Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

541–550 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#541
post #355

Earlier quoted context omitted.

It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. Most (though not all) users are looking for encryption to protect their data from a thief who steals their laptop and who could extract their passwords, banking info, etc. Not from the government using a warrant in a criminal investigation. If you're one of the subset of people worried about the governmen…

> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyo…

> What's the equivalent of thinking users are this stupid?

What's the equivalent of thinking security aficionados are clueless?

Security advice is dumb and detached from life, and puts ubdue burden on people that's not like anything else in life.

Sharing passwords is a feature, or rather a workaround because this industry doesn't recognize the concept of temporary delegation of authority, even though it's the basics of everyday life and work. That's what you do when you e.g. send your kid on a grocery run with your credit card.

Asking users to keep their 2FA recovery keys or disk encryption keys safe on their own - that's beyond ridiculous. Nothing else in life works that way. Not your government ID, not your bank account, not your password, not even the nuclear launch codes. Everything people are used to is fixable; there's always a recovery path for losing access to accounts or data. It may take time and might involve paying a notary or a court case, but there is always a way. But not so with encryption keys to your shitposts and vacation pictures in the cloud.

Why would you expect people to follow security advice correctly? It's detached from reality, dumb, and as Bitcoin showed, even having millions of dollars on the line doesn't make regular people capable of being responsible with encryption keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#542

Earlier quoted context omitted.

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

> logging into MS Teams I mean, this is one application nobody should ever log into!

Teams in the browser, on Linux. That is reasonably harmless.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#543
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

it's easy to design a system where the center doesn't have the key and thus can't be compelled.

but they didn't do so.

and it's surely just a coincidence, because m$ has always been such an ethical company.

and it's surely not by design to centralize power by locking out competing criminals from the user's data, but not themselves.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#544
post #467

Earlier quoted context omitted.

Then don't enable encryption? Basically I cannot rescue the files on my own disk but the police can?

> Basically I cannot rescue the files on my own disk but the police can? I think you're misunderstanding. You can rescue the files on your own disk when you place the key in your MS account. There's no scenario where you can't but the police can.

If I happen to know that my key is there.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#546

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

Just remember, never use or recommend Debian-family(Ubuntu/Mint) or you will be back to windows. Do not fall for the marketing term Stable, which means outdated and contains bugs that are fixed. Fedora is my recommendation. I remind people Fedora is not Arch. Fedora is a consumer grade OS that is so good, I don't lump it in with the word Linux.

Fedora is good and fairly stable, but it has bugged on me a few times.

In the past 3 years: - mouse/cursor issues due to some kernel upgrade I think, as Fedora stays close to upstream - unresponsive computer due to a bug in the AMD graphics driver

Both were easy to fix (kernel cmdline change or just kept updating my computer), and I absolutely recommend Fedora. That's what I'd use if I had servers. But, you'll probably have to debug _some_ issues if you use something less-used like AMD.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#547
post #355

Earlier quoted context omitted.

> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyo…

> What's the equivalent of thinking users are this stupid? What's the equivalent of thinking security aficionados are clueless? Security advice is dumb and detached from life, and puts ubdue burden on people that's not like anything else in life. Sharing passwords is a feature , or rather a workaround because this industry doesn't recognize the concept of temporary delegation of authority , even though it's the basic…

Your credit card analogy is doing a lot of heavy lifting here, but it's carrying the wrong cargo. Sending your kid to the shops with your card is temporary delegation, not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". And; you know that you've done it, you have personally weighed the risks and if something happens with your card/key in that window: you can hold them to account. (granted, keys can be copied)

> Nothing else in life works that way. Not your government ID, not your bank account, not your password, not even the nuclear launch codes.

Brilliant examples of why you're wrong:

Government IDs have recovery because the government is the trusted authority that verified you exist in the first place. Microsoft didn't issue your birth certificate.

Nuclear launch codes are literally designed around not giving any single entity complete access, hence the two-person rule and multiple independent key holders. You've just argued for my position.

Banks can reset your PIN because they're heavily regulated entities with legal obligations and actual consequences for breaching trust. Microsoft's legal department is larger than most countries' regulators.

> even having millions of dollars on the line doesn't make regular people capable of being responsible with encryption keys.

Right, so the solution is clearly to hand those keys to a corporation that's subject to government data requests, has been breached multiple times, and whose interests fundamentally don't align with yours? The problem with Bitcoin isn't that keys are hard - it's that the UX is atrocious. The solution is better tooling, not surveillance capitalism with extra steps.

You're not arguing for usability. You're arguing that we should trust a massive corporation more than we trust ourselves, whilst simultaneously claiming users are too thick to keep a recovery key in a drawer. Pick a lane.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#548
post #518
post #355

Earlier quoted context omitted.

