Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

671–680 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#671

Earlier quoted context omitted.

We have Elitebooks at work and can confirm that the 8x0 series, at least until G8, has superb Linux support out of the box (and I run Arch, by the way). IME it's actually better than Windows, since both my AMD and Intel models have had things not working on Windows (the AMD still often hangs during sleep). > Getting one with a QHD to UHD screen is mandatory But I have to ask: are those screens actually any good? Ours…

> But I have to ask: are those screens actually any good? Ours have FHD panels, and I have not seen a single one with a decent screen. Yeah, I brought up the screens because the FHD screens are not good and there's a chance you might end up with a SureView screen. The QHD screens suit my needs, they support HDR and higher refresh rates. I'm not a designer or someone who can speak to color quality/contrast/etc, though…

> Yeah, I brought up the screens because the FHD screens are not good and there's a chance you might end up with a SureView screen.

I actually prefer the SureView to the regular one for code / office work because it's much brighter and usable outside in the summer if there's shade. The other one needs to be at least at 80% brightness inside to be usable. Then again, it's OK in the dark, so YMMV.

> I'm not a designer or someone who can speak to color quality/contrast/etc, though.

Right, but those panels are quite bad, so I think it's good you've advised people to steer clear of them. Then again, some people don't care, so they could save a buck or two. Lower resolution is also easier to deal with for people still running X11 and multiple screens.

> I buy them on the consumer side when there's a >60% off sale [...] you can find recent ones for a few hundred bucks with HP support for a year or more.

Huh, I dind't know they got so low even relatively new. I was looking for some sff desktops on ebay the other day, and previous-gen ones weren't much cheaper than brand new current gens (I was looking in the EU).

I think for people who don't care about "great" screens but do care about Linux support these are a really great deal, especially if you don't expect to abuse them.

I'm generally very happy with my 845 G8, I only ever hear its fan when compiling. The only thing it's missing is thunderbolt, but AFAIK this wasn't available on AMD CPUs at all at the time.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#672
post #583

Earlier quoted context omitted.

Eh, not for laptops - I say as someone who switched to Linux from windows in past year. I have spent a decent few days to get long battery life on Linux (fedora), with sleep hibernate + encryption. And I am still thinking that the Linux scheduler is not correctly using Intel's pcore/ecore on 13th gen correctly.

I just got a lunar lake laptop and in CachyOS you can just enable either scx_lavd or scx_bpfland from the kernel settings. I use them both: bpfland guarantees that the active application runs smoothly even if you compile code in the background, and lavd focuses on energy saving a bit more. They both understand how to use the P and E cores: especially the lavd scheduler puts the active app to a P core and all the back…

> you can just enable either scx_lavd or scx_bpfland from the kernel settings

So Linux is still nowhere near an option for non technical users.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#673

Earlier quoted context omitted.

Teams inside a VM it is, then.

Just Teams in a browser tab instead. Does it actively require running as a full app to do anything?

No, but you have to use a Chromium browser on Windows, otherwise your life will be miserable.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#674

Earlier quoted context omitted.

Only because others you communicate with may not have ADP turned on, which is a flaw with any service that you cannot control what the other end does or does not do, not unique to Apple/iMessage outside of using something like Signal.

Most other E2EE messaging services do not break their own E2EE by intentionally uploading messages or encryption keys to servers owned by the same company in a form that they can read. For example, Google's Messages app does not do this for E2EE conversations. This isn't something that only Signal cares about.

How do you know the messages app doesn't so this

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#675
post #583

Earlier quoted context omitted.

I just got a lunar lake laptop and in CachyOS you can just enable either scx_lavd or scx_bpfland from the kernel settings. I use them both: bpfland guarantees that the active application runs smoothly even if you compile code in the background, and lavd focuses on energy saving a bit more. They both understand how to use the P and E cores: especially the lavd scheduler puts the active app to a P core and all the back…

> you can just enable either scx_lavd or scx_bpfland from the kernel settings So Linux is still nowhere near an option for non technical users.

It just depends on one distro to default on scx_bpfland.

For technical users, it's already the best option.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#676
post #674

Earlier quoted context omitted.

