Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

661–670 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#661
post #659

Earlier quoted context omitted.

If you distrust Windows that much, isn't the only real option to just not use it?

That's yet another brilliantly simple plan that you've outlined! Would you like for me to demonstrate how it, too, is short-sighted?

I don't think so.

If you believe Windows to be so actively malicious that it would go behind your back and enable key backups after you've explicitly disabled them, you should probably assume that it will steal your encrypted information in other ways too.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#662
post #465

Earlier quoted context omitted.

I’ve been diving down the BYOD rabbit hole recently. At enterprise scale it’s not “hook in with your vpn, job done”, it’s got to be managed . Remote wipe on exit, prove the security settings, disk encryption, EDR. What this means for the user is your personal device is rather invasively managed. If you want Linux, your distro choice may be heavily restricted. What you can do with that personal device might be restric…

All of that won't stop anyone from exfiltrating whatever they want to exfiltrate.

Of course, but like so many of these things, it’s about compliance audits and insurance. Actual effectiveness is a distant concern.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#663

Earlier quoted context omitted.

I’ll bite. What Linux distro currently has the nicest desktop experience? I work on a MacBook but my desktop is a windows PC that I use for gaming and personal projects. I hear Proton has made the former pretty good now, and the latter is mostly in WSL for me anyway. Maybe a good time to try. What do you suggest? I’ll try it in a VM or live usb.

There are so many distros that it really depends on your use-case and it's hard to make a generic suggestion. Ubuntu is a common recommendation for first timers, mainly because as the most popular distro you'll easily be able to Google when you need help with something, and it also uses the most popular package format (.deb). There's also Linux Mint which is basically Ubuntu but with some of the latter's more questio…

This was a helpful answer. It really is hard to make a choice if you've left the ecosystem for a while. My mac as well as windows+WSL have been good enough for a while, but this post got me curious. And mind you, I'm not completely out of touch with _linux_ - its running two servers in my basement. I've installed slackware from floppies and compiled gentoo. But it's never been the year of the linux desktop for me.

I ended up booting Mint with Cinnamon. I like it. It's pretty intuitive coming from macos/windows, and I'm in the terminal half the time anyway. Installing the nvidia driver was easy, then steam does a good job installing whatever compatibility layers it needs. I'll do CUDA next and try it for a month or so.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#664

Earlier quoted context omitted.

> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Except the steps to to that are disable bitlocker, create a local user account (assuming you initially signed in with a Microsoft account because Ms now forces it on you for home editions of windows), delete your existing keys from OneDrive, then re-encrypt using y…

> make sure not to sign into your Microsoft account or link it to Windows again That's not so easy. Microsoft tries really hard to get you to use a Microsoft account. For example, logging into MS Teams will automatically link your local account with the Microsoft account, thus starting the automatic upload of all kinds of stuff unrelated to MS Teams. In the past I also had Edge importing Firefox data (including store…

It's exceptionally more straightforward than people think and is listed as one command on AtlasOS's guide.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#665

It's interesting how many comments these days are like, "well of course". Back in the day hackernews had some fire and resistance. Too many tech workers decided to rollover for the government and that's why we are in this mess now. This isn't an argument about law, it's about designing secure systems. And lazy engineers build lazy key escrow the government can exploit.

> Back in the day hackernews had some fire and resistance Hackernews is a public forum, and the people here change constantly. "Back in the day" there were mostly posts about LISP and startup equity. It's obviously not the same people here now. > Too many tech workers decided to rollover for the government Again, not the same group of people. In the 2000s "tech workers" might have mostly been Californians. Now they'r…

Oops, someone graced me with the downvote-without-comment, the sure sign that I didn't obfuscate my comment enough to get it past the plankton.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#666

Earlier quoted context omitted.

I bought and returned an AMD Framework. I knew what I was getting into, but the build quality + firmware quality were lacking, sleep was bad and I'm not new to fixing Linux sleep issues. Take a look at the Linux related support threads on their forum. I've been using AMD EliteBooks, the firmware has Linux happy paths, the hardware is supported by the kernel and Modern Standby actually works well. Getting one with a Q…

We have Elitebooks at work and can confirm that the 8x0 series, at least until G8, has superb Linux support out of the box (and I run Arch, by the way). IME it's actually better than Windows, since both my AMD and Intel models have had things not working on Windows (the AMD still often hangs during sleep). > Getting one with a QHD to UHD screen is mandatory But I have to ask: are those screens actually any good? Ours…

> But I have to ask: are those screens actually any good? Ours have FHD panels, and I have not seen a single one with a decent screen.

