18 ms·
Microsoft will give the FBI a Windows PC data encryption key if ordered
- SketchySeaBeast 8mo agoDuplicate story. Previous discussion here. https://news.ycombinator.com/item?id=46735545 https://news.ycombinator.com/item?id=46735545 Edit: Nevermind.
- cromka 8mo agoNo it isn't. This is an evolution of that story.
- davidguetta 8mo agoLol it's been 20 years now that the whole world should stop to be all surprised pikachu about that.
- hsuduebc2 8mo agoExactly. Being again and again surprised that corporations will defend you for literally no reason is kinda delusional.
- cromka 8mo agoThat's a reductionist view. Apple, at least, based a big portion of their image on privacy and encryption. If a company does that and is then proven otherwise, it does a tremendous damage to the brand and stock value and is something shareholders would absolutely sue the board and CEO for. Things like these happened many times in the past. This isn't that simple.
- hsuduebc2 8mo agoNobody today cares about their encryption, their main sales pich now is convenience and luxury. They still need to comply with law which they do. In US or China. Nothing reductionist about stating a fact.
- cromka 8mo agoAnd I agree with that, too. This whole discussion made me realize they pivoted their PR. They probably had to because everyone wants the AI and there's no AI with privacy, at least not with the current processing power of portable devices.
- _blk 8mo agoA Proton model makes this very simple: full cooperation and handover and virtually nothing to be extracted from the data. Size is somewhat of a metadata, ip connection points and maybe date of first use and when data changes occurred... I'm all for law enforcement, but that job has to be old-school Proof of Work bound and not using blanket data collection and automated speeding ticket mailer. But I guess it's not done more because the free data can't be analyzed and sold.
- hsuduebc2 8mo agoThis is quite elegant solution.
- michaelt 8mo agoFor a long time, if you used full disk encryption, the encryption key never left your machine. If you forgot your password, the data was gone - tough luck, should have made a backup. That's still how it works on Linux. Pretty surprising they'd back up the disk encryption secrets to the cloud at all, IMHO, let alone that they'd back it up in plaintext.
- B1FIDO 8mo agoWell, for a consumer notebook or mobile device, the threat model typically envisions a thief grabbing it from a coffeehouse or hotel room. So your key needs to be safeguarded from the opportunist who possesses your hardware illegally. Linux can be fairly well-secured against state-level threat actors, but honestly, if your adversary is your own nation-state, then no amount of security is going to protect you! For Microsoft and the other consumer-OS vendors, it is typically a bad user-experience for any user, particularly a paying subscriber, to lose access to their account and their cloud apps. There are many ways to try and cajole the naïve user into storing their recovery key somewhere safe, but the best way is to just do it for them. A recovery key stored in the user's own cloud account is going to be secure from the typical threats that consumers will face. I, for one, am thankful that there is peace of mind both from the on-device encryption, as well as the straightforward disaster recovery methods.
- jordanb 8mo agoThe problem is mass-surveillance and dragnets. Obviously if the state wants to go after you no laws will protect you. As we've seen they can even illegally collect evidence and then do a parallel construction to "launder" the evidence. But One-drive is essentially a mass-surveillance tool. It's a way to load the contents of every single person's computer into Palentir or similar tools and, say, for instance, "give me a list of everyone who harbors anti-ICE sentiments." By the way my windows computer nags me incessantly about "setting up backups" with no obvious way to turn off the nags, only a "remind me later" button. I assume at some point the option to not have backups will go away.
- 8mo ago
- shoknawe 8mo agoVeracrypt https://veracrypt.io/en/Home.html https://veracrypt.io/en/Home.html
- sandworm101 8mo agohttps://linuxmint.com/ https://linuxmint.com/ https://ubuntu.com/download/desktop https://ubuntu.com/download/desktop https://archlinux.org/ https://archlinux.org/ https://www.kali.org/get-kali/#kali-platforms https://www.kali.org/get-kali/#kali-platforms https://fedoraproject.org/ https://fedoraproject.org/ Every bad day for microsoft is yet another glorious day for linux.
- smartmic 8mo ago> Every bad day for microsoft is yet another glorious day for linux. Nah. If that were the case, Linux would dominate personal computer statistics. The reality is that most mainstream users just don't care. But, of course, that won't stop us.
- guerrilla 8mo agoIt's just a matter of time. It's obvious the tides are turning.
