5 ms·
BitLocker uploads device encryption keys to SkyDrive
- higherpurpose 12y agoWho needs "nefarious" backdoors, when Microsoft can just present them as "features" for users, that law enforcement can use just as easily, if not more so than a backdoor? I'd love for Microsoft to do out-of-the-box encryption while keeping the keys in the TPM, in all Windows 10 laptops, just like Android 5.0 and iOS 8.0, but it's not going to happen. Microsoft has too much of a cozy relationship with law enforcement to do something like that. It's not just a coincidence that it is the first company to join PRISM, or that Skype was added to PRISM not when it was owned by the Swedish, not when it was owned by eBay, but the same month Microsoft announced its acquisition. http://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_slide_5.jpg http://upload.wikimedia.org/wikipedia/commons/c/c7/Prism_sli...
- UnoriginalGuy 12y agoSo just two be clear, BitLocker has (at least) two modes of operation, normal mode where you yourself/your company are responsible for managing your encryption keys and passive "device encryption" mode which is enabled by default on many consumer devices (e.g. Surface 3, Surface RT, Windows Phone, etc). http://en.wikipedia.org/wiki/BitLocker#Device_encryption http://en.wikipedia.org/wiki/BitLocker#Device_encryption So the complaint is essentially, an encryption mode which is a freebie on many devices which traditionally would have no drive encryption at all is somehow spying for the NSA by uploading decryption keys. But the problem I have with that line of thinking is: Without device encryption many devices wouldn't have drive encryption at all and therefore the NSA (with possession of the device) could trivially retrieve that data. If you really want NSA-secure BitLocker encryption then why the heck don't you just set up BitLocker yourself instead of using Microsoft's "feature-limited" device encryption mode? The key won't be put on OneDrive in that situation. Also if Microsoft did enable full BitLocker on many consumer devices, do you really trust your average person to keep their keys safe? Or explain that there is no forgotten password feature, that their family photos are just "fucking gone" [0]. [0] https://www.youtube.com/watch?v=GWxC8ezE4Dk https://www.youtube.com/watch?v=GWxC8ezE4Dk
- t0mas88 12y agoThe problem is that Microsoft gives users a false sense of security. Marketing speak for this feature is "Your device is always automatically encrypted", which results in users thinking their data is safe. The content is then automatically backed up to Microsoft servers, to which users will not have much of an objection since it's encrypted anyway. But then behind their backs, Microsoft not only stores the encryption keys as a backup but also immediately shares them with the NSA that has full access to those backups. So basically they fucked up three times: 1. Marketing encryption while it's not safe, 2. Storing accessible backups of your data on their servers and 3. Actively sharing those backups with the NSA. Out of those, #1 would be an excusable thing that many companies do, #2 is a reason to mistrust them and #3 is a reason never to store anything with Microsoft ever again. It's just not acceptable to take my data, promise me it is encrypted, then lie about it and freely share my data with the NSA whenever they want.
- UVB-76 12y agoI think you are misunderstanding here. BitLocker is a full disk encryption system. Under the "device encryption" scheme discussed here, the recovery key is stored on Microsoft servers, but the content remains on the physical device. I assume if a user was to backup their data using one of Microsoft's other services (e.g. OneDrive), that data would be encrypted under a different regime. The BitLocker arrangement does provide users with some degree of security, in that an adversary would need access both to the physical device and the recovery keys on Microsoft servers to retrieve a user's data.
- tankenmate 12y agoPRISM (or NSL, or similar) + ANT (or 0 day hack or other) == compromised drive
- firepacket 12y agoI don't understand- how they are lying exactly? Don't they explicitly ask you if you want to backup your recovery key to the cloud? Is it really that hard to read prompts and change the default setting to manage your own key backup? If checking a single radio button is all it takes to NSA-proof your device, I'd say we are in pretty good shape. What is everyone complaining about?
- deleted 12y ago[deleted]
- cryptolect 12y agoThis is a wonderful example of NSA meddling. With one hand, Microsoft gives everyone out-of-box encryption, which it can use to demonstrate how well it's protecting consumers. With the other hand, by virtue of a 'feature' to assist consumers, it's providing access to the NSA via SkyDrive copies of encryption keys. Everyone's happy! Best of all, enterprise customers don't have a reason to complain, because the SkyDrive backup 'feature' shouldn't apply to their deployment scenarios. The only people with a complain are those that use the default option. We should keep vigilant for these security 'features' that are undermined by implementation. The NSA has years of practice at this, and we're playing catchup.
- mattfrommars 12y agoSo Onedrive isn't safe? Should I stop using it if I value my privacy?
- godgod 12y agoyes. If you value your privacy...stop using anything by Microsoft. Outlook.com as well. Windows is backdoored NSAKEY