Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

361–370 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#362
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

Remember when the original dev of TrueCrypt (the VeraCrypt predecessor) suddenly abandoned the project and wrote that people should use BitLocker instead? [1] [2]

We now know that BitLocker is not secure, and an intelligent open source dev saying that was probably knowingly not saying the truth.

The best explanation to me is that this was said under duress, because somebody wanted people to move away from the good TrueCrypt to something they could break.

[1] https://truecrypt.sourceforge.net

[2] https://en.wikipedia.org/wiki/TrueCrypt#End_of_life_announce...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#363

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

The median user's threat model doesn't include the government, but does include data loss, forgetting the password, or a thief stealing your laptop. Microsoft struck the right balance. I'm glad the knee-jerk absolutists are marginal, for one. A world run by you people would be much worse for anyone who isn't you.

Today the median users threat model absolutely includes the government! They are snatching people up left and right, including their electronics.

I don’t get how people like you trust the corporation or the government that much. If we were all more cognizant of security and privacy, it would be much harder for large orgs to break our society the way they are doing today.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#364

Earlier quoted context omitted.

> it was really easy to set up without a Microsoft account. By "really easy" do you mean you had a checkbox? Or "really easy" in that there's a secret sequence of key presses at one point during setup? Or was it the domain join method? Googling around, I'm not sure any of the methods could be described as "really easy" since it takes a lot of knowledge to do it.

I recently had to install Windows for the first time in ages because reasons, and it really wasn’t very hard. The setup really just presents two options at a time: the cloudy option, and the other option. If in doubt, the flashy one is the cloudy one. I kept selecting the non cloudy option and got to the desktop without signing up for anything. Sure it took more clicking than last time I went through this, but really…

You're a bit vague here, but I'm 99% sure such options were not available when I installed Win 11 a few months ago.

Chastising people about "yelling" is not really an appropriate thing to say here.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#365
post #271

Earlier quoted context omitted.

This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.

Furthermore it seems like it's specific to Azure AD, and I'm guessing it probably only has effect if you enable to option to back up the keys to AD in the first place, which is not mandatory I'd be curious to see a conclusive piece of documentation about this, though

Regular AD also has this feature, you can store the encryption keys in the domain controller. I don't think it's turned on by default, but you can do that with a group policy update.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#366

Earlier quoted context omitted.

There is no law yet . Where I live, government passed a similar law to the UK's online identification law not too long ago. It creates obligations for operating system vendors to provide secure identity verification mechanisms. Can't just ask the user if they're over 18 and believe the answer. The goal is of course to censor social media platforms by "regulating" them under the guise of protecting children. In practi…

Which law is that?

Online Safety Act in the UK.

In Brazil, where I live, it's law 15.211/2025. It makes it so that the tech industry must verify everyone's identity in order to proactively ban children from the harmful activities. It explicitly mentions "terminal operating systems" when defining which softwares the law is supposed to regulate.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#367

Earlier quoted context omitted.

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

It is sad that we got to here from when the worst problem was a tile start menu (I liked 8.1 and it ran good on fairly trash hardware.)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#368
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

None of this matters. XKCD. Hit him with this $5 wrench until he gives you the keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#370
post #306

Earlier quoted context omitted.

You mean, trust and reputation of Apple? They're not exactly high: https://news.ycombinator.com/item?id=46252114 https://news.ycombinator.com/item?id=45520407 https://news.ycombinator.com/item?id=42014588 https://news.ycombinator.com/item?id=26644216

None of these really match the scenario we're discussing here. Some are typical big company stuff, some are technical edge cases, but none are "Apple lies about a fundamental security practice consistently and with malice"

> "Apple lies about a fundamental security practice consistently and with malice"

Uploading passwords to the cloud should count. Also this: https://sneak.berlin/20231005/apple-operating-system-surveil...

Post reply on HN