Earlier quoted context omitted.
You can always count on someone coming along and defending the multi-trillion dollar corporation that just so happens to take a screenshot of your screen every few seconds (among many, many - too many other things)
Microsoft doesn't take the screenshot; their operating system does if Recall is enabled, and although the screenshots themselves are stored in an insecure format and location, Microsoft doesn't get them by default.
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
581–590 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#582Earlier quoted context omitted.
Your credit card analogy is doing a lot of heavy lifting here, but it's carrying the wrong cargo. Sending your kid to the shops with your card is temporary delegation , not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". And; you know that you've done it, you have person…
Let's be serious for a second and consider what's more useful based on the likelihood of these things actually happening. You're saying it's likely to happen that a laptop thief also is capable to stealing the recovery key from Microsoft'servers? So therefore it would be better that users lost all their data if - an update bungles the tpm trust - their laptop dies and they extract the hard drive - they try to install…
The question isn't "cloud escrow vs nothing". It's "cloud escrow vs local backup". One protects you from hardware failure. The other protects you from hardware failure whilst also making you vulnerable to data breaches, government requests, and corporate policy changes you have zero control over.
You've solved a technical problem by creating a political one. Great.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#583Earlier quoted context omitted.
Linux is so much better than it used to be. You really don't need to be technical. I have been recommending Kubuntu to Windows people. I find it's an easier bet than Linux Mint. You get the stability of Ubuntu, plus the guarantee of a Windows-like environment. Yes, I know, Linux Mint supports Plasma, but I honestly think the "choose your desktop" part of the setup process is more confusing to a newbie than just recom…
Eh, not for laptops - I say as someone who switched to Linux from windows in past year. I have spent a decent few days to get long battery life on Linux (fedora), with sleep hibernate + encryption. And I am still thinking that the Linux scheduler is not correctly using Intel's pcore/ecore on 13th gen correctly.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#584Earlier quoted context omitted.
Your credit card analogy is doing a lot of heavy lifting here, but it's carrying the wrong cargo. Sending your kid to the shops with your card is temporary delegation , not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". And; you know that you've done it, you have person…
> Sending your kid to the shops with your card is temporary delegation, not permanent key escrow to a third party you don't control. It's the difference between lending someone your house key for the weekend and posting a copy to the council "just in case you lose yours". Okay, then take sharing your PINs with your spouse. Or for that matter, account passwords or phone unlock patterns. It's a perfectly normal thing t…
> Okay, then take sharing your PINs with your spouse.
Sharing with your spouse is consensual, temporary, and revocable. You know you've done it, you trust that specific person, and you can change it later. Uploading your keys to Microsoft is none of these things.
> But Microsoft issued your copy of Windows and Bitlocker and is the one responsible for your data getting encrypted.
Microsoft sold you software. They didn't verify your identity, they're not a regulated financial institution, and they have no duty of care beyond their terms of service. The fact that they encrypted your drive doesn't make them a trustworthy custodian of the keys any more than your locksmith is entitled to copies of your house keys.
> For normal people, Microsoft is not a threat actor here. Nor is the government.
"Normal people" includes journalists, lawyers, activists, abuse survivors, and anyone else Microsoft might be legally compelled to surveil. Your threat model is "thieves and stalkers". Mine includes the state. Both are valid, but only one of us is forcing our model on everyone by default.
> the world runs on trust. Trust is a feature.
Trust in the wrong entity is a vulnerability. You're arguing we should trust a corporation with a legal department larger than most countries' regulators, one that's repeatedly been breached and is subject to government data requests in every jurisdiction it operates.
Your doctors-breaking-GDPR example is particularly telling: you've observed that bad UX causes people to route around security, and concluded that security is the problem rather than the UX. The solution to "delegation is hard" isn't "give up and trust corporations". It's "build better delegation mechanisms". One is an engineering problem. The other is surrender dressed as pragmatism.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#585FYI BitLocker is on by default in Windows 11. The defaults will also upload the BitLocker key to a Microsoft Account if available. This is why the FBI can compel Microsoft to provide the keys. It's possible, perhaps even likely, that the suspect didn't even know they had an encrypted laptop. Journalists love the "Microsoft gave " framing because it makes Microsoft sound like they're handing these out because they lik…
> It protects their data in the event that someone steals the laptop, but still allows them to recover their own data later from the hard drive. False. If you only put the keys on the Microsoft account, and Microsoft closes your account for whatever reason, you are done.
done here meaning you've lost your data which uhhh, is currently on a drive in the hands of thieves, so what did you lose again?
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#586Earlier quoted context omitted.
> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.
It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#587Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#588It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
There was no “back in the day” where big tech was on our side. Stop being a poser
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#589Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#590Earlier quoted context omitted.
> So what happens if your motherboard gets fried and you don't have backups of your recovery key or your data? If you don't have backups of your data, you've already lost regardless of where your recovery key lives. That's not an encryption problem, that's a "you didn't do backups" problem, which, I'll agree is a common issue. I wonder if the largest software company on the planet (with an operating system in practic…
> I wonder if the largest software company on the planet (with an operating system in practically every home) can help with making that better. Seems like Apple can, weird. If you're talking about time machine, windows has had options built in since NT.