Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

631–640 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#631
post #20

This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

> This is by far one of the best advertisements for LUKS/VeraCrypt I've ever seen.

LUKS isn't all rainbows and butterflies either [https://news.ycombinator.com/item?id=46708174]. This vulnerability has been known for years, and despite this, nothing has been done to address it.

Furthermore, if you believe that Microsoft products are inherently compromised and backdoored, running VeraCrypt instead of BitLocker on Windows likely won’t significantly improve your security. Implementing a VeraCrypt backdoor would be trivial for Microsoft.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#632

Earlier quoted context omitted.

> The real issue is that you can't be sure that the keys aren't uploaded even if you opt out. The fully security conscious option is to not link a Microsoft account at all. I just did a Windows 11 install on a workstation (Windows mandatory for some software) and it was really easy to set up without a Microsoft account.

Last time I needed to install Windows 11, avoiding making a Microsoft account required (1) opening a command line to run `oobe/bypassnro`, and (2) skipping past the wifi config screen. While these are quick steps, neither of those are at all "easy", since they require a user to first know that it is an option in the first place. And newer builds of Windows 11 are removing these methods, to force use of a Microsoft ac…

It goes even deeper than this, because your account can be linked to a microsoft account later, by logging into microsoft services like Teams.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#633

Earlier quoted context omitted.

Some people will hurt themselves if given dangerous tools, but if you take all the dangerous items out of the tool shop, there won't be any tools left. Microsoft seems to feel constant pressure to dumb Windows down, but if you look at the reasons people state when switching to Linux, control is a frequent theme. People want the dangerous power tools.

Tool manufacturers include all kinds of annoying safety devices to attempt to prevent injury, or at least to give them some cover in a lawsuit. Table saw blade guards and riving knives are an ironic example here: I've yet to hear a story of a woodworker that lost a finger on a table saw that wouldn't have been able to avoid that injury if they kept one of those safety devices on the saw. Everyone thinks the annoyance…

Right, but none of those safety devices invalidate the underlying purpose of the tools. Disk encryption is used, for many people, for privacy. Uploading the keys to Microsoft defeats a lot of that.

If you bought a table saw and the "safety device" is that it won't run, I would imagine you'd be pissed too.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#634

Earlier quoted context omitted.

> Journalists love the "Microsoft gave" framing because it makes Microsoft sound like they're handing these out because they like the cops, but that's not how it works. If your company has data that the police want and they can get a warrant, you have no choice but to give it to them. I’m not sure how you’re criticizing the “gave” framing when you’re describing and stating Microsoft literally giving the keys to the F…

Because "gave" implies a favor or a one sided exchange. It implies that Microsoft is just giving away keys for no reason! Better, and more accurate wording, would be that "Microsoft surrendered keys" or "Microsoft ceded keys". Or "Microsoft legally compelled to give the keys". If Microsoft did so without a warrant, then "gave" would be more tonally accurate. In addition, none of this is new. They've been turning over…

The fact that none of this is new undermines your point. Microsoft knew that law enforcement would ask for keys, based on their prior experience and the sack of meat sitting between their ears.

They, knowing that, chose to design a system that trivially allows this. That is a choice. In that sense, they did give up the keys. They certainly did not have to design it that way, nor was it done in ignorance.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#636
post #409

Earlier quoted context omitted.

Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive. > sign into your Microsoft account or link it to Windows again. For reference, I did accidentally login into my Microsoft account once on my local account (registered in the online accounts panel). While Edge automatically enabled synchronization without any form of consent from my part, it does not look like that my Bitlocke…

> Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive. Given that: 1. Retail licenses (instead of OEM ones) can be transferred to new machines 2. Microsoft seems to be making a pattern of allowing retail and OEM licenses to newer versions of Windows for free A $60 difference in license cost, one-time, isn't such a big deal unless you're planning on selling your entire PC down t…

> A $60 difference

Oh, the difference in dollar is less than I expected. And you're right, after checking, the difference in price in the USA is $60 ($139 Home and $199 Pro). In France, Windows 11 Home is 145€ compared to 259€ for Windows 11 Pro: https://www.microsoft.com/fr-fr/d/windows-11-famille/dg7gmgf... - https://www.microsoft.com/fr-fr/d/windows-11-professionnel/d... (USB key is selected by default but the download edition is the same price).

