[HN Gopher] Microsoft gave FBI set of BitLocker encryption keys ...
       ___________________________________________________________________
        
       Microsoft gave FBI set of BitLocker encryption keys to unlock
       suspects' laptops
        
       Author : bookofjoe
       Score  : 515 points
       Date   : 2026-01-23 17:58 UTC (5 hours ago)
        
 (HTM) web link (techcrunch.com)
 (TXT) w3m dump (techcrunch.com)
        
       | bigyabai wrote:
       | Quid pro quo.
        
         | advisedwang wrote:
         | What quid pro quo? Is there an allegation that the FBI gave
         | Microsoft something in exchange?
         | 
         | As far as I can see this particular case is a straightforward
         | search warrant. A court absolutely has the power to compel
         | Microsoft to hand over the keys.
         | 
         | The bigger question is why Microsoft has the recovery feature
         | at all. But honestly I believe Microsoft cares so little about
         | privacy and security that they would do it just to end the
         | "help customers who lose their key" support tickets, with no
         | shady government deal required. I'd want to see something more
         | than speculation to convince me otherwise.
        
       | londons_explore wrote:
       | > The case involved several people suspected of fraud related to
       | the Pandemic Unemployment Assistance program
       | 
       | If it were preventing a mass murder I might feel differently...
       | 
       | But this is protecting the money supply (and indirectly the
       | governments control).
       | 
       | Not a reason to violate privacy IMO, especially when at the time
       | this was done these people were only _suspected_ of fraud, not
       | convicted.
        
         | SoftTalker wrote:
         | They had a warrant. That's enough. Nobody at Microsoft is going
         | to be willing to go to jail for contempt to protect fraudsters
         | grifting off of the public taxpayer. Would you?
        
         | Aurornis wrote:
         | > Not a reason to violate privacy IMO, especially when at the
         | time this was done these people were only suspected of fraud,
         | not convicted.
         | 
         | Well you can't really wait until the conviction to collect
         | evidence in a criminal trial.
         | 
         | There are several stages that law enforcement must go through
         | to get a warrant like this. The police didn't literally phone
         | up Microsoft and ask for the keys to someone's laptop on a
         | hunch. They had to have already confiscated the laptop, which
         | means they had to have collected enough early evidence to prove
         | suspicion and get a judge to sign off and so on.
        
       | cogman10 wrote:
       | > Microsoft told Forbes that the company sometimes provides
       | BitLocker recovery keys to authorities, having received an
       | average of 20 such requests per year.
       | 
       | At least they are honest about it, but a good reason to switch
       | over to linux. Particularly if you travel.
       | 
       | If microsoft is giving these keys out to the US government, they
       | are almost certainly giving them to all other governments that
       | request them.
        
         | Aurornis wrote:
         | It's not like companies have a choice. If they have a key in
         | their possession and law enforcement gets an order for it, they
         | have to provide it.
        
           | function_seven wrote:
           | That only strengthens the parent point. Switch to an OS where
           | this requirement doesn't come into play if you're worried
           | about any governments having a backdoor into your own
           | machine.
        
             | charcircuit wrote:
             | If you sync your Linux machines key in the cloud, police
             | could subpoena it too. The solution is not to switch to
             | Linux, but to stop storing it in plain text in the cloud.
        
               | NewsaHackO wrote:
               | Do you know what a private key means in this context?
        
               | charcircuit wrote:
               | No, I don't. The bitlocker key is a symmetric key.
        
               | NewsaHackO wrote:
               | Ok, do you at least know what private means?
        
               | charcircuit wrote:
               | Not public.
        
             | Aurornis wrote:
             | > Switch to an OS where this requirement doesn't come into
             | play
             | 
             | I use BitLocker on my Windows box without uploading the
             | keys. I don't even have it connected to a Microsoft
             | account. This isn't a requirement.
        
               | knowitnone3 wrote:
               | except Microsoft probably as a master key
        
           | Zambyte wrote:
           | > It's not like companies have a choice.
           | 
           | > If they have a key in their possession [...]
           | 
           | So they do have a choice.
        
             | mc32 wrote:
             | People/users have an option to keep the key themselves.
             | Most wouldn't bother to manage encryption keys.
        
           | egorfine wrote:
           | And even if they don't have the key. Case in point:
           | https://medium.com/@tahirbalarabe2/the-encryption-dilemma-
           | wh...
        
             | zugi wrote:
             | Thanks for the link, interesting article. The UK is among
             | the worst in this regard.
             | 
             | Regarding the article's Apple example:
             | 
             | > The FBI eventually found a third party to break into the
             | phone, but the tension between privacy and security remains
             | unresolved.
             | 
             | This is actually quite resolved.
             | 
             | - Tech companies in the US are free to write secure
             | encryption technologies without backdoors.
             | 
             | - Government is free to try to break it when they have
             | valid legal authority.
             | 
             | - Tech companies are obligated to turn over information in
             | their possession when given a legal warrant signed by a
             | judge based on probable cause that a crime has occurred.
             | 
             | - Tech companies are _not_ required to help hack into
             | systems on the government 's behalf.
             | 
             | As far as I'm concerned, in the US things are perfectly
             | resolved, and quite well I think. It's the government and
             | fear-mongers who constantly try to "unresolve" things.
        
         | TrainedMonkey wrote:
         | All other governments is a stretch here, but likelihood of at
         | least one another government getting same privileges is
         | extremely high.
        
         | slashdave wrote:
         | Why take the drastic step of switching to linux (a difficult
         | endeavor) when you can simply turn off key uploading.
        
           | varun_ch wrote:
           | Why continue to use an operating system that's adversarial
           | towards you?
        
             | bogwog wrote:
             | I will never understand this from software engineers/tech
             | people in general. That demographic knows how technology
             | works, and are equipped to see exactly where and how
             | Microsoft is taking advantage of them, and how the
             | relationship is all take and zero give from their end.
             | These people are also in the strongest position to switch
             | to Linux.
             | 
             | The only explanation that makes sense to me is that there's
             | an element of irrationality to it. Apple has a well known
             | cult, but Microsoft might have one that's more subtle? Or
             | maybe it's a reverse thing where they hate Linux for some
             | equally irrational reasons? That one is harder to
             | understand because Linux is just a kernel, not a
             | corporation with a specific identity or spokesperson
             | (except maybe Torvalds, but afaik he's well-regarded by
             | everyone)
        
           | wolvoleo wrote:
           | Because that gives you a lot more control over your computer
           | than just solving this particular issue. If you care about
           | privacy it's definitely a good idea.
        
           | egorfine wrote:
           | Because Microsoft absolutely _will_ make it mandatory
           | somewhere in the not so distant future.
        
           | knowitnone3 wrote:
           | oh man, it's so difficult even teenagers can do it within an
           | hour and all they have to do is click on a few buttons.
        
       | Aurornis wrote:
       | FYI BitLocker is on by default in Windows 11. The defaults will
       | also upload the BitLocker key to a Microsoft Account if
       | available.
       | 
       | This is why the FBI can compel Microsoft to provide the keys.
       | It's possible, perhaps even likely, that the suspect didn't even
       | know they had an encrypted laptop. Journalists love the
       | "Microsoft _gave_ " framing because it makes Microsoft sound like
       | they're handing these out because they like the cops, but that's
       | not how it works. If your company has data that the police want
       | and they can get a warrant, you have no choice but to give it to
       | them.
       | 
       | This makes the privacy purists angry, but in my opinion it's the
       | reasonable default for the average computer user. It protects
       | their data in the event that someone steals the laptop, but still
       | allows them to recover their own data later from the hard drive.
       | 
       | Any power users who prefer their own key management should follow
       | the steps to enable Bitlocker without uploading keys to a
       | connected Microsoft account.
        
         | whalesalad wrote:
         | Any power users should avoid Windows entirely.
        
           | bigyabai wrote:
           | If by "power user" you mean "enemy of the state", there's a
           | lot of software you'd be better-off avoiding.
        
             | phanimahesh wrote:
             | That is a strange viewpoint. Are we calling everyone who
             | wants some control over their computers enemies of the
             | state?
        
               | bigyabai wrote:
               | It's holistic philosophy. You're not going to save
               | yourself from FBI surveillance by avoiding Windows, I
               | guarantee that to you.
        
               | thewebguyd wrote:
               | You're not going to avoid any state surveillance if the
               | state is really interested in you specifically.
               | 
               | But you can still help prevent abuses of mass
               | surveillance without probable cause by making such
               | surveillance as expensive and difficult as possible for
               | the state
        
               | WarOnPrivacy wrote:
               | > Are we calling everyone who wants some control over
               | their computers enemies of the state?
               | 
               | As of today at 00:00 UTC, no.                   But
               | there's an increasingly possible future         where
               | authoritarian governments will brand users         who
               | practice 'non-prescribed use' as enemies of the state.
               | And when we have a government who's leader         openly
               | gifts deep, direct access to federal power         to
               | unethical tech leaders who've funded elections
               | (ex:Thiel),         that branding would be a powerful
               | perk to have access to         (even if indirectly).
        
             | wolvoleo wrote:
             | "enemy of the state" depends a lot on the current state of
             | the state.
             | 
             | Eg in England you're already an enemy of the state when you
             | protest against Israel's actions in Gaza. In America if you
             | don't like civilians being executed by ICE.
             | 
             | This is really a bad time to throw "enemy of the state"
             | around as if this only applies to the worst people.
             | 
             | Current developments are the ideal time to show that these
             | powers can be abused.
        
               | blipvert wrote:
               | Very much hyperbolic about the UK. You're fine protesting
               | against Israel, but Palestine Action is a proscribed
               | group (not that I agree with that!) and that will land
               | you in trouble.
        
             | pawelduda wrote:
             | Maybe he's just trying to avoid Candy Crush Saga
        
               | amitav1 wrote:
               | I can't think of anybody apart from Osama bin Laden who
               | wouldn't want to play Candy Crush. \s
        
             | anonym29 wrote:
             | https://news.ycombinator.com/item?id=46700219
             | 
             | Criticizing the current administration? That sounds like
             | something an enemy of the state would do!
             | 
             | Prepare yourself for the 3am FBI raid, evildoer! You're an
             | enemy of the state, after all, that means you _deserve_ it!
             | /s
        
           | drnick1 wrote:
           | This. Real "power users" (as opposed to people who aren't
           | completely computer-illiterate) use the likes of Arch Linux
           | and Gentoo and self-host whatever "cloud" services they need,
           | they aren't running Windows and paying for Copilot 365
           | subscriptions.
        
         | mattmaroon wrote:
         | It's definitely better than no encryption at all, which would
         | be what most people would have otherwise.
        
         | cesarb wrote:
         | > Any power users who prefer their own key management should
         | follow the steps to enable Bitlocker without uploading keys to
         | a connected Microsoft account.
         | 
         | Once the feature exists, it's much easier to use it by
         | accident. A finger slip, a bug in a Windows update, or even a
         | cosmic ray flipping the "do not upload" bit in memory, could
         | all lead to the key being accidentally uploaded. And it's a
         | silent failure: the security properties of the system have
         | changed without any visible indication that it happened.
        
