5 ms·
That isn't Bit Locker, it's device encryption which is supported in 8.1 (Home) and Windows RT where naive users are more likely to forget to backup the key and
by wfjackson 12y ago
That isn't Bit Locker, it's device encryption which is supported in 8.1 (Home) and Windows RT where naive users are more likely to forget to backup the key and hence lose data.
BitLocker is only available in the professional,enterprise and ultimate versions of Windows 8.1 and it does not automatically backup the key to an MS account.
- xnull2guest 12y ago"BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices." http://technet.microsoft.com/en-us/library/dn306081.aspx http://technet.microsoft.com/en-us/library/dn306081.aspx Device Encryption is supported by Bitlocker for all major skews including Windows Server 2012 R2. They have also backported Device Encryption to 8. Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument doesn't stack up with the fact that OneDrive/SkyDrive is enrolled in PRISM.
- wfjackson 12y agoThe big difference is that it's automatic on RT, Phone and 8.1 if the hardware supports it. Think Grandma's PC. Do you really want her to see the option window about where to store a recovery key? For the other SKUs, an option window pops up when you enable BitLocker asking about backup location.
- wfjackson 12y ago>Edit: Per your comment below you recognize that it is enabled automatically on PCs - and this is supported by the documentation provided. The grandma argument doesn't stack up with the fact that OneDrive/SkyDrive is enrolled in PRISM. The encryption is automatic, hence it makes sense that the backup is forced. Given that many Windows user get confused when their icons are moved, it would be hard to expect them to manage decryption keys. A significant percentage could lose their data. This is still better than earlier versions of personal use Windows where the data wasn't encrypted at all and all one had to do is to connect the hard drive on a different computer. On Professional and Enterprise versions, when you choose to encrypt, the dialog box with the choice does appear, I just tried.
- xnull2guest 12y agoIt does not matter whether a dialog box appears. Have you confirmed that the keys are not pushed into OneDrive? (That's the thing to check.) So what you are saying is that bitlocker keys are automatically uploaded to OneDrive and OneDrive is PRISM, but this isn't key escrow for government. The backup can both be for Grandma and Federal Law Enforcement. They are not mutually exclusive. My original point stands. Modern Windows Bitlocker keys are automatically placed into a location where TLAs can request them.
- wfjackson 12y agoBitLocker is not the same as Device Encryption. Please stop confusing the two. Also you have been unable to say what you want Microsoft to do in grandma's case.
- xnull2guest 12y ago"BitLocker provides support for device encryption on x86 and x64-based computers with a TPM that supports connected stand-by. Previously this form of encryption was only available on Windows RT devices." http://technet.microsoft.com/en-us/library/dn306081.aspx http://technet.microsoft.com/en-us/library/dn306081.aspx They are not the same. Agreed. Sorry about the confusion. Anyway, it's true that modern Windows Operating Systems, even on non-RT devices, upload bitlocker keys automatically and transparently to the cloud, where the data is indexed for the PRISM program. They do this with Device Encryption, which is supported by Bitlocker on x86 and x64-based computers with a TPM that supports connected stand-by. Edit: Regarding Grandma. Keys can be stored on a non-boot internal drive. Keys can be shown on the screen as a QR code (and the screen can tell Grandma to take a picture). Grandma's keys can be printed out on a small detachable USB or SD/MicroSD device with a kilobyte of space. The machine can provide provisional encryption until Grandma's computer can connect to a printer (where it gets printed). Grandma's computer could send the key over USB/Bluetooth/Wifi to a trusted computer friend after pairing (such as a 'tech savvy' niece/nephew). There are plenty of options. The 'grandma clause' is not mutually exclusive with key escrow. OneDrive is a nice place for grandma AND a nice place for the FBI.
- 12y ago
- justcommenting 12y agovia matthew green recently: So per @justintroutman and now confirmed, Microsoft has substantially weakened its disk encryption in Windows 8. Now uses plain CBC mode.
- xnull2guest 12y agoYup, the diffuser was removed years ago. The designer of the diffuser removed was Neils Ferguson, the cryptographer who called out DUAL_EC as a backdoor in 2004. The stated reason was FIPS compliance.
- tptacek 12y agoDo you understand what the "diffuser" in Bitlocker was intended to do? Virtually every other mainstream FDE scheme uses XTS, which is also not authenticated; XTS is literally the ECB mode of tweakable block ciphers.
- xnull2guest 12y ago> Do you understand what the "diffuser" in Bitlocker was intended to do? Yes. > Virtually every other mainstream FDE scheme uses XTS, which is also not authenticated; XTS is literally the ECB mode of tweakable block ciphers. Not really relevant?
- tptacek 12y agoIf you think the point I made about XTS isn't really relevant, I'm going to timidly suggest that you don't actually understand Elephant. I apologize in advance for saying that, but I think it's more productive to be honest than tactful in this case.
- xnull 12y agoAES CBC + Elephant != XTS Elephant 'mixes' the blocks on a sector level to limit CBC block modification attacks. It does not limit the maximum size to align to sectors. It is not XTS. Nor is my claim that Elephant is what you want or need. Merely that it was removed, that Ferguson designed it, and that FIPS compliance was the underlying justification.