Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

501–510 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#501

Earlier quoted context omitted.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

Lenovo T and X series are excellent and cheap as dirt used. There is also System 76. Or you could get a MacBook and boot Linux on that. Some older ones work well, I hear.

> Or you could get a MacBook and boot Linux on that. Some older ones work well, I hear.

Is linux support on the M1/M2 models as good as linux support on x86 laptops? My understanding was that there's still a fair bit of hardware that isn't fully supported. Like, external displays and Bluetooth.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#502

Earlier quoted context omitted.

> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.

It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.

Mine already is... it's so nice not to be disrespected every time I turn on my laptop.

I recommend it.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#503

Earlier quoted context omitted.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

They don't. I don't know what they're talking about, but I've had fewer problems with linux on my framework than weird stuff on my OSX work machine. And I'm running Alpine on my framework, so if anything should be wonky it's this one.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#504
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

MacOS has this feature as well. It used to be called "Allow my iCloud account to unlock my disk," but it keeps getting renamed and moved around in new MacOS versions. I think it's now tied together with remote password resets into one option called "allow user to reset password using Apple Account."

To be fair, which makes it even more ominous with Apple. At least Microsoft explicitly informs you during setup and isn't trying to hide it behind some vague language about "resetting password".

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#505
post #269

I consider myself pretty pro-privacy, but there is so much dragnet surveillance and legitimate breaches of the fourth amendment that I have a hard time getting up in arms over a company complying with a valid search warrant that is scoped to three hard drives (and which required law enforcement to have physical possession of the drives to begin with). This is so much more reasonable than (for example) all the EU chat…

A lot of them are not really legitimate though. There's a reason that 4th amendment needs a modern version to require a warrant for tapping of any sort for things people generally assume are private. Flock, palantir, etc need to all go bankrupt, starved of data to spy on. In an ideal world of course. Maybe someday we'll wake up from the nightmare.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#506

I have opted out of all cloud services in my windows installation; I use a passphrase, too (it is even before booting the computer). I feel like this is pretty safe

except MS could easily turn something on without you knowing and be uploading your files to their cloud. Yes, I believe they would stoop that low and even lower.

or just save all your keystrokes and regular screen captures with "Recall"

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#507
post #64

Earlier quoted context omitted.

>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?

> IBM estimated in 1996 that one error per month per 256 MiB of RAM was expected for a desktop computer. From the wikipedia article on "Soft error", if anyone wants to extrapolate.

Rounding that to 1 error per 30 days per 256M, for 16G of RAM that would translate to 1 error roughly every half a day. I do not believe that at all, having done memory testing runs for much longer on much larger amounts of RAM. I've seen the error counters on servers with ECC RAM, which remain at 0 for many months; and when they start increasing, it's because something is failing and needs replaced. In my experience RAM failures are much rarer than for HDDs and SSDs.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#508
post #333

Earlier quoted context omitted.

Keys are stored securely in a TPM in the sense that a random program has no access to it. They are not stored safely there in the sense that they couldn’t possibly get destroyed. TPM hardware, or the motherboard that hosts it, occasionally fails. Or you might want to migrate your physical hard drive to a different PC. That’s the purpose of backing up the keys to the cloud. Alternatively, you can write down a recovery…

There's also no security in the communication between the CPU and the TPM, so you can plug in a chip that intercepts it and copies all the keys, or plug the TPM into a chip that pretends to be the CPU and derives identical keys.

[deleted]

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#509

Earlier quoted context omitted.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

I bought and returned an AMD Framework. I knew what I was getting into, but the build quality + firmware quality were lacking, sleep was bad and I'm not new to fixing Linux sleep issues. Take a look at the Linux related support threads on their forum.

I've been using AMD EliteBooks, the firmware has Linux happy paths, the hardware is supported by the kernel and Modern Standby actually works well. Getting one with a QHD to UHD screen is mandatory, though, and I wouldn't buy a brand new model without confirming it has working hardware on linux-hardware.org.

If you look online, HP has a YouTube channel with instructional videos for replacing and repairing every part of their laptops. They are made to make memory, storage and WiFi/5G card replacements easy, parts are cheap and the after market for them is healthy.

I've also had good luck with their support, they literally overnight'd a new laptop with a return box for the broken one in a day.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#510
post #238

Earlier quoted context omitted.

Or: Put all of Windows inside of a VM, within a host that uses disk encryption -- and let it run amok inside of its sandbox. I did this myself for about 8 years, from 2016-2024. During that time my desktop system at home was running Linux with ZFS and libvirt, with Windows in a VM. That Windows VM was my usual day-to-day interface for the entire system. It was rocky at first, but things did get substantially better a…

If you’re doing your work inside the windows machine, what protection does Linux as a host get you?

The topic is bitlocker, and Microsoft, and keys.

With a VM running on an encrypted file system, whatever a warrant for a bitlocker key might normally provide will be hidden behind an additional layer that Microsoft does not hold the keys to.

(Determining whether that is useful or not is an exercise for the person who believes that they have something to hide.)

Post reply on HN