Live data from Hacker News

Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

techcrunch.com

681–690 of 694 posts

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#681

Earlier quoted context omitted.

> the problem is that you usually don't have guarantees that the updates you get are genuine A point of order: you do have that guarantee for most Linux distro packages. All 70,000 of them in Debian's case. And all Linux distro distribute their packages anonymously, so they can never target just one individual. That's primarily because they aren't trying to make money out of you. Making money requires a billing relat…

> so they can never target just one individual You assume the binary can't just have a machine check in itself that activates only on the target's computer.

Yes, they can do that. But they can't select who gets the binary, so everybody gets it. Debian does reproducible builds on trusted machines so they would have to infect the source.

You can safely assume the source will be viewed by a lot of people over time, so the change will be discovered. The source is managed mostly by git, so there would be history about who introduced the change.

The reality is open source is so far ahead on proprietary code on transparency, there is almost no contest at this point. If a government wants to compromise proprietary code it's easy, cheap, and undetectable. Try the same with open source it's still cheap, but the social engineering ain't easy, and it will be detected - it's just a question of how long it takes.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#682

Earlier quoted context omitted.

In court? Not really. These warrants are on solid ground from a legal standpoint. To the point that fighting them could be a sanction-able kind of grandstanding.

Sanction-able? I'm not saying you shouldn't comply with a valid warrant, I'm saying that you should object to whether there was probable cause for the warrant.

Yeah you shouldn't object in bad faith. I.e., you need to genuinely believe there's no probably cause here, and that's not a reasonable position.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#683

Hear that? It's the sound of the year of the Linux desktop. It's time - it's never been easier, and there's nothing you'll miss about Windows.

Just remember, never use or recommend Debian-family(Ubuntu/Mint) or you will be back to windows. Do not fall for the marketing term Stable, which means outdated and contains bugs that are fixed. Fedora is my recommendation. I remind people Fedora is not Arch. Fedora is a consumer grade OS that is so good, I don't lump it in with the word Linux.

I disagree, for me desktop (K)Ubuntu's 6 month release cycle works great. Feels like a nice balance between stability and freshness.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#684

Earlier quoted context omitted.

Because "gave" implies a favor or a one sided exchange. It implies that Microsoft is just giving away keys for no reason! Better, and more accurate wording, would be that "Microsoft surrendered keys" or "Microsoft ceded keys". Or "Microsoft legally compelled to give the keys". If Microsoft did so without a warrant, then "gave" would be more tonally accurate. In addition, none of this is new. They've been turning over…

In fairness, the link is specifically for "Advanced Dat Protection for iCloud". This has nothing to do with local whole-disk encryption like FileVault or BitLocker. In Apple's case, even when the user enables iCloud FileVault key backup, that key is still end-to-end encrypted and Apple cannot access it. As a matter of fact, while Apple regularly receives legal warrants for access, they are ineffective because Apple h…

> This has nothing to do with local whole-disk encryption like FileVault or BitLocker.

Wrong. When you set up a Mac laptop, it gives you the option to escrow keys. ADP disables that and ADP also prevents key escrow for iDevice backups.

This is changed in Tahoe, but that's a really important callout that you need to make (and that you aren't making)

> In Apple's case, even when the user enables iCloud FileVault key backup, that key is still end-to-end encrypted and Apple cannot access it.

This is not true for older but relevant versions of macos. It was changed in Tahoe.

With ADP enabled (which the vast majority of users do not have), this is completely incorrect. This is still factually wrong, and dangerously misleading.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#685

Earlier quoted context omitted.

The iCloud Keychain is end-to-end encrypted.[0] Apple can't decrypt it. That said, when setting up FileVault, you have the option to escrow your recovery key with Apple. If you enable that, Apple can get the recovery key. [0] https://support.apple.com/en-us/102651

From the linked Apple page... "For additional privacy and security, 15 data categories — including Health and passwords in iCloud Keychain — are end-to-end encrypted. Apple doesn't have the encryption keys for these categories, and we can't help you recover this data if you lose access to your account. The table below includes a list of data categories that are always protected by end-to-end encryption." The FileVaul…

> The FileVault keys are stored in the iCloud Keychain and Apple does not have access to them, full stop :-)

It's worth pointing out that as an absolute statement, this is false, full stop :-)

For one, it depends on the version of macos. For another, on the version of macos that it IS "fixed", your terminology is wrong.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#686
post #281

Earlier quoted context omitted.

There is no other way for this to work that won't result in an absolutely massive number of people losing their data permanently who had no idea their drive was encrypted. Well there is, leave BitLocker disabled by default and the drive unencrypted. Now the police don't even have to ask! With this scheme the drive is recoverable by the user and unreadable to everyone except you, Microsoft, and the police. Surely that…

"Apple does the same thing with FileVault when you set up with your iCloud account where, again, previously your disk was just left unencrypted" Nah, the FileVault key is stored in your iCloud Keychain when you choose to backup the key to iCloud. And the keychain is end-to-end encrypted. Only the user has access.

> Only the user has access

This user has been spreading this falsehood so heavily in this thread that it's almost suspicious.

When you store your FileVault key in iCloud, it is in escrow (ie accessible by Apple) on older but relevant versions of ios and macos. On newer versions, the situation is improved. However, the terminology on newer versions has changed from "icloud keychain", so frankly, I still think you were talking out of your ass.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#687

Earlier quoted context omitted.

Nah, Apple doesn't do this. If the user's MacOS FileVault disk encryption key is "stored in iCloud" it resides in the users iCloud Keychain which is end-to-end encrypted. This creates a situation similar to the iPhone, where Apple does not have the ability to access the user's data and therefore cannot comply with a warrant for access (which really annoys organizations like the FBI and Interpol)

I'm sorry, but you're wrong, and wrong in a way that is dangerous. You're conflating two separate things. > If the user's MacOS FileVault disk encryption key is "stored in iCloud" it resides in the users iCloud Keychain which is end-to-end encrypted. First: Keychains synced to iCloud are encrypted end to end, as is iCloud Keychain. However: when you set up FileVault, you are prompted to put escrow your keys in the cl…

And by the way, the situation is improved in tahoe and closer to what you've described, but it's still not a guarantee if you upgraded from an older version.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#688

Earlier quoted context omitted.

Because "gave" implies a favor or a one sided exchange. It implies that Microsoft is just giving away keys for no reason! Better, and more accurate wording, would be that "Microsoft surrendered keys" or "Microsoft ceded keys". Or "Microsoft legally compelled to give the keys". If Microsoft did so without a warrant, then "gave" would be more tonally accurate. In addition, none of this is new. They've been turning over…

The fact that none of this is new undermines your point. Microsoft knew that law enforcement would ask for keys, based on their prior experience and the sack of meat sitting between their ears. They, knowing that, chose to design a system that trivially allows this. That is a choice. In that sense, they did give up the keys. They certainly did not have to design it that way, nor was it done in ignorance.

Apple did this too, though. So did Google.

Actually, Apple changed this in Tahoe but it's still a decade plus of this exposure and knowledge of this exposure.

Re: Microsoft gave FBI set of BitLocker encryption keys to unlock suspects' laptops

#690

Earlier quoted context omitted.

Sanction-able? I'm not saying you shouldn't comply with a valid warrant, I'm saying that you should object to whether there was probable cause for the warrant.

Yeah you shouldn't object in bad faith. I.e., you need to genuinely believe there's no probably cause here, and that's not a reasonable position.

If they don't have any evidence that'd lead them to believe the data they're searching for is on that laptop, then you can reasonably object that there's no probable cause to search the laptop.
Post reply on HN