Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

341–350 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#342
post #228

Earlier quoted context omitted.

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

Do we have confirmation that it’s a must to upload the key if you use an MS account with Windows? Is it proven that it's not possible to configure Windows to have an MS account linked, maybe even to use OneDrive, while not uploading the BitLocker key? Btw - my definition of “possible” would include anything possible in the UI - but if you have to edit the registry or do shenanigans in the filesystem to disable the up…

I just checked on my personal desktop, which has Windows 11 installed using a local user account and is signed into my MS account for OneDrive and my account is listed as having no recovery codes in the cloud. I don’t recall editing anything in the registry to accomplish this it was the default behavior for having a local user account. I copied my recovery codes when I built the machine and pasted them into an E2EE iPhone note which should allow me to recover my machine if disaster strikes (also everything is backed up to Backblaze using their client side encryption).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#343

Earlier quoted context omitted.

I can't believe it took this long. We have mandatory identification for all kinds of things that are illegal to purchase or engage in under a certain age. Nobody wants to prosecute 12 year old kids for lying when the clicked the "I am at least 13 years old" checkbox when registering an account. The only alternative is to do what we do with R-rated movies, alcohol, tobacco, firearms, risky physical activities (i.e. bu…

The problem is the implementation is hasty. When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. We can't trust every private company that now has to verify age to not store that information with whatever questionable security. If we aren't going to…

I definitely don't disagree that the implementation is problematic, I'm just surprised it took this long for it to happen.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#344

Earlier quoted context omitted.

I'll always remember - when I was first learning about it, one of the interesting counter-arguments to ignoring privacy was "what if the Nazis come back, would you want them to have your data?". I suppose there's some debate these days, but hostile governments seem a lot closer than they were 10-15 years ago. Will this make people care? Probably not, but you never know.

"Closer"? They're already here. Trusting corporations or governments is inherently moronic.

Even in the best of times. Why widen your attack surface unnecessarily? Do you tell people your passwords and PINs at parties?

What governments and corporations (and plenty of bad actors in the FOSS world) have done is make this the default; made it easy to mindlessly hand people your privacy without even knowing. Opt-out, if you know the setting exists, and can find it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#345

Earlier quoted context omitted.

I can't believe it took this long. We have mandatory identification for all kinds of things that are illegal to purchase or engage in under a certain age. Nobody wants to prosecute 12 year old kids for lying when the clicked the "I am at least 13 years old" checkbox when registering an account. The only alternative is to do what we do with R-rated movies, alcohol, tobacco, firearms, risky physical activities (i.e. bu…

The problem is that there is nothing done to protect privacy. There is already plenty of entities that not only have reliable way of proving it's you that have access to account, but also enough info to return user's age without disclosing anything else, like banks or govt sites, they could (or better, be forced to) provide interface to that data. Basically "pick your identity provider" -> "auth on their site" -> "st…

I don't disagree that the implementation is all kinds of wrong. I'm just surprised it took them this long to compel it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#346
post #154

Earlier quoted context omitted.

Uploading your encryption keys is not just "any sort of feature".

You're right, it's less intrusive than uploading your files directly, like a backup does.

On the contrary: a backup can be fully encrypted by a key under the user's control that isn't available to the storage provider.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#347

Earlier quoted context omitted.

The problem is the implementation is hasty. When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. We can't trust every private company that now has to verify age to not store that information with whatever questionable security. If we aren't going to…

> When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. Beer, sure. But if you buy certain decongestants, they do log your ID. At least that's the case in Texas.

In PA they scan your ID if you buy beer. There could be a full digital record of all my beer purchases for past 15+ years, although I'm not aware of any aggregation of this data that is happening. Not that I expect anyone doing it would talk about it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#348

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

Just remember, never use or recommend Debian-family(Ubuntu/Mint) or you will be back to windows. Do not fall for the marketing term Stable, which means outdated and contains bugs that are fixed. Fedora is my recommendation. I remind people Fedora is not Arch. Fedora is a consumer grade OS that is so good, I don't lump it in with the word Linux.

Once you've got a bit of savvy, do Arch. But if you're looking for "good" and "just works" and you don't want to tinker and/or occasionally scream at your computer in inchoate fury, Fedora is the way.

You can build your ideal fantasy setup piecewise, and I definitely recommend getting there, but Fedora is nice, and clean, and has plenty of "just works", and 99.999% of the problems you might run into, someone else has, too, and they wrote a treatise and tutorial on how to fix it and why it happened.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#349

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance. Most of the comments are fire and resistance, but they commonly take ragebait and run with the assumptions built-in to clickbait headlines. > Too many tech workers decided to rollover for the government and that's why we are in this mess now. I take it you've never worked at a company when law enforcement comes knocking for data? The internet tough guy fantas…

> I take it you've never worked at a company when law enforcement comes knocking for data? The solution to that is to not have the data in the first place. You can't avoid the warrants for data if you collect it, so the next best thing is to not collect it in the first place.

Until the NSA knocks on your door and says encrypt it like this.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#350
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Microsoft could have done key backups to secure enclaves that will only return them to a user able to produce valid signatures using a backup code or otherwise they hold. Hell they were the ones that normalized remote attestation.

But Microsoft chose to keep them plain text, and thus they are, and will continue to be abused.

We must not victim blame. This is absolutely corruption on microsofts part.

Post reply on HN