- hunter-gatherer 8mo agoI would also argue that _what_ personal computing means to most people has also evolved, even with younger generations. My gen Z nephew the other day was faberglasted when he learned I use my Documents, Videos, Desktop folders, ect. He literally asked "What is the Documents folder even for?". To most people, stuff is just magically somewhere (the cloud) and when they get a new machine tbey just expect it all to be there and work. I feel like these cryptography and legality discussions here on HackerNews always miss the mark because we overestimate hiw much most people care. Speaking of younger generations, I also get the feeling that there isn't such a thing as "digital sovereignty" or "ownership", at least not by the same definitions we gen x and older millennials internalize those definitions. Across the generations, there are always a few groups to where cryptographic ownership really matter, such as journalists, protesters, and so on. Here on HN I feel like we tend to over-geeneralize these use cases to everybody, and then we are surprised when most people don't actually care.
- politelemon 8mo agoThe major OS vendors (apple, google, ms) are complicit in data turnover and have been for over ten years now. It has been reported multiple times so I'm struggling to see the angle being projected here. This feels like click harvesting got the HN "Microsoft bad" crowd.
- internet2000 8mo agoThe San Bernardino iPhone case proves that Apple is very much so not complicit.
- cromka 8mo agoThis was a decade ago, before the big tech went to brown nose Trump on live TV. We live in different reality nowadays. Apple doesn't even market their encryption and safety anymore, like they did on massive billboards all over the world.
- internet2000 8mo agoThey've only done more since 2016. Lockdown mode: https://support.apple.com/en-us/105120 https://support.apple.com/en-us/105120 Advanced Data Protection for iCloud: https://support.apple.com/en-us/108756 https://support.apple.com/en-us/108756
- cromka 8mo agoSure, but these are all mere statements. You don't know if they fully back that until there's a public standoff with law enforcement/administration and there weren't any in recent years. Yet at the same time it's hard to believe there were no attempts from that government to decrypt some devices they needed. So the fact we hear nothing about it is also an information to me. Sure, this is all speculation, but all things considered... Besides, they fully comply with Chinese requirements, so... PS. Others report Filevault keys are also being backed to iCloud since September and they didn't tell anyone: https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/ https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...
- cromka 8mo agoAny reason to believe Apple won't do the same with whatever we backup in iCloud?
- nickmccann 8mo agoIf you have advanced data protection enabled, Apple claims: “No one else can access your end-to-end encrypted data — not even Apple — and this data remains secure even in the case of a data breach in the cloud.” https://support.apple.com/en-us/102651 https://support.apple.com/en-us/102651
- cromka 8mo agoYeah, the problem is whether they already bent over for Trump admin or not yet.
- Noaidi 8mo agoYes, I know this sounds conspiratorial, but I think the whole Liquid Ass thing was a rush to put some other software in Apple products to appease the Trump admin. For example, it is new in Tahoe that they store your filevault encryption key in your icloud keychain without telling you. https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/ https://sixcolors.com/post/2025/09/filevault-on-macos-tahoe-...
- cromka 8mo agoMy conspiration theory about Liquid Ass is their hardware for past 5 years was so good that they needed to make people finally upgrade it. My Air M1 16GB worked absolutely fine until it slowed down immensely on macOS 26.
- eddyg 8mo agoWhich is a very good thing. iCloud is much more secure than most people realize because most people don’t take the 30 minutes to learn how it is architected. You can (and should) watch https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for all the details about how iCloud is protected, but especially the time-linked section. :)
- lovebeans 8mo agoYes and this is a good thing. No organization, no matter how large or powerful, should be beyond the reach of the law.
- preisschild 8mo agoIdeally they wouldnt even have this key / the private data in the first place
- lovebeans 8mo agoThe user can opt out of this if they want.
- direwolf20 8mo agoHow?
- stabbles 8mo agoThat's a false dichotomy. You can hold an organization accountable to the law without requiring them to maintain a "master key" to your private data.
- lovebeans 8mo agoIt isn't required.
- Dylan16807 8mo agoI have no idea what you mean. If the user keys were protected, that would not put Microsoft beyond the reach of the law. To Microsoft it's just a few bytes they never do anything with.
- daft_pink 8mo agoAt least they’re honest.
