Earlier quoted context omitted.
> MS doesn't have a magic way to reach into your laptop and pluck the keys. Of course they do! They can just create a Windows Update that does it. They have full administrative access to every single PC running Windows in this way.
People really pay too little attention to this attack avenue. It's both extremely convenient and very unlikely to be detected; especially given that most current systems are associated to an account. I'd be surprised if it's not widely used by law enforcement, when it's not possible to hack a device in more obvious ways. Please check theupdateframework.io if you have a say in an update system.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
551–560 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#552FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#553Earlier quoted context omitted.
> It's not like companies have a choice. > If they have a key in their possession [...] So they do have a choice.
People/users have an option to keep the key themselves. Most wouldn’t bother to manage encryption keys.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#554Earlier quoted context omitted.
Apple approaches it different with iCloud. You have a clear option to not hand these keys over. It shows that your idea of how the market works clearly is not representative of the actual market.
You realize the famous case of Apple pushing back against the govt ended because their encryption was breakable by a third party, right?
1. The famous 2016 San Bernardino case predates Advanced Data Protection technology of iCloud backups. It was never about encryption keys, it was about signing a ‘bad’ iOS update.
2. Details are limited, but it involved a third-party exploit to gain access to the device, not to break the encryption (directly). These are different things and should both be addressed for security, but separately.
Evidently, after this case ended, Apple continued its efforts. It rolled out protecting backups from Apple, and the requirement of successful user authentication before installing iOS updates (which is also protecting against Apple or stolen signing keys).
There is a market here.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#555Earlier quoted context omitted.
Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…
Generally I recommend people use PopOS. It's well suited for laptops, as that's what System76 is focused on a they're shipping laptops with Nvidia GPUs. I personally prefer Arch based distorts like endeavor but even with wide community support it's just more likely a noob will face an error. Fwiw I've only faced one meaningful error in the last 3 years in endeavor but I've also been daily driving Linux for 15 years n…
Truly, and to really drive it home, I’ve loved PopOS but this latest release is just too half baked. I think anyone considering it should either wait a year or use something else, and Kubuntu seems like a reasonable alternative for people coming from Windows or MacOS.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#556FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
However a hostile foreign government has less control over me.
As such using a tool of a hostile foreign government (Microsoft) needs to be understood and avoided.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#557Earlier quoted context omitted.
I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…
Is your last name Segurakreischer? Have them try - leave the Windows computer online and accessible, give your parents a linux box and have them use it exclusively unless they absolutely 100% need to get back on the Windows machine for some reason, and talk with you about it. Set up a NAS with an external HD and a shared folder on both the windows and linux box, so if they actually do need to go back to Windows, they…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#558FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#559This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.
Sadly VeraCrypt is not optimized for SSDs and has a massive performance impact compared to Bitlocker for full disk encryption because the SSD doesn't know what space is used/free with VeraCrypt.
first of all trim only affects write speed (somewhat), which is not really all that important for non-server use.
it also has some impact on wear which is probably more interesting than its performance impact.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#560Earlier quoted context omitted.
Buy a laptop with less problems on Linux if that's your intention.
What laptops would you recommend? I didn’t realise framework laptops struggled with Linux?