Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
361–370 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#362This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.
We now know that BitLocker is not secure, and an intelligent open source dev saying that was probably knowingly not saying the truth.
The best explanation to me is that this was said under duress, because somebody wanted people to move away from the good TrueCrypt to something they could break.
[1] https://truecrypt.sourceforge.net
[2] https://en.wikipedia.org/wiki/TrueCrypt#End_of_life_announce...
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#363It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
The median user's threat model doesn't include the government, but does include data loss, forgetting the password, or a thief stealing your laptop. Microsoft struck the right balance. I'm glad the knee-jerk absolutists are marginal, for one. A world run by you people would be much worse for anyone who isn't you.
I don’t get how people like you trust the corporation or the government that much. If we were all more cognizant of security and privacy, it would be much harder for large orgs to break our society the way they are doing today.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#364Earlier quoted context omitted.
> it was really easy to set up without a Microsoft account. By "really easy" do you mean you had a checkbox? Or "really easy" in that there's a secret sequence of key presses at one point during setup? Or was it the domain join method? Googling around, I'm not sure any of the methods could be described as "really easy" since it takes a lot of knowledge to do it.
I recently had to install Windows for the first time in ages because reasons, and it really wasn’t very hard. The setup really just presents two options at a time: the cloudy option, and the other option. If in doubt, the flashy one is the cloudy one. I kept selecting the non cloudy option and got to the desktop without signing up for anything. Sure it took more clicking than last time I went through this, but really…
Chastising people about "yelling" is not really an appropriate thing to say here.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#365Earlier quoted context omitted.
This is for the _ActiveDirectory_. If your machine is joined into a domain, the keys will be stored in the AD. This does not apply to standalone devices. MS doesn't have a magic way to reach into your laptop and pluck the keys.
Furthermore it seems like it's specific to Azure AD, and I'm guessing it probably only has effect if you enable to option to back up the keys to AD in the first place, which is not mandatory I'd be curious to see a conclusive piece of documentation about this, though
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#366Earlier quoted context omitted.
There is no law yet . Where I live, government passed a similar law to the UK's online identification law not too long ago. It creates obligations for operating system vendors to provide secure identity verification mechanisms. Can't just ask the user if they're over 18 and believe the answer. The goal is of course to censor social media platforms by "regulating" them under the guise of protecting children. In practi…
Which law is that?
In Brazil, where I live, it's law 15.211/2025. It makes it so that the tech industry must verify everyone's identity in order to proactively ban children from the harmful activities. It explicitly mentions "terminal operating systems" when defining which softwares the law is supposed to regulate.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#367Earlier quoted context omitted.
Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.
> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#368FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#369Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#370Earlier quoted context omitted.
You mean, trust and reputation of Apple? They're not exactly high: https://news.ycombinator.com/item?id=46252114 https://news.ycombinator.com/item?id=45520407 https://news.ycombinator.com/item?id=42014588 https://news.ycombinator.com/item?id=26644216
None of these really match the scenario we're discussing here. Some are typical big company stuff, some are technical edge cases, but none are "Apple lies about a fundamental security practice consistently and with malice"
Uploading passwords to the cloud should count. Also this: https://sneak.berlin/20231005/apple-operating-system-surveil...