Live data from Hacker News

Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

techspot.com

71–80 of 280 posts

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#71

Earlier quoted context omitted.

I think there's been some miscommunication. If the bitlocker activation happens during tricking the user into going from a local account to online account, it is without the user's consent or real participation. They haven't printed out a copy of the key or moved it to a usb drive. They aren't aware their drives are being encrypted. They can't set up recovery keys now because the computer itself only shows the blue a…

You can set up recovery keys at any point in time, not just at creation. Just because people don't do it doesn't mean it isn't and hasn't been available for almost 2 decades.

And presumably the instructions for this have been on display on our local planning department in Alpha Centauri? If a user isn't even aware that their local disk is being encrypted without their knowledge or consent then why would they think to set up recovery keys?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#72
post #4

Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.

That's called LUKS2 and it's the default on Linux. You just type passphrase on boot. It's not tied to the motherboard.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#73
post #62

Earlier quoted context omitted.

[flagged]

Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles

>Yeah man we've been saying negative things about them for like 40 years

Well gee, I wonder why people have been saying negative things about them for so long?

Perhaps if it's been that long there's a kernel of truth to the matter.

Perhaps they're a shitty company who does shitty things selling shitty products.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#75
post #68
post #54

Earlier quoted context omitted.

How would that leave them homeless?

Presumably, not paying out for these bugs which often take weeks of research to find.

Who in their right mind bets on bug bounties to cover their basic needs? They should be highly employable with these kind of skills.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#76
I just digged into the exploit a little bit more and what it does it targets BitLocker in TPM only mode. That means that there is no preboot authentication or anything. What happens is secure boot validates the boot chain and the TPM gives out the encryption keys by itself. When you have physical access, it doesn't really make a difference. If there is a stick you can boot from and drop into an emergency shell or if you have to buy a $5 microcontroller and solder it to certain pins on the main board to sniff the TPM keys. What Microsoft is doing here in general they are selling something that is not secure. They are selling it as as full disk encryption but it's not. Someone who can flash a flash drive with an exploit and drop to a shell and use it to browse and copy files. Can also just buy that microcontroller and watch your YouTube with you How to solder. So the "exploit" isn't The problem here the problem is the false sense of security that Microsoft is selling.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#77
post #62

Earlier quoted context omitted.

[flagged]

Yeah man we've been saying negative things about them for like 40 years must we constantly dwell on what they do wrong? It's time we find positive angles

They keep doing negative things that influence the industry and infringe upon the freedoms of hundreds of millions of people. Yes we should keep dwelling on that.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#78
> Security professionals generally recommend avoiding reliance on any single encryption system and instead evaluating well-reviewed full-disk encryption alternatives such as VeraCrypt.

What does this even mean? Nobody is using multiple encryption schemes on top of each other, are they?

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#79
post #38
post #4

Maybe I’m an outlier but I don’t want my drives encrypted at all. I rather have all my data be accessible if things go catastrophic, I.E. having to pull the drive out of a broken computer and put it in another computer to access the files. I just want it to be plug and play.

If "things go catastrophic" your hard drive is not usable at all anymore. At the very least some files can't be recovered at all. So you need backups in any case. Once you have backups, you might as well encrypt your hard drives, especially if you store these in different locations (which you should). An advantage of encryption is that it makes it easier to give away or resell devices. With recent encryption schemes…

That’s not true. I’ve had many computers that refuse to turn on and I was able to recover the files by removing the drive and loading it into a USB hard drive reader and recover the files.

Re: Security researcher says Microsoft built a Bitlocker backdoor, releases exploit

#80
post #11

At what point will Security professionals start turning down roles that involve “securing” MS Products? I’m already at this point. Securing Microsoft products is busy work while waiting to have it undercut by the next wave of MS’s insane tech debt and greed. And now backdoors!

You are confused. They are not "security" roles, they are compliance roles. That's all most enterprise customers really care about. They satisfied all of the compliance rules, and are following "best practices" (influenced by MS), anything that happens is not their fault.
Post reply on HN