Most other E2EE messaging services do not break their own E2EE by intentionally uploading messages or encryption keys to servers owned by the same company in a form that they can read. For example, Google's Messages app does not do this for E2EE conversations. This isn't something that only Signal cares about.

How do you know the messages app doesn't so this

The security of the E2EE in Android's cloud backup system was audited by NCC group with the results published publicly. And as one of the most widely used messaging apps in the world, using a standardized protocol for E2EE, Google's Messages app has been studied by security researchers who almost certainly would have discovered this by now. OTOH, Apple's iMessage is documented to do non-E2EE backups that Apple can read.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#677

Earlier quoted context omitted.

Oops, someone graced me with the downvote-without-comment, the sure sign that I didn't obfuscate my comment enough to get it past the plankton.

You've been on HN long enough to know not to complain about downvotes.

Oh no, the rules police

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#678

Earlier quoted context omitted.

None of this matters. XKCD. Hit him with this $5 wrench until he gives you the keys.

Mass surveillance through $5 wrench (and massive thug salary) attacks do not scale, but mass surveillance through turn-key decryption does.

>massive thug salary

Common misconception due to movie brain. The average "salary" of a misc gang member is under Anyway wrench hitting does not need to scale. They only want the passwords of people they perceive as being a threat to them which is a very small number of people.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#679
post #409

Earlier quoted context omitted.

Note that password-based Bitlocker requires Windows Pro which is quite a bit more expensive. > sign into your Microsoft account or link it to Windows again. For reference, I did accidentally login into my Microsoft account once on my local account (registered in the online accounts panel). While Edge automatically enabled synchronization without any form of consent from my part, it does not look like that my Bitlocke…

Not anymore, modern hardware running Windows 11 Home now also has FDE, technically running on BitLocker, just that it's called "Device Encryption" and doesn't have the same options: https://support.microsoft.com/en-us/windows/device-encryptio... > For reference, I did accidentally login into my Microsoft account once on my local account (registered in the online accounts panel) Those don't usually count as the "prima…

Yes, Windows 11 Home has FDE and I used it, but no password unlock. Attempting to switch to password unlocking will result in an error saying that password unlocking is not available in the current Windows edition. TPM based unlocking did work on Home for example. (but required entering the recovery key after every reboot to Fedora for some reason).

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#680

Earlier quoted context omitted.

> Yes. The thing is: Microsoft made the design decision to copy the keys to the cloud, in plaintext. And they made this decision with the full knowledge that the cops could ask for the data. Apple does this too. So does Google. This is nothing new. It's a commonly used feature by the average user who loses their password or their last device. During set up, they even explicitly inform the user that their bitlocker ke…

Nah, Apple doesn't do this. If the user's MacOS FileVault disk encryption key is "stored in iCloud" it resides in the users iCloud Keychain which is end-to-end encrypted. This creates a situation similar to the iPhone, where Apple does not have the ability to access the user's data and therefore cannot comply with a warrant for access (which really annoys organizations like the FBI and Interpol)

I'm sorry, but you're wrong, and wrong in a way that is dangerous. You're conflating two separate things.

> If the user's MacOS FileVault disk encryption key is "stored in iCloud" it resides in the users iCloud Keychain which is end-to-end encrypted.

First: Keychains synced to iCloud are encrypted end to end, as is iCloud Keychain.

However: when you set up FileVault, you are prompted to put escrow your keys in the cloud. If you do that, those keys are NOT end-to-end encrypted.

Further: this is an explicit user feature. It is how "cloud unlock" of a machine with FileVault works. Apple also offers Advanced Data Protection, which is more akin to what you're describing, but requires opting in.

> This creates a situation similar to the iPhone, where Apple does not have the ability to access the user's data and therefore cannot comply with a warrant for access

Another potentially dangerous statement: while this is true for a locked phone, if you use iCloud backups for your device with "standard" level of protection, Apple stores the backups and maintains key escrow.

You've made some statements that in an absolute form that go from beyond wrong and to being actively dangerous to users. Please re-align yourself to reality here https://support.apple.com/en-us/102651#standard and the services security section at https://help.apple.com/pdf/security/en_US/apple-platform-sec...

Post reply on HN