Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

61–70 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#61
post #4

Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.

I was happy to give up my side-hobby of drilling drives after FDE became standard everywhere. Plug and play is great, but you don't want it to be plug and play for whoever pulls your drive out of the trash.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#62

Earlier quoted context omitted.

Can’t wait to read the blogpost of what have truly happened and motivated this person to expose M$ like this

[flagged]

Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#63
post #13

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

Cool. Everyone's threat model is different. As long as we're not writing passwords on sticky notes attached to the monitor, I don't think there's any need to be throwing stones.

Sensitive data written down on a sticky note is arguably more secure than that same data sitting on an unencrypted hard drive, at least in a home setting.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#64
post #14

Earlier quoted context omitted.

My harddrives (laptop, work laptop, desktop, server) contain emails, browser sessions, saved passwords, personal data from family and friends. I do not want someone stealing my laptop on a train ride potentially being able to have all of that data. With a proper real backup strategy, i have everything save. I do not need easy access to a hard drive from a broken computer. But hey you do you :)

Are you saying you bring your desktop on a train ride as well? Laptops with encryption make sense; if you need to encrypt your desktop, I have questions.

My inference machine is the only drive I leave unencrypted, but that's because it has the models on it, llama.cpp, and nothing else, and I want it back up and running services after a power-failure. My other desktops are encrypted to make hard drive disposal easy.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#65

Title sounds conspiratorial, but it lines up well with the controversy around TrueCrypt's discontinuation which, I believe, specifically called out BitLocker as an alternative to use in future.

You're probably thinking of VeraCrypt, which is a fork of TrueCrypt. I don't think BitLocker is related.

https://en.wikipedia.org/wiki/TrueCrypt#End_of_life_announce... - they are referring to this event, and the SourceForge page is still displaying the message along with a guide on how to enable BitLocker.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#66
post #24

Earlier quoted context omitted.

> This is not to defend Microsoft But you are defending MS, conflating a bunch of things, mainly full disk encryption and cloud backups. There's a big difference between Apples cloud backup which has documented behavior and a backdoor. I'm also fairly confidant in Apple's full disk encryption, they've gone to court to defend it. There also a lot more data points we can use to judge Apple vs Microsoft on privacy and s…

I think my message wooshed. I was not comparing disk encryption and iCloud backups. My point is that insecure defaults are Apple and other's alternative to backdoors. They give plausible deniability ("how is someone able to recover their data if they lost their credentials and we used E2E?"), while at the same time satisfying law enforcement, because the vast majority of people is not aware of them. Another example i…

Signal won't let us download our own data and back it up using our own secure systems. Whatever its other merits it gets 0% for backup policy.

Though I suppose then I have to give a negative % to all the systems that have insecure online backups. This whole area is a train wreck really.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#67
post #36

Earlier quoted context omitted.

I don't use Microsoft products generally but not with even with your computer would I run VeraCrypt.

Ever since the TrueCrypt fiasco years ago, I have no trust in that brand.

Is there a brand you do have trust in? I’ve kind of thrown my hands up, considered my attack surface is dude stealing my laptop and not the state department wants my 4chan history, and just use the encryption tools provided by Apple and Microsoft

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#68
post #54

Earlier quoted context omitted.

I read it as the author is / was going through the vulnerability disclosure process with Microsoft and they're annoyed for unclear reasons and decided to publicly disclose, rather than being an insider.

How would that leave them homeless?

Presumably, not paying out for these bugs which often take weeks of research to find.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#69
post #5
post #4

Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.

What's not plug and play if using some sensible fde like idk, dm-crypt? You are only a passphrase away from mounting that drive in any other system you plug it into.

That's my question, because my root is encrypted, I move encrypted disks all the time, and have a couple of encrypted external drives. It's trivial.

But I'm sure that some of the millions of things that I've missed as windows has become what it has become makes this simplicity seem like a scifi absurdity. I don't think that they can even log into their own computers without asking Microsoft for permission over the network. I'm sure the idea of encryption must have been overcomplicated to the point of absurdity in order to trap customers too, I just don't know about it.

I suppose you should just count your blessings (of ignorance) and be available to help your friends with cryptsetup if they decide to flee windows.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#70
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

As opposed to iOS, which does iCloud backups that are not E2E encrypted by default, so that law enforcement can request your chats (except Signal because they opt out), browser history, etc.? You can enable ADP for E2E encrypted backups, but it's probable not going to help you much, because the people you are communicating with likely didn't. This is not to defend Microsoft, more to say that all these companies were…

[deleted]
Post reply on HN