6 ms·
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account. Once
by cesarb 9mo ago
> Any power users who prefer their own key management should follow the steps to enable Bitlocker without uploading keys to a connected Microsoft account.
Once the feature exists, it's much easier to use it by accident. A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. And it's a silent failure: the security properties of the system have changed without any visible indication that it happened.
- tokyobreakfast 9mo ago>even a cosmic ray flipping the "do not upload" bit in memory Stats on this very likely scenario?
- halfmatthalfcat 9mo agoIt's "HN-likely" which translates to "almost never" in reality.
- patja 9mo agoEspecially since HN readers are more likely to be using ECC memory
- smegger001 9mo agoif cosmic ray bit flips were so rare then ecc ram wouldn't be a thing.
- Sayrus 9mo agoECC protects against more events than cosmic rays. Those events are much more likely, for instance magnetic/electric interferences or chip issues.
- wang_li 9mo agoIn the 2010 era of RAM density, random bit flips were really uncommon. I worked with over a thousand systems which would report ECC errors when they happen and the only memorable events at all were actual DIMM failures. Also, around 1999-2000, Sun blamed cosmic rays for bit flips for random crashes with their UltraSPARC II CPU modules.
- mapontosevenths 9mo ago> actual DIMM failures. Yep, hardware failures, electrical glitches, EM interference... All things that actually happen to actual people every single day in truly enormous numbers. It ain't cosmic rays, but the consequences are still flipped bits.
- direwolf20 9mo agoThose random unexplainable events are also referred to casually as "cosmic rays"
- Supermancho 9mo agoHappens all the time, in reality (even on the darkside). When the atmosphere fails (again, happening all the time), error correction usually handles the errant bits.
- strbean 9mo ago> IBM estimated in 1996 that one error per month per 256 MiB of RAM was expected for a desktop computer. From the wikipedia article on "Soft error", if anyone wants to extrapolate.
- d1sxeyes 9mo agoThat makes it vanishingly unlikely. On a 16GB RAM computer with that rate, you can expect 64 random bit flips per month. So roughly you could expect this happen roughly once every two hundred million years. Assuming there are about 2 billion Windows computers in use, that’s about 10 computers a year that experience this bit flip.
- eszed 9mo ago> 10 computers a year experience this bit flip That's wildly more than I would have naively expected to experience a specific bit-flip. Wow!
- mapontosevenths 9mo agoScale makes the uncommon common. Remember kids, if she's one in a million that means there are 11 of her in Ohio alone.
- d1sxeyes 9mo ago~800 bit flips per year per computer. 2 billion computers with 800 bit flips each is 1,600,000,000,000 (one point six trillion) bit flips. Big numbers are crazy.
- justsomehnguy 9mo agoI saw a computer with 'system33', 'system34' folders personally. Also you would never actually know it happened because... it's not ECC. And with ECC memory we replace a RAM stick every two-three months explicitly because ECC error count is too high.
- 9mo ago
- homebrewer 9mo agoGiven enough computers, anything will happen. Apparently enough bit flips happen in domains (or their DNS resolution) that registering domains one bit away from the most popular ones (e.g. something like gnogle.com for google.com) might be worth it for bad actors. There was a story a few years ago, but I can't find it right now; perhaps someone will link it.
- pixl97 9mo agohttps://www.youtube.com/watch?v=aT7mnSstKGs https://www.youtube.com/watch?v=aT7mnSstKGs Was in DEFCON19.
- homebrewer 9mo agoGreat, thanks. Here's a discussion on this site: https://news.ycombinator.com/item?id=4800489 https://news.ycombinator.com/item?id=4800489
- lanyard-textile 9mo agoA very old game speedrun -- of the era that speedruns weren't really a "thing" like they are today -- apparently greatly benefited from a hardware bit flip, and it was only recently discovered. Can't find an explanatory video though :(
- direwolf20 9mo agoThe Tick Tock Clock upwarp in Super Mario 64. All evidence that exists of it happening is a video recording. The most similar recording was generated by flipping a single bit in Mario's Y position, compared to other possibilities that were tested, such as warping Mario up to the closest ceiling directly above him.
