Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

571–580 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#571
post #547

Earlier quoted context omitted.

> What's the equivalent of thinking users are this stupid? What's the equivalent of thinking security aficionados are clueless? Security advice is dumb and detached from life, and puts ubdue burden on people that's not like anything else in life. Sharing passwords is a feature , or rather a workaround because this industry doesn't recognize the concept of temporary delegation of authority , even though it's the basic…

Your credit card analogy is doing a lot of heavy lifting here, but it's carrying the wrong cargo. Sending your kid to the shops with your card is temporary delegation , not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". And; you know that you've done it, you have person…

> Sending your kid to the shops with your card is temporary delegation, not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours".

Okay, then take sharing your PINs with your spouse. Or for that matter, account passwords or phone unlock patterns. It's a perfectly normal thing that many people (including myself) do, because it enables ad-hoc delegation. "Honey, can you copy those photos to my laptop and send them to godparents?", asks my wife as she hands me her phone and runs to help our daughter with something - implicitly trusting me with access to her phone, thumbdrive, Windows account, e-mail account, and WhatsApp/Messenger accounts.

This kind of ad-hoc requests happen for us regularly, in both directions, without giving it much of a thought[0]. It's common between couples, variants of that are also common within family (e.g. grandparents delegating most of computer stuff to their adult kids on an ad-hoc basis), and variants of that also happen regularly in workplaces[1], despite the whole corporate and legal bureaucracy trying its best to prevent it[2].

> Government IDs have recovery because the government is the trusted authority that verified you exist in the first place. Microsoft didn't issue your birth certificate.

But Microsoft issued your copy of Windows and Bitlocker and is the one responsible for your data getting encrypted. It's obvious for people to seek recourse with them. This is how it works in every industry other than tech, which is why I'm a supporter of governments actually regulating in requirements for tech companies to offer proper customer support, and stop with the "screw up managing 2FA recovery keys, lose your account forever" bullshit.

> Banks can reset your PIN because they're heavily regulated entities with legal obligations and actual consequences for breaching trust.

As it should be. As it works everywhere, except tech, and especially except in the minds of security aficionados.

> Nuclear launch codes are literally designed around not giving any single entity complete access, hence the two-person rule and multiple independent key holders.

Point being, if enough right people want the nukes to be launched, the nukes will be launched. This is about the highest degree of responsibility on the planet, and relevant systems do not have the property of "lose the encryption key we told you 5 years ago to write down, and it's mathematically proven that no one can ever access the system anymore". It would be stupid to demand that.

That's the difference between infosec industry and real life: in real life, there is always a way to recover. Infosec is trying to normalize data and access being fundamentally unrecoverable after even a slightest fuckup, which is a degree of risk individuals and society have not internalized yet, and are not equipped to handle.

> Right, so the solution is clearly to hand those keys to a corporation that's subject to government data requests, has been breached multiple times, and whose interests fundamentally don't align with yours?

Yes. For normal people, Microsoft is not a threat actor here. Nor is the government. Microsoft is offering a feature that keeps your data safe from thieves and stalkers (and arguably even organized crime), but that doesn't require you to suddenly treat your laptop with more care than you treat your government ID. They can do this, because for users of this feature, Microsoft is a trusted party.

Ultimately, that's what security aficionados and cryptocurrency people don't get: the world runs on trust. Trust is a feature.

--

[0] - Though less and less of that because everyone and their dog now wants to require 2FA for everything. Instead of getting the hint that passwords are not meant to identify a specific individual, they're doubling down and tying every other operation to a mobile phone, so delegating desktop operations often requires handing over your phone as well, defeating the whole point. This is precisely what I mean by the industry not recognizing or supporting the concept of delegation of authority.

[1] - The infamous practice of writing passwords on post-it notes isn't just because of onerous password requirements, it's also a way to facilitate temporary delegation of authority. "Can you do X for me? Password is on a post-it in the top drawer."

