Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

401–410 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#401
post #140

Earlier quoted context omitted.

I don't think there's a good answer here. Users absolutely 100% will lose their password and recovery key and not understand that even if the bytes are on a desk physically next to you, they are gone. Gone baby gone. In university, I helped a friend set up encryption on a drive w/ his work after a pen drive with work on it was stolen. He insisted he would not lose the password. We went through the discussion of "this…

Then you don't want encrypt by default and anyone who goes out of their way knows what they're doing

Okay, so then the default for 95% of users is no encryption at all and police (or the far more likely thief, roommate, etc) don't even have to bother with a warrant to get all your data.

Improving the situation ... how exactly?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#402
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> This makes the privacy purists angry, but in my opinion it's the reasonable default for the average computer user.

Absolutely not. If my laptop tells me that it is encrypted by default, I don't like that the default is to also hold a copy of the keys in case big brother wants them.

Call me a "privacy purist" all you want, but it shouldn't be normal to expect the government to have access to a key to your house.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#403

Earlier quoted context omitted.

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

Linux is so much better than it used to be. You really don't need to be technical.

I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment.

Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recommending a distro with the most Windows-like UI and a straightforward installation.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#404

Hello there! Have you heard of our lord and savior, Linux?

> Yes, but Which version/fork?

If I earn my living from a company that doesn't make Linux versions, should i still switch?

Should my customers?

It's a great idea, and my work does not touch the internet, but the confusing variations of linux do not a happy workfoce make.

Your 'lord and saviour' can fuck off, with all the others, I prefer science.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#405

Earlier quoted context omitted.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

Is your last name Segurakreischer? Have them try - leave the Windows computer online and accessible, give your parents a linux box and have them use it exclusively unless they absolutely 100% need to get back on the Windows machine for some reason, and talk with you about it. Set up a NAS with an external HD and a shared folder on both the windows and linux box, so if they actually do need to go back to Windows, they…

> Is your last name Segurakreischer?

Afraid I don't get the reference if this is a joke, but no that is not my last name.

I've offered similar solutions to this; a VM that they can RDP into, or just a VM running locally with Winboat or Winapps so they could work with the apps they need to, but they won't entertain the idea.

Honestly I kind of think they're adding increasing conditions just so I stop bothering them about it. I think they very much do not want to change operating systems and they know that just saying that won't be a valid enough excuse to get my to shut up about it.

Before people give me shit over trying to force my dogma on them, I should point out that when their computers break (e.g. Windows Update decides to brick their computer), I am the one that is expected to fix them. I don't think it's unreasonable that if I'm expected to do the repairs on the computer that I get a say in what's installed on them.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#406
post #351

Earlier quoted context omitted.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

I use macOS most of the time, but switch to a Windows VM for Excel. Without the same keyboard shortcuts, the macOS version ends up having a fraction of the power available to experienced users of the Windows version. For people who use Excel extensively, LibreOffice or Google Sheets would have to offer some remarkable new killer features to make it worth the switch. I don’t think feature parity alone would make the b…

I mean, I think not having Copilot being shoved at you and not having advertisements pushed on you and having recovery tools that actually work and basically a lifetime of free updates would be a pretty big value add for Linux over Windows, and those go beyond feature parity.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#407

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

> What happens if I forget my keys? … restore contents from backups.

What happens if you forget your backup keys?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#408
post #298

Earlier quoted context omitted.

You missed the important part: > For this threat model We're talking about a hypothetical scenario where a state actor getting the information encrypted by the E2E encryption puts your life or freedom in danger. If that's you, yes, you absolutely shouldn't trust US corporations, and you should absolutely be auditing the source code. I seriously doubt that's you though, and it's certainly not me. The sub-title from th…

Okay, so yes I grant your point that people where governments are the threat model should be auditing source code. I also grant that many things are possible (where the journalist says "isn't possible"). However, what remains true is that Microsoft appears to store this data in a manner that can be retrieved through "simple" warrants and legal processes, compared to Apple where these encryption keys are stored in a m…

> retrieved through "simple" warrants and legal processes

The fact it requires an additional engineering step is not an impediment. The courts could not care less about the implementation details.

> compared to Apple where these encryption keys are stored in a manner that would require code changes to accomplish.

That code already exists at apple: the automated CSAM reporting apple does subverts their icloud E2E encryption. I'm not saying they shouldn't be doing that, it's just proof they can and already do effectively bypass their own E2E encryption.

A pedant might say "well that code only runs on the device, so it doesn't really bypass E2E". What that misses is that the code running on the device is under the complete and sole control of apple, not the device's owner. That code can do anything apple cares to make it do (or is ordered to do) with the decrypted data, including exfiltrating it, and the owner will never know.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#409
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive.

> sign into your Microsoft account or link it to Windows again.

For reference, I did accidentally login into my Microsoft account once on my local account (registered in the online accounts panel). While Edge automatically enabled synchronization without any form of consent from my part, it does not look like that my Bitlocker recovery key is listed on https://account.microsoft.com/devices/recoverykey. But since I unlinked my account, it could be that it was removed automatically (but possible still cached somewhere).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#410

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

With Bitlocker it is still possible to have single password-based key. But enabling that requires to enter a few commands on the command line.

It requires the Pro edition of Windows too.
Post reply on HN