           | tokyobreakfast wrote:
           | >even a cosmic ray flipping the "do not upload" bit in memory
           | 
           | Stats on this very likely scenario?
        
             | halfmatthalfcat wrote:
             | It's "HN-likely" which translates to "almost never" in
             | reality.
        
               | patja wrote:
               | Especially since HN readers are more likely to be using
               | ECC memory
        
               | smegger001 wrote:
               | if cosmic ray bit flips were so rare then ecc ram
               | wouldn't be a thing.
        
               | Sayrus wrote:
               | ECC protects against more events than cosmic rays. Those
               | events are much more likely, for instance
               | magnetic/electric interferences or chip issues.
        
               | wang_li wrote:
               | In the 2010 era of RAM density, random bit flips were
               | really uncommon. I worked with over a thousand systems
               | which would report ECC errors when they happen and the
               | only memorable events at all were actual DIMM failures.
               | 
               | Also, around 1999-2000, Sun blamed cosmic rays for bit
               | flips for random crashes with their UltraSPARC II CPU
               | modules.
        
               | mapontosevenths wrote:
               | > actual DIMM failures.
               | 
               | Yep, hardware failures, electrical glitches, EM
               | interference... All things that actually happen to actual
               | people every single day in truly enormous numbers.
               | 
               | It ain't cosmic rays, but the consequences are still
               | flipped bits.
        
               | direwolf20 wrote:
               | Those random unexplainable events are also referred to
               | casually as "cosmic rays"
        
               | Supermancho wrote:
               | Happens all the time, in reality (even on the darkside).
               | When the atmosphere fails (again, happening all the
               | time), error correction usually handles the errant bits.
        
             | strbean wrote:
             | > IBM estimated in 1996 that one error per month per 256
             | MiB of RAM was expected for a desktop computer.
             | 
             | From the wikipedia article on "Soft error", if anyone wants
             | to extrapolate.
        
               | d1sxeyes wrote:
               | That makes it vanishingly unlikely. On a 16GB RAM
               | computer with that rate, you can expect 64 random bit
               | flips per month.
               | 
               | So roughly you could expect this happen roughly once
               | every two hundred million years.
               | 
               | Assuming there are about 2 billion Windows computers in
               | use, that's about 10 computers a year that experience
               | this bit flip.
        
               | eszed wrote:
               | > 10 computers a year experience this bit flip
               | 
               | That's wildly more than I would have naively expected to
               | experience a specific bit-flip. Wow!
        
               | mapontosevenths wrote:
               | Scale makes the uncommon common. Remember kids, if she's
               | one in a million that means there are 11 of her in Ohio
               | alone.
        
               | d1sxeyes wrote:
               | ~800 bit flips per year per computer. 2 billion computers
               | with 800 bit flips each is 1,600,000,000,000 (one point
               | six trillion) bit flips.
               | 
               | Big numbers are crazy.
        
               | justsomehnguy wrote:
               | I saw a computer with 'system33', 'system34' folders
               | personally. Also you would never actually know it
               | happened because... it's not ECC. And with ECC memory we
               | replace a RAM stick every two-three months explicitly
               | because ECC error _count_ is too high.
        
             | homebrewer wrote:
             | Given enough computers, anything will happen. Apparently
             | enough bit flips happen in domains (or their DNS
             | resolution) that registering domains one bit away from the
             | most popular ones (e.g. something like gnogle.com for
             | google.com) might be worth it for bad actors. There was a
             | story a few years ago, but I can't find it right now;
             | perhaps someone will link it.
        
               | pixl97 wrote:
               | https://www.youtube.com/watch?v=aT7mnSstKGs
               | 
               | Was in DEFCON19.
        
               | homebrewer wrote:
               | Great, thanks. Here's a discussion on this site:
               | 
               | https://news.ycombinator.com/item?id=4800489
        
               | lanyard-textile wrote:
               | A very old game speedrun -- of the era that speedruns
               | weren't really a "thing" like they are today --
               | apparently greatly benefited from a hardware bit flip,
               | and it was only recently discovered.
               | 
               | Can't find an explanatory video though :(
        
               | direwolf20 wrote:
               | The Tick Tock Clock upwarp in Super Mario 64. All
               | evidence that exists of it happening is a video
               | recording. The most similar recording was generated by
               | flipping a single bit in Mario's Y position, compared to
               | other possibilities that were tested, such as warping
               | Mario up to the closest ceiling directly above him.
        
               | tavavex wrote:
               | I'm pretty sure that while no one knows the cause
               | definitively, many people agreed that the far more likely
               | explanation for the bit change was a hardware fault
               | (memory error, bad cartridge connection or something
               | similar) or other, more powerful sources of interference.
               | The player that recorded the upwarp had stated that they
               | often needed to tilt the cartridge to get the game to
               | run, showing that the connection had already degraded.
               | The odds of it being caused by a cosmic ray single-event
               | upset seem to be vanishingly low, especially since
               | similar (but not identical) errors have already been
               | recorded on the N64.
        
             | drysine wrote:
             | At google "more than 8% of DIMM memory modules were
             | affected by errors per year" [0]
             | 
             | More on the topic: Single-event upset[1]
             | 
             | [0] https://en.wikipedia.org/wiki/ECC_memory
             | 
             | [1] https://en.wikipedia.org/wiki/Single-event_upset
        
               | Aloisius wrote:
               | _> At google  "more than 8% of DIMM memory modules were
               | affected by errors per year"_
               | 
               | That's all errors including permanent hardware failure,
               | not just transient bit flips or from cosmic rays.
        
           | gruez wrote:
           | >A finger slip, a bug in a Windows update, or even a cosmic
           | ray flipping the "do not upload" bit in memory, could all
           | lead to the key being accidentally uploaded.
           | 
           | This is absurd, because it's basically a generic argument
           | about any sort of feature that vaguely reduces privacy. Sorry
           | guys, we can't have automated backups in windows (even opt
           | in!), because if the feature exists, a random bitflip can
           | cause everything to be uploaded to microsoft against the
           | user's will.
        
             | salawat wrote:
             | What part of "We can't have nice things" do you not
             | understand?
        
               | gruez wrote:
               | The part where you're asking me about the phrase when
               | it's not been used anywhere in this thread prior to your
               | comment.
        
             | redox99 wrote:
             | Uploading your encryption keys is not just "any sort of
             | feature".
        
               | gruez wrote:
               | You're right, it's less intrusive than uploading your
               | files directly, like a backup does.
        
               | lazide wrote:
               | I'm still pissed about the third+ time one drive
               | 'helpfully' backed up all my files after I disabled it.
               | 
               | So that may not be a great example of you're trying to
               | make people like Microsoft.
        
               | JoshTriplett wrote:
               | On the contrary: a backup can be fully encrypted by a key
               | under the user's control that isn't available to the
               | storage provider.
        
           | Aurornis wrote:
           | If users are so paranoid that they worry about a cosmic ray
           | bit flipping their computer into betraying them, they're
           | probably not using a Microsoft account at all with their
           | Windows PC.
        
             | SoftTalker wrote:
             | If your security requirements are such that you need to
             | worry about legally-issued search warrants, you should not
             | connect your computer to the internet. Especially if it's
             | running Windows.
        
               | direwolf20 wrote:
               | In the modern political environment, everyone should be
               | worried about that.
        
               | fc417fc802 wrote:
               | In all political environments everyone should be worried
               | about that. The social temperature can change rapidly and
               | you generally can't force a third party to destroy copies
               | of your things in a reliable manner.
        
               | oskarw85 wrote:
               | Because all cops are honest, all warrants are lawful and
               | nothing worrying happens in the land of freedom right
               | now.
        
               | Terr_ wrote:
               | And what's more, that perfect situation could _never_
               | change in the future.
               | 
               | Me-30-years-ago would have called today's government
               | crimes and corruption an implausible fever dream.
        
               | qmr wrote:
               | Appeal to the law fallacy.
        
               | zhengyi13 wrote:
               | Right, this is just a variation on "If you have nothing
               | to hide..."
               | 
               | ETA: You're not wrong; folk who have specific, legitimate
               | opsec concerns shouldn't be using certain tools. I just
               | initially read your post a certain way. Apologies if it
               | feels like I put words in your mouth.
        
             | spixy wrote:
             | and use ECC memory
        
           | jollyllama wrote:
           | There's a lot of sibling comments to mine here that are
           | reading this literally, but instead, I would suggest the
           | following reading: "I never selected that option!" "Huh, must
           | have been a cosmic ray that uploaded your keys ;) Modern OS
           | updates _never_ obliterate user-chosen configurations "
        
             | hparadiz wrote:
             | They just entirely ignore them instead.
        
           | bobbob1921 wrote:
           | This is correct, I also discovered while preparing several
           | ThinkPads for a customer based on a Windows 11 image i made,
           | that even if you have bitlocker disabled you may also need to
           | check that hardware disk encryption is disabled as well (was
           | enabled by default in my case). Although this is different
           | from bitlocker in that the encryption key is stored in the
           | TPM, it is something to be aware of as it may be unexpected.
        
           | egorfine wrote:
           | Oh, no accidents needed. Microsoft will soon forcibly extract
           | and upload keys to their servers.
           | 
           | Before you downvote, please entertain this one question: have
           | you been able to predict that mandatory identification of
           | online users under the guise of protecting children would
           | literally be implemented in leading western countries in such
           | a quick fashion? If you were, then upvote my comment instead
           | because you know that will happen. If you couldn't even
           | imagine this say in 2023 - then upvote my comment instead
           | because neither you can imagine mandatory key extraction.
        
             | zdragnar wrote:
             | I can't believe it took this long.
             | 
             | We have mandatory identification for all kinds of things
             | that are illegal to purchase or engage in under a certain
             | age. Nobody wants to prosecute 12 year old kids for lying
             | when the clicked the "I am at least 13 years old" checkbox
             | when registering an account. The only alternative is to do
             | what we do with R-rated movies, alcohol, tobacco, firearms,
             | risky physical activities (i.e. bungee jumping liability
             | waiver) etc... we put the onus of verifying identification
             | on the suppliers.
             | 
             | I've always imagined this was inevitable.
        
               | thewebguyd wrote:
               | The problem is the implementation is hasty.
               | 
               | When I go buy a beer at the gas station, all I do is show
               | my ID to the cashier. They look at it to verify DOB and
               | then that's it. No information is stored permanently in
               | some database that's going to get hacked and leaked.
               | 
               | We can't trust every private company that now has to
               | verify age to not store that information with whatever
               | questionable security.
               | 
               | If we aren't going to do a national registry that
               | services can query to get back only a "yes or no" on
               | whether a user is of age or not, then we need regulation
               | to prevent the storage of ID information.
               | 
               | We should still be able to verify age while remaining
               | psuedo-anonymous.
        
               | xp84 wrote:
               | We should easily be able to, but the problem of tech
               | illiteracy is probably our main barrier. To build such a
               | system you'd need to issue those credentials to the end
               | users. Those users in turn would eagerly believe
               | conspiracy theories that the digital ID system was
               | actually stealing their data or making it available to
               | MORE parties instead of fewer (compared to using those ID
               | verification services we have today).
        