- Noaidi 8mo agoApple will do this too. Your laptop encryption key is stored in your keychain (without telliing you!). All is needed is a warrant for your iCloud account and they also have access to your laptop. sixcolors.com/post/2025/09/filevault-on-macos-tahoe-no-longer-uses-icloud-to-store-its-recovery-key/
- _blk 8mo agoThanks, that's good to know. I suspect WhatsApp's "we're fully E2E encrypted" would be similar too.
- cedws 8mo agoIt's most software. Cryptography is user-unfriendly. The mechanisms used to make it user friendly sacrifice security. There's a saying that goes "not your keys not your crypto" but this really extends to everything. If you don't control the keys something else does behind the scenes. A six digit PIN you use to unlock your phone or messaging app doesn't have enough entropy to be secure, even to derive a key-encryption-key. If you pass a KDF with a hardness of ~5 seconds a four digit PIN to derive a key, then you can brute force the whole 10,000 possible PINs in ~13 hours. After ~6.5 hours you would have a 50% chance of guessing correctly. Six digit PIN would take significantly longer, but most software uses a hardness nowhere near 5 seconds.
- bigyabai 8mo agoTake it a step further, even - "End-to-End-Encryption" is complete security theater if the user doesn't control either end. We joke and say that maybe Microsoft could engineer a safer architecture, but they can also ship an OTA update changing the code ad-hoc. If the FBI demands cooperation from Microsoft, can they really afford to say "no" to the feds? The architecture was busted from the ground-up for the sort of cryptographic expectations most people have.
- coppsilgold 8mo ago> A six digit PIN you use to unlock your phone or messaging app doesn't have enough entropy to be secure The PIN is not usually used for cryptography, it's used to authorize the TEE (secure enclave) to do it for you. It's usually difficult or impractical to get the keys from the TEE.
- ntoskrnl_exe 8mo agoPretty sure the same applies to all the passwords/passkeys/2FA codes stored in the Authenticator app with cloud backup on.
- zekica 8mo agoOnly if that authenticator/password manager app is not end-to-end encrypted.
- mcsniff 8mo agoNo, not "only". E2EE is now used as a dog whistle. Who holds/controls the keys on both ends?
- arielcostas 8mo agoEnd-to-end usually means only the data's owner (aka the customer) holds the keys needed. The term most used across password managers and similar tools is "zero knowledge encryption", where only you know the password to a vault, needed to decrypt it. There's a "data encryption key", encrypted with a hash derived of your username+master password, and that data encryption key is used locally to decrypt the items of your vault. Even if everything is stored remotely, unless the provider got your raw master password (usually, a hash of that is used as the "password" for authentication), your information is totally safe. A whole other topic is communications, but we're talking decryption keys here
- ntoskrnl_exe 8mo agoThat's right, and Microsoft Authenticator isn't.
- bdavbdav 8mo agoUse 1Password or similar instead. They’re keyed against a key they don’t have access to.
- morshu9001 8mo ago
- dist-epoch 8mo agoEverybody should have access to your hard drive, not just the FBI, so please do not encrypt your hard-drive. If you encrypt your drive and upload the key to Microsoft, you are engaging in anti-competitive behavior since you give them access to your data, but not also to the local thief. Just don't encrypt your drive if you cant be bothered to secure your key. Encryption-neutrality.
- expedition32 8mo agoHonestly I have no problem with this but I do remember a lot of gaslighting about how America is free and Europe a totalitarian state.
- zb3 8mo agoThe problem is not that they will give the key (government can force them - this is expected), but that they even have the key in the first place.. I bet this is done without proper consent, or with choice like "yes" vs "maybe later"..
- cornholio 8mo agoBeyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Do we really, really, fully understand the implications of allowing for private contracts that can trump criminal law?
- hermanzegerman 8mo agoThey could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent
- p_ing 8mo agoForcing implies there are zero ways to begin with a local only account (or other non-Microsoft Account). That's simply not true.
- bdavbdav 8mo agoDisagree. If the path is shrouded behind key presses and commands which are unpublished by MS (and in some instances routes that have been closed), it may as well be.
- p_ing 8mo ago> it may as well be. That defies the definition of "forced". Forced means no option. You can disagree all you want -- but at a technical level, you're incorrect.
- selfhoster11 8mo agoTry doing this as a normies without technical guidance. Technically correct, this time, is not the benchmark.
- lingrush4 8mo agoVery different phrasing between the headline and the subtitle: > Microsoft confirms it will give the FBI your Windows PC data encryption key if asked > Microsoft says it will hand those over to the FBI if requested via legal order Microsoft complying with legal orders is not news. But why hire actual journalists when you can just lie in your headlines and still get clicks?