- tavavex 9mo agoI'm pretty sure that while no one knows the cause definitively, many people agreed that the far more likely explanation for the bit change was a hardware fault (memory error, bad cartridge connection or something similar) or other, more powerful sources of interference. The player that recorded the upwarp had stated that they often needed to tilt the cartridge to get the game to run, showing that the connection had already degraded. The odds of it being caused by a cosmic ray single-event upset seem to be vanishingly low, especially since similar (but not identical) errors have already been recorded on the N64.
- drysine 9mo agoAt google "more than 8% of DIMM memory modules were affected by errors per year" [0] More on the topic: Single-event upset[1] [0] https://en.wikipedia.org/wiki/ECC_memory https://en.wikipedia.org/wiki/ECC_memory [1] https://en.wikipedia.org/wiki/Single-event_upset https://en.wikipedia.org/wiki/Single-event_upset
- Aloisius 9mo ago> At google "more than 8% of DIMM memory modules were affected by errors per year" That's all errors including permanent hardware failure, not just transient bit flips or from cosmic rays.
- drysine 9mo agoYou are right. Apologies for spreading false information( "We provide strong evidence that memory errors are dominated by hard errors, rather than soft errors, which previous work suspects to be the dominant error mode." [0] "Memory errors can be caused by electrical or magnetic interference (e.g. due to cosmic rays), can be due to problems with the hardware (e.g. a bit being permanently damaged), or can be the result of corruption along the data path between the memories and the processing elements. Memory errors can be classified into soft errors, which randomly corrupt bits but do not leave physical damage; and hard errors, which corrupt bits in a repeatable manner because of a physical defect." "Conclusion 7: Error rates are unlikely to be dominated by soft errors. We observe that CE [correctable errors] rates are highly correlated with system utilization, even when isolating utilization effects from the effects of temperature. In systems that do not use memory scrubbers this observation might simply reflect a higher detection rate of errors. In systems with memory scrubbers, this observations leads us to the conclusion that a significant fraction of errors is likely due to mechanism other than soft errors, such as hard errors or errors induced on the datapath. The reason is that in systems with memory scrubbers the reported rate of soft errors should not depend on utilization levels in the system. Each soft error will eventually be detected (either when the bit is accessed by an application or by the scrubber), corrected and reported. Another observation that supports Conclusion 7 is the strong correlation between errors in the same DIMM. Events that cause soft errors, such as cosmic radiation, are expected to happen randomly over time and not in correlation. Conclusion 7 is an interesting observation, since much previous work has assumed that soft errors are the dominating error mode in DRAM. Some earlier work estimates hard errors to be orders of magnitude less common than soft errors and to make up about 2% of all errors." [0] https://www.cs.toronto.edu/~bianca/papers/sigmetrics09.pdf https://www.cs.toronto.edu/~bianca/papers/sigmetrics09.pdf
- deleted 9mo ago[deleted]
- gruez 9mo ago>A finger slip, a bug in a Windows update, or even a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. This is absurd, because it's basically a generic argument about any sort of feature that vaguely reduces privacy. Sorry guys, we can't have automated backups in windows (even opt in!), because if the feature exists, a random bitflip can cause everything to be uploaded to microsoft against the user's will.
- salawat 9mo agoWhat part of "We can't have nice things" do you not understand?
- gruez 9mo agoThe part where you're asking me about the phrase when it's not been used anywhere in this thread prior to your comment.
