top 50 comments

sorted by: hot top controversial new old
[–] 449 points 7 months ago (12 children)

So, this means Microsoft has copies of every single bitlocker key, meaning that a bad actor could obtain them... Thereby making bitlocker less than worthless, it's an active threat.
MS really speedrunning worst possible software timeline

  • source
  • hideshow 15 child comments
  • [–] 222 points 7 months ago (20 children)

    They don't have a copy of every single Bitlocker key. They do have a copy of your Bitlocker key if you are dumb enough to allow it to sync with your Microsoft account, you know, "for convenience."

    Don't use a Microsoft account with Windows, even if you are forced to use Windows.

  • source
  • parent
  • hideshow 24 child comments
  • [–] 149 points 7 months ago (2 children)

    To use Windows without a Microsoft account requires tech literacy these days, I thought. I would not be suprised if users didn't choose to sync with a MS account but it's doing it anyway, if that's what MS want.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 53 points 7 months ago (1 child)

    If you sign in with a Microsoft account at all I don't believe there's the capability to opt out.

    I only use local accounts. I have never had a Microsoft account. I never will.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 58 points 7 months ago (10 children)

    You can't do that anymore, at least not with a normal Windows installation. All of the tricks of forcing it offline, clicking cancel 10 times and jumping up and down don't work anymore, they've disabled them all, the only way to install Windows 11 now (using the normal Microsoft installer) is by linking it to a Microsoft account.

  • source
  • parent
  • hideshow 12 child comments
  • [–] 35 points 7 months ago (1 child)

    Using Rufus still works. I did it as recently as a couple of days ago.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (8 replies)
  • [–] 45 points 7 months ago

    It's a bit harsh and unfair to say "you are dumb enough to allow it". Microsoft makes it damn near impossible to avoid this unless you are extremely particular and savvy about it, and never have an off day where you make a mistake while using your PC.

  • source
  • parent
  • load more comments (16 replies)
  • [–] 48 points 7 months ago (2 children)

    No they do not have copies of every Bitlocker key.

    Bitlocker by default creates a 48-bit recovery code that can be used to unlock an encrypted drive. If you run Windows with a personal Microsoft account it offers to backup that code into your Microsoft account in case your system needs recovered. The FBI submitted a supoena to request the code for a person's encrypted drive. Microsoft provided it, as required by law.

    Bitlocker does not require that key be created, and you don't have to save it to Microsoft's cloud.

    This is just a case of people not knowing how things work and getting surprised when the data they save in someone else's computer is accessed using the legal processes.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 13 points 7 months ago (1 child)

    If you sign into a Microsoft account during setup, Microsoft automatically turns on bitlocker and sends the key off to Microsoft for safe keeping. You are right, there are other ways to handle bitlocker, but that's way beyond most people, and I don't think Microsoft even tells you this during setup. It's honestly a lifesaver for when bitlocker breaks(and it does), but it comes at a cost. In the business world, this is seen as a huge benefit, as we aren't trying to protect from the US government, mostly petty theft and maybe some corporate espionage.

    As is often the case, the real solution is Linux, but that, too, is far beyond most people until manufacturers start shipping Linux machines to big box stores and even then they'd probably not enable any encryption.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (9 replies)
    [–] 131 points 7 months ago (5 children)
    load more comments (5 replies)
    [–] 125 points 7 months ago (19 children)

    The word "Gave" is really doing some heavy lifting in that title. Microsoft produced the keys in response to a warrant as required by law.

    If you don't want a company, any company, to produce your data when given a warrant then you can't give the company that data. At all. Ever.

    Not fast food joints, not Uber, not YouTube, not even the grocery store.

  • source
  • hideshow 21 child comments
  • [–] 88 points 7 months ago (14 children)

    Yes. But this completely invalidates the encryption. If anyone can decrypt your data without you giving the keys to them, it is not really encrypted.

  • source
  • parent
  • hideshow 15 child comments
  • load more comments (13 replies)
  • load more comments (17 replies)
    [–] 92 points 7 months ago
    [–] 62 points 7 months ago

    Linux. LUKS it yourself or it isn't really encrypted.

  • source
  • [–] 48 points 7 months ago (8 children)

    What does Microsoft think the fucking point of encryption is? Do they think I am encrypting my data to protect it from my dog?

  • source
  • hideshow 9 child comments
  • load more comments (7 replies)
    [–] 46 points 7 months ago (4 children)
    load more comments (4 replies)
    [–] 36 points 7 months ago

    A single bitter, crowing "hah!" at whoever thought there wasn't at least this much overlap between our corporate and government masters. Welcome to hell kid, shoutout to whatever's being trained on the last ~30 years of everything that touched the internet in the NSA's Utah data center. Rose coloured PRISM though, I dream of the day when someone makes those search tools public and I can reminisce through my preteen MSN Messenger convos

  • source
  • [–] 35 points 7 months ago (1 child)

    What a slap to the faces of everyone who had been locked out of their data because they never knew about this crap and thus never saved their keys

  • source
  • hideshow 2 child comments
  • [–] 34 points 7 months ago (1 child)

    People called me paranoid when I said this would happen someday...

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 28 points 7 months ago (4 children)

    Daily reminder that verified boot is objectively superior to "secure boot", once again a common Linux W and another example of Google actually promoting some good security practices

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [+] 28 points 7 months ago* (last edited 5 months ago)
    [–] 26 points 7 months ago (2 children)

    Wasn't this by design? Otherwise why keeping the decryption keys on servers located in the united states'?

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 23 points 7 months ago

    BitLocker provides for a recovery key. This is to allow someone to regain access to an encrypted device in the event that they lose their PIN, any one of these scenarios happen, OR when suspects do not want to cooperate with LEOs.

    Find your BitLocker recovery key

    If the target device is part of an enterprise and managed with EntraId/Intune this is the option. Escrowed keys.

  • source
  • [–] 19 points 7 months ago (6 children)

    Why is anyone surprised by this? And what kind of imbecile commits crimes and uses windows? 🤣

  • source
  • hideshow 6 child comments
  • load more comments (6 replies)
    [–] 18 points 7 months ago (1 child)

    Microslop is openly anti consumer. Why would you hand them your encryption keys?

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 18 points 7 months ago (4 children)

    Remember when Truecrypt got suspiciously terminated? That was the goal

  • source
  • hideshow 5 child comments
  • [–] 18 points 7 months ago (3 children)

    Is anyone shocked by this? With everything that DHS, FBI, ICE, military, elected representatives, etc. are all doing without any concern or care for laws, civil rights, human rights, the Constitution, this should not be a shock to anyone. Corporations are bending over backwards to appease the talking orange and make more money. They do not care as long as profits are up and the shareholders are happy. A companies primary legal responsibility is to the shareholders, not the customers.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 17 points 7 months ago

    Federal investigators in Guam believed the devices held evidence that would help prove individuals handling the island’s Covid unemployment assistance program were part of a plot to steal funds.

    Damn, they weren't even doing this to go after pedos.

    I'm curious where in the economic ladder this person fell. Rich enough to get a significant amount of money from the system, but still too poor to make the government look the other way.

  • source
  • [–] 14 points 7 months ago (2 children)

    IIRC am pretty sure they have been doing this for years(since Windows 8).

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    load more comments
    view more: next ›