[2] - GDPR or not, I still heard from doctors I know personally that sharing passwords to access patient data is common, and so is bringing some of it back home on a thumb drive, to do some work after hours. On the one hand, this creates some privacy risks for patient (and legal risk for hospitals) - but on the other hand, these doctors don't do it because they hate GDPR or their patients. They do it because it's the only way they can actually do their jobs effectively. If rules were actually enforced to prevent it, people would die. This is what I mean when I say that security advice is often dumb and out of touch with reality, and ignored for very good reasons.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#572

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

I've been trying to get my parents to move, but until Microsoft Office desktop is able to be run natively on there my parents won't entertain the subject. I've tried to get them to use the web version of office, I've tried to get them to use OnlyOffice and LibreOffice, I've even tried showing them LaTeX as a last ditch effort, but no, if it isn't true Microsoft Branded Office 2024, the topic isn't even worth discussi…

Your parents have a point. I've been switching most of my family's PCs to linux in the past few years and I miss Office. It is as easy to use as OnlyOffice and as powerful as LibreOffice for my tasks. There exists no equivalent on linux.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#574
post #5

FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…

> "Microsoft gave"

While it is true that NSLs or other coercion tactics will force them to give out the keys, it is also true that this is only possible because Microsoft implemented a fatally flawed system where they have access to the keys.

Any system where a third party has access to cleartext or the keys to decrypt to cleartext is completely broken and must not be used.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#575
post #409

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive. > sign into your Microsoft account or link it to Windows again. For reference, I did accidentally login into my Microsoft account once on my local account (registered in the online accounts panel). While Edge automatically enabled synchronization without any form of consent from my part, it does not look like that my Bitlocke…

> Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive.

Given that:

1. Retail licenses (instead of OEM ones) can be transferred to new machines

2. Microsoft seems to be making a pattern of allowing retail and OEM licenses to newer versions of Windows for free

A $60 difference in license cost, one-time, isn't such a big deal unless you're planning on selling your entire PC down the line and including the license with it. Hell, at this point, I haven't purchased a Windows license for my gaming PC since 2013 - I'm still using the same activation key from my retail copy of Windows 8 Pro.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#577
post #32

Earlier quoted context omitted.

You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)

Sorry to interrupt the daily rage session with some neutral facts about how Windows and the law work. > that just so happens to take a screenshot of your screen every few seconds Recall is off by default. You have to go turn it on if you want it.

Daily rage is exactly what technology affine people need to direct at Microslop, while helping their loved ones and ideally businesses transition away from the vendor lockin onto free software.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#578
post #544

Earlier quoted context omitted.

> Basically I cannot rescue the files on my own disk but the police can? I think you're misunderstanding. You can rescue the files on your own disk when you place the key in your MS account. There's no scenario where you can't but the police can.

If I happen to know that my key is there.

You'd have to be quite daft not to. The Bitlocker lock out screen has a qr code and a link telling you to go fetch your recovery key.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#579
post #547

Earlier quoted context omitted.

> What's the equivalent of thinking users are this stupid? What's the equivalent of thinking security aficionados are clueless? Security advice is dumb and detached from life, and puts ubdue burden on people that's not like anything else in life. Sharing passwords is a feature , or rather a workaround because this industry doesn't recognize the concept of temporary delegation of authority , even though it's the basic…

Your credit card analogy is doing a lot of heavy lifting here, but it's carrying the wrong cargo. Sending your kid to the shops with your card is temporary delegation , not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". And; you know that you've done it, you have person…

Let's be serious for a second and consider what's more useful based on the likelihood of these things actually happening.

You're saying it's likely to happen that a laptop thief also is capable to stealing the recovery key from Microsoft'servers?

So therefore it would be better that users lost all their data if - an update bungles the tpm trust - their laptop dies and they extract the hard drive - they try to install another OS alongside but fuck up the tpm trust along the way - they have to replace a Mainboard - they want to upgrade their pc ?

I know for a fact which has happened to me more often.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#580
post #548
post #518

Earlier quoted context omitted.

So what happens if your motherboard gets fried and you don’t have backups of your recovery key or your data? TPMs do fail on occasion. A bank PIN you can call and reset, they can already verify your identity through other means.

> So what happens if your motherboard gets fried and you don't have backups of your recovery key or your data? If you don't have backups of your data, you've already lost regardless of where your recovery key lives. That's not an encryption problem, that's a "you didn't do backups" problem, which, I'll agree is a common issue. I wonder if the largest software company on the planet (with an operating system in practic…

> I wonder if the largest software company on the planet (with an operating system in practically every home) can help with making that better. Seems like Apple can, weird.

If you're talking about time machine, windows has had options built in since NT.

Post reply on HN