Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

71–80 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#72
Due to Third Party Doctrine, Microsoft doesn't even NEED a "legal order." It's merely a courtesy which they could change at any time.

Based on the sheer number of third parties we're required to use for our day to day lives, that is ridiculous and Third Party Doctrine should be eliminated.

Ref: https://en.wikipedia.org/wiki/Third-party_doctrine

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#73
post #59

If tech companies implemented real, e2e encryption for all user data, there would be a huge outcry, as the most notable effect would be lots of people losing access to their data irrevocably. I'm all for criticizing tech companies but it's pointless to demand the impossible.

Just say "we are storing your keys on our servers so you won't lose them" and follow that with either "do you trust us" or even "we will share this key with law enforcement if compelled". Would be fine. Let people make these decisions.

Besides, bit ocker keys are really quite hard to lose.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#74
post #8

Any reason to believe Apple won't do the same with whatever we backup in iCloud?

Any American company will hand over data stored on their server (that they have access to) in response to a warrant.

Apple provides an optional encryption level (ADP) where they don't have a copy of your encryption key.

When Apple doesn't have the encryption key, they can't decrypt your data, so they can't provide a copy of the decrypted data in response to a warrant.

They explain the trade off during device setup: If Apple doesn't have a copy of the key, they can't help you if you should lose your copy of the key.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#75

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#76
post #59

If tech companies implemented real, e2e encryption for all user data, there would be a huge outcry, as the most notable effect would be lots of people losing access to their data irrevocably. I'm all for criticizing tech companies but it's pointless to demand the impossible.

is it just me or would "Microsoft refuses to comply with a legal search warrant" be an actual, surprising news story? like of course MSFT is going to hand over to authorities whatever they ask for if there's a warrant, imagine if they didn't (hint: not good for business. their customers are governments and large institutions, a reputation for "going rogue" would damage their brand quite a bit)

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#77
post #32

Earlier quoted context omitted.

Well, for a consumer notebook or mobile device, the threat model typically envisions a thief grabbing it from a coffeehouse or hotel room. So your key needs to be safeguarded from the opportunist who possesses your hardware illegally. Linux can be fairly well-secured against state-level threat actors, but honestly, if your adversary is your own nation-state, then no amount of security is going to protect you! For Mic…

> Well, for a consumer notebook or mobile device, the threat model typically envisions a thief grabbing it from a coffeehouse or hotel room. ...in which case having a cloud backup of the full disk encryption key is pointless, because you don't have access to the disk any more.

> pointless

Full-disk encryption is the opposite of pointless, my dude! The notebook-thief cannot access my data! That is the entire point!

No, I cannot recover the data from an HDD or SSD that I don't possess. But neither can the thief. The thief cannot access the keys in my cloud. Isn't that the point?

If a thief steals a notebook that isn't encrypted at all, then they can go into the storage, even forensically, and extract all my data! Nobody needs a "key" or credentials to do that! That was the status quo for decades in personal computing--and even enterprise computing. I've had "friends" give me "decommissioned" computers that still had data on their HDD from some corporation. And it would've been readable if I had tried.

The thief may have stolen a valuable piece of kit, but now all she has is hardware. Not my data. Not to mention, if your key was in a cloud backup, isn't most of your important data in the cloud, as well? Hopefully the only thing you lost with your device are the OS system files, and your documents are safely synced??

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#78
post #25

Earlier quoted context omitted.

If you have advanced data protection enabled, Apple claims: “No one else can access your end-to-end encrypted data — not even Apple — and this data remains secure even in the case of a data breach in the cloud.” https://support.apple.com/en-us/102651

Please read this section of Apple's own document before you talk about their "advanced data protection". The following information may be available from iCloud if a user has enabled Advanced Data Protection for iCloud: https://www.apple.com/legal/privacy/law-enforcement-guidelin... Do you think Tim Cook gave that gold bar to Trump for nothing?

>Please read this section of Apple's own document

Don't know if the problem is on my end but your link goes to a 20 page document. If this is not a mistake you should quote the actual section and text you are referrimg to.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#79
post #53

Earlier quoted context omitted.

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

Forcing implies there are zero ways to begin with a local only account (or other non-Microsoft Account). That's simply not true.

Disagree. If the path is shrouded behind key presses and commands which are unpublished by MS (and in some instances routes that have been closed), it may as well be.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#80

Earlier quoted context omitted.

https://linuxmint.com/ https://ubuntu.com/download/desktop https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.

> Every bad day for microsoft is yet another glorious day for linux. Nah. If that were the case, Linux would dominate personal computer statistics. The reality is that most mainstream users just don't care. But, of course, that won't stop us.

It's just a matter of time. It's obvious the tides are turning.
Post reply on HN