"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…
I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.
Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
41–50 of 280 posts
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#42"Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt". If they put a backdoor into FDE it would make more sense to advise people to stop using windows at all and using Linux instead. If they put a backdoor in FDE you can be sure there is not just one backdoor in the operating system itself…
I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#43Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#44Earlier quoted context omitted.
Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.
Simple hypothetical: "A disaster hits and the workstation owner is unable to return to the location the workstation is stored. During that time period the workstation is stolen by a gang of looters."
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#45Earlier quoted context omitted.
As opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were…
>You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. That just sounds like a fundamental issue with security in general, not specific to Apple/Microsoft.
I have found that even many tech people have incorrect beliefs about these things, like assuming that iCloud Backups are E2E encrypted by default or that disabling Allow Apps to Request to Track disables trackers inside apps.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#46Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#47Earlier quoted context omitted.
My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)
Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.
Every machine is encrypted, unlocked per login.
Encryption is basically free so.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#48Earlier quoted context omitted.
My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)
Cool. Everyone's threat model is different. As long as we're not writing passwords on sticky notes attached to the monitor, I don't think there's any need to be throwing stones.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#49Earlier quoted context omitted.
I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.
Ever since the TrueCrypt fiasco years ago, I have no trust in that brand.
Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
#50Earlier quoted context omitted.
As opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were…
> This is not to defend Microsoft But you are defending MS, conflating a bunch of things, mainly full disk encryption and cloud backups. There's a big difference between Apples cloud backup which has documented behavior and a backdoor. I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it. There also a lot more data points we can use to judge Apple vs Microsoft on privacy and s…
Another example is WhatsApp on Android, by default when backups are enabled, they are stored unencrypted in Google Drive. A good counter-example is Signal, which opts out of backups on iOS and Android and the only option is to do E2E backups to their own servers.
I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it.
FWIW, in the last leaked report, iPhone was not an issue AFU for Cellebrite (macOS is most likely even easier due to looser security):
https://discuss.grapheneos.org/d/14344-cellebrite-premium-ju...