               | criddell wrote:
               | > When I go buy a beer at the gas station, all I do is
               | show my ID to the cashier. They look at it to verify DOB
               | and then that's it. No information is stored permanently
               | in some database that's going to get hacked and leaked.
               | 
               | Beer, sure. But if you buy certain decongestants, they do
               | log your ID. At least that's the case in Texas.
        
               | dragonwriter wrote:
               | > But if you buy certain decongestants, they do log your
               | ID.
               | 
               | Yeah, but many people don't actually think War on Drugs
               | policies are a model for civil liberties that should be
               | extended beyond that domain (or, in many cases, even
               | tolerated _in_ that domain.) That policy has been
               | effective, I guess, in promoting the sales of alternative
               | "decongestants" (that don 't actually work), though it
               | did little to curb use and harms from the drugs it was
               | supposed to control by attacking supply.
        
               | trashface wrote:
               | In PA they scan your ID if you buy beer. There could be a
               | full digital record of all my beer purchases for past 15+
               | years, although I'm not aware of any aggregation of this
               | data that is happening. Not that I expect anyone doing it
               | would talk about it.
        
               | dragonwriter wrote:
               | > If we aren't going to do a national registry that
               | services can query to get back only a "yes or no" on
               | whether a user is of age or not
               | 
               | And note that if we are, the records of the request to
               | that database are an even bigger privacy timebomb than
               | those of any given provider, just waiting for malicious
               | actors with access to government records.
        
               | tzs wrote:
               | > If we aren't going to do a national registry that
               | services can query to get back only a "yes or no" on
               | whether a user is of age or not, then we need regulation
               | to prevent the storage of ID information.
               | 
               | Querying a national registry is not good because the
               | timing of the queries could be matched up with the timing
               | of site logins to possibly figure out the identities of
               | anonymous site users.
               | 
               | A way to address this, at the cost of requiring the user
               | to have secure hardware such as a smart phone or a smart
               | card or a hardware security token or similar is for your
               | government to issue you signed identity documents that
               | you store and that are bound cryptographically to your
               | secure hardware.
               | 
               | A zero knowledge protocol can later be used between your
               | secure hardware and the site you are trying to use that
               | proves to the site you have ID that says you are old
               | enough and it is bound to your hardware without revealing
               | anything else from your ID to the site.
               | 
               | This is what the EU had been developing for a few years.
               | It is currently undergoing a series of large scale field
               | trials, with release to the public later this year, with
               | smart phones as the initial secure hardware. Member
               | starts will be required to support it, and any mandatory
               | age verification laws they pass will require sites to
               | support it (they can also support other methods).
               | 
               | All the specs are open and the reference implementations
               | are also open source, so other jurisdictions could adopt
               | this.
               | 
               | Google has released an open source library for a similar
               | system. I don't know if it is compatible with the EU
               | system or not.
               | 
               | I think Apple's new Digital ID feature in Wallet is also
               | similar.
               | 
               | We really need to get advocacy groups that are lobbying
               | on age verification bills to try to make it so when the
               | bills are passed (and they will be) they at least allow
               | sites to support some method like those described above,
               | and ideally require sites to do so.
        
               | teepo wrote:
               | Depending on the gas station... I've been to at least a
               | dozen in Texas where the clerk scanned the back of my DL
               | for proof of age. I'm assuming that something is getting
               | stored somewhere..
        
               | zdragnar wrote:
               | I definitely don't disagree that the implementation is
               | problematic, I'm just surprised it took this long for it
               | to happen.
        
               | freedomben wrote:
               | > _When I go buy a beer at the gas station, all I do is
               | show my ID to the cashier. They look at it to verify DOB
               | and then that 's it. No information is stored permanently
               | in some database that's going to get hacked and leaked._
               | 
               | That's how it _should_ be, but it 's not how it _is_.
               | Many places now scan your ID into their computer (the
               | computer which, btw, tracks everything you buy). It may
               | not go to a government database (yet) but it 's most
               | certainly being stored.
        
               | egorfine wrote:
               | > We should still be able to verify age while remaining
               | psuedo-anonymous.
               | 
               | That would completely defeat the purpose. The goal is to
               | identify online users, not protect children.
        
               | tavavex wrote:
               | I don't think that's quite right. The age-gating of the
               | internet is part of a brand new push, it's not just
               | patching up a hole in an existing framework. At least in
               | my Western country, all age-verified activities were
               | things that could've put someone in direct, obvious
               | danger - drugs, guns, licensing for something that could
               | be dangerous, and so on. In the past, the 'control' of
               | things that were just information was illusory. Movie
               | theaters have policies not to let kids see high-rated
               | movies, but they're not strictly legally required to do
               | so. Video game stores may be bound by agreements or
               | policy not to sell certain games to children, but these
               | barriers were self-imposed, not driven by law.
               | Pornography has really been the only exception I can
               | think of. So, demanding age verification to be able to
               | access large swaths of the internet (in some cases
               | including things as broad as social media, and similar)
               | is a huge expansion on what was in the past, instead of
               | just them closing up some loopholes.
        
               | PunchyHamster wrote:
               | The problem is that there is nothing done to protect
               | privacy.
               | 
               | There is already plenty of entities that not only have
               | reliable way of proving it's you that have access to
               | account, but also enough info to return user's age
               | without disclosing anything else, like banks or govt
               | sites, they could (or better, be forced to) provide
               | interface to that data.
               | 
               | Basically "pick your identity provider" -> "auth on their
               | site" -> "step showing that only age will be shared" ->
               | response with user's age and the query's unique ID that's
               | not related to the user account id
        
               | zdragnar wrote:
               | I don't disagree that the implementation is all kinds of
               | wrong. I'm just surprised it took them this long to
               | compel it.
        
         | wolvoleo wrote:
         | It would make me a lot less angry if Microsoft didn't go out of
         | their way to force people to use a Microsoft account of course.
        
         | postalcoder wrote:
         | I'm not sure how to do this on Windows, but to disable
         | FileVault cloud key backup on Mac, go to `Settings > Users &
         | Groups > click on the (i) tooltip next to your account` and
         | uncheck "Allow user to reset password using Apple Account".
         | 
         | This is a part of Settings that you will never see at a passing
         | glance, so it's easy to forget that you may have it on.
         | 
         | I'd also like to gently push back against the cynicism
         | expressed about having a feature like this. There are more
         | people who benefit from a feature like this than not. They're
         | more likely thinking "I forgot my password and I want to get
         | the pictures of my family back" than fully internalizing the
         | principles and practices of self custody - one of which is that
         | if you lose your keys, you lose everything.
        
           | Melatonic wrote:
           | Or use a local account to login ?
        
             | dcrazy wrote:
             | I'm not sure if you misunderstand how macOS accounts work
             | or how FileVault works.
             | 
             | There are two ways to log into macOS: a local user account
             | or an LDAP (e.g. OpenDirectory, Active Directory) account.
             | Either of these types of accounts may be associated with an
             | iCloud account. macOS doesn't work like Windows where your
             | Microsoft account _is_ your login credential for the local
             | machine.
             | 
             | FileVault key escrow is something you can enable when
             | enabling FileVault, usually during initial machine setup.
             | You must be logged into iCloud (which happens in a previous
             | step of the Setup Assistant) and have iCloud Keychain
             | enabled. The key that wraps the FileVault volume encryption
             | key will be stored in your iCloud Keychain, which is end-
             | to-end encrypted with a key that Apple does not have access
             | to.
             | 
             | If you are locked out of your FileVault-encrypted laptop
             | (e.g. your local user account has been deleted or its
             | password has been changed, and therefore you cannot provide
             | the key to decrypt the volume encryption key), you can
             | instead provide your iCloud credentials, which will use the
             | wrapping key stored in escrow to decrypt the volume
             | encryption key. This will get you access to the drive so
             | you can copy data off or restore your local account
             | credentials.
        
               | duskwuff wrote:
               | > There are two ways to log into macOS: a local user
               | account or an LDAP (e.g. OpenDirectory, Active Directory)
               | account.
               | 
               | And just in case it wasn't clear enough, I'd add: a local
               | user account is standard. The only way you'd end up with
               | an LDAP account is if you're in an organization that
               | deliberately set your computer up for networked login;
               | it's not a typical configuration, nor is it a component
               | used by iCloud.
        
         | vik0 wrote:
         | You can always count on someone coming along and defending the
         | multi-trillion dollar corporation that just so happens to take
         | a screenshot of your screen every few seconds (among many, many
         | - too many other things)
        
           | patja wrote:
           | Are you referring to Microsoft Recall? My understanding is
           | that is opt-in and only stored locally.
        
             | parliament32 wrote:
             | Stored locally.. until it's uploaded by OneDrive or Windows
             | Backup?
        
           | Aurornis wrote:
           | Sorry to interrupt the daily rage session with some neutral
           | facts about how Windows and the law work.
           | 
           | > that just so happens to take a screenshot of your screen
           | every few seconds
           | 
           | Recall is off by default. You have to go turn it on if you
           | want it.
        
             | dns_snek wrote:
             | It only became off by default after those "daily rage
             | sessions" created sufficient public pressure to turn them
             | off.
             | 
             | Microsoft also happens to own LinkedIn which conveniently
             | "forgets" all of my privacy settings every time I decide to
             | review them (about once a year) and discover that they had
             | been toggled back to the privacy-invasive value without my
             | knowledge. This has happened several times over the years.
        
           | LoganDark wrote:
           | Microsoft doesn't take the screenshot; their operating system
           | does if Recall is enabled, and although the screenshots
           | themselves are stored in an insecure format and location,
           | Microsoft doesn't get them by default.
        
           | gruez wrote:
           | Yes, because object level facts matter, and it's
           | intellectually dishonest to ignore the facts and go straight
           | into analyzing which side is the most righteous, like:
           | 
           | >Microsoft is an evil corporation, so we must take all bad
           | stories about them at face value. You're not some corpo
           | bootlicker, now, are you? Now, in unrelated news, I heard
           | Pfizer, another evil corporation with a dodgy history[1] is
           | insisting their vaccines are safe...
           | 
           | [1] https://en.wikipedia.org/wiki/Pfizer#Legal_issues
        
           | yoyohello13 wrote:
           | I big demographic of HN users are people who want to be the
           | multi-trillion dollar corporation so it's not too surprising.
           | In this case though I think they are right. And I'm a big
           | time Microsoft hater.
        
             | dijit wrote:
             | The defenders of Microsoft are right?
             | 
             | How?
             | 
             | There _is no point_ locking your laptop with a passphrase
             | if that passphrase is thrown around.
             | 
             | Sure, maybe some thief can't get access, but they
             | _probably_ can if they can convince Microsoft to hand over
             | the key.
             | 
             | Microsoft should not have the key, thats part of the whole
             | point of FDE; nobody can access your drive except you.
             | 
             | The cost of this is that if you lose your key: you also
             | lose the data.
             | 
             | We have trained users about this for a decade, there have
             | been countless dialogues explaining this, even if we were
             | dumber than we were (we're not, despite what we're being
             | told: users just have fatigue from over stimulation due to
             | shitty UX everywhere); then it's still a bad default.
        
