7 ms·
Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would w
by cornholio 9mo ago
Beyond the crypto architecture debate, I don't really understand how could anyone imagine a world where MS could just refuse such a request. How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"?
Do we really, really, fully understand the implications of allowing for private contracts that can trump criminal law?
- hermanzegerman 9mo agoThey could just ask before uploading your encryption key to the cloud. Instead they force people to use a Microsoft Account to set up their windows and store the key without explicit consent
- p_ing 9mo agoForcing implies there are zero ways to begin with a local only account (or other non-Microsoft Account). That's simply not true.
- bdavbdav 9mo agoDisagree. If the path is shrouded behind key presses and commands which are unpublished by MS (and in some instances routes that have been closed), it may as well be.
- p_ing 9mo ago> it may as well be. That defies the definition of "forced". Forced means no option. You can disagree all you want -- but at a technical level, you're incorrect.
- selfhoster11 9mo agoTry doing this as a normies without technical guidance. Technically correct, this time, is not the benchmark.
- rvnx 9mo agoAnyway Microsoft and any software developer can be compelled to practically do anything, you don't want to be blocked in some jurisdictions (even less the US) and the managers do not want to go to jail to protect a terrorist, especially if nobody is going to know that they helped. Some even go that far that they push an update that exfiltrates data from a device (and some even do on their own initiative). And even if you are not legally compelled. Money or influence can go a long way. For example, the fact that HTTPS communications were decipherable by the NSA for almost 20 years, or, whoops, no contract with DoD ("not safe enough"...) Once the data is in the hands of the intelligence services, from a procedure perspective they can choose what to do next (e.g. to officialize this data collection through physical collection of the device, or do nothing and try to find a more juicy target). It's not in the interest of anyone to prevent such collection agreement with governments. It's just Prism v2. So seems normal that Microsoft gives the keys, the same that Cloudflare may give information about you and the others. They don't want to have their lives ruined for you.
- bad_haircut72 9mo agoIm going to shoot you unless you say the magic word - and technically Im not even forcing you into it, you could have said the magic word and got out of it!! Whats the magic word? not telling!
- bdavbdav 9mo agoX didn’t force Y to the ground. If Y had made different choices, worked out more, was stronger, Y could have fought back.
- cornholio 9mo agoThat's a crypto architecture design choice, MS opted for the user-friendly key escrow option instead of the more secure strong local key - that requires a competent user setting a strong password and saving recovery codes, understanding the disastrous implication of a key loss etc. Given the abilities of the median MS client, the better choice is not obvious at all, while "protecting from a nation-state adversary" was definitely not one of the goals.
- wobfan 9mo agoWhile you're right, they also went out of their way to prevent competent users from using local accounts and/or not upload their BitLocker keys. I could understand if the default is an online account + automatic key upload, but only if you add an opt-out option to it. It might not even be visible by default, like, idk, hide it somewhere so that you can be sure that the median MS user won't see it and won't think about it. But just fully refusing to allow your users to decide against uploading the encryption key to your servers is evil, straight up.
- JasonADrury 9mo agoYou can just ... not select the option to upload your keys to MS? During the setup you get to choose where to store your bitlocker recovery key.
- _lnrx 9mo agoThe last time I've installed windows, bitlocker was enabled automatically and the key was uploaded without my consent. Yes, you can opt out of it while manually activating bitlocker, but I find it infuriating that there's no such choice at the system installation process. It's stupid that after system installation a user supposed to renecrypt their system drive if they don't want this.
- herewulf 9mo agoHow would you even know that your opt-out request isn't silently ignored? Or your re-encrypted drive's key got backed up to the cloud because an update silently inverted a flag?
- JasonADrury 9mo agoThe alternative is just not having FDE on by default, it really isn't "require utterly clueless non-technical users to go through complicated opt-in procedure for backups to avoid losing all their data when they forget their password". And AFAICT, they do ask, even if the flow is clearly designed to get the user to back up their keys online.
- antiframe 9mo agoNo, encryption keys should never be uploaded to someone else's computer unencrypted. The OOBE should give users a choice between no FDE or FDE with a warning that they should not forget their password or FDE and Microsoft has their key and will be able to recover their disk and would be compelled to share the key with law enforcement. By giving the user the three options with consequences you empower the user to address their threat model how they see fit. There is no good default choice here. The trade offs are too varied.
- JasonADrury 9mo agoAlways on FDE with online backups is a perfectly reasonable default. The OOBE does offer the users the choice to not back up their key online, even if it's displayed less prominently. >By giving the user the three options with consequences you empower the user to address their threat model how they see fit. Making it too easy for uneducated users to make poor choices is terrible software design.
