Earlier quoted context omitted.
If you’re doing your work inside the windows machine, what protection does Linux as a host get you?
The topic is bitlocker, and Microsoft, and keys. With a VM running on an encrypted file system, whatever a warrant for a bitlocker key might normally provide will be hidden behind an additional layer that Microsoft does not hold the keys to. (Determining whether that is useful or not is an exercise for the person who believes that they have something to hide.)
Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
591–600 of 694 posts
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#592Earlier quoted context omitted.
That's nice. I, however, like getting my paycheck, and so I have no choice.
teams works fine in website form for me because it IS a website (that uses an extra ~1gb of ram running as a desktop app because its also a separate browser)
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#593Earlier quoted context omitted.
They're Microsoft and it's Windows. They always have the ability to fetch the key. The question is do they ever fetch and transmit it if you opt out? The expected answer would be no. Has anyone shown otherwise? Because hypotheticals that they could are not useful.
Considering all the shenanigans Microsoft has been up to with windows 11 and various privacy, advertising, etc. stuff? Hell, all the times they keep enabling one drive despite it being really clear I don’t want it, and then uploading stuff to the cloud that I don’t want? I have zero trust for Microsoft now, and not much better for them in the past either.
One day they came in and found an icon on their desktop labeled “Where are my files?” that explained they had all been moved in OneDrive following an update. This prompted my clients to go into full meltdown mode, as they knew exactly what this meant. We ultimately got a BAA from Microsoft just because we don’t trust them not to violate federal laws again.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#594Earlier quoted context omitted.
> If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. You can encrypt secrets end-to-end - just look at how password managers work - and it means the cops can only su…
Where did you get that they are stored in plaintext?
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#595Earlier quoted context omitted.
Plenty of companies would do that if they could. The problem is it has become illegal for them to do that now. KYC/AML laws form the financial arm of warrantless global mass surveillance.
KYC/AML is luckily still confined to the financial sector. There's no law for operating system vendors to do KYC/AML.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#596Here's a story about what the FBI may do when they don't unlock the laptop: https://cointelegraph.com/news/fbi-cant-be-blamed-for-wiping... Perhaps next time, an agent will copy the data, wipe the drive, and say they couldn't decrypt it. 10 years ago agents were charged for diverting a suspect's Bitcoin, I feel like the current leadership will demand a cut.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#597Earlier quoted context omitted.
The problem is the implementation is hasty. When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. We can't trust every private company that now has to verify age to not store that information with whatever questionable security. If we aren't going to…
> When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. Beer, sure. But if you buy certain decongestants, they do log your ID. At least that's the case in Texas.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#598It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.
The median user's threat model doesn't include the government, but does include data loss, forgetting the password, or a thief stealing your laptop. Microsoft struck the right balance. I'm glad the knee-jerk absolutists are marginal, for one. A world run by you people would be much worse for anyone who isn't you.
Ask a non techy user:
* How do they backup their data/do they backup their data at all?
* Do they know 3-2-1 rule? Are they following it?
I bet 90% people will answer no to some of the questions.
And data backup is much more of an everyday topic compared to disk encryption.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#599Earlier quoted context omitted.
> Too many tech workers decided to rollover for the government s/workers/Corporations/
A Corporation can't do anything without a worker's consent.
I hope you put your money where your mouth is.
Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops
#600Earlier quoted context omitted.
Yes, they push the MS account stuff very hard. I've found Windows so actively hostile to the user that I basically only use Linux now. I used to be a windows user, it has really devolved to the point where it's easier for me to use Linux (though I'm technical). I really feel for the people who aren't technical and are forced to endure the crap that windows pushes on users now.
> actively hostile That’s the real problem MS has. It’s becoming a meme how bad the relationship between the user and windows is. It’s going to cause generational damage to their company just so they can put ads in the start menu.