             | nitwit005 wrote:
             | This happens everywhere. There is a reason there are memes
             | about people defending multi-billion dollar corporations.
        
           | zer00eyz wrote:
           | https://en.wikipedia.org/wiki/Room_641A ... Then, years later
           | every one acts like Snowden had some big reveal.
           | 
           | There is the old password for candy bar study:
           | https://blog.tmb.co.uk/passwords-for-chocolate
           | 
           | Do users care? I would posit that the bulk of them do not,
           | because they just dont see how it applies to them, till they
           | run into some type of problem.
        
           | mcmcmc wrote:
           | AI enshittification is irrelevant here. Why is someone
           | pointing out that sensible secure defaults are a good thing
           | suddenly defending the entire company?
        
             | ChromaticPanic wrote:
             | Uploading your encryption keys up to someone else's machine
             | is not a sensible default
        
               | crazygringo wrote:
               | It generally is, because in the vast majority of cases
               | users will not keep a local copy and will lose their
               | data.
               | 
               | Most (though not all) users are looking for encryption to
               | protect their data from a thief who steals their laptop
               | and who could extract their passwords, banking info, etc.
               | Not from the government using a warrant in a criminal
               | investigation.
               | 
               | If you're one of the subset of people worried about the
               | government, you're generally not using default options.
        
               | ChromaticPanic wrote:
               | For laptops sure, but then those are not reasons for it
               | to be default on desktops too. Are most Windows users on
               | laptops? I highly doubt that. So it is not a sensible
               | default.
        
               | Xss3 wrote:
               | Most pc users are using laptops, yes. Above 60%.
               | 
               | Even offices usually give people laptops over desktops so
               | that they can bring it to meetings.
        
               | dijit wrote:
               | > It generally is, because in the vast majority of cases
               | users will not keep a local copy and will lose their
               | data.
               | 
               | What's the equivalent of thinking users are this stupid?
               | 
               | I seem to recall that the banks repeatedly tell me _not_
               | to share my PIN number with anyone, including (and
               | especially) bank staff.
               | 
               | I'm told not to share _images_ of my house keys on the
               | internet, let alone handing them to the government or
               | whathaveyou.
               | 
               | Yet for some unknown reason _everyone_ should send their
               | disk encryption keys to one of the largest companies in
               | the world (largely outside of legal jurisdiction),
               | because _they_ _themselves_ can 't be trusted.
               | 
               | Bear in mind that with a(ny) TPM chip, you don't need to
               | _remember_ anything.
               | 
               | Come off it mate. You're having a laugh aren't you?
        
         | paulpauper wrote:
         | VeraCrypt exists for this reason or other open source programs.
         | Why would you ever trust encryption to closed source?
        
         | Hizonner wrote:
         | The "reasonable default" is to force the user to actually make
         | the choice, probably after forcing the user to prove they
         | understand the implications.
        
           | x0x0 wrote:
           | I don't think there's a good answer here.
           | 
           | Users absolutely 100% will lose their password and recovery
           | key and not understand that even if the bytes are on a desk
           | physically next to you, they are gone. Gone baby gone.
           | 
           | In university, I helped a friend set up encryption on a drive
           | w/ his work after a pen drive with work on it was stolen. He
           | insisted he would not lose the password. We went through the
           | discussion of "this is real encryption. If you lose the
           | password, you may as well have wiped the files. It is not in
           | any way recoverable. I need you to understand this."
           | 
           | 6 weeks is all it took him.
        
             | thewebguyd wrote:
             | Apple gives users the choice during set up assistant, no
             | reason Microsoft can't.
        
             | knollimar wrote:
             | I bet he learned a valuable lesson
        
         | Melatonic wrote:
         | Exactly. And any halfway decent corporate IT setup would be
         | managing the keys themselves as well (although I would imagine
         | many third party tools could also be compelled to do this with
         | a proper warrant)
         | 
         | Bitlocker on by default (even if Microsoft does have the keys
         | and complies with warrants) is still a hell if a lot better
         | than the old default of no encryption. At least some rando
         | can't steal your laptop, pop out the HDD, and take whatever
         | data they want.
        
         | riversflow wrote:
         | > you have no choice but to give it to them
         | 
         | There is always a choice.
        
         | drnick1 wrote:
         | > Any power users who prefer their own key management should
         | follow the steps to enable Bitlocker without uploading keys to
         | a connected Microsoft account.
         | 
         | The real issue is that you can't be sure that the keys aren't
         | uploaded even if you opt out.
         | 
         | At this point, the only thing that can restore trust in
         | Microsoft is open sourcing Windows.
        
           | Aurornis wrote:
           | > The real issue is that you can't be sure that the keys
           | aren't uploaded even if you opt out.
           | 
           | The fully security conscious option is to not link a
           | Microsoft account at all.
           | 
           | I just did a Windows 11 install on a workstation (Windows
           | mandatory for some software) and it was really easy to set up
           | without a Microsoft account.
        
             | vanviegen wrote:
             | And how do you know the keys are never uploaded if you
             | don't have an account?
        
               | jjnoakes wrote:
               | The same way you know that your browser session secrets,
               | bank account information, crypto private keys, and other
               | sensitive information is never uploaded. That is to say,
               | you don't, really - you have to partially trust Microsoft
               | and partially rely on folks that do black-box testing,
               | network analysis, decompilation, and other investigative
               | techniques on closed-source software.
        
               | criddell wrote:
               | Air gap the machine.
        
             | MereInterest wrote:
             | Last time I needed to install Windows 11, avoiding making a
             | Microsoft account required (1) opening a command line to
             | run `oobe/bypassnro`, and (2) skipping past the wifi config
             | screen. While these are quick steps, neither of those are
             | at all "easy", since they require a user to first know that
             | it is an option in the first place.
             | 
             | And newer builds of Windows 11 are removing these methods,
             | to force use of a Microsoft account. [0]
             | 
             | [0] https://www.windowslatest.com/2025/10/07/microsoft-
             | confirms-...
        
               | zyx321 wrote:
               | By selecting Domain Join, which is available on
               | Professional edition and above.
        
             | epistasis wrote:
             | > it was really easy to set up without a Microsoft account.
             | 
             | By "really easy" do you mean you had a checkbox? Or "really
             | easy" in that there's a secret sequence of key presses at
             | one point during setup? Or was it the domain join method?
             | 
             | Googling around, I'm not sure any of the methods could be
             | described as "really easy" since it takes a lot of
             | knowledge to do it.
        
               | catchmost wrote:
               | I recently had to install Windows for the first time in
               | ages because reasons, and it really wasn't very hard. The
               | setup really just presents two options at a time: the
               | cloudy option, and the other option. If in doubt, the
               | flashy one is the cloudy one. I kept selecting the non
               | cloudy option and got to the desktop without signing up
               | for anything. Sure it took more clicking than last time I
               | went through this, but really wasn't nearly as bad as
               | people say and didn't take any windows know-how or
               | googling. Might be very different between editions and
               | regions though...
               | 
               | Edit: ofc we all agree local accounts needs to be a
               | supported option, but perhaps we should be more careful
               | about yelling from the rooftops that it's practically
               | impossible. I've been told for years now that it's really
               | hard or impossible, and it really was not that hard
               | (yet...)
        
               | epistasis wrote:
               | You're a bit vague here, but I'm 99% sure such options
               | were not available when I installed Win 11 a few months
               | ago.
               | 
               | Chastising people about "yelling" is not really an
               | appropriate thing to say here.
        
         | g947o wrote:
         | > It protects their data in the event that someone steals the
         | laptop, but still allows them to recover their own data later
         | from the hard drive.
         | 
         | False. If you only put the keys on the Microsoft account, and
         | Microsoft closes your account for whatever reason, you are
         | done.
        
         | throwway120385 wrote:
         | Correct me if I'm wrong, but isn't forcing you to divulge your
         | encryption password compelled speech? So the police can crack
         | my phone but they can't force me to tell them my PIN.
        
           | fn-mote wrote:
           | In the US.
           | 
           | But this is irrelevant to the argument made above, right?
        
           | dcrazy wrote:
           | Warrants are a mechanism by which speech is legally
           | compelled.
           | 
           | The 5th Amendment gives you the right to refuse speech that
           | might implicate you in a crime. It doesn't protect Microsoft
           | from being compelled to provide information that may
           | implicate one of its customers in a crime.
        
             | salawat wrote:
             | Indeed. Third Party Doctrine has undermined 4th/5th
             | Amendment protections due to the hair brained power grab
             | that was "if you share info with a third party as art of
             | the only way of doing business, you waive 4th Amendment
             | protections. I ironically, Boomers basically knee-capped
             | Constitutional protections for the very data most
             | critically in need of protection in a network state.
             | 
             | Only fix is apparently waiting until enough for to cram
             | through an Amendment/set a precedent to fix it.
        
               | qingcharles wrote:
               | Well, SCOTUS has ummed and erred over several cases about
               | whether to extend the 4th Amend to third party data in
               | some scenarios. IIRC there is an online email case
               | working up through 9th Cir right now?
               | 
               | One of the reasons giving for (usually) now requiring a
               | warrant to open your phone they grab from you is because
               | of the amount of third-party data you can access through
               | it, although IIRC they framed is a regular 4th Amend
               | issue by saying if you had a security camera inside your
               | house the police would be bypassing the warrant
               | requirement by seeing directly into your abode.
        
           | direwolf20 wrote:
           | They can't force you to tell them your PIN in some countries,
           | but they can try all PINs, and they can search your desk
           | drawer to find the post-it where you wrote your PIN.
        
             | qingcharles wrote:
             | They can also hold you in a jail cell until the end of time
             | until you give it up, in many places.
        
             | kstrauser wrote:
             | Good PINs are ones you're not allowed to brute force. You
             | can easily configure an iPhone to wipe itself after too
             | many wrong guesses. There's a single checkbox labeled
             | "Erase Data", saying "Erase all data on this iPhone after
             | 10 failed passcode attempts."
             | 
             | You bet I have that enabled.
        
               | fylo wrote:
               | My toddler would wipe my phone with that on
        
               | kstrauser wrote:
               | We each have our own threat models. Toddlers are high on
               | that list, to be sure.
        
           | thewebguyd wrote:
           | Yes, _you_ cannot be compelled to testify against yourself,
           | but Microsoft is under no such obligation when served a
           | warrant because of third party doctrine. Microsoft holding
           | bitlocker recovery keys is considered you voluntarily giving
           | the information to a third party, so the warrant isn 't
           | compelling _you_ to do anything, so not a rights violation.
           | 
           | But, the 5th amendment is also why its important to not rely
           | on biometrics. Generally (there are some gray areas) in the
           | US you cannot be compelled to give up your password, but
           | biometrics are viewed as physical evidence and not protected
           | by the 5th.
        
