Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

271–280 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#271

> Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt. What does this even mean? Nobody is using multiple encryption schemes on top of each other, are they?

I've heard this before, so what I think it means is this: If you want to encrypt some data that gets stored persistently somewhere on your machine, rather than invent an application-specific encryption scheme for that data alone, instead use a mainstream full-partition encryption mechanism, then store the data as plaintext within said partition.

But how is that not relying on a single encryption system?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#272

Well I doubt anyone would be surprised with a backdoor in MS product, there have been many of them already, I frankly doubt anyone with "disk encryption" on Windows would think that it's NSA-proof (or script-kiddy clever, as shown in this article :))

> there have been many of them already

source: trust me bro

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#273

Earlier quoted context omitted.

Why do you need a separate PIN anyway? Shouldn't your Windows password be enough? Having to enter two different codes makes it unlikely a majority would use the system. I would be surprised if iOS or Android required a separate PIN for encryption.

Whose/Which Windows password? The OS is inherently multi-user. Plus if you ever needed to change or reset your password, that complicates the encryption.

On the other hand, Microsoft has thousands of SWEs, surely a few of them must be smart enough to figure this out.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#274

Earlier quoted context omitted.

Don't be so sure. Veracrypt is a fork of Truecrypt, which was famously shuttered after security rumours started spreading - all the way to NSA interventions aimed at the developers. One rumour even said they intentionally shut it down to prevent a possible backdoor compromise. Popular encryption tools for public use will always be priority targets for three letter agencies. And there's more than enough legal leeway h…

In my humble opinion US TLAs don't need to touch Veracrypt at all. They are already in Windows, so keymaterial exfiltration is probably a child's play for them.

Veracrypt is in part so popular because it has excellent multi-platform support.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#275
post #138

Earlier quoted context omitted.

macOS solved this (and a lot of other problems) by putting the OS on a separate read-only partition - technically an APFS volume - that doesn’t get encrypted. Microsoft’s backwards-compatibility obsession might not let them make that the default, but they could at least make it an option.

Not encrypting the OS means it's no longer considered FDE in my opinion. But Windows doesn't need the OS to decrypt a BitLocker volume anyway because the bootloader can do it... otherwise how could a FDE disk ever boot in the first place?

Why not? The macOS OS partition is signed and read-only. Unless you disable SIP (which you shouldn't), your OS partition is bit-for-bit identical to everyone else's.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#276
post #275

Earlier quoted context omitted.

Not encrypting the OS means it's no longer considered FDE in my opinion. But Windows doesn't need the OS to decrypt a BitLocker volume anyway because the bootloader can do it... otherwise how could a FDE disk ever boot in the first place?

Why not? The macOS OS partition is signed and read-only. Unless you disable SIP (which you shouldn't), your OS partition is bit-for-bit identical to everyone else's.

> your OS partition is bit-for-bit identical to everyone else's

Unless I want to change it... or have multiple OSes/partitions where I need the entire disk encrypted.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#277
post #34

Earlier quoted context omitted.

Simple hypothetical: "A disaster hits and the workstation owner is unable to return to the location the workstation is stored. During that time period the workstation is stolen by a gang of looters."

Ah yes a typical Tuesday for me

I'm not getting insurance for the normal case. I get insurance for the bad cases.

The good thing though: the effort is low. You think through it once and you have your encryption and backup strategy for a long time.

I have a NAS System which only runs when i need it, i scrub every month and that basic setup is the same for the last 12 years.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#280

Earlier quoted context omitted.

Yeah I'm getting a lot of pressure to be a "team player" lately. I've told them over and over I'm not capable of that and that has never been a problem before. But we have a hipster new VP who is really pushy and wants to generalise everything.

If you worked for me and you said you're not capable of being part of a team I'd immediately start looking to replace you. You might be a 100x rockstar developer. You might even be the best software engineer in the world. But the vast majority of good software is built by teams of people. It doesn't matter how good you are if you can't play nice with others. I'd rather have a team of "merely" good engineers than one…

In other words, you want replaceable cogs rather than human beings.
Post reply on HN