> It generally is, because in the vast majority of cases users will not keep a local copy and will lose their data. What's the equivalent of thinking users are this stupid? I seem to recall that the banks repeatedly tell me not to share my PIN number with anyone, including (and especially) bank staff. I'm told not to share images of my house keys on the internet, let alone handing them to the government or whathaveyo…

So what happens if your motherboard gets fried and you don’t have backups of your recovery key or your data? TPMs do fail on occasion. A bank PIN you can call and reset, they can already verify your identity through other means.

> So what happens if your motherboard gets fried and you don't have backups of your recovery key or your data?

If you don't have backups of your data, you've already lost regardless of where your recovery key lives. That's not an encryption problem, that's a "you didn't do backups" problem, which, I'll agree is a common issue. I wonder if the largest software company on the planet (with an operating system in practically every home) can help with making that better. Seems like Apple can, weird.

> TPMs do fail on occasion.

So do Microsoft's servers. Except Microsoft's servers are a target worth attacking, whereas your TPM isn't. When was the last time you heard about a targeted nation-state attack on someone's motherboard TPM versus a data breach at a cloud provider?

> A bank PIN you can call and reset, they can already verify your identity through other means.

Banks can do that because they're regulated financial institutions with actual legal obligations and consequences for getting it wrong. They also verified your identity when you opened the account, using government ID and proof of address.

Microsoft is not your bank, not your government, and has no such obligations. When they hand your keys to law enforcement, which they're legally compelled to do, you don't get a phone call asking if that's alright.

The solution to TPM failure is a local backup of your recovery key, stored securely. Not uploading it to someone else's computer and hoping for the best.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#549
post #280

Earlier quoted context omitted.

The defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you als…

Just to be clear: bitlocker is NOT encrypting with your login password! I could be a little fuzzy on the details but I believe how it works is that your TPM (Trusted Platform Module) is able to decrypt your laptop, but will only do so if there is a fully signed and trusted boot chain, so if somebody gains access to your laptop and attempts to boot into anything other than Windows, it will ask for the bitlocker key be…

> nobody who is using Windows cares about encryption or even knows what it is!

Right, so the solution is to silently upload their encryption keys to Microsoft's servers without telling them? If users don't understand encryption, they certainly don't understand they've just handed their keys to a third party subject to government data requests.

> otherwise a regular user will happen to mess around with their bios one day and accidentally lock themselves permanently out of their computer.

This is such transparent fear-mongering. How often does this actually happen versus how often are cloud providers breached or served with legal requests? You're solving a hypothetical edge case by creating an actual security vulnerability.

Encryption by default and cloud key escrow are separate decisions. You can have one without the other. The fact that Microsoft chose both doesn't make the second one necessary, it makes it convenient for Microsoft.

> If you want regular FDE without giving Microsoft the key you can go ahead and do it fairly easily!

Then why isn't that the default with cloud backup as opt-in? Oh right, because then Microsoft wouldn't have everyone's keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#550
post #517
post #280

Earlier quoted context omitted.

The defenders of Microsoft are right? How? There is no point locking your laptop with a passphrase if that passphrase is thrown around. Sure, maybe some thief can't get access, but they probably can if they can convince Microsoft to hand over the key. Microsoft should not have the key, thats part of the whole point of FDE; nobody can access your drive except you. The cost of this is that if you lose your key: you als…

The vast, vast majority of Windows users don't know their laptops are encrypted, don't understand encryption, and don't know what bitlocker is. If their keys weren't stored in the cloud, these users could easily lose access to their data without understanding how or why. So for these users, which again is probably >99% of all windows users, storing their keys in the cloud makes sense and is a reasonable default. Not…

> The vast, vast majority of Windows users don't know their laptops are encrypted, don't understand encryption, and don't know what bitlocker is.

Mate, if 99% of users don't understand encryption, they also don't understand that Microsoft now has their keys. You can't simultaneously argue that users are too thick to manage keys but savvy enough to consent to uploading them.

> If their keys weren't stored in the cloud, these users could easily lose access to their data without understanding how or why.

As opposed to losing access when Microsoft gets breached, or when law enforcement requests their keys, or when Microsoft decides to lock them out? You've traded one risk for several others, except now users have zero control.

The solution to "users might lock themselves out" is better UX for local key backup, not "upload everyone's keys to our servers by default and bury the opt-out". One is a design problem, the other is a business decision masquerading as user protection.

> The only thing I would really fault Microsoft for here is making it overly difficult to disable the cloud storage for users who do understand all the implications.

That's not a bug, it's the entire point. If it were easy to disable, people who understand the implications would disable it. Can't have that, can we?

Post reply on HN