- sokoloff 8mo agoHeadline says “…if asked” Article and facts are “…if served with a valid legal order compelling it” ∴ Headline is clickbait.
- iammjm 8mo agoYou are arguing semantics, whereas the point is that A) they have your keys, and B) they will give them away if they will have to
- mattmaroon 8mo agoNo, that’s binary thinking. The degree to which they will resist giving them away matters. I’d much rather they require a warrant than just give it to any enforcement agency that sends them an email asking. The former is what I expect.
- kenjackson 8mo agoIt’s really just A. Point B is pretty much just derived from there.
- a3w 8mo agoasked, not ordered. Seems fine.
- guerrilla 8mo agoNo, that's how I interpreted the headline.
- lifetimerubyist 8mo agoI would prefer “it is impossible for Microsoft to give the keys because that’s not how their encryption works”.
- mattmaroon 8mo agoThat’s the case if you change a setting. The default setting is a good mix of protecting people from the trouble they’re far more likely to run into (someone steals their laptop) while still allowing them back in if they forget their password. The previous default setting was no encryption at all which is worse in every case.
- unixhero 8mo agoStallman was correct
- jxdxbx 8mo agoIf tech companies implemented real, e2e encryption for all user data, there would be a huge outcry, as the most notable effect would be lots of people losing access to their data irrevocably. I'm all for criticizing tech companies but it's pointless to demand the impossible.
- rocqua 8mo agoJust say "we are storing your keys on our servers so you won't lose them" and follow that with either "do you trust us" or even "we will share this key with law enforcement if compelled". Would be fine. Let people make these decisions. Besides, bit ocker keys are really quite hard to lose.
- zzzeek 8mo agois it just me or would "Microsoft refuses to comply with a legal search warrant" be an actual, surprising news story? like of course MSFT is going to hand over to authorities whatever they ask for if there's a warrant, imagine if they didn't (hint: not good for business. their customers are governments and large institutions, a reputation for "going rogue" would damage their brand quite a bit)
- jonplackett 8mo agoHe headline misleading - they will give it if there’s a court order, not just if asked. Still crap but the headline is intentionally inaccurate for clickbaiting
- rwmj 8mo agoMicrosoft confirms it will obey the law.
- takoid 8mo agoRelated discussion from yesterday: https://news.ycombinator.com/item?id=46735545 https://news.ycombinator.com/item?id=46735545
- modzu 8mo agonot your keys? not your crypto
- FabHK 8mo ago"US firm confirms it will comply with US law if asked."
- betaby 8mo agoUnless that's a data privacy or monopoly related. Then they won't.
- caseysoftware 8mo agoDue to Third Party Doctrine, Microsoft doesn't even NEED a "legal order." It's merely a courtesy which they could change at any time. Based on the sheer number of third parties we're required to use for our day to day lives, that is ridiculous and Third Party Doctrine should be eliminated. Ref: https://en.wikipedia.org/wiki/Third-party_doctrine https://en.wikipedia.org/wiki/Third-party_doctrine
- orbital-decay 8mo ago>people who voluntarily give information to third parties Is it the case with BitLocker? The voluntary part.
- Am4TIfIsER0ppos 8mo agoSure. You voluntarily use windows. You could use something else or nothing so you chose to use it. You are not compelled to use it by law. You are just strongly compelled by a small carrot and a large stick. The same applies to a smart phone BTW.
- direwolf20 8mo agoFrom a legal perspective yes since the government didn't force you to
- throwconsti 8mo agoMS confirms it has to comply with warrants to the consternation of many.
- cynicalsecurity 8mo agoVeraCrypt.
- deleted 8mo ago[deleted]
- hohithere 8mo agoDamn I love my dear little tux.
- 0dayman 8mo agoshocking
- shevy-java 8mo agoNot surprising. The whole Win11 feels like a spy-tool for the government. Just that "recall" anti-feature nobody needs - except for those who want to sniff and spy after people.
- Zak 8mo agoThe headline is misleading. It says that Microsoft will provide the key if asked, but the linked statement to Forbes says Microsoft will provide the key if it receives a valid legal order. These have different meanings. Microsoft is legally entitled to refuse a request from law enforcement, and subject to criminal penalties if it refuses a valid legal order. It does illustrate a significant vulnerability in that Microsoft has access to user keys by default. The public cannot be sure that Microsoft employees or criminals are unable to access those keys.