           | nly wrote:
           | In the UK they can jail you just for not providing an
           | encryption key
        
             | matja wrote:
             | RIPA 2000 part III section 49
        
           | mmh0000 wrote:
           | In theory...
           | 
           | In practice: https://en.wikipedia.org/wiki/In_re_Boucher
           | 
           | The government gets what the government wants.
        
         | kypro wrote:
         | I think this is a fair position and believe you're making it in
         | good faith, but I can't help but disagree.
         | 
         | I think the reasonable default here would be to not upload to
         | MS severs without explicit consent about what that means in
         | practise. I suspect if you actually asked the average person if
         | they're okay with MS having access to all of the data on their
         | device (including browser history, emails, photos) they'd
         | probably say no if they could.
         | 
         | Maybe I'm wrong though... I admit I have a bad theory of mind
         | when it comes to this stuff because I struggle to understand
         | why people don't value privacy more.
        
         | armada651 wrote:
         | > If your company has data that the police want and they can
         | get a warrant, you have no choice but to give it to them.
         | 
         | They can fight the warrant, if you don't at least object to it
         | then "giving the keys away" is not an incorrect
         | characterization.
        
           | plagiarist wrote:
           | This is my thought also. So they're only holding the keys to
           | prevent anyone from whining about lost data, they don't
           | actually want to be responsible.
        
         | mistercheph wrote:
         | Yeah guys, if it's encrypted by default, it's not a violation
         | of user security or privacy expectations to have a set of
         | master keys that you hold onto and give to third parties to
         | decrypt user devices. I mean it was just encrypted by
         | default... by default...
        
         | thewebguyd wrote:
         | > Any power users who prefer their own key management should
         | follow the steps to enable Bitlocker without uploading keys to
         | a connected Microsoft account.
         | 
         | Except the steps to to that are disable bitlocker, create a
         | local user account (assuming you initially signed in with a
         | Microsoft account because Ms now forces it on you for home
         | editions of windows), delete your existing keys from OneDrive,
         | then re-encrypt using your local account and make sure not to
         | sign into your Microsoft account or link it to Windows again.
         | 
         | A much more sensible default would be to give the user a choice
         | right from the beginning much like how Apple does it. When you
         | go through set up assistant on mac, it doesn't assume you are
         | an idiot and literally asks you up front "Do you want to store
         | your recovery key in iCloud or not?"
        
           | modeless wrote:
           | They don't do that for iMessage though...
           | https://james.darpinian.com/blog/apple-imessage-encryption
        
             | thewebguyd wrote:
             | Only because others you communicate with may not have ADP
             | turned on, which is a flaw with any service that you cannot
             | control what the other end does or does not do, not unique
             | to Apple/iMessage outside of using something like Signal.
        
               | modeless wrote:
               | Most other E2EE messaging services do not break their own
               | E2EE by intentionally uploading messages or encryption
               | keys to servers owned by the same company in a form that
               | they can read. For example, Google's Messages app does
               | not do this for E2EE conversations. This isn't something
               | that only Signal cares about.
        
           | dgrunwald wrote:
           | > make sure not to sign into your Microsoft account or link
           | it to Windows again
           | 
           | That's not so easy. Microsoft tries really hard to get you to
           | use a Microsoft account. For example, logging into MS Teams
           | will automatically link your local account with the Microsoft
           | account, thus starting the automatic upload of all kinds of
           | stuff unrelated to MS Teams.
           | 
           | In the past I also had Edge importing Firefox data (including
           | stored passwords) without me agreeing to do so, and then
           | uploading those into the Cloud.
           | 
           | Nowadays you just need to assume that all data on Windows
           | computers is available to Microsoft; even if you temporarily
           | find a way to keep your data out of their hands, an update
           | will certainly change that.
        
             | LtdJorge wrote:
             | Teams inside a VM it is, then.
        
               | dvfjsdhgfv wrote:
               | It's not just Teams. You need to be constantly vigilant
               | not to make any change that would let them link your MS
               | account to Windows. And they make it more and more
               | difficult not only to install but also use Windows
               | without a Microsoft account. I think they'll also enforce
               | it on everybody eventually.
        
               | prmoustache wrote:
               | You need to just stop using windows and that's it.
               | 
               | The only windows I am using is the one my company makes
               | me use but I don't do anything personal on it. I have my
               | personal computer next to it in my office running on
               | linux.
        
               | ssl-3 wrote:
               | Or: Put all of Windows inside of a VM, within a host that
               | uses disk encryption -- and let it run amok inside of its
               | sandbox.
               | 
               | I did this myself for about 8 years, from 2016-2024.
               | During that time my desktop system at home was running
               | Linux with ZFS and libvirt, with Windows in a VM. That
               | Windows VM was my usual day-to-day interface for the
               | entire system. It was rocky at first, but things did get
               | substantially better as time moved on. I'll do it again
               | if I have a compelling reason to.
        
             | theLiminator wrote:
             | Yes, they push the MS account stuff very hard. I've found
             | Windows so actively hostile to the user that I basically
             | only use Linux now.
             | 
             | I used to be a windows user, it has really devolved to the
             | point where it's easier for me to use Linux (though I'm
             | technical). I really feel for the people who aren't
             | technical and are forced to endure the crap that windows
             | pushes on users now.
        
               | J_Shelby_J wrote:
               | > actively hostile
               | 
               | That's the real problem MS has. It's becoming a meme how
               | bad the relationship between the user and windows is.
               | It's going to cause generational damage to their company
               | just so they can put ads in the start menu.
        
               | josephg wrote:
               | It's a pity for Apple that they keep making macOS worse
               | with each major update. Modern Apple hardware running
               | snow leopard would be a thing of beauty.
               | 
               | At this rate, my next laptop might end up being a
               | framework running Linux.
        
               | seemaze wrote:
               | I switched from Windows to Mac 15 years ago. It was a
               | revelation when the terrible habits of verbally abusing
               | my computer and anxiety saving files every 22 seconds
               | just evaporated.
               | 
               | Those old habits have been creeping back lately through
               | all the various *OS 26 updates. I too now have Linux on
               | Framework. Not perfect, but so much better for my
               | wellbeing.
        
               | b112 wrote:
               | Maoboro cigarettes uaed to be for women, including red
               | tipped filters to hide lipstick marks. Sales waned, so
               | they actually rebranded the cigarette for men, and even
               | succeeded in making it a definition of manliness.
               | 
               | Advertising stories like that, make sure M$ execs could
               | care less about damage to their image.
               | 
               | Especially when profit leers its head.
               | 
               | (at least, I presume?!?)
        
               | to11mtm wrote:
               | It is sad that we got to here from when the worst problem
               | was a tile start menu (I liked 8.1 and it ran good on
               | fairly trash hardware.)
        
             | xp84 wrote:
             | Do we have confirmation that it's a must to upload the key
             | if you use an MS account with Windows? Is it proven that
             | it's not possible to configure Windows to have an MS
             | account linked, maybe even to use OneDrive, while not
             | uploading the BitLocker key?
             | 
             | Btw - my definition of "possible" would include anything
             | possible in the UI - but if you have to edit the registry
             | or do shenanigans in the filesystem to disable the upload
             | from happening, I would admit that it's basically
             | mandatory.
        
               | ls612 wrote:
               | I just checked on my personal desktop, which has Windows
               | 11 installed using a local user account and is signed
               | into my MS account for OneDrive and my account is listed
               | as having no recovery codes in the cloud. I don't recall
               | editing anything in the registry to accomplish this it
               | was the default behavior for having a local user account.
               | I copied my recovery codes when I built the machine and
               | pasted them into an E2EE iPhone note which should allow
               | me to recover my machine if disaster strikes (also
               | everything is backed up to Backblaze using their client
               | side encryption).
        
             | replyifuagree wrote:
             | > logging into MS Teams
             | 
             | I mean, this is one application nobody should ever log
             | into!
        
               | IAmBroom wrote:
               | That's nice.
               | 
               | I, however, like getting my paycheck, and so I have no
               | choice.
        
               | spockz wrote:
               | Of course. But I suppose you run Teams on a company
               | provided/managed, or at least paid for by the company,
               | device?
               | 
               | Just don't use that machine for anything private.
               | 
               | Is anyone using their private devices for work? (Also
               | there is teams for Linux and on the web, if that is not
               | prevented by the policy of your org.)
        
               | klardotsh wrote:
               | In the startup world, BYOD is/was exceedingly common. All
               | but two jobs of my career were happy to allow me to use
               | my own Linux laptop and eschew whatever they were
               | otherwise going to give me.
               | 
               | Obviously enterprises aren't commonly BYOD shops, but
               | SMBs and startups certainly can be.
               | 
               | ... whether the people who would do such BYOD things are
               | at all likely to be Windows users who care about this
               | Bitlocker issue, is a different debate entirely.
        
               | elzbardico wrote:
               | Then the founders do something really stupid, and the law
               | decides that your equipment may be evidence.
               | 
               | Unless you're a founder, you should always use company
               | provided equipment.
        
               | layer8 wrote:
               | That means you'll do that on the work machine provided by
               | your employer, not on your personal machine.
        
               | plaguuuuuu wrote:
               | teams works fine in website form for me because it IS a
               | website (that uses an extra ~1gb of ram running as a
               | desktop app because its also a separate browser)
        
           | shawnz wrote:
           | Why would you need to create a local account? You can just
           | not choose to store the keys in your Microsoft account during
           | BitLocker setup: https://www.diskpart.com/screenshot/en/other
           | s/windows-11/win...
           | 
           | Admittedly, the risks of choosing this option are not clearly
           | laid out, but the way you are framing it also isn't accurate
        
             | shakna wrote:
             | All "Global Reader" accounts have
             | "microsoft.directory/bitlockerKeys/key/read" permission.
             | 
             | Whether you opt in, or not, if you connect your account to
             | Microsoft, then they do have the ability fetch the
             | bitlocker key, if the account is not local only. [0] Global
             | Reader is builtin to everything +365.
             | 
             | [0] https://github.com/MicrosoftDocs/entra-
             | docs/commit/2364d8da9...
        
               | crazygringo wrote:
               | They're Microsoft and it's Windows. They always have the
               | _ability_ to fetch the key.
               | 
               | The question is _do_ they ever fetch and transmit it if
               | you opt out?
               | 
               | The expected answer would be no. Has anyone shown
               | otherwise? Because hypotheticals that they _could_ are
               | not useful.
        
               | lazide wrote:
               | Considering all the shenanigans Microsoft has been up to
               | with windows 11 and various privacy, advertising, etc.
               | stuff?
               | 
               | Hell, all the times they keep enabling one drive despite
               | it being really clear I don't want it, and then uploading
               | stuff to the cloud that I don't want?
               | 
               | I have zero trust for Microsoft now, and not much better
               | for them in the past either.
        
               | cyberax wrote:
               | This is for the _ActiveDirectory_. If your machine is
               | joined into a domain, the keys will be stored in the AD.
               | 
               | This does not apply to standalone devices. MS doesn't
               | have a magic way to reach into your laptop and pluck the
               | keys.
        
               | riskable wrote:
               | > MS doesn't have a magic way to reach into your laptop
               | and pluck the keys.
               | 
               | Of course they do! They can just create a Windows Update
               | that does it. They have full administrative access to
               | every single PC running Windows in this way.
        
