Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

451–460 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#451

Earlier quoted context omitted.

> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works. If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. I’m not sure how you’re criticizing the “gave” framing when you’re describing and stating Microsoft literally giving the keys to the F…

Because "gave" implies a favor or a one sided exchange. It implies that Microsoft is just giving away keys for no reason! Better, and more accurate wording, would be that "Microsoft surrendered keys" or "Microsoft ceded keys". Or "Microsoft legally compelled to give the keys". If Microsoft did so without a warrant, then "gave" would be more tonally accurate. In addition, none of this is new. They've been turning over…

In fairness, the link is specifically for "Advanced Dat Protection for iCloud". This has nothing to do with local whole-disk encryption like FileVault or BitLocker.

In Apple's case, even when the user enables iCloud FileVault key backup, that key is still end-to-end encrypted and Apple cannot access it. As a matter of fact, while Apple regularly receives legal warrants for access, they are ineffective because Apple has no way to fulfill that request/requirement.

Microsoft has chosen to store the BitLocker key backups in a manner that maintains their (Microsoft's) access. But, this is a choice Microsoft has made its not an intrinsic requirement of a key escrow system. And in the end, it enables law enforcement to compel them to turn over these keys when a judge issues a warrant.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#452
post #281

Earlier quoted context omitted.

Hacker News defending corporate key escrow. Wow. > It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive. It allows /anyone/ to recover their data later. You don't have to be a "purist" to hate this.

There is no other way for this to work that won't result in an absolutely massive number of people losing their data permanently who had no idea their drive was encrypted. Well there is, leave BitLocker disabled by default and the drive unencrypted. Now the police don't even have to ask! With this scheme the drive is recoverable by the user and unreadable to everyone except you, Microsoft, and the police. Surely that…

"Apple does the same thing with FileVault when you set up with your iCloud account where, again, previously your disk was just left unencrypted"

Nah, the FileVault key is stored in your iCloud Keychain when you choose to backup the key to iCloud. And the keychain is end-to-end encrypted. Only the user has access.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#453
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

At Microsoft-scale, data requests from law enforcement are an inevitability. Designing a system such that their requests are answerable is a choice. Signal's cloud backup system is an example of a different choice being made.

^^^ This

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#454
post #300

Earlier quoted context omitted.

Of course. But I suppose you run Teams on a company provided/managed, or at least paid for by the company, device? Just don’t use that machine for anything private. Is anyone using their private devices for work? (Also there is teams for Linux and on the web, if that is not prevented by the policy of your org.)

In the startup world, BYOD is/was exceedingly common. All but two jobs of my career were happy to allow me to use my own Linux laptop and eschew whatever they were otherwise going to give me. Obviously enterprises aren’t commonly BYOD shops, but SMBs and startups certainly can be. … whether the people who would do such BYOD things are at all likely to be Windows users who care about this Bitlocker issue, is a differe…

I’ve been diving down the BYOD rabbit hole recently. At enterprise scale it’s not “hook in with your vpn, job done”, it’s got to be managed. Remote wipe on exit, prove the security settings, disk encryption, EDR.

What this means for the user is your personal device is rather invasively managed. If you want Linux, your distro choice may be heavily restricted. What you can do with that personal device might be restricted (all the EDR monitoring), and you’ll probably take a performance and reliability hit. Not better than just a second laptop for most people.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#455
post #279

Earlier quoted context omitted.

The same is true for Apple laptops! Take a look in your Passwords app and you will see it automatically saves and syncs your laptop decryption key into the cloud. So all the state needs to get into your laptop is to get access from Apple to your iCloud account.

The iCloud Keychain is end-to-end encrypted.[0] Apple can't decrypt it. That said, when setting up FileVault, you have the option to escrow your recovery key with Apple. If you enable that, Apple can get the recovery key. [0] https://support.apple.com/en-us/102651

From the linked Apple page...

"For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption."

The FileVault keys are stored in the iCloud Keychain and Apple does not have access to them, full stop :-)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#457

My Linux drives are all encrypted, and one of the wonderful features of this is that there is no entity or force on this planet that can decrypt them. What happens if I forget my keys? Same thing that happens if my computer gets struck by a meteor. New drive, new key, restore contents from backups. It's simple, secure, set-and-forget, and absolutely nobody but me and your favored deity have any idea what's on my driv…

> there is no entity or force on this planet that can decrypt them.

At this point I think all of the modern, widely used symmetric cryptography that humans have invented will never be broken in practice, even by another more technologically advanced civilization.

On the asymmetric side, it's a different story. It seems like we were in a huge rush to standardize because we really needed to start PQ encrypting data in transit. All the lattice stuff still seems very green to me. I put P(catastrophic attack) at about 10% over the next decade.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#458

Earlier quoted context omitted.

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

It’s funny because I started with Windows 3.1 and it was actively user hostile then. From 3.1 to XP it was awful. Then it got slightly better with 7, and went downhill from there.

Realistically, a major Linux distro is the most user-beneficial thing you can do and today it is easier than ever. If my 12 year old can figure out how to use it productively, so can anyone. Switch today and enjoy.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#459

Earlier quoted context omitted.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

Lenovo T and X series are excellent and cheap as dirt used. There is also System 76. Or you could get a MacBook and boot Linux on that. Some older ones work well, I hear.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#460

Earlier quoted context omitted.

Some people will hurt themselves if given dangerous tools, but if you take all the dangerous items out of the tool shop, there won't be any tools left. Microsoft seems to feel constant pressure to dumb Windows down, but if you look at the reasons people state when switching to Linux, control is a frequent theme. People want the dangerous power tools.

Tool manufacturers include all kinds of annoying safety devices to attempt to prevent injury, or at least to give them some cover in a lawsuit. Table saw blade guards and riving knives are an ironic example here: I've yet to hear a story of a woodworker that lost a finger on a table saw that wouldn't have been able to avoid that injury if they kept one of those safety devices on the saw. Everyone thinks the annoyance…

Genuine safety requires you give people literal kids toys. Those tools were made less dangerous, not safe.
Post reply on HN