Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

611–620 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#611
This happens with every company that has your sensitive info. When the government asks for your info, the companies provide it.

Some ways around this is to either not store sensitive user data on servers, or if that needs to happen then encrypt it with user supplied keys.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#612

Earlier quoted context omitted.

The iCloud Keychain is end-to-end encrypted.[0] Apple can't decrypt it. That said, when setting up FileVault, you have the option to escrow your recovery key with Apple. If you enable that, Apple can get the recovery key. [0] https://support.apple.com/en-us/102651

From the linked Apple page... "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption." The FileVaul…

> Apple does not have access to them

Unless they are given a warrant, then they magically have access to your encrypted data.

https://www.businessinsider.com/apple-fbi-icloud-investigati...

If they can get access to your icloud, they can get access to your laptop if you store your decryption key in your keychain.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#614
post #411

Earlier quoted context omitted.

People know the system well enough to write FOSS implementations of it; I think they would have noticed and sounded the alarm if there were a possible master key.

I don't think anybody is interested in reverse-engineering closed-source OS to check if it works as documented; it;s easier to just use Linux which has open-source code.

> I don't think

Well at least you got that part correct. Do you just not know about security researchers? Or even bug bounty programs?

Why are you even on this forum? Doesn't seem like you know much about technology

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#615
I gave up on osx 5 years ago. I gave up on Linux 3 years ago.

Today, 2 out of 3 of my machines are KDE fedora. The last one is TBD because my kids are using it.

I didn't have a choice for machine 1 because it wasn't eligible for windows 11 and windows 10 security updates were EOL. Machine 2 quickly followed.

At the time, there had been disappointing windows news every few months. Since there have continued to be disappointing windows news every few months.

I expect more disappointing windows news to follow.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#616
post #300

Earlier quoted context omitted.

Of course. But I suppose you run Teams on a company provided/managed, or at least paid for by the company, device? Just don’t use that machine for anything private. Is anyone using their private devices for work? (Also there is teams for Linux and on the web, if that is not prevented by the policy of your org.)

In the startup world, BYOD is/was exceedingly common. All but two jobs of my career were happy to allow me to use my own Linux laptop and eschew whatever they were otherwise going to give me. Obviously enterprises aren’t commonly BYOD shops, but SMBs and startups certainly can be. … whether the people who would do such BYOD things are at all likely to be Windows users who care about this Bitlocker issue, is a differe…

>All but two jobs of my career were happy to allow me to use my own Linux laptop

But they wouldn't have provided you with a corporate device if you asked?

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#618

Earlier quoted context omitted.

It’s a pity for Apple that they keep making macOS worse with each major update. Modern Apple hardware running snow leopard would be a thing of beauty. At this rate, my next laptop might end up being a framework running Linux.

I switched from Windows to Mac 15 years ago. It was a revelation when the terrible habits of verbally abusing my computer and anxiety saving files every 22 seconds just evaporated. Those old habits have been creeping back lately through all the various *OS 26 updates. I too now have Linux on Framework. Not perfect, but so much better for my wellbeing.

The 7 did not behave like that.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#619

Based on the comments in the thread, I sense I will be in the minority, but for most consumers this is a reasonable default. Broadly speaking, the threat model most users are concerned with doesn't account for their government. The previous default is no encryption at rest, which doesn't protect from the most common threats, like theft or tampering. With BitLocker on, a new risk for users is created: loss of access t…

I think it’s a reasonable default if Microsoft weren’t able to access your encryption keys.

Apple has that figured out. Your keys can be stored in your cloud synced keychain but only you can decrypt that keychain.

That’s why they couldn’t help the FBI to decrypt devices even when compelled.

Microsoft should have done the same. They should never find themselves in a place where they can be compromised like this.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#620

Earlier quoted context omitted.

That link you provided is a "conspiracy theory," even by the author's own admission. That article is also outdated; OCSP is as dead as a doornail (no doubt in part because it could be used for surveillance) and they fixed the cleartext transmission of hardware identifiers. Are you expecting perfection here? Or are you just being argumentative?

> That link you provided is a "conspiracy theory," even by the author's own admission. "Conspiracy theory" is not the same as a crazy, crackhead theory. See: Endward Snowden. Full quote from the article: > Mind you, this is definitionally a conspiracy theory; please don’t let the connotations of that phrase bias you, but please feel free to read this (and everything else on the internet) as critically as you wish. >…

> Have you got any links for that?

It was noted at the bottom of the article as a follow up.

> I expect basic things people should expect from a company promoting themselves as respecting privacy. And I don't expect them to be much worse than GNU/Linux in that respect (but they definitely are).

The problem with the word “basic” is that it’s entirely subjective. What you consider “basic,” others consider advanced. Plus the floor has shifted over the years as threat actors have become more knowledgeable, threats more sophisticated, and technologies advanced.

Finally, the comparison to Linux doesn’t make a lot of sense. Apple provides a solution of integrated hardware, OS, and services. Linux has a much smaller scope; it’s just a kernel. If you don’t operate services, then by definition, you don’t have any transmitted data to protect. Nevertheless, if you consider the software packages that distros package alongside that kernel, I would encourage you to peruse the CVE databases to see just how many security notices have been filed against them and which remain open. It’s not all sunshine and roses over in Linux land, and never has been.

Post reply on HN