               | shawnz wrote:
               | Furthermore it seems like it's specific to _Azure_ AD,
               | and I 'm guessing it probably only has effect if you
               | enable to option to back up the keys to AD in the first
               | place, which is not mandatory
               | 
               | I'd be curious to see a conclusive piece of documentation
               | about this, though
        
               | cyberax wrote:
               | Regular AD also has this feature, you can store the
               | encryption keys in the domain controller. I don't think
               | it's turned on by default, but you can do that with a
               | group policy update.
        
           | gruez wrote:
           | >Except the steps to to that are disable bitlocker, create a
           | local user account (assuming you initially signed in with a
           | Microsoft account because Ms now forces it on you for home
           | editions of windows), delete your existing keys from
           | OneDrive, then re-encrypt using your local account and make
           | sure not to sign into your Microsoft account or link it to
           | Windows again.
           | 
           | 1. Is there any indication it forcibly uploads your recovery
           | keys to microsoft if you're signed into a microsoft account?
           | Looking at random screenshots, it looks like it presents you
           | an option https://helpdeskgeek.com/wp-
           | content/pictures/2022/12/how-to-...
           | 
           | 2. I'm pretty sure you don't have to decrypt and rencrypt the
           | entire drive. The actual key used for encrypting data is
           | never revealed, even if you print or save a recovery key.
           | Instead, it generates a "protectors", which encrypts the
           | actual key using the recovery key, then stores the encrypted
           | version on the drive. If you remove a recovery method (ie.
           | protector), the associated recovery key becomes immediately
           | useless. Therefore if your recovery keys were backed up to
           | microsoft and you want to opt out, all you have to do is
           | remove the protector.
        
           | fpoling wrote:
           | With Bitlocker it is still possible to have single password-
           | based key. But enabling that requires to enter a few commands
           | on the command line.
        
             | lazide wrote:
             | And you can be sure it didn't add a 'recovery' key, how?
        
           | pnw wrote:
           | You can turn it off without resorting to a local account,
           | although it's non-obvious.
           | 
           | GPEdit -> Computer Configuration - Administrative Templates -
           | Windows Components - BitLocker Drive Encryption - Operating
           | System Drives - "Choose how BitLocker-protected operating
           | system drives can be recovered"
           | 
           | Repeat for other drives.
        
         | throwaway85825 wrote:
         | That would be all well and good if any of this was communicated
         | to the user.
        
         | giancarlostoro wrote:
         | To be fair, if they didn't have BitLocker enabled at all, the
         | FBI would have just scanned the hard-drive as-is. The only
         | usefulness of BitLocker is if a stranger steals your laptop,
         | assuming Microsoft doesn't hand out the keys to just anybody,
         | your files should be safe, in theory.
        
         | matheusmoreira wrote:
         | Power users should stop bothering with Windows nonsense and
         | install Linux instead so that they can actually have control
         | over their system.
         | 
         | It's 2026. The abuses of corporations are well documented.
         | Anyone who still chooses Windows of their own volition is quite
         | literally asking for it and they deserve everything that
         | happens to them.
        
           | SmellTheGlove wrote:
           | I'll bite. What Linux distro currently has the nicest desktop
           | experience? I work on a MacBook but my desktop is a windows
           | PC that I use for gaming and personal projects. I hear Proton
           | has made the former pretty good now, and the latter is mostly
           | in WSL for me anyway. Maybe a good time to try.
           | 
           | What do you suggest? I'll try it in a VM or live usb.
        
             | amitav1 wrote:
             | Something with KDE. Never used KDE extensively because I
             | hate non-tiling WMs, but something like Kubuntu would give
             | you a more windows-esque experience by default. Here's the
             | download link:
             | 
             | https://kubuntu.org/download/
             | 
             | Bon appetit!
        
               | andai wrote:
               | I don't use KDE either, but it does seem to be the most
               | Windows adjacent choice. Unless you like very old
               | versions of Windows in which case you may prefer XFCE
               | like me (Xubuntu or the xfce variant of Linux mint).
               | 
               | I heard Kubuntu is not a great distro for KDE, but I
               | can't comment on that personally.
        
             | mmh0000 wrote:
             | That's literally like asking "What car has the best driving
             | experience?". There is no one answer.
             | 
             | If you want something that "just works," Linux Mint[1] is a
             | great starting point. That gets you into Linux without any
             | headache. Then, later when bored, you can branch out into
             | the thousands[2] of Linux distributions that fill every
             | possible niche
             | 
             | [1] https://linuxmint.com/
             | 
             | [2] https://distrowatch.com/dwres.php?resource=major
        
               | PlatoIsADisease wrote:
               | I would never, recommend anything from Debian-family for
               | consumer use. Its literally outdated linux, under the
               | marketing 'stable'.
               | 
               | Fedora is so significantly better.
               | 
               | I wouldn't confuse popularity for good. Ubuntu gave away
               | free CDs in the 2000s and are living off old marketing.
               | 
               | Debian family is so bad. You will be in the terminal
               | constantly just trying to get stuff to work. Stick to a
               | well maintained, up to date, consumer distro, Fedora.
               | 
               | (reminder that Fedora is Not Arch)
        
             | jbstack wrote:
             | There are so many distros that it really depends on your
             | use-case and it's hard to make a generic suggestion. Ubuntu
             | is a common recommendation for first timers, mainly because
             | as the most popular distro you'll easily be able to Google
             | when you need help with something, and it also uses the
             | most popular package format (.deb). There's also Linux Mint
             | which is basically Ubuntu but with some of the latter's
             | more questionable choices removed (e.g. snaps) and minus
             | the big corp owner. By using one of these you'll also be
             | learning skills relevant to Debian (which Ubuntu is derived
             | from) which is a solid choice for servers.
             | 
             | Regardless of which distro you choose, your "desktop
             | experience" will be mostly based on what desktop
             | environment you pick, and you are free to switch between
             | them regardless of distro. Ubuntu for example provides
             | various installers that come with different DEs installed
             | by default (they call them "flavours":
             | https://ubuntu.com/desktop/flavors), but you can also just
             | switch them after installation. I say "mostly" because some
             | distros will also customise the DE a bit, so you might find
             | some differences.
             | 
             | "Nicest desktop experience" is also too generic to really
             | give a proper suggestion. There are DEs which aim to be
             | modern and slick (e.g. GNOME, KDE Plasma, Cinnamon),
             | lightweight (LXQt), or somewhere in between (Xfce). For
             | power users there's a multitude of tiling window managers
             | (where you control windows with a keyboard). Popular
             | choices there are i3/sway or, lately, Niri. All of these
             | are just examples, there are plenty more DEs / WMs to pick
             | from.
             | 
             | Overall my suggestion would be to start with something
             | straightforward (Mint would probably be my first choice
             | here), try all the most popular DEs and pick the one you
             | like, then eventually (months or years later) switch to a
             | more advanced distro once you know more what your goals are
             | and how you want to use the system. For example I'm in the
             | middle of migrating to NixOS because I want a fully
             | declarative system which gives the freedom to experiment
             | without breaking your system because you can switch between
             | different temporary environments or just rollback to
             | previous generations. But I definitely wouldn't have been
             | ready for that at the outset as it's way more complex than
             | a more traditional distro.
        
             | taberiand wrote:
             | If you're a developer, try NixOS. The code based
             | configuration can be daunting but LLMs are very good at
             | writing it.
        
               | jbstack wrote:
               | Not sure it's good as a starter distro, but other than
               | that I agree. I was put off NixOS for a long time despite
               | loving the principles behind it. Then a few weeks ago I
               | had ChatGPT give me a short course on it, including
               | flakes and the basics of the Nix language. I completed
               | that in a few hours and achieved more than I ever had
               | reading the Nix docs and blogs etc. Now I'm able to use
               | an LLM to help me write flakes while also understanding
               | what it is doing (I'm not a fan of blindly using AI
               | generated code).
        
               | taberiand wrote:
               | That's what I'm getting at - the nixos learning curve is
               | flattened out completely with LLMs to the point that I do
               | recommend it as a starter distro for anyone technically
               | competent (as it's still crucial to actually read and
               | understand what the LLM produces)
        
             | amlib wrote:
             | If you want maximum commodity and as many things to "just
             | work" as possible out of the box, go for good old plain
             | Ubuntu.
             | 
             | If you care a little more about your privacy and is willing
             | to sacrifice some commodity, go for Fedora. It's community
             | run and fairly robust. You may have issues with media
             | codecs, nvidia drivers and few other wrinkles though. The
             | "workstation" flavor is the most mature, but you may want
             | to give the KDE version a try.
             | 
             | If you want an adventure, try everything else people are
             | recommending here :)
        
             | matheusmoreira wrote:
             | For gaming I suggest a Steam Deck. I love mine, it's an
             | awesome Linux device. Not locked down either.
        
           | jbstack wrote:
           | You only have to run through a modern Windows installer to
           | understand how screwed you are if you install it. Last time I
           | did this for a disposable Windows VM (a couple of years ago)
           | I remember having to click through a whole bunch of prompts
           | asking about all the different types of data Microsoft wanted
           | my computer to send them. Often the available answers weren't
           | "yes" or "no" but more like "share all data" vs "share just
           | some data". After that I recall being forced to sign up for
           | an outlook account just to create a local login unless I
           | unplugged my network cable during the install. I've heard
           | they have closed that loophole in recent installers.
           | 
           | I'd already long since migrated away from Windows but if I'd
           | been harbouring any lingering doubts, that was enough to
           | remove them.
        
         | joering2 wrote:
         | > you have no choice but to give it to them
         | 
         | Will they shoot me in head?
         | 
         | What if I truly forgot the password to my encrypted drive? Will
         | they also shoot me in the head?
        
           | qingcharles wrote:
           | Do they need to actually shoot you? Have you had a loaded gun
           | pressed to your head and asked for your password?
           | 
           | What about your wife's head? Your kids' heads?
        
         | SilverElfin wrote:
         | Doesn't windows 11 force you to use a Microsoft account
        
         | bilekas wrote:
         | There needs to be more awareness into setting up W11 install
         | ISO's which can be modified to disable bitlocker by default,
         | disable the online account requirement.
         | 
         | I recently needed to make a bootable key and found that Rufus
         | out of the box allows you to modify the installer, game
         | changer.
        
         | wing-_-nuts wrote:
         | >Any power users who prefer their own key management should
         | follow the steps to enable Bitlocker without uploading keys to
         | a connected Microsoft account.
         | 
         | I have W11 w a local account and no bitlocker on my desktop
         | computer, but the sheer amount of nonsense MS has been doing
         | these days has really made me question if 'easy modding*' is
         | really enough of a benefit for me to not just nuke it and
         | install linux yet again
         | 
         | * You _can_ get the MO2 mod manager running under linux, but it
         | 's a pain, much like you can also supposedly run executable
         | mods (downgraders, engine patches, etc) in the game's context,
         | but again, pain
        
         | throwawayqqq11 wrote:
         | The reasonable default is transparency about it and 2FA for
         | recovery scenarios.
        
