4 ms·
>> Does tying those keys to your MS account fix that failure method? >Yes. Bitlocker recovery keys are escrowed to the Microsoft account. Which then opens the
by r2_pilot 2y ago
>> Does tying those keys to your MS account fix that failure method?
>Yes. Bitlocker recovery keys are escrowed to the Microsoft account.
Which then opens the door to other attack vectors, even government.
- doubled112 2y agoI’d imagine most people would like some insurance in the event of loss or theft, but are not worried about government. I’m vulnerable to the $8 wrench attack, but enjoy knowing it is only a VISA problem if I leave it a laptop the bus.
- r2_pilot 2y agoI mention that only because it's one avenue. I figured obviously on a place like Hacker News that malicious agents aside from government could also compromise the security of 3rd party-held keys; as always security is a matter of difficult tradeoffs and anticipated threat categories.
- seabass-labrax 2y agoI'm genuinely curious to know how VISA helps (or doesn't) in your analogy - what is a 'VISA problem'?
- doubled112 2y agoMostly a joke, but I swipe a card and the problem goes away. No need to worry anymore.
- seabass-labrax 2y agoAh, thank you; I get it now: you don't need to worry about data theft because the drive was encrypted, so the only remaining problem is buying a replacement - a 'VISA' problem. I rather like that way of putting it; I might use it myself :)
- vel0city 2y agoVISA as in the credit card not a travel permit
- vel0city 2y agoAs opposed to just not encrypting their data at all and letting everyone who ends up with the drive have their data. So one scenario, everyone can access the data if they get the drive. The other, the government might get Microsoft to release the encryption keys.
- r2_pilot 2y ago>As opposed to just not encrypting their data at all and letting everyone who ends up with the drive have their data. You are presenting a false dilemma where either Bitlocker is in use or the drive is entirely unencrypted; there are other ways to ensure data integrity in the face of physical compromise.
- whyoh 2y ago1. It's not a false dilemma, it's more of a question of how to handle the "average Joe" user that doesn't know how to store encryption keys. I don't like how this automatic encryption is implemented, by the way, but sending the keys to MS servers is not the worst idea ever. 2. Bitlocker can totally be used without a MS account and without sending keys anywhere and without TPM... But seeing how most people fail to RTFM we're back to point 1.