- xp84 9mo ago> The alternative is just not having FDE on by default yes, it would be. So, the current way, 99% of people are benefitting from knowing their data is secure when very common thefts occur, and 1% of people have the same outcome as if their disk was unencrypted: When they're arrested and their computers seized, the cops have their crime secrets. What's wrong?
- jeroenhd 9mo agoPhones have had FDE enabled by default for years. Nobody needs backup keys for those. Of course this feature comes at the cost of no longer being able to have low level control over your device, but this isn't a binary choice.
- shevy-java 9mo agoIt makes sense if you consider the possibility of a secret deal between the government and a giant corporation. The deal is that people's data is never secure. It's a nightmare actually.
- deleted 9mo ago[deleted]
- jMyles 9mo ago> Do we really, really, fully understand the implication of allowing private contracts that trump criminal law? ...it's not that at all. We don't want private contracts to enshrine the same imbalances of power; we want those imbalances rendered irrelevant. We hope against hope that people who have strength, money, reputation, legal teams, etc., will be as steadfast in asserting basic rights as people who have none of those things. We don't regard the FBI as a legitimate institution of the rule of law, but a criminal enterprise and decades-long experiment in concentration of power. The constitution does not suppose an FBI, but it does suppose that 'no warrant shall issue but upon probable cause... particularly describing the place to be searched, and the persons or things to be seized' (emphasis mine). Obviously a search of the complete digital footprint and history of a person is not 'particular' in any plain meaning of that word. ...and we just don't regard the state as having an important function in the internet age. So all of its whining and tantrums and pepper spray and prison cells are just childish clinging to a power structure that is no longer desirable.
- cornholio 9mo agoI think legally the issue was adjudicated by analogy to a closed safe: while the exact contents of the safe is unknown beforehand, it is reasonable it will contain evidence, documents, money, weapons etc. that are relevant, so if a warrant can be issued in that case compelling a locksmith to open it, then by analogy it can be issued against an encrypted device. Without doubt, this analogy surely breaks down as society changes to become more digital - what about a Google Glass type of device that records my entire life, or the glasses of all people detected around me? what about the device where I uploaded my conscience, can law enforcement simply probe around my mind and find direct evidence of my guilt? Any written constitution is just a snapshot of a social contract at a particular historical time and technological development point, so it cannot serve as the ultimate source of truth regarding individual rights - the contract is renegotiated constantly through political means. My question was more general: how could we draft that new social contract to the current age, how could we maintain the balance where the encrypted device of a suspected child predator and murderer is left encrypted, despite the fact that some 3rd party has the key, because we agreed that is the correct way to balance freedoms and law enforcement? It just doesn't sound stable in a democracy, where the rules of that social contract can change, it would contradict the moral intuitions of the vast majority.
- b65e8bee43c2ed0 9mo agoI don't think that many people here are naive enough to believe that any business would fight the government for the sake of its customers. I think most of us are simply appalled by this blatantly malicious behavior. I'm not buying all these "but what if the user is an illiterate, senile 90-year-old with ADHD, huh?" attempts to rationalize it away. it's the equivalent of the guy who installed your door keeping a copy of your keys by unspoken default - "what if your toddler locks himself out, huh?" I know the police can just break down my door, but that doesn't mean I should be ok with some random asshole having my keys.
- blargthorwars 9mo agoAssume good intent. If Microsoft didn't escrow the keys, the next HN post would be "mIcR0SofT Ate mY chILDhooD pHOTos!!"
- Dylan16807 9mo agoSo don't secretly encrypt data someone else owns on their device!
- ExoticPearTree 9mo agoEncrypt the BL key with the user's password? I mean there are a lot of technical solutions besides "we're gonna keep the BL keys in the clear and readily available for anyone".
- bdavbdav 9mo agoI thought this was what happened. Clearly not :( That’s the idea with services like 1Password (which I suppose is ultimately doing the same thing) - you need both the key held on the device and the password. I suppose this all falls apart when the PC unlock password is your MS account password, the MS account can reset the local password. In Mac OS / Linux, you reset the login password, you loose the keychain.
- narmiouh 9mo agoIn case of 1password, I would think it would be challenging to do what you are saying, at least for shared password vaults.
- digiown 9mo agoOn Linux the typical LUKS setup is entirely separate from the login password. You don't lose anything if you forget the login password. You can just reset it with a live USB or similar. If you mean the secure boot auto-unlock type of setup and you don't have a key backup, then you cannot reset your login password at all. You have to wipe the drive.
