Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

481–490 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#481
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

Unfortunately Microsoft are working hard to get rid of local accounts, meaning the alternative here isn't much of an alternative.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#482
post #280

Earlier quoted context omitted.

I big demographic of HN users are people who want to be the multi-trillion dollar corporation so it’s not too surprising. In this case though I think they are right. And I’m a big time Microsoft hater.

The defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you als…

Just to be clear: bitlocker is NOT encrypting with your login password! I could be a little fuzzy on the details but I believe how it works is that your TPM (Trusted Platform Module) is able to decrypt your laptop, but will only do so if there is a fully signed and trusted boot chain, so if somebody gains access to your laptop and attempts to boot into anything other than Windows, it will ask for the bitlocker key because the TPM won't play ball.

The important bit here is that ~*nobody* who is using Windows cares about encryption or even knows what it is! This is all on by default, which is a good thing, but also means that yes, of course Microsoft has to store the keys, because otherwise a regular user will happen to mess around with their bios one day and accidentally lock themselves permanently out of their computer.

If you want regular FDE without giving Microsoft the key you can go ahead and do it fairly easily! But realistically if the people in these cases were using Linux or something instead the police wouldn't have needed an encryption key because they would never have encrypted their laptop in the first place.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#483
post #411

Earlier quoted context omitted.

except Microsoft probably as a master key

People know the system well enough to write FOSS implementations of it; I think they would have noticed and sounded the alarm if there were a possible master key.

I don't think anybody is interested in reverse-engineering closed-source OS to check if it works as documented; it;s easier to just use Linux which has open-source code.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#484

Earlier quoted context omitted.

What is your proof they don't have a duplicate key that also unlocks it? A firm handshake from Tim?

If they say they don't, and they do, then that's fraud, and they could be held liable for any damages that result. And, if word got out that they were defrauding customers, that would result in serious reputational damage to Apple (who uses their security practices as an industry differentiator) and possibly a significant customer shift away from them. They don't want that.

Cooperating with law enforcement cannot be a fraud. Fraud is lying to get illegal gains. I think, it's legally ok to lie if the goal is to catch a criminal and help the government.

For example, in 20th century, an European manufacturer of encryption machines (Crypto AG [1]) made a backdoor at request of governments and never got punished - instead it got generous payments.

[1] https://en.wikipedia.org/wiki/Crypto_AG

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#485
post #281

Earlier quoted context omitted.

Hacker News defending corporate key escrow. Wow. > It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive. It allows /anyone/ to recover their data later. You don't have to be a "purist" to hate this.

There is no other way for this to work that won't result in an absolutely massive number of people losing their data permanently who had no idea their drive was encrypted. Well there is, leave BitLocker disabled by default and the drive unencrypted. Now the police don't even have to ask! With this scheme the drive is recoverable by the user and unreadable to everyone except you, Microsoft, and the police. Surely that…

> who had no idea their drive was encrypted

I think you just identified the problem clearly.

> Now the police don't even have to ask!

Security is not a switch you can turn on and forget about. Plus the police have extraordinary real world powers to compel you to disclose the necessary information anyways. Unless you're holding state secrets, which, c'mon, you're almost certainly going to give in and cooperate at some point. It wouldn't make for a great Hollywood movie but it would accurately reflect day to day reality.

> unreadable to everyone except you, Microsoft, and the police.

That's two too many. It should either be unreadable to everyone but me or readable by anyone with physical access. Does it not occur to people that you can still rely on physical security even in computing?

> Apple does the same thing

The two corporate computing giants do the same thing? I am not surprised but I also don't see it as a worthwhile data point.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#486
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

You can encrypt a Bitlocker volume without syncing your keys even if you do log in with a Microsoft account, at least last time I was configuring Bitlocker.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#487
post #235
post #205

Earlier quoted context omitted.

Why would you need to create a local account? You can just not choose to store the keys in your Microsoft account during BitLocker setup: https://www.diskpart.com/screenshot/en/others/windows-11/win... Admittedly, the risks of choosing this option are not clearly laid out, but the way you are framing it also isn't accurate

All "Global Reader" accounts have "microsoft.directory/bitlockerKeys/key/read" permission. Whether you opt in, or not, if you connect your account to Microsoft, then they do have the ability fetch the bitlocker key, if the account is not local only. [0] Global Reader is builtin to everything +365. [0] https://github.com/MicrosoftDocs/entra-docs/commit/2364d8da9...

They could also just push an update to change it anyways to grab it.

If you really don't trust Microsoft at all then don't use Windows.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#488
post #383
post #308

Earlier quoted context omitted.

You can turn it off without resorting to a local account, although it's non-obvious. GPEdit -> Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Operating System Drives → “Choose how BitLocker-protected operating system drives can be recovered” Repeat for other drives.

I imagine you have to re-encrypt the drive after that, though, for it to have some real effect

No, the actual data encryption key doesn't need to change unless you're very paranoid. The backup key and your normal key is just to decrypt the data encryption key.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#489

Earlier quoted context omitted.

Then you don't want encrypt by default and anyone who goes out of their way knows what they're doing

Okay, so then the default for 95% of users is no encryption at all and police (or the far more likely thief, roommate, etc) don't even have to bother with a warrant to get all your data. Improving the situation ... how exactly?

Because now all the people at the computer recycle shop can't access all your old files including your family photos and saved passwords. They'd be missing out on all that fun.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#490
post #21
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the securit…

> a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded.

Nah, no shot.

Post reply on HN