12 ms·
Microsoft Gives Details About Its Controversial Disk Encryption
- jron 11y ago"I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to do so. The spokesperson told me they could not answer that question."
- isomorphic 11y agoThat's pretty much all one needs to know regarding BitLocker.
- wfunction 11y agoI was thinking the same thing. Why the hell would they say such a thing if the answer is no?
- caskance 11y agoBecause that is the only answer they are allowed to give.
- wfunction 11y agoAnd why would they not be allowed to say no?
- nickpsecurity 11y agoAs a3n said, there was a NSL, FISA warrant, or other legal threat that says they can't reveal even the existence of it. Saying yes reveals the existence in an obvious way. Saying no might get them in trouble if revealed to be lying later in court or mainstream media. So, like with classified matters, the safest comment is to not have one. Neutral. It's proven to work in terms of liability in majority of cases.
- tptacek 11y agoPlease cite such a case --- meaning, a case in which a software vendor faced civil or criminal liability for revealing the existence of a backdoor shipped in its product. Since you used the word "proven", a single example seems like a very reasonable request.
- nickpsecurity 11y agoThat's a trap. I just said a situation where'd they might do time for revealing it. You essentially want me to show where they reveal it. A tall order but I'll try anyway. Yahoo fought the FISA court, lost, and others were shown same decision showing resistance would be treated criminally [1]. Lavabit was ordered to give up their key to FBI, not talk about it, and lie to users about their privacy. (Google court docs if you doubt last part.) Finally, the ECI-classified leaks have a slide that says the "FBI compels" [2] the cooperation of U.S. companies with NSA's secret program(s). Compel is undefined. Yet, FBI is a LEO and involuntary compliance with them usually follows threats, yes? The same term is also used in this [3] document citing the specific, federal laws. Both are consistent with Yahoo's claims and leverage same laws. So, I believe that the FBI and NSA might have worked together to use legal threats related to Patriot Act to force companies to comply with SIGINT-enabling for collection purposes. The other ECI leaks mention U.S. companies that were cooperative and made their systems "exploitable" for "SIGINT-enabling." So, they offer money first and call the FBI if that doesn't work. Almost everyone caved so I'm guessing there's a significant, legal threat there. They're not telling you in detail because it's classified: releasing the info is a felony. Who would after seeing what happened to other whistleblowers... It's why I recommend privacy-focused companies being located in Iceland or countries similarly non-cooperative with police state activities. At least one can legally resist subversion in those countries rather than experience... whatever FBI does... for not subverting one's products. [1] https://www.techdirt.com/articles/20130614/10341723470/yahoo-fought-back-against-prism-lost-secret-ruling.shtml https://www.techdirt.com/articles/20130614/10341723470/yahoo... [2] https://firstlook.org/theintercept/document/2014/10/10/eci-whipgenie-classification-guide/ https://firstlook.org/theintercept/document/2014/10/10/eci-w... [3] https://www.nsa.gov/public_info/_files/speeches_testimonies/2013_08_09_the_nsa_story.pdf https://www.nsa.gov/public_info/_files/speeches_testimonies/...
- caskance 11y agoMost likely because they comply with lawful requests from the legitimate governments of nations they operate in.
- a3n 11y agoBecause an NSL told them not to?
- mattjorgs 11y agoWhat's the point of encryption if the government can still force the creators to decrypt it at the drop of a legal reason, which may or may not be substantial?
- jbigelow76 11y agoBecause people other than the government might want access to data you would rather them not have?
- joshstrange 11y agoWhat you are missing is that if the government has access then ANYONE can have access. That's the problem with backdoors ANYONE can walk through them. If I encrypt data I want to be the ONLY person who can decrypt it. If not then it's no better than security through obscurity.
- bad_user 11y agoNot "anyone", but it's all a matter of price. Given enough resources, all back-doors are shallow :-) And when speaking of encryption, people should be concerned with crime syndicates or with industrial espionage, in other words entities that might have the resources to find and access those back-doors.