- DmitryO 8mo agoThe same way you cannot be sure that FBI is not criminals
- deleted 8mo ago[deleted]
- TeMPOraL 8mo agoIt's a catchy meme for sure, but when people actually start to believe - like for real, not just the usual talking shit that passes for "conversation" with normal people - that law enforcement officers are worse thugs than regular thugs -- that's a fast way to turn into a failed state, where that actually is true. Causality here actually works both ways, because in free(ish) societies, law enforcement derives its authority more from people's intersubjective belief in that authority, and less from actual use of force.
- deleted 8mo ago[deleted]
- deleted 8mo ago[deleted]
- bigbadfeline 8mo ago> when people actually start to believe... that law enforcement officers are worse thugs than regular thugs -- that's a fast way to turn into a failed state, where that actually is true. It's quite clear that if law enforcement officers are indeed worse or just like regular thugs the failed state will soon materialize regardless of what people think about the issue. Moreover, isn't the fastest way to a failed state to have people believe that their security agencies are good and proper when in reality they aren't? That kind of naivete is surely a lot worse than a bit of paranoia.
- djoldman 8mo ago> ... if asked This is blurring of fact drives click bait. The origin of this is a Forbes article[0] where the quote is: "Microsoft confirmed to Forbes that it does provide BitLocker recovery keys if it receives a valid legal order." [0] https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/ https://www.forbes.com/sites/thomasbrewster/2026/01/22/micro...
- notepad0x90 8mo agoI don't understand this, it's actually baffling. Why was the question being asked to begin with let along a whole post being made about this? If they have a legal request from a law enforcement agency of any country they operate in, they either comply or see executives in prison. Is how bitlocker works not well known perhaps? I don't think it's a secret. The whole schtick is that you get to manage windows computers in a corporate fleet remotely, that includes being able to lock-out or unlock volumes. The only other way to do that would be for the person using the device to store the keys somewhere locally, but the whole point is you don't trust the people using the computers, they're employees. If they get fired, or if they lose the laptop, them being the only people who can unlock the bitlocker volume is a very bad situation. Even that aside, the logistics of people switching laptops, help desk getting a laptop and needing to access the volume and similar scenarios have to be addressed. Nothing about this and how bitlocker works is new. Even in the safer political climates of pre-2025, you're still looking at prosecution if you resist a lawful order. You can fight gag-orders, or the legality of a request, but without a court order to countermand the feds request, you have to comply. Microsoft would do the same in China, Europe, middle east,etc.. the FBI isn't special.
- maxglute 8mo ago>Microsoft would do the same in China, Europe, middle east,etc.. the FBI isn't special. One would presume US agencies has leverage to access global data.
- notepad0x90 8mo agoSure, I don't disagree but that isn't what this discussion is about. It's about a lawful publicized request. For microsoft, they don't need any leverages, they can just use a FISA order, they can force you to keep it a secret. Their leverage is federal prison.
- Timothycquinn 8mo agoTime to use Linux as the on the metal OS.
- Jigsy 8mo agoI do find it quite interesting how people support this idea (because they got a warrant), but are vehemently against the idea of backdooring encryption. How is this any different?
- jmward01 8mo agoActual freedom starts with freedom of thought which requires spaces that you can truly believe are safe. The push for the surveillance world is rapidly eroding the places someone can not only be safe to think but feel safe to think in. The 'feel safe' is deeply important here. The arguments of 'if you have nothing to hide' do not make anyone feel safe, they do the opposite and they chill free thought. The second, very clear, argument is that the state can't be trusted in the long run. Period. Maybe you love your elected officials today but tomorrow they could be actively out to harm you. Every tool we allow the state to use needs to be viewed with this level of extreme skepticism and even very clear benefits need to be debated vigorously. Encryption, and technologies like it, may allow hiding criminal activity but they also provide people a sense of security to think freely and stave off political power grabs. We recognize the fundamental right to free speech and give great latitude to it even when it is harmful and hateful, we need to recognize the fundamental right to free thought and recognize that encryption and similar tools are critical to it.
