FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
481–490 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#482Earlier quoted context omitted.
I big demographic of HN users are people who want to be the multi-trillion dollar corporation so it’s not too surprising. In this case though I think they are right. And I’m a big time Microsoft hater.
The defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you als…
The important bit here is that ~*nobody* who is using Windows cares about encryption or even knows what it is! This is all on by default, which is a good thing, but also means that yes, of course Microsoft has to store the keys, because otherwise a regular user will happen to mess around with their bios one day and accidentally lock themselves permanently out of their computer.
If you want regular FDE without giving Microsoft the key you can go ahead and do it fairly easily! But realistically if the people in these cases were using Linux or something instead the police wouldn't have needed an encryption key because they would never have encrypted their laptop in the first place.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#483Earlier quoted context omitted.
except Microsoft probably as a master key
People know the system well enough to write FOSS implementations of it; I think they would have noticed and sounded the alarm if there were a possible master key.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#484Earlier quoted context omitted.
What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?
If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.
For example, in 20th century, an European manufacturer of encryption machines (Crypto AG [1]) made a backdoor at request of governments and never got punished - instead it got generous payments.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#485Earlier quoted context omitted.
Hacker News defending corporate key escrow. Wow. > It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive. It allows /anyone/ to recover their data later. You don't have to be a "purist" to hate this.
There is no other way for this to work that won't result in an absolutely massive number of people losing their data permanently who had no idea their drive was encrypted. Well there is, leave BitLocker disabled by default and the drive unencrypted. Now the police don't even have to ask! With this scheme the drive is recoverable by the user and unreadable to everyone except you, Microsoft, and the police. Surely that…
I think you just identified the problem clearly.
> Now the police don't even have to ask!
Security is not a switch you can turn on and forget about. Plus the police have extraordinary real world powers to compel you to disclose the necessary information anyways. Unless you're holding state secrets, which, c'mon, you're almost certainly going to give in and cooperate at some point. It wouldn't make for a great Hollywood movie but it would accurately reflect day to day reality.
> unreadable to everyone except you, Microsoft, and the police.
That's two too many. It should either be unreadable to everyone but me or readable by anyone with physical access. Does it not occur to people that you can still rely on physical security even in computing?
> Apple does the same thing
The two corporate computing giants do the same thing? I am not surprised but I also don't see it as a worthwhile data point.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#486FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#487Earlier quoted context omitted.
Why would you need to create a local account? You can just not choose to store the keys in your Microsoft account during BitLocker setup: https://www.diskpart.com/screenshot/en/others/windows-11/win... Admittedly, the risks of choosing this option are not clearly laid out, but the way you are framing it also isn't accurate
All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...
If you really don't trust Microsoft at all then don't use Windows.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#488Earlier quoted context omitted.
You can turn it off without resorting to a local account, although it's non-obvious. GPEdit -> Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Operating System Drives → “Choose how BitLocker-protected operating system drives can be recovered” Repeat for other drives.
I imagine you have to re-encrypt the drive after that, though, for it to have some real effect
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#489Earlier quoted context omitted.
Then you don't want encrypt by default and anyone who goes out of their way knows what they're doing
Okay, so then the default for 95% of users is no encryption at all and police (or the far more likely thief, roommate, etc) don't even have to bother with a warrant to get all your data. Improving the situation ... how exactly?
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#490FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…
Nah, no shot.