4 ms·
I think this is worth repeating: "I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to
by jron 11y ago
I think this is worth repeating:
"I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to do so. The spokesperson told me they could not answer that question." - https://firstlook.org/theintercept/2015/06/04/microsoft-disk-encryption/ https://firstlook.org/theintercept/2015/06/04/microsoft-disk...
- nickpsecurity 11y agoIt doesn't mean anything because it's a standard move to reduce legal risk. No comment is almost always the safest answer. This applies to individuals too: https://www.youtube.com/watch?v=6wXkI4t7nuc https://www.youtube.com/watch?v=6wXkI4t7nuc
- LMAlVvQjSGj 11y agoIt's a pathetic stance.
- belorn 11y agoIt is a move to reduce trust in a market where trust is the single most important aspect. Schneier's article is all about whom he trust, why he trust them, and conclusion he makes based on that trust. If you bought a security product and the developer of it describes its strength as "No comment", would you trust it? Personally I am sticking with the abandoned TrueCrypt until a successful fork has been created or luks + dmcrypt has been ported to windows.
- nickpsecurity 11y agoIf you were right, then the most trustworthy companies would have the most market share while offering us good EULA's. Looking at top software names, it's clear trust and success in the market place have almost nothing to do with each other. It's actually opposite with the dirtiest companies on top in most places. Negative media definitely hurts the bottom line but majority of time isn't an issue. They have PR people for that. There have always been companies that share source with customers, use stronger security tech, warranty their code, and so on. They were minority players pre-Snowden with many having left that market because so few cared. (myself included) Post-Snowden, they're still minority players with the market mostly going for whoever promises the most on their web sites & in media. Trust and security have always come 2nd (5th?) to all kinds of other criteria for buyers in the IT market. If you doubt, look at number of Facebook or Gmail users vs number using more private alternatives. People & companies sell themselves out in droves.
- Maarten88 11y agoPersonally I don't believe there's a backdoor in the technology but think they can (and probably will) comply if you have a backup key stored in the cloud, which Windows 8 consumer versions do by default (https://onedrive.live.com/recoverykey https://onedrive.live.com/recoverykey). That would explain the evasive answer. There were earlier stories from a developer building Bitlocker indicating the FBI did want a backdoor at the time but ultimately settled for this. You can avoid sending the backup key to the cloud, but I'd advise to keep a backup of this key somewehere: I have had to use a backup key on several occasions after a bad reboot.