         | kermatt wrote:
         | If you are super concerned about their privacy, should you be
         | using Windows anyway? Or any commercial OS for that matter?
        
         | estimator7292 wrote:
         | > Journalists love the "Microsoft gave" framing because it
         | makes Microsoft sound like they're handing these out because
         | they like the cops, but that's not how it works. If your
         | company has data that the police want and they can get a
         | warrant, you have no choice but to give it to them.
         | 
         | These two statements are in _no way_ mutually exclusive.
         | Microsoft is gobbling up your supposedly private encryption
         | keys _because_ they love cops and _want_ an excuse to give your
         | supposedly private data to cops.
         | 
         | Microsoft could simply _not collect your keys_ and then would
         | have no reason or excuse to hand them to cops.
         | 
         | Microsoft _chose_ to do this.
         | 
         | Do not be charitable to fascists.
        
         | michaelt wrote:
         | _> If your company has data that the police want and they can
         | get a warrant, you have no choice but to give it to them._
         | 
         | Yes. The thing is: Microsoft made the design decision to copy
         | the keys to the cloud, in plaintext. And they made this
         | decision with the full knowledge that the cops could ask for
         | the data.
         | 
         | You _can_ encrypt secrets end-to-end - just look at how
         | password managers work - and it means the cops can only
         | subpoena the useless ciphertext. But Microsoft decided not to
         | do that.
         | 
         | I dread to think how their passkeys implementation works.
        
         | Retr0id wrote:
         | At Microsoft-scale, data requests from law enforcement are an
         | inevitability. Designing a system such that their requests are
         | answerable is a choice. Signal's cloud backup system is an
         | example of a different choice being made.
        
         | knowitnone3 wrote:
         | So you're saying Microsoft gave the FBI the key?
        
         | Centigonal wrote:
         | MacOS has this feature as well. It used to be called "Allow my
         | iCloud account to unlock my disk," but it keeps getting renamed
         | and moved around in new MacOS versions. I think it's now tied
         | together with remote password resets into one option called
         | "allow user to reset password using Apple Account."
        
         | morshu9001 wrote:
         | The problem is they don't make this clear to the user or make
         | it easy to opt out. Contrast with how Apple does it.
        
         | alephnerd wrote:
         | Also, this essay by Mickens at USENIX over a decade ago -
         | https://www.usenix.org/system/files/1401_08-12_mickens.pdf
         | 
         | Tl;dr - "Basically, you're either dealing with Mossad or not-
         | Mossad. If your adversary is not-Mossad, then you'll probably
         | be fine if you pick a good password and don't respond to emails
         | from ChEaPestPAiNPi11s@ virus-basket.biz.ru. If your adversary
         | is the Mossad, YOU'RE GONNA DIE AND THERE'S NOTHING THAT YOU
         | CAN DO ABOUT IT" (Mickens, 2014)
        
         | themafia wrote:
         | Hacker News defending corporate key escrow. Wow.
         | 
         | > It protects their data in the event that someone steals the
         | laptop, but still allows them to recover their own data later
         | from the hard drive.
         | 
         | It allows /anyone/ to recover their data later. You don't have
         | to be a "purist" to hate this.
        
           | Spivak wrote:
           | There is no other way for this to work that won't result in
           | an absolutely massive number of people losing their data
           | permanently who had no idea their drive was encrypted. Well
           | there is, leave BitLocker disabled by default and the drive
           | unencrypted. Now the police don't even have to ask!
           | 
           | With this scheme the drive is recoverable by the user and
           | unreadable to everyone except you, Microsoft, and the police.
           | Surely that's a massive improvement over sitting in plaintext
           | readable by the world. The people who are prepared to do
           | proper key management will know how to do it themselves.
           | 
           | Apple does the same thing with FileVault when you set up with
           | your iCloud account where, again, previously your disk was
           | just left unencrypted.
        
         | knallfrosch wrote:
         | 20 requests per year also doesn't sound like a privacy problem.
         | These are people where the police got a search warrant for the
         | hard drives.
         | 
         | I'd be more concerned about access to cloud data (emails,
         | photos, files.)
        
         | Noaidi wrote:
         | The same is true for Apple laptops! Take a look in your
         | Passwords app and you will see it automatically saves and syncs
         | your laptop decryption key into the cloud.
         | 
         | So all the state needs to get into your laptop is to get access
         | from Apple to your iCloud account.
        
         | b65e8bee43c2ed0 wrote:
         | >The defaults will also upload the BitLocker key to a Microsoft
         | Account if available.
         | 
         | >This is why the FBI can compel Microsoft to provide the keys.
         | 
         | >in my opinion it's the reasonable default
         | 
         | I really can't imagine what kind of person would say that with
         | a straight face. Hanlon's razor be damned, I have to ask: are
         | you a Microsoft employee or investor?
        
         | coderatlarge wrote:
         | user notification is another major litmus test.
        
         | jajuuka wrote:
         | Similar case with Apple devices. They default to backing up to
         | Apple servers where they are unencrypted. So they can provide
         | data to police if requested. But for anyone concerned about
         | privacy they can use Advanced Data Protection which encrypts
         | all their data and prevents Apple from reading it or recovering
         | it.
         | 
         | Definitely agree that choices like these are the most sane for
         | the default user experience and that having these advanced
         | options for power users to do with it what they want is a fair
         | compromise. Wish more people were open to designing software
         | for the average person and compromising on a middle ground the
         | benefits both kinds of users.
        
         | ratelimitsteve wrote:
         | >can compel Microsoft to provide the keys
         | 
         | can they compel testimony? keys, passcodes and the like are
         | usually considered testimony. did they try? the usual story
         | here is that they don't have to, that the big corporations will
         | turn over any info they have on request because they can and
         | the government makes a better friend than a single user. the
         | article mentions 20 "requests" per year on average but doesn't
         | say anything about the government using force.
         | 
         | I agree with your conclusion though: data you share with anyone
         | is data you've shared with everyone and that includes your
         | encryption keys. if that matters to you, then you need to take
         | active steps to ensure your own security because compelled or
         | not, the cloud providers aren't here to help keep you safe.
        
         | PunchyHamster wrote:
         | > Any power users who prefer their own key management should
         | follow the steps to enable Bitlocker without uploading keys to
         | a connected Microsoft account.
         | 
         | You mean "Install Linux",because that's easier than dealing
         | with the steps required to do that on Windows
        
         | lrvick wrote:
         | Microsoft could have done key backups to secure enclaves that
         | will only return them to a user able to produce valid
         | signatures using a backup code or otherwise they hold. Hell
         | they were the ones that normalized remote attestation.
         | 
         | But Microsoft chose to keep them plain text, and thus they are,
         | and will continue to be abused.
         | 
         | We must not victim blame. This is absolutely corruption on
         | microsofts part.
        
         | elzbardico wrote:
         | And the only reason windows uploads the keys is that Microsoft
         | wants to help the government while fucking you.
        
         | BLKNSLVR wrote:
         | So long as Microsoft also "give customer set of BitLocker
         | encryption keys to unlock their own laptop" in the right set of
         | conditions.
        
         | citizenpaul wrote:
         | None of this matters. XKCD. Hit him with this $5 wrench until
         | he gives you the keys.
        
           | beeflet wrote:
           | Mass surveillance through $5 wrench (and massive thug salary)
           | attacks do not scale, but mass surveillance through turn-key
           | decryption does.
        
         | lokar wrote:
         | This is a really bad take
         | 
         | The choice is not between honoring the warrant and breaking the
         | law.
         | 
         | They can go to a judge and fight the warrant. Other companies
         | have done this.
         | 
         | Microsoft won't, one more reason I will never use anything from
         | them.
        
       | tucnak wrote:
       | Water is wet. More news at 11
        
         | yndoendo wrote:
         | Water is not wet. Water makes non-hydrophobic materials wet.
         | 
         | This news piece from a non-tech organization will help educate
         | non-tech people.
        
       | tokyobreakfast wrote:
       | This is almost certainly users who elect to store their BitLocker
       | keys in OneDrive.
       | 
       | Don't think Apple wouldn't do the same.
       | 
       | If you don't want other people to have access to your keys, don't
       | give your keys to other people.
        
         | parineum wrote:
         | Both Microsoft and Apple (I think Apple does) have the option
         | to encrypt those keys with the user's password where they are
         | storing them.
        
         | malfist wrote:
         | It is the default setting on windows 11 to share your key with
         | microsoft.
        
           | raverbashing wrote:
           | It's also the "default" in Windows 11 to require a recovery
           | bitlocker key every time you do a minor modification to the
           | "bios" like changing the boot order
        
         | giobox wrote:
         | > Don't think Apple wouldn't do the same.
         | 
         | Of course Apple offers a similar feature. I know lots of people
         | here are going to argue you should never share the key with a
         | third party, but if Apple and Microsoft didn't offer key escrow
         | they would be inundated with requests from ordinary users to
         | unlock computers they have lost the key for. The average user
         | does not understand the security model and is rarely going to
         | store a recovery key at all, let alone safely.
         | 
         | > https://support.apple.com/en-om/guide/mac-help/mh35881/mac
         | 
         | Apple will escrow the key to allow decryption of the drive with
         | your iCloud account if you want, much like Microsoft will
         | optionally escrow your BitLocker drive encryption key with the
         | equivalent Microsoft account feature. If I recall correctly
         | it's the default option for FileVault on a new Mac too.
        
           | tokyobreakfast wrote:
           | That's what I said. I admit the double-negative grammar is a
           | bit confusing.
        
           | ezfe wrote:
           | Apple's solution is iCloud Keychain which is E2E encrypted,
           | so would not be revealed with a court order.
        
             | tokyobreakfast wrote:
             | What is your proof they don't have a duplicate key that
             | also unlocks it? A firm handshake from Tim?
        
               | otterley wrote:
               | If they say they don't, and they do, then that's fraud,
               | and they could be held liable for any damages that
               | result. And, if word got out that they were defrauding
               | customers, that would result in serious reputational
               | damage to Apple (who uses their security practices as an
               | industry differentiator) and possibly a significant
               | customer shift away from them. They don't want that.
        
               | tokyobreakfast wrote:
               | Absent the source code, it's incredibly difficult to
               | disprove when the only proof you have is good vibes.
        
               | otterley wrote:
               | There are many things you can't prove or disprove in this
               | world. That's where trust and reputation comes in - to
               | fill the uncertainty gap.
        
               | fsflover wrote:
               | You mean, trust and reputation of Apple? They're not
               | exactly high:
               | 
               | https://news.ycombinator.com/item?id=46252114
               | 
               | https://news.ycombinator.com/item?id=45520407
               | 
               | https://news.ycombinator.com/item?id=42014588
               | 
               | https://news.ycombinator.com/item?id=26644216
        
               | otterley wrote:
               | At the end of the day, it's all about how you weigh the
               | evidence. If those examples are sufficient to tip the
               | scales for you, that's your choice. However, Apple's
               | overall trustworthiness--particular when it comes to
               | protecting people's sensitive data--remains high for in
               | the market. Even the examples you posted aren't
               | especially pertinent to that (except for iCloud Keychain,
               | where the complaint isn't whether Apple is securely
               | storing it, but the fact that it got transmitted to them
               | in the first place, and there exists some unresolved
               | ambiguity about whether it is appropriately deleted on
               | demand).
        