- MichaelGG 11y agoSeeing how cheaply the KGB compromised FBI and CIA agents, it's probably a price many can reach. You don't need to compromise the key, just fake evidence so as to put the target under suspicion and get it decrypted. They must often chase down false leads, so this might be rather unnoticeable.
- sliverstorm 11y agoGovernment access doesn't require a backdoor per-se, does it? Can't you encrypt something with two public keys, such that either associated private key alone can decrypt? http://stackoverflow.com/questions/597188/encryption-with-multiple-different-keys http://stackoverflow.com/questions/597188/encryption-with-mu... Multi-encrypt the harddrive with YourPubKey & SpooksPubKey, and viola. The spooks have access, without giving criminals access (unless they steal SpooksPrivateKey, but is that any more risky than theft of YourPrivateKey?)
- alyx 11y agoConsidering Schneier has been outspoken for decades about the importance of open source cryptography, I asked if he recommends that other people use BestCrypt, even though it’s proprietary. “I do recommend BestCrypt,” Schneier told me, “because I have met people at the company and I have a good feeling about them. Of course I don’t know for sure; this business is all about trust. But right now, given what I know, I trust them.“ Uhh what? So following that same logic, if I know people at Microsoft who wrote the code for BitLocker, and I trust them, I should trust BitLocker.
- drzaiusapelord 11y agoI've said it before: Schneier is an empty suit. He knows what buttons to hit in geek culture to get viral traffic, but a lot of what he preaches is questionable and seemingly personal and subjective. If anyone else would have said this they would have been instantly buried.
- nickpsecurity 11y agoHe's far from an empty suit given the diverse work he's done that's arguably good. He does occasionally make spot judgments that seem weak and go in what I believe is the wrong direction at times. Unlike many, I post counterpoints to him each time on his own blog and he makes no attempts to censor/grayout those via moderation. He rarely gets into those debates: we sort them out instead. Yet, he lets it all stand for his crowd to read. Not the typical action of either someone trying to hide their incompetence or an ego-maniac. This attitude of his is why a number of us contributed there for years. Plenty of what we posted also pre-empted the Snowden leaks (incl many TAO attacks). Plenty to learn archived over there.
- jron 11y agoBruce's comment is quite bizarre. Here is a slightly better quote from him in 2013: "Be suspicious of commercial encryption software, especially from large vendors. My guess is that most encryption products from large US companies have NSA-friendly back doors, and many foreign ones probably do as well. It's prudent to assume that foreign products also have foreign-installed backdoors. Closed-source software is easier for the NSA to backdoor than open-source software. Systems relying on master secrets are vulnerable to the NSA, through either legal or more clandestine means." The article would have been far better if they only included Microsoft's answers and ended the piece with the same line: "Whatever you choose, if trusting a proprietary operating system not to be malicious doesn’t fit your threat model, maybe it’s time to switch to Linux."
- joshstrange 11y agoI generally like and agree with FirstLook/Intercept articles but this.... > Microsoft, after considerable prodding, provided me with answers to some longstanding questions about BitLocker’s security. The company told me which random number generator BitLocker uses to generate encryption keys, alleviating concerns about a government backdoor in that subsystem And then to answer it: > Microsoft told me that while the backdoored algorithm is included with Windows, it is not used by BitLocker, nor is it used by other parts of the Windows operating system by default. According to Microsoft, the default PRNG for Windows is an algorithm known as CTR_DRBG, not Dual_EC_DRBG, and when BitLocker generates a new key it uses the Windows default. Oh they "told you", great I guess we will just take them at face value and move on case clo... FUCK NO. Are you fucking kidding me???? MS may be getting better over all as a company by security/privacy is something I still don't trust them one bit on. That's not to say I think Apple is some bastion of privacy but MS has been in bed with the government for a LOT longer and hasn't been anywhere near as supportive of privacy/security as Apple has been as of late. This ENTIRE article is supposed to be take on faith and I'm sorry but that's not good enough. It's one thing to say "Some encryption is better than none" or "It will protect your from run-of-the-mill thieves but not the government" but to eat up everything MS said as fact is insane... And as one more gem: > I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to do so. The spokesperson told me they could not answer that question. MS knows what side their bread is buttered on and let me give you a hint, it's not the consumer side.
