Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#279Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#280Earlier quoted context omitted.
Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.
If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…