Yeah, I brought up the screens because the FHD screens are not good and there's a chance you might end up with a SureView screen. The QHD screens suit my needs, they support HDR and higher refresh rates. I'm not a designer or someone who can speak to color quality/contrast/etc, though.

I eventually had an issue with the keyboard on a G8 model, a key popped off 3 years into using it, but I've also had that same issue with the keyboard of every laptop I've owned including every MacBook from 2006-2018, so the problem is likely me.

> These are also fairly expensive, around 1500 EUR, and the components are of questionable quality. The SSDs in particular are dog-slow (but they're very easy to replace).

I buy them on the consumer side when there's a >60% off sale, I would not pay the sticker price for them, and get them with the intention of replacing the innards so I spec them out with the least I can.

If you don't care about new, if you buy Ebay open box/refurbished Elitebooks, you can find recent ones for a few hundred bucks with HP support for a year or more. The overnight laptop replacement I got was for a refurbed Elitebook I bought on Ebay and HP replaced it without question.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#667

Earlier quoted context omitted.

> Back in the day hackernews had some fire and resistance Hackernews is a public forum, and the people here change constantly. "Back in the day" there were mostly posts about LISP and startup equity. It's obviously not the same people here now. > Too many tech workers decided to rollover for the government Again, not the same group of people. In the 2000s "tech workers" might have mostly been Californians. Now they'r…

Oops, someone graced me with the downvote-without-comment, the sure sign that I didn't obfuscate my comment enough to get it past the plankton.

You've been on HN long enough to know not to complain about downvotes.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#668
post #659

Earlier quoted context omitted.

That's yet another brilliantly simple plan that you've outlined! Would you like for me to demonstrate how it, too, is short-sighted?

I don't think so. If you believe Windows to be so actively malicious that it would go behind your back and enable key backups after you've explicitly disabled them, you should probably assume that it will steal your encrypted information in other ways too.

This continued usage of the word "you," as if directly and specifically targeted at me, that you're using: At first, I thought it was a mistake, but now I'm pretty sure that it is a very deliberate word choice on your part.

Therefore, based on that...

Since this is about me, then: I'd like to ask that you please stop fucking with me.

We can discuss whatever concepts that you'd like to discuss, in generalities, but I, myself, am not on the menu for discussion.

Thank you kindly!

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#669

Earlier quoted context omitted.

I saw a computer with 'system33', 'system34' folders personally. Also you would never actually know it happened because... it's not ECC. And with ECC memory we replace a RAM stick every two-three months explicitly because ECC error count is too high.

Got any old microwaves with doors that don't quite shut all the way nearby? Or radiation sources?

Nah, office building. And memtest confirmed what that was a faulty RAM stick.

But it was quite amusing to see in my own eyes: computer mostly worked fine but occasionally would cry what "Can't load library at C:\WINDOWS\system33\somecorewindowslibrary.dll".

I didn't even notice at first just though it was a virus or a consequences of a virus infection until I caught that '33' thing. Gone to check and there were system32, system33, system34...

So when the computer booted up cold at the morning everything were fine but at some time and temp the unstable cell in the RAM module started to fluctuate and mutate the original value of a several bits. And looks like it was in a quite low address that's why it often and repeatedly was used by the system for the same purpose: or the storage of SystemDirectory for GetSystemDirectory or the filesystem MFT.

But again, it's the only time where I had a factual confirmation of a memory cell failure and only because it happened at the right (or not so, in the eyes of the user of that machine) place. How many times all these errors just silently go unnoticed, cause some bit rot or just doesn't affect anything of value (your computer just froze, restarted or you restarted it yourself because it started to behave erratically) is literally unknown - because that's is not a ECC memory.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#670
post #668

Earlier quoted context omitted.

I don't think so. If you believe Windows to be so actively malicious that it would go behind your back and enable key backups after you've explicitly disabled them, you should probably assume that it will steal your encrypted information in other ways too.

This continued usage of the word "you," as if directly and specifically targeted at me, that you're using: At first, I thought it was a mistake, but now I'm pretty sure that it is a very deliberate word choice on your part. Therefore, based on that... Since this is about me, then: I'd like to ask that you please stop fucking with me. We can discuss whatever concepts that you'd like to discuss, in generalities, but I,…

Don't be silly, the indefinite "you" was simply the most natural construct to use there.

In no way should my use of the indefinite "you" be construed as a reference to ssl-3 specifically, it is an indefinite reference to literally anyone.

Post reply on HN