- MBlume 11y ago> Whatever you choose, if trusting a proprietary operating system not to be malicious doesn’t fit your threat model, maybe it’s time to switch to Linux.
- joshstrange 11y ago1 line at the bottom of a blog post does not forgive the rest of it...
- SomeStupidPoint 11y ago> Microsoft told me that while the backdoored algorithm is included with Windows, it is not used by BitLocker, nor is it used by other parts of the Windows operating system by default. According to Microsoft, the default PRNG for Windows is an algorithm known as CTR_DRBG, not Dual_EC_DRBG, and when BitLocker generates a new key it uses the Windows default. This actually sounds a lot like the government mandated a backdoored crypto algorithm in to a suite of crypto algorithms, and then Microsoft was forced to implement the backdoored algorithm in order to get certified for the suite, which is required for government contracts. > I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to do so. The spokesperson told me they could not answer that question. There's a ton of perfectly benign reasons that a spokesman would decline to answer that question, and since we don't have a direct quotation, we don't even know what the response actually was. I don't particularly like Microsoft, but I feel like we should blame them for the things they actually do, not hold them to unreasonable standards.
- AaronFriel 11y agoI'm surprised Microsoft hasn't implemented AES-XTS with REFS in Windows 10. Okay, that was perhaps an acronym too far. REFS is Microsoft's answer to the new generation of copy-on-write filesystems, akin to ZFS and BTRFS. It checksums all data on disk to verify integrity. AES-XTS is a block cipher mode that avoids many of the problems of AES-CBC, although neither is as bad as EBC. But like all block cipher modes used for FDE, they're susceptible to malleability attacks. That's because there's just no room in a sector to store authentication information. Enter: a filesystem that performs checksumming and performs authentication at a higher level. It's a little disappointing to me that Bitlocker was weakened and, from the outside, it appears no significant effort was undertaken to resolve this using tech Microsoft already has. The weak link may be some NTFS features that REFS doesn't implement, as currently Microsoft doesn't support using REFS for your system drive.
- wumbernang 11y agoI use bitlocker on my laptop and my portable backup usb stick. I have no illusion that it's probably back doored but I continue to use it simply as a casual insurance policy against doing something stupid like leaving the storage device on a train. It's most likely beyond the average man to decrypt my data and that's good enough for me. Applying the grey man principle, hiding in plain sight by blending into the crowd is a good approach. If you have something to hide, do it via a side channel, preferably off line and carry on using what everyone else does for everything else.
- MichaelGG 11y agoRemoval of the diffuser is very suspicious, given its importance. Machines were weaker when Vista shipped, so that's an odd claim, about security. And since AES-NI is more widespread I'd bet overall the system is even faster! They should back up such a claim with solid benchmarks (I never had a problem with it.) Plus they could make it optional, and/or disable it on low power machines. MS should have pushed to get the diffuser into whatever "standards" (I'm guessing OPAL/eDrive) they are worried about. And IIRC, the diffuser is quite fast, but nothing stops them from implementing an even faster one.
- pbsd 11y ago> And IIRC, the diffuser is quite fast Kinda. When Elephant was designed AES-NI did not exist, and so AES was expected to work at somewhere between 10-20 cycles per byte. Elephant worked somewhere between 5-10 cpb, so it was not a lot of overhead. Post-AES-NI, however, the majority of CPU time is now spent on the diffuser. Furthermore, SSDs were not popular at the time this was designed. So the relative low speed of software AES + diffuser was not that big a deal. Now, with 500 MB/s and higher drives, cipher speed matters. For reference, 10 cpb translates to ~200 MB/s in your average 2 GHz processor. This is not to say that removing Elephant was a good idea, but the performance argument is not entirely unreasonable. It is of course possible to design a new diffuser that can take better advantage of modern chips; maybe they should do that.