- salawat 9mo ago>This is absurd, because it's basically a generic argument about any sort of feature that vaguely reduces privacy. Sorry guys, we can't have automated backups in windows (even opt in!), because if the feature exists, a random bitflip can cause everything to be uploaded to microsoft against the user's will. This is a dismissal of an objection to a software system implemented such that it performs in a discrete manner by default(no info leaves until I explicitly tell it to; this would be a nice thing, if you hadn't noticed). You repudiate the challenge on the basis of "we want to implement $system that escrows keys by default; a bad thing, but great for the company and host government in which said thing is widely adopted). You may not have used the exact words; but the constellation of factors is still there. We can't have nice things (machines that don't narc, do what we tell them, etc.) because there are other forces at work in our society making these things an impossibility. It is regrettable you do not see the pattern, but then again, that may be for the better for you. I wouldn't wish the experience of seeing things the way I do on anyone else. Definitely not a fun time. But it is certainly there.
- Aurornis 9mo agoIf users are so paranoid that they worry about a cosmic ray bit flipping their computer into betraying them, they're probably not using a Microsoft account at all with their Windows PC.
- SoftTalker 9mo agoIf your security requirements are such that you need to worry about legally-issued search warrants, you should not connect your computer to the internet. Especially if it's running Windows.
- direwolf20 9mo agoIn the modern political environment, everyone should be worried about that.
- fc417fc802 9mo agoIn all political environments everyone should be worried about that. The social temperature can change rapidly and you generally can't force a third party to destroy copies of your things in a reliable manner.
- oskarw85 9mo agoBecause all cops are honest, all warrants are lawful and nothing worrying happens in the land of freedom right now.
- Terr_ 9mo agoAnd what's more, that perfect situation could never change in the future. Me-30-years-ago would have called today's government crimes and corruption an implausible fever dream.
- qmr 9mo agoAppeal to the law fallacy.
- 9mo ago
- jollyllama 9mo agoThere's a lot of sibling comments to mine here that are reading this literally, but instead, I would suggest the following reading: "I never selected that option!" "Huh, must have been a cosmic ray that uploaded your keys ;) Modern OS updates never obliterate user-chosen configurations"
- hparadiz 9mo agoThey just entirely ignore them instead.
- bobbob1921 9mo agoThis is correct, I also discovered while preparing several ThinkPads for a customer based on a Windows 11 image i made, that even if you have bitlocker disabled you may also need to check that hardware disk encryption is disabled as well (was enabled by default in my case). Although this is different from bitlocker in that the encryption key is stored in the TPM, it is something to be aware of as it may be unexpected.
- egorfine 9mo ago[flagged]
- zdragnar 9mo agoI can't believe it took this long. We have mandatory identification for all kinds of things that are illegal to purchase or engage in under a certain age. Nobody wants to prosecute 12 year old kids for lying when the clicked the "I am at least 13 years old" checkbox when registering an account. The only alternative is to do what we do with R-rated movies, alcohol, tobacco, firearms, risky physical activities (i.e. bungee jumping liability waiver) etc... we put the onus of verifying identification on the suppliers. I've always imagined this was inevitable.
- thewebguyd 9mo agoThe problem is the implementation is hasty. When I go buy a beer at the gas station, all I do is show my ID to the cashier. They look at it to verify DOB and then that's it. No information is stored permanently in some database that's going to get hacked and leaked. We can't trust every private company that now has to verify age to not store that information with whatever questionable security. If we aren't going to do a national registry that services can query to get back only a "yes or no" on whether a user is of age or not, then we need regulation to prevent the storage of ID information. We should still be able to verify age while remaining psuedo-anonymous.
- zdragnar 9mo agoI definitely don't disagree that the implementation is problematic, I'm just surprised it took this long for it to happen.
- xp84 9mo agoWe should easily be able to, but the problem of tech illiteracy is probably our main barrier. To build such a system you’d need to issue those credentials to the end users. Those users in turn would eagerly believe conspiracy theories that the digital ID system was actually stealing their data or making it available to MORE parties instead of fewer (compared to using those ID verification services we have today).
- JCattheATM 9mo ago> a cosmic ray flipping the "do not upload" bit in memory, could all lead to the key being accidentally uploaded. Nah, no shot.