Conversation
>Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects’ laptops: reports

How is that possible? How did they have the keys?
3
0
0

@chjara they are backed up on onecloud by default

0
0
1
>But, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud,

Sure, why not. Whatever.
3
0
0
@chjara Well it's Microsoft, plus like proprietary software with auto-updates means you can push whatever software you want (hence why the term botnet is appropriate for those).
1
0
1
@lanodan Even simpler than that. The keys are just sent to Microsoft.
1
0
0
@chjara Your computer?
Our computer.
(And not in the commie meaning, sadly)
0
0
1
Like, I understand why. If an average person forgets their password and brings their computer to a repair shop or whatever they're not gonna like the answer "your data's gone forever", FDE is mostly in cases of theft and so on. Threat models and all that. Still, doesn't mean I like that.
1
0
0
@chjara@akko.tuxcrafting.xyz but tbf I am the kind of highly advanced computer user who uses the windows 11 business editions iso to install windows 11 without a microsoft account so
0
0
1
@chjara i'm wondering why are they encrypting the disks in the first place. it's a horrible design to encrypt data and not let the owner of the device know that it's encrypted, that's a sure way to have data loss. did microsoft make the average computer user so illiterate that they'd not understand if they were given a choice between fde or not when installing the system?
1
0
1
@arh FDE with online key backups is transparent to the user in all manners (data loss is impossible because recovery keys are always backed up), and it prevents the data from being acquired on theft. Pretty sure that's all it is about.
1
0
0
@chjara last time i checked, interrupting the startup or restarting into bios was supposed to trip a flag that required you to input the bitlocker key, which you could no longer look up in your account since you can't boot anymore without the key, which would reset the flag. so that way you could "lock yourself out" unless you have another device that can look up the synced key online; and if you bring your computer to a repair shop that needs to enter bios they're not going to have it either and the customer would very likely have no clue what bitlocker is if they were never told about it. is it different nowadays?
0
0
1

@chjara I remember hearing this about BitLocker when people were starting to move to Windows 10 a decade ago. Genuinely surprised only now it’s being reported on, since this kind of shit was obviously inevitable.

0
0
1