- MichaelGG 11y agoNice numbers, thanks. Is Elephant even available, though? Even if someone has a low end chip but needs a high IO rate and thus must turn off Elephant, why kill off the feature? That's what's so odd. They admit it's critical, then go on to completely delete it, no mention of why (until this one line explanation now). For many users, the perf impact is irrelevant. I rarely do high rate IO (boot and copying movies); even large compiles I doubt are hitting the 100MB/sec level. At 5cbp, even a low end Atom will get 100-200+MB/sec, right? What low end devices are pushing that on any frequent enough basis to hurt the user? And, given their weight, they could have forced these requirements into eDrive, and offload it all to the SSD controller.
- 11y ago
- AdmiralAsshat 11y agoHere's the most worrying line of the article, in my opinion: Asked about instances in which Microsoft built methods to bypass its security and about backdoors generally, a company spokesperson told me that Microsoft doesn’t consider complying with legitimate legal requests backdoors. Which says to me, "There are no backdoors, provided we redefine the word 'backdoor' to be exclude all of the mechanisms we currently employ."
- MichaelGG 11y agoCould also refer to users keeping their key backed up in their Microsoft Account.
- nickpsecurity 11y agoThe article is a horrendous failure by The Intercept, which I usually love to read. The most important part of evaluating trust is character. Microsoft's character on the topic is to use low-quality software processes until forced otherwise, notify NSA etc about bugs so they can hit them, help them do the same with third party software (eg Skype), backdoor their own stuff (eg NSAKEY), and so on. This is one of the least trustworthy companies in existence with a known track record in subverting security and crypto of their customers. So, his research comes down to two major options: the above company's crypto product with assurances of their PR team; a proprietary product with no troubling history & endorsed by a well-known cryptographer. If Win8 and above, he should start talking about BestCrypt rather than dropping a whole extra paragraph on Bitlocker's advantages and how its fine for the average user. It's not fine because (a) the source screws all of its users, (b) alternatives only flourish if you support them (vote with wallet), and (c) a site accepting submissions on corrupt organizations by leakers should never recommend trusting security tech of a corrupt organization whose contributes to the evils they report on. So, this post is just stupid except for the tiny parts where it mentions alternatives. Matter of fact, it reads like an advertisement written with the assistance of Microsoft's lawyers and publicists. I'm not saying it was but any objective investigation should never look like that. Conclusion: Don't trust The Intercept for INFOSEC advice, don't trust Microsoft for security/crypto, use BestCrypt if on modern Windows, use VeraCrypt for Win7 or earlier, and switch to Linux if possible for extra transparency/options.
- tptacek 11y agoNSAKEY is not a Microsoft NSA backdoor. Given where it lived in the security design for Microsoft, it doesn't even make sense as an NSA backdoor.
- nickpsecurity 11y ago"Microsoft said that the key's symbol was "_NSAKEY" because the NSA is the technical review authority for U.S. export controls, and the key ensures compliance with U.S. export laws" (Wikipedia on NSAKEY) We actually don't know what it is past that. So, Microsoft says it was required for export approval & made backup key. NSA controls those export requirements. A declassified CIA document [1] from the period shows export changes were pro-escrow and most big companies were onboard. In short, the NSA, FBI, CIA, and other companies agreed on escrow keys for export of strong cryptography. Microsoft added an escrow (err backup) key called _NSAKEY for export approval. Logically, we should assume it was a COMSEC backdoor for NSA so Microsoft could make money on exports. Assuming anything else is logically questionable given no hard data contradicting this and Microsoft's history of covert cooperation with NSA in much worse ways. Hard data as in statements by Microsoft such as above straight up saying who ordered the change and what it does vs the mere speculation we saw elsewhere. [1] http://www.foia.cia.gov/sites/default/files/DOC_0006231614.pdf http://www.foia.cia.gov/sites/default/files/DOC_0006231614.p...