- bdavbdav 9mo agoKeychain, not FDE.
- arielcostas 9mo agoAt this point, end-to-end encryption is a solved problems when password managers exist. Not doing it means either Microsoft doesn't care enough, or is actually interested on keeping it this way
- AnthonyMouse 9mo ago> How exactly would we draft laws to this effect, "the authorities can subpoena for any piece of evidence, except when complying to such a request might break the contractual obligations of a third party towards the suspect"? Perhaps in this case they should be required to get a warrant rather than a subpoena?
- seanhunter 9mo agoA subpoena (specifically a subpoena duces tecum[1]) is the legal instrument that a court or other legal agency uses to compel someone to provide evidence. Seems entirely appropriate in this case. [1] The other kind is subpoena testificandum, which compels someone to testify.
- AnthonyMouse 9mo agoIf they need a warrant to search your desk then they should need a warrant to search your computer.
- seanhunter 9mo agoAnd they do. But if they want to compel your accountant to provide evidence (say) they use a subpoena. So if they want to compel Microsoft to provide evidence they should use a subpoena.
- AnthonyMouse 9mo agoA technical difference being that your key/password is not itself "evidence" of anything. A practical difference being that the relationship is more akin to that of a landlord rather than an accountant.
- constantcrying 9mo ago> don't really understand how could anyone imagine a world where MS could just refuse such a request By simply not having the ability to do so. Of course Microsoft should comply with the law, expecting anything else is ridiculous. But they themselves made sure that they had the ability to produce the requested information.
- mrweasel 9mo agoRight, Microsoft have the ability to recover the key, because average people lose their encryption keys and will blame Microsoft if they can't unlock their computer and gain access to their files. BitLocker protects you from someone stealing your computer to gain access to your files, that's it. It's no good in a corporate setting or if you're worried about governments spying on you. I'm honestly not entirely convinced that disk encryption be enabled by default. How much of a problem was stolen personal laptops really? Corporate machine, sure, but leave the master key with the IT department.
- j45 9mo agoThis make little to no sense. This is being reported on because it seems newsworthy and a departure from the norm. Apple also categorically says they refuse such requests. It's a private device. With private data. Device and data owned by the owner. Using sleight of hand and words to coax a password into a shared cloud and beyond just seems to indicate the cloud is someone else's computer, and you are putting the keys to your world and your data insecurely in someone else's computer. Should windows users assume their computer is now a hostile and hacked device, or one that can be easily hacked and backdoored without their knowledge to their data?
- blackcatsec 9mo agoFirstly, Apple does not refuse such requests. In fact, it was very widely publicized in the past couple of weeks that Apple has removed Advanced Data Protection for users in the UK. So while US users still enjoy Advanced Data Protection from Apple, UK users do not. It is entirely possible that Apple's Advanced Data Protection feature is removed legally by the US as well, if the regime decides they want to target it. I suspect there are either two reasons why they do not: Either the US has an additional agreement with Apple behind the scenes somewhere, OR the US regime has not yet felt that this was an important enough thing to go after. There is precedent in the removal, Apple has shown they'll do the removal if asked/forced. What makes you think they wouldn't do the same thing in the US if Trump threatened to ban iPhone shipments from China until Apple complied? The options for people to manage this stuff themselves are extremely painful for the average user for many reasons laid out in this thread. But the same goes for things like PGP keys. Managing PGP keys, uploading to key servers, using specialized mail clients, plugging in and unplugging the physical key, managing key rotation, key escrow, and key revocation. And understanding the deep logic behind it actually requires a person with technical expertise in this particular solution to guide people. It's far beyond what the average end user is ever going to do.
- ViktorRay 9mo agoYou seem to be forgetting the time the Obama administration asked Apple to unlock a suspect’s iPhone and Apple refused.
- Saris 9mo agoSure that's valid, they do need to conply with legal orders. But they don't need to store bitlocker keys in the first place, they only need to turn over data they actually have.
- ddtaylor 9mo agoMicrosoft killed local accounts in Windows 11 and made this the default path by users: Your private encryption keys are sent to Microsoft in a way that requires no other keys. This is a failure and doesn't happen on systems like LUKS. I understand Microsoft wants to be able to look nice and unlock disks when people forget their passwords, but doing so allows anyone to exploit this. Windows systems and data are more vulnerable because of this tradeoff they made.
- contrarian1234 9mo agoHave the recipient server be owned by a priest and API metadata that says it's a confession