- vardalab 8mo agoExactly! I agree about feeling free to think is important. I am a legal immigrant here on the green card, and I was randomly looking at my iCloud photos, and there were two of them where I was wearing a 2024 elections t-shirt of the losing side. The t-shirt was given to me as a gag gift, and I just had taken a picture of it to show it to the sender for giggles. Now looking at this old image. I had second thoughts. What if on the border crossing some officer sees a t-shirt and doesn't agree with it? Maybe I should delete the image. And it's not the first time I want to go post something online, but I've stopped myself. What if it comes back and bites me? Even though it might be an innocuous tweet, nothing egregious, but I just don't want to engage. And this is how freedom goes. This feels as bad as it was growing up in the Soviet Union.
- direwolf20 8mo agoYou should definitely delete that image, as people have been denied entry or arrested at borders based on their social media history and pictures on their phone.
- uberman 8mo agoThis issue aside, if anyone has the keys what value are they in the end? Has Microsoft ever refused to unlock someone's pc stating that they could not technically do that? Isn't storing keys like this akin to storing passwords in clear text?
- nickevante 8mo agoThe headline is slightly misleading. Microsoft can only provide the key if you are using a Microsoft Account which automatically escrows the BitLocker recovery key to OneDrive. If you use a Local Account (which requires bypassing the OOBE internet check during setup) or explicitly disable key backup, the key never leaves the TPM. The issue isn't the encryption algorithm its the convenience selection.
- chmorgan_ 8mo ago[dead]
- dismalaf 8mo agoLocal company complies with the law. In other news, the sky is blue...
- upofadown 8mo agoIf you are not typing in a passphrase or plugging in a device containing a key to unlock your disk then the secret exists somewhere else. Chances are that secret is available to others. The root issue here is that the user is not being made clearly aware of where the secret is stored and what third party(s) have access to it or reasonably might be able to get access to it. These sorts of things should be very unsurprising to the people who depend on them...
- bdhcuidbebe 8mo agoBut, the pile of reasons for not running windows is already through the roof…
- _zagj 8mo agoWhich is really galling when you consider how many Windows 11 users have inadvertently been locked out of their own bought-and-paid-for computers thanks to BitLocker.
- TheRealPomax 8mo agoWhat's that? Windows, due to its market position, should not be allowed to force users into online-only accounts? Agreed.
- TheRealPomax 8mo agoTitle should read "Microsoft confirms it will give the FBI your Windows PC data encryption key if court-ordered to do so". Just because the article is click bait doesn't mean the HN entry needs to be, too. Sure, the fact that MS has your keys at all is no less problematic for it, but the article clearly explains that MS will do this if legally ordered to do so. Not "when the FBI asks for it". Which is how things work: when the courts order you to do something, you either do that thing, or you are yourself violating the law.
- Palmik 8mo agoDoes Microsoft let you encrypt the key with your password / passphrase (with a backup you can write down)?
- winstonwinston 8mo agoTechnically it is possible to configure butlocker using passphrase instead of a TPM. It is not easy though. It is configured via GPO. However it is not a local account password. It is a separate passphrase which you need to provide early in boot process, similar to LUKS on linux systems. It works on windows computers without TPM, i’m not sure is it supported on systems that actually have TPM available.
- grigio 8mo agoBecause yours Windows PC isn't yours
- pregnenolone 8mo agoI’m not trying to defend Microsoft, but I think people are being a bit dramatic. It's a fairly reasonable default setting for average users who simply want their data protected from theft. On the other hand, users should be able to opt out from the outset, and above all, without having to fiddle with the manage-bde CLI or group policy settings. With Intel Panther Lake (I'm not sure about AMD), Bitlocker will be entirely hardware-accelerated using dedicated SoC engines – which is a huge improvement and addresses many commonly known Full Disk Encryption vulnerabilities. However, in my opinion some changes still need to be made, particularly for machines without hardware acceleration support: - Let users opt out of storing recovery keys online during setup. - Let users choose between TPM or password based FDE during setup and let them switch between those options without forcing them to deal with group policies and the CLI. - Change the KDF to a memory-hard KDF - this is important for both password and PIN protected FDE. It's 2026 - we shouldn't be spamming SHA256 anymore. - Remove the 20 char limit from PIN protectors and make them alphanumerical by default. Windows 11 requires TPM 2.0 anyway so there's no point in enforcing a 20 char limit. - Enable TPM parameter encryption for the same reasons outlined above.
- hinkley 8mo agoIf you don’t think Intel put back doors into that then I fear for the future.
