Live data from Hacker News

Microsoft will give the FBI a Windows PC data encryption key if ordered

windowscentral.com

81–90 of 346 posts

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#81

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

I thought this was what happened. Clearly not :( That’s the idea with services like 1Password (which I suppose is ultimately doing the same thing) - you need both the key held on the device and the password.

I suppose this all falls apart when the PC unlock password is your MS account password, the MS account can reset the local password. In Mac OS / Linux, you reset the login password, you loose the keychain.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#82
post #53

Earlier quoted context omitted.

Forcing implies there are zero ways to begin with a local only account (or other non-Microsoft Account). That's simply not true.

Disagree. If the path is shrouded behind key presses and commands which are unpublished by MS (and in some instances routes that have been closed), it may as well be.

> it may as well be.

That defies the definition of "forced". Forced means no option. You can disagree all you want -- but at a technical level, you're incorrect.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#83
post #70

Headline says “…if asked” Article and facts are “…if served with a valid legal order compelling it” ∴ Headline is clickbait.

You are arguing semantics, whereas the point is that A) they have your keys, and B) they will give them away if they will have to

No, that’s binary thinking. The degree to which they will resist giving them away matters.

I’d much rather they require a warrant than just give it to any enforcement agency that sends them an email asking. The former is what I expect.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#84
post #30
post #17

Earlier quoted context omitted.

Yeah, the problem is whether they already bent over for Trump admin or not yet.

Yes, I know this sounds conspiratorial, but I think the whole Liquid Ass thing was a rush to put some other software in Apple products to appease the Trump admin. For example, it is new in Tahoe that they store your filevault encryption key in your icloud keychain without telling you. https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...

But iCloud Keychain is end-to-end encrypted using device-specific keys, so Apple cannot read items in your iCloud Keychain (modulo adding their own key as a device key, rolling out a backdoor, etc. but that applies to all proprietary software).

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#85

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

They could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent

The alternative is just not having FDE on by default, it really isn't "require utterly clueless non-technical users to go through complicated opt-in procedure for backups to avoid losing all their data when they forget their password".

And AFAICT, they do ask, even if the flow is clearly designed to get the user to back up their keys online.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#86
post #69

Earlier quoted context omitted.

That's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" wa…

While you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think abou…

You can just ... not select the option to upload your keys to MS? During the setup you get to choose where to store your bitlocker recovery key.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#88
post #57

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

> Do we really, really, fully understand the implication of allowing private contracts that trump criminal law? ...it's not that at all. We don't want private contracts to enshrine the same imbalances of power; we want those imbalances rendered irrelevant. We hope against hope that people who have strength, money, reputation, legal teams, etc., will be as steadfast in asserting basic rights as people who have none of…

I think legally the issue was adjudicated by analogy to a closed safe: while the exact contents of the safe is unknown beforehand, it is reasonable it will contain evidence, documents, money, weapons etc. that are relevant, so if a warrant can be issued in that case compelling a locksmith to open it, then by analogy it can be issued against an encrypted device.

Without doubt, this analogy surely breaks down as society changes to become more digital - what about a Google Glass type of device that records my entire life, or the glasses of all people detected around me? what about the device where I uploaded my conscience, can law enforcement simply probe around my mind and find direct evidence of my guilt? Any written constitution is just a snapshot of a social contract at a particular historical time and technological development point, so it cannot serve as the ultimate source of truth regarding individual rights - the contract is renegotiated constantly through political means.

My question was more general: how could we draft that new social contract to the current age, how could we maintain the balance where the encrypted device of a suspected child predator and murderer is left encrypted, despite the fact that some 3rd party has the key, because we agreed that is the correct way to balance freedoms and law enforcement? It just doesn't sound stable in a democracy, where the rules of that social contract can change, it would contradict the moral intuitions of the vast majority.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#89
post #4

Veracrypt https://veracrypt.io/en/Home.html

https://linuxmint.com/ https://ubuntu.com/download/desktop https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.

And MacOS, which I suspect may be the more obvious choice for many users.

Re: Microsoft will give the FBI a Windows PC data encryption key if ordered

#90

Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications…

Encrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".

At this point, end-to-end encryption is a solved problems when password managers exist. Not doing it means either Microsoft doesn't care enough, or is actually interested on keeping it this way
Post reply on HN