Microsoft Gave FBI BitLocker Encryption Keys, Exposing Privacy Flaw (www.forbes.com)
from floofloof@lemmy.ca to cybersecurity@infosec.pub on 23 Jan 23:11
https://lemmy.ca/post/59154512

#cybersecurity

threaded - newest

bad_news@lemmy.billiam.net on 24 Jan 04:01 next collapse

It has been known since BitLocker first existed, that Microsoft breaks it for states. This is why TrueCrypt came into being.

Kissaki@programming.dev on 24 Jan 09:37 collapse

It’s possible for users to store those keys on a device they own, but Microsoft also recommends BitLocker users store their keys on its servers for convenience.

Pretty obvious that if you hand over the (recovery) keys that they’d follow court orders.

Of course, the criticism about defaults is warranted. At the same time, even outside of control concerns, it’s fairly obvious why Microsoft would choose user convenience and ability to recover data over loss of data.

It should be a well informed choice that makes the risks clear when setting it up.