- pregnenolone 8mo ago> If you don’t think Intel put back doors into that then I fear for the future. If that’s what you’re worried about, you shouldn’t be using computers at all. I can pretty much guarantee that Linux will adopt SoC based hardware acceleration because the benefits – both in performance and security – outweigh the theoretical risks.
- hinkley 8mo agoThey resisted hardware RNG when it first was introduced. Brian Cantrill is trying to end this nonsense but we shall see if they end up being the lone voice or not.
- anonymousiam 8mo agoIt's already established that your disk encryption keys are in the Microsoft cloud whether you want them there or not. It's just a small step from there to your local government having the key too. Some governments claim to respect the privacy of their citizens, but there are always exceptions. Most governments likely have direct access to the keys, and don't even need to make the request.
- akagusu 8mo agoNo surprises here. There are people out there warning this would happen soon or later, and urging people to stop using Microsoft products, but of course, nobody cared about it as usual.
- b00ty4breakfast 8mo agoit is perhaps mildly surprising that they have access to user encryption keys, but anyone surprised, over 20 years post-Patriot Act, that an American corporation is willing to cooperate with American federal law enforcement has maybe not been paying attention.
- faragon 8mo agoWhy Microsoft stores the encryption keys of the users in their servers? Key recovery is convenient, but in my opinion it should exist the "opt out" option, without MS being involved in the key storage in their datacenters.
- wslh 8mo agoIf I remember well from installing Windows you can store the keys yourself without a cloud backup. What am I missing?
- pedalpete 8mo agoControversial question here. When someone is arrested, the police can get a subpoena to enter your house, right? There they can collect evidence regarding the case. Digital protections should exist, but should they exist beyond what is available in the physical world? If so, why? I think the wording of this is far too lenient and I understand the controversy of "if asked" vs "valid legal order", neither of which strictly say "subpoena", and of course, the controversy of how laws are interpreted/ignored in one country in particularly (yes, I'm looking at you USA). Should there be a middle ground? Or should we always consider anything that is digital off-limits?
- _jab 8mo agoCompletely agree. Crazier question: what’s wrong with a well-intentioned surveillance state? Preventing crime is a noble goal, and sometimes I just don’t think some vague notion of privacy is more important than that. I sometimes feel that the tech community would find the above opinion far more outlandish than the general population would.
- B1FIDO 8mo ago> what’s wrong with a well-intentioned surveillance state? https://en.wikipedia.org/wiki/Wings_of_Desire https://en.wikipedia.org/wiki/Wings_of_Desire tl;dw: A well-intentioned surveillance state may, in fact, love the beings they are surveilling. They may fall in love so deeply, that they want to become like us. I know it's a revolutionary concept.
- gopher_space 8mo agoThere’s nothing inherently wrong with the panopticon. Your society is what makes it good or evil.
- danans 8mo ago> When someone is arrested, the police can get a subpoena to enter your house, right? That's a warrant. A subpoena is an order to appear in court.
- banku_brougham 8mo agowhenever someone mentions the FBI I think of of a picture of the current highly incompetent and malevolent director.
- hdgvhicv 8mo agoIf you potentially are a target for the us government you should avoid Microsoft. Given that the us government is happy to execute us citizens and invade other countries that basically means everyone.
- junglistguy 8mo ago[dead]
- commandersaki 8mo agoThis is no different to Apple placing the encryption key for Filevault as plaintext on disk when it is turned off (the default). Both companies make it easy for you to recover data in event of a catastrophe.
- ChrisArchitect 8mo ago[dupe] Discussion on source: https://news.ycombinator.com/item?id=46731694 https://news.ycombinator.com/item?id=46731694 And earlier: https://news.ycombinator.com/item?id=46735545 https://news.ycombinator.com/item?id=46735545
- seanhunter 8mo ago“American company will comply with American law”. I’m shocked. Shocked I tell you!
- chrisss395 8mo agoMy wife is an insurance litigation attorney and regularly requests social media data from Microsoft, Meta, etc. for people. Generally they hand it over without issue; I think Apple is the only one to have pushed back at times.
- MetroWind 8mo agoObviously...?
- Camiladiaz 8mo ago[dead]
- daveheinrich 8mo agoMy recommendation goes to CIPHERTRACES [DOT] COM
- daveheinrich 8mo agoMy recommendation goes to CIPHERTRACES [DOT] COM This team was able to execute and investigate the loss of over $85,000.00 Usdt of I and my friend we have started getting our refunds and we are grateful