Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

551–560 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#551
post #396

Earlier quoted context omitted.

> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.

People really pay too little attention to this attack avenue. It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account. I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways. Please check theupdateframework.io if you have a say in an update system.

I actually misremembered what theupdateframework.io is, I thought it provided more protections...

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#552
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

[deleted]

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#553
post #24
post #17

Earlier quoted context omitted.

> It's not like companies have a choice. > If they have a key in their possession [...] So they do have a choice.

People/users have an option to keep the key themselves. Most wouldn’t bother to manage encryption keys.

put $10 into the pub box for commenting without reading the OP, or at least being reasonably well informed before commenting.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#554
post #448

Earlier quoted context omitted.

Apple approaches it different with iCloud. You have a clear option to not hand these keys over. It shows that your idea of how the market works clearly is not representative of the actual market.

You realize the famous case of Apple pushing back against the govt ended because their encryption was breakable by a third party, right?

There are some errors in what you write, and despite that, it is not clear to me what the supposed ‘realization’ would be.

1. The famous 2016 San Bernardino case predates Advanced Data Protection technology of iCloud backups. It was never about encryption keys, it was about signing a ‘bad’ iOS update.

2. Details are limited, but it involved a third-party exploit to gain access to the device, not to break the encryption (directly). These are different things and should both be addressed for security, but separately.

Evidently, after this case ended, Apple continued its efforts. It rolled out protecting backups from Apple, and the requirement of successful user authentication before installing iOS updates (which is also protecting against Apple or stolen signing keys).

There is a market here.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#555
post #403

Earlier quoted context omitted.

Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…

Generally I recommend people use PopOS. It's well suited for laptops, as that's what System76 is focused on a they're shipping laptops with Nvidia GPUs. I personally prefer Arch based distorts like endeavor but even with wide community support it's just more likely a noob will face an error. Fwiw I've only faced one meaningful error in the last 3 years in endeavor but I've also been daily driving Linux for 15 years n…

I’ve been using PopOS for the last five years and while I generally agree… the latest release using Cosmic by default has a lot to be desired. Cosmic will eventually be good but right now it’s far from it and I had to install Gnome as a stop gap just to have a functional desktop environment. I’ll probably ditch PopOS for Arch + KDE but I haven’t had the time to do so yet for my workstation.

Truly, and to really drive it home, I’ve loved PopOS but this latest release is just too half baked. I think anyone considering it should either wait a year or use something else, and Kubuntu seems like a reasonable alternative for people coming from Windows or MacOS.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#556
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

You’re ignoring the international element. If I’m a Danish organisation then sure, the Danish government can compel me to do things.

However a hostile foreign government has less control over me.

As such using a tool of a hostile foreign government (Microsoft) needs to be understood and avoided.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#557

Earlier quoted context omitted.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

Is your last name Segurakreischer? Have them try - leave the Windows computer online and accessible, give your parents a linux box and have them use it exclusively unless they absolutely 100% need to get back on the Windows machine for some reason, and talk with you about it. Set up a NAS with an external HD and a shared folder on both the windows and linux box, so if they actually do need to go back to Windows, they…

Or just let them use whatever they want…

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#558
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

Does using the "manage-bde -protectors -add" command to add a device key encrypted by a local recovery key, followed by the "manage-bde -protectors -delete" command to delete the device key encrypted by the uploaded key not work?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#559
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

Sadly VeraCrypt is not optimized for SSDs and has a massive performance impact compared to Bitlocker for full disk encryption because the SSD doesn't know what space is used/free with VeraCrypt.

i want to see some real world numbers about that "massive" impact of trim, which is repeated regularly.

first of all trim only affects write speed (somewhat), which is not really all that important for non-server use.

it also has some impact on wear which is probably more interesting than its performance impact.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#560

Earlier quoted context omitted.

Buy a laptop with less problems on Linux if that's your intention.

What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?

I've used Dell Inspiron laptops in the past, never had a problem. WiFi, multimonitor output, bluetooth, etc all work out of the box with Debian or Ubuntu.
Post reply on HN