▲ 108 ▼ Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects' laptops: Reports | TechCrunch (techcrunch.com) submitted 7 months ago by cm0002@libretechni.ca to c/privacy@lemmy.ca 9 comments fedilink hide all child comments
[–] SpikesOtherDog@ani.social 4 points 7 months ago (1 child) These are only the keys saved to Microsoft accounts. permalink fedilink source parent hideshow 2 child comments replies: [–] stoy@lemmy.zip 6 points 7 months ago (2 children) There is nothing to prevent MS from sending the keys from every intune instance. permalink fedilink source parent hideshow 4 child comments replies: [–] wizardbeard@lemmy.dbzer0.com 4 points 7 months ago (1 child) You don't have to store them in intune, as far as I know. I'm not a desktop engineer, but I know at my workplace they historically are stored in AD. permalink fedilink source parent hideshow 2 child comments replies: [–] SpikesOtherDog@ani.social 3 points 7 months ago Here it depends. Is AD in Azure? This privacy statement seems to indicate that Microsoft has full access to your data and that it's just company policy that keeps them out. If your servers are on site and firewalled, then Microsoft would need some sort of remote access tool that tracks each server. This means that on-site licensing and patching needs to be done. I can't think of any other service off the top of my head, but I'm only a desktop engineer. permalink fedilink source parent [–] phil@lymme.dynv6.net 1 point 7 months ago No such issue with end-to-end encryption, as only the end user devices have the keys. It's used by Apple (that was the main argument in the FBI wanting to unlock iPhones), some messaging services like Signal and Whatsapp, only mentioning big tech. Of course, you have to trust them when it's closed source. Here the story is that Microslop chose from the beginning centralized keys that they own and can share. It' s all well known, but the news is that they really did it. permalink fedilink source parent
[–] stoy@lemmy.zip 6 points 7 months ago (2 children) There is nothing to prevent MS from sending the keys from every intune instance. permalink fedilink source parent hideshow 4 child comments replies: [–] wizardbeard@lemmy.dbzer0.com 4 points 7 months ago (1 child) You don't have to store them in intune, as far as I know. I'm not a desktop engineer, but I know at my workplace they historically are stored in AD. permalink fedilink source parent hideshow 2 child comments replies: [–] SpikesOtherDog@ani.social 3 points 7 months ago Here it depends. Is AD in Azure? This privacy statement seems to indicate that Microsoft has full access to your data and that it's just company policy that keeps them out. If your servers are on site and firewalled, then Microsoft would need some sort of remote access tool that tracks each server. This means that on-site licensing and patching needs to be done. I can't think of any other service off the top of my head, but I'm only a desktop engineer. permalink fedilink source parent [–] phil@lymme.dynv6.net 1 point 7 months ago No such issue with end-to-end encryption, as only the end user devices have the keys. It's used by Apple (that was the main argument in the FBI wanting to unlock iPhones), some messaging services like Signal and Whatsapp, only mentioning big tech. Of course, you have to trust them when it's closed source. Here the story is that Microslop chose from the beginning centralized keys that they own and can share. It' s all well known, but the news is that they really did it. permalink fedilink source parent
[–] wizardbeard@lemmy.dbzer0.com 4 points 7 months ago (1 child) You don't have to store them in intune, as far as I know. I'm not a desktop engineer, but I know at my workplace they historically are stored in AD. permalink fedilink source parent hideshow 2 child comments replies: [–] SpikesOtherDog@ani.social 3 points 7 months ago Here it depends. Is AD in Azure? This privacy statement seems to indicate that Microsoft has full access to your data and that it's just company policy that keeps them out. If your servers are on site and firewalled, then Microsoft would need some sort of remote access tool that tracks each server. This means that on-site licensing and patching needs to be done. I can't think of any other service off the top of my head, but I'm only a desktop engineer. permalink fedilink source parent
[–] SpikesOtherDog@ani.social 3 points 7 months ago Here it depends. Is AD in Azure? This privacy statement seems to indicate that Microsoft has full access to your data and that it's just company policy that keeps them out. If your servers are on site and firewalled, then Microsoft would need some sort of remote access tool that tracks each server. This means that on-site licensing and patching needs to be done. I can't think of any other service off the top of my head, but I'm only a desktop engineer. permalink fedilink source parent
[–] phil@lymme.dynv6.net 1 point 7 months ago No such issue with end-to-end encryption, as only the end user devices have the keys. It's used by Apple (that was the main argument in the FBI wanting to unlock iPhones), some messaging services like Signal and Whatsapp, only mentioning big tech. Of course, you have to trust them when it's closed source. Here the story is that Microslop chose from the beginning centralized keys that they own and can share. It' s all well known, but the news is that they really did it. permalink fedilink source parent