This amounts to a difference of 114€ or 135$ at the current exchange rate which is significantly more. Also surprised that Windows Pro is 189% of the price of the Home edition in France but 143% in the USA.

I initially bought the Home edition but could not upgrade to pro without buying a full license so I had to bear the full cost of the French Pro license, which lead to an upgrade cost of 259€ instead of just $60. (basically I had to buy the pro version to get password unlock with Bitlocker since TPM unlock was broken with dual boot, needed to enter the recovery key after every boot to Fedora). If it was possible to only pay for the difference they did not make it obvious.

And in general paying this much for an OS that still pushes dark pattern and ads onto me leaves quite a bad taste in my mouth; I wouldn't mind paying a subscription if I could get an OS that does what I want and gets fully out of my way. (but I guess subscription would come with mandatory online accounts which is part of the problem at hand here).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#637
post #612

Earlier quoted context omitted.

From the linked Apple page... "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption." The FileVaul…

> Apple does not have access to them Unless they are given a warrant, then they magically have access to your encrypted data. https://www.businessinsider.com/apple-fbi-icloud-investigati... If they can get access to your icloud, they can get access to your laptop if you store your decryption key in your keychain.

You are conflating iCloud Keychain with the rest of the iCloud data. iCloud keychain is always end-to-end encrypted. Apple cannot decrypt it even if they receive a subpoena. The other iCloud data like your photos are not end-to-end encrypted by default unless you turn on Advanced Data Protection (ADP).

https://support.apple.com/en-us/102651 There is a table showing exactly what is E2EE under Standard vs ADP mode.

In the news article you shared above, it's very likely this person did not have ADP turned on. So everything in their iCloud that is not E2EE by default could be decrypted by Apple.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#639

Earlier quoted context omitted.

Generally I recommend people use PopOS. It's well suited for laptops, as that's what System76 is focused on a they're shipping laptops with Nvidia GPUs. I personally prefer Arch based distorts like endeavor but even with wide community support it's just more likely a noob will face an error. Fwiw I've only faced one meaningful error in the last 3 years in endeavor but I've also been daily driving Linux for 15 years n…

I’ve been using PopOS for the last five years and while I generally agree… the latest release using Cosmic by default has a lot to be desired. Cosmic will eventually be good but right now it’s far from it and I had to install Gnome as a stop gap just to have a functional desktop environment. I’ll probably ditch PopOS for Arch + KDE but I haven’t had the time to do so yet for my workstation. Truly, and to really drive…

That's unfortunate to hear.

I'd give kde a shot. It's been my preferred DE for years. But check out the below wiki and poke around for what your style is. The beauty of linux is adapting to you and switching DEs is a quick change (you do not need to change your DM to change your DE).

If you're interested on Arch then give something like EndeavourOS a shot. Cachy is getting popular these days too but I haven't used it. But I feel its going to be as easy as using Endeavour or Manjaro and those are very convenient distros for Arch with direct Nvidia GPU support. Though if you want you learn Linux I suggest going Vanilla Arch. You'll learn a lot from the install process (it isn't uncommon to mess up. You won't brick anything and learning about the chroot environment will help you in the future of you do mess things up)

https://wiki.archlinux.org/title/Desktop_environment

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#640
You should carry around a Ventoy stick with Debian/XFCE and perhaps Mint on it, and a 16 TB external disk, and nag people in your local environment to let you back up their stuff and move them off MICROS~1 operating systems.

Tell them you work in IT and that you'll make their computer faster and more secure. Don't mention Linux by name.

Post reply on HN