Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

471–480 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#471
post #96

Earlier quoted context omitted.

Why continue to use an operating system that’s adversarial towards you?

I will never understand this from software engineers/tech people in general. That demographic knows how technology works, and are equipped to see exactly where and how Microsoft is taking advantage of them, and how the relationship is all take and zero give from their end. These people are also in the strongest position to switch to Linux. The only explanation that makes sense to me is that there's an element of irra…

Or maybe Windows just works better for their use-case? Did you consider that?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#472

Earlier quoted context omitted.

Why take the drastic step of switching to linux (a difficult endeavor) when you can simply turn off key uploading.

oh man, it's so difficult even teenagers can do it within an hour and all they have to do is click on a few buttons.

Yeah, the real question is what comes after the install...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#473
post #403

Earlier quoted context omitted.

Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.

Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…

Generally I recommend people use PopOS. It's well suited for laptops, as that's what System76 is focused on a they're shipping laptops with Nvidia GPUs. I personally prefer Arch based distorts like endeavor but even with wide community support it's just more likely a noob will face an error. Fwiw I've only faced one meaningful error in the last 3 years in endeavor but I've also been daily driving Linux for 15 years now

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#474
post #396

Earlier quoted context omitted.

> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.

People really pay too little attention to this attack avenue. It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account. I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways. Please check theupdateframework.io if you have a say in an update system.

Isn't it the same with many Linux distros?

Updates are using root to run?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#475
post #403

Earlier quoted context omitted.

Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…

Eh, not for laptops - I say as someone who switched to Linux from windows in past year. I have spent a decent few days to get long battery life on Linux (fedora), with sleep hibernate + encryption. And I am still thinking that the Linux scheduler is not correctly using Intel's pcore/ecore on 13th gen correctly.

If you have an Nvidia GPU you're generally going to need to edit the systemd services and change some kernel settings. This is a real pain point to be honest and it should be easier than it is (usually not too bad tbh)

If you want I can try to help you debug it. I don't have a fedora system but I can spin up a VM or nspawn to try to match your environment if you want

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#476

Earlier quoted context omitted.

That makes it vanishingly unlikely. On a 16GB RAM computer with that rate, you can expect 64 random bit flips per month. So roughly you could expect this happen roughly once every two hundred million years. Assuming there are about 2 billion Windows computers in use, that’s about 10 computers a year that experience this bit flip.

I saw a computer with 'system33', 'system34' folders personally. Also you would never actually know it happened because... it's not ECC. And with ECC memory we replace a RAM stick every two-three months explicitly because ECC error count is too high.

Got any old microwaves with doors that don't quite shut all the way nearby? Or radiation sources?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#477
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

Sadly VeraCrypt is not optimized for SSDs and has a massive performance impact compared to Bitlocker for full disk encryption because the SSD doesn't know what space is used/free with VeraCrypt.

VeraCrypt can be set to pass through TRIM. It just makes it really obvious which sectors are unused within your encrypted partition (they read back as 00 bytes)

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#479
I think most people don't understand that 99% of people don't know what data encryption is and definitely don't care about it. If it weren't for Bitlocker, their laptops wouldn't be encrypted at all! And of course if your software (Windows) encrypts by default but you don't want to bother the average user with the details (because they don't know anything about this or care about it) you will need to store the key in case they need it.

To everyone saying 'time to use Linux!'; recognize that if these people were using Linux, their laptops wouldn't be encrypted at all!

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#480
post #235

Earlier quoted context omitted.

All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...

They're Microsoft and it's Windows. They always have the ability to fetch the key. The question is do they ever fetch and transmit it if you opt out? The expected answer would be no. Has anyone shown otherwise? Because hypotheticals that they could are not useful.

> Because hypotheticals that they could are not useful.

Why? They are useful to me and I appreciate the hypotheticals because it highlights the gaps between "they can access my data and I trust them to do the right thing" and "they literally can't access my data so trust doesn't matter."

Post reply on HN