               | ezfe wrote:
               | None of these really match the scenario we're discussing
               | here. Some are typical big company stuff, some are
               | technical edge cases, but none are "Apple lies about a
               | fundamental security practice consistently and with
               | malice"
        
               | PlatoIsADisease wrote:
               | Cognitive Dissonance. You already made up your mind, no
               | evidence will change it. Any evidence you get is cast
               | aside for one reason or another.
        
               | fsflover wrote:
               | > "Apple lies about a fundamental security practice
               | consistently and with malice"
               | 
               | Uploading passwords to the cloud should count. Also this:
               | https://sneak.berlin/20231005/apple-operating-system-
               | surveil...
        
               | direwolf20 wrote:
               | The government would never prosecute a company for fraud
               | where that fraud consists of cooperating with the
               | government after promising to a suspected criminal that
               | they wouldn't.
        
               | otterley wrote:
               | That's not the scenario I was thinking of. There are
               | other possibilities here, like providing a decryption key
               | (even if by accident) to a criminal who's stolen a
               | business's laptop, or if a business had made contractual
               | promises to their customers, based on Apple's promises to
               | them. The actions would be private (civil) ones, not
               | criminal fraud prosecution.
               | 
               | Besides, Apple's lawyers aren't stupid enough to forget
               | to carve out a law-enforcement demand exception.
        
               | PlatoIsADisease wrote:
               | Apple has the number 1 marketing team in the world. They
               | got away with PRISM and terrible security.
               | 
               | They are immune to reputation damage. Teens and moms
               | don't care.
        
               | eddyg wrote:
               | You should watch the _whole_ BlackHat talk (from 2016!)
               | from Apple 's Head of Security Engineering and
               | Architecture, but especially this part:
               | 
               | https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s
        
               | PlatoIsADisease wrote:
               | Lot of trust in the words that cannot be verified.
        
             | jcalvinowens wrote:
             | > Apple's solution is iCloud Keychain which is E2E
             | encrypted, so would not be revealed with a court order.
             | 
             | Nope. For this threat model, E2E is a complete joke when
             | both E's are controlled by the third party. Apple could be
             | compelled by the government to insert code in the client to
             | upload your decrypted data to another endpoint they
             | control, and you'd never know.
        
               | dcrazy wrote:
               | That was tested in the San Bernardino shooter case. Apple
               | stood up and the FBI backed down.
        
               | jcalvinowens wrote:
               | It's incredibly naive to believe apple will continue to
               | be able to do that.
        
               | ezfe wrote:
               | Yeah and Microsoft could insert code to upload the
               | bitlocker keys. What's your point? Even linux could do
               | that if they were compelled to.
        
               | jcalvinowens wrote:
               | > Even linux could do that if they were compelled to.
               | 
               | An open source project absolutely cannot do that without
               | your consent if you build your client from the source.
               | That's my point.
        
               | ezfe wrote:
               | Wait I'm sorry do you build linux from source and review
               | all code changes?
        
               | jcalvinowens wrote:
               | You missed the important part:
               | 
               | > For this threat model
               | 
               | We're talking about a hypothetical scenario where a state
               | actor getting the information encrypted by the E2E
               | encryption puts your life or freedom in danger.
               | 
               | If that's you, yes, you absolutely shouldn't trust US
               | corporations, and you should absolutely be auditing the
               | source code. I seriously doubt that's you though, and
               | it's certainly not me.
               | 
               | The sub-title from the original forbes article (linked in
               | the first paragraph of TFA):
               | 
               | > But companies like Apple and Meta set up their systems
               | so such a privacy violation isn't possible.
               | 
               | ...is completely utterly false. The journalist swallowed
               | the marketing whole.
        
               | ezfe wrote:
               | Okay, so yes I grant your point that people where
               | governments are the threat model should be auditing
               | source code.
               | 
               | I also grant that many things are possible (where the
               | journalist says "isn't possible").
               | 
               | However, what remains true is that Microsoft appears to
               | store this data in a manner that can be retrieved through
               | "simple" warrants and legal processes, compared to Apple
               | where these encryption keys are stored in a manner that
               | would require code changes to accomplish.
               | 
               | These are fundamentally different in a legal framework
               | and while it doesn't make Apple the most perfect amazing
               | company ever, it shames Microsoft for not putting in the
               | technical work to accomplish these basic barriers to
               | retrieving data.
        
               | armadyl wrote:
               | This is a wildly unrealistic viewpoint. This would assume
               | that you somehow know the language of the client you're
               | building and have total knowledge over the entire
               | codebase and can easily spot any sort of security issues
               | or backdoors, assuming you're using software that you
               | yourself didn't make (and even then).
               | 
               | This also completely disregards the history of
               | vulnerability incidents like XZ Utils, the infected NPM
               | packages of the month, and even for example CVEs that
               | have been found to exist in Linux (a project with
               | thousands of people working on it) for over a decade.
        
         | piccirello wrote:
         | In Apple's case, starting with macOS Tahoe, Filevault saves
         | your recovery key to your iCloud Keychain [0]. iCloud Keychain
         | is end-to-end encrypted, and so Apple doesn't have access to
         | the key.
         | 
         | As a US company, it's certainly true that given a court order
         | Apple would have to provide these keys to law enforcement.
         | That's why getting the architecture right is so important. Also
         | check out iCloud Advanced Data Protection for similar
         | protections over the rest of your iCloud data.
         | 
         | [0] https://sixcolors.com/post/2025/09/filevault-on-macos-
         | tahoe-...
        
         | teejmya wrote:
         | > Don't think Apple wouldn't do the same.
         | 
         | Except for that time they didn't.
         | 
         | https://www.apple.com/customer-letter/
        
         | paulpauper wrote:
         | Just use open source encryption
        
         | eddyg wrote:
         | You shouldn't include Apple in this.
         | 
         | As of macOS Tahoe, the FileVault key you (optionally) escrow
         | with Apple is stored in the iCloud Keychain, which is
         | cryptographically secured by HSM-backed, rate-limited
         | protections.
         | 
         | You can (and should) watch
         | https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s for all the
         | details about how iCloud is protected.
        
           | bigyabai wrote:
           | You can (and should) read _Mr. Fart 's Favorite Colors_ as a
           | response, explaining how "perfect" security becomes the enemy
           | of principled security: https://medium.com/@blakeross/mr-
           | fart-s-favorite-colors-3177...                 Unbreakable
           | phones are coming. We'll have to decide who controls the
           | cockpit: The captain? Or the cabin?
           | 
           | The security in iOS is not to designed make _you_ safer, in
           | the same way that cockpit security doesn 't protect economy
           | class from rogue pilots or business-class terrorists. Apple
           | made this decision years ago, they're right there in Slide 5
           | of the Snowden PRISM disclosure. Today, Tim stands tall next
           | to POTUS. Any preconceived principle that Apple might have
           | once clung to is forfeit next to their financial reliance on
           | American protectionism:
           | https://www.cnbc.com/2025/09/05/trump-threatens-trade-
           | probe-...
        
         | PlatoIsADisease wrote:
         | I was going to say: "Well Apple historically is an easy target
         | of Pegasus" but that can only be used a few times before Apple
         | figures out the exploit and fixes it. Its more expensive than
         | just asking the Apple.
         | 
         | But given PRISM, I'm sure Apple will just give it up.
        
       | Jigsy wrote:
       | This is by far one of the best advertisements for LUKS/VeraCrypt
       | I've ever seen.
        
         | jhallenworld wrote:
         | Agree, use Linux, use LUKS.
         | 
         | PGP WDE was a preferred corporate solution, but now you have to
         | trust Broadcom.
        
         | Coeur wrote:
         | Remember when the original dev of TrueCrypt (the VeraCrypt
         | predecessor) suddenly abandoned the project and wrote that
         | people should use BitLocker instead? [1] [2]
         | 
         | We now know that BitLocker is not secure, and an intelligent
         | open source dev saying that was probably knowingly not saying
         | the truth.
         | 
         | The best explanation to me is that this was said under duress,
         | because somebody wanted people to move away from the good
         | TrueCrypt to something they could break.
         | 
         | [1] https://truecrypt.sourceforge.net
         | 
         | [2]
         | https://en.wikipedia.org/wiki/TrueCrypt#End_of_life_announce...
        
       | dmitrygr wrote:
       | This is why local account setup is so important on windows, and
       | why microsoft makes it harder and harder each update.
        
         | paulpauper wrote:
         | or not use microsoft products for encryption
        
       | SilverElfin wrote:
       | This is disappointing but I wonder if this is quid pro quo.
       | Microsoft and Nadella want to appear to be cooperating with the
       | government, so they are given more government contracts and so
       | they don't get regulatory problems (like on antitrust or
       | whatever).
        
       | ferrouswheel wrote:
       | It's interesting how many comments these days are like, "well of
       | course".
       | 
       | Back in the day hackernews had some fire and resistance.
       | 
       | Too many tech workers decided to rollover for the government and
       | that's why we are in this mess now.
       | 
       | This isn't an argument about law, it's about designing secure
       | systems. And lazy engineers build lazy key escrow the government
       | can exploit.
        
         | Aurornis wrote:
         | > Back in the day hackernews had some fire and resistance.
         | 
         | Most of the comments are fire and resistance, but they commonly
         | take ragebait and run with the assumptions built-in to
         | clickbait headlines.
         | 
         | > Too many tech workers decided to rollover for the government
         | and that's why we are in this mess now.
         | 
         | I take it you've never worked at a company when law enforcement
         | comes knocking for data?
         | 
         | The internet tough guy fantasy where you boldly refuse to
         | provide the data doesn't last very long when you realize that
         | it just means you're going to be crushed by the law and they're
         | getting the data anyway.
        
           | nemomarx wrote:
           | If you design it so you don't have access to the data, what
           | can they do? I'm sure there's some cryptographic way to avoid
           | Microsoft having direct access to the keys here.
        
             | t-3 wrote:
             | If you design it so you don't have access to the data, how
             | do you make money?
             | 
             | Microsoft (and every other corporation) _wants_ your data.
             | They don 't want to be a responsible custodian of your
             | data, they want to sell it and use it for advertising and
             | maintaining good relationships with governments around the
             | world.
        
               | NegativeK wrote:
               | > If you design it so you don't have access to the data,
               | how do you make money?
               | 
               | The same way companies used to make money, before they
               | started bulk harvesting of data and forcing ads into
               | products that we're _already_ _paying_ _for_?
               | 
               | I wish people would have integrity instead of squeezing
               | out every little bit of profit from us they can.
        
               | bnjms wrote:
               | People arguably cannot have integrity unless all other
               | companies they compete with also have integrity. The
               | answer is legislation. We have no reason to allow our
               | government to use "private" companies to do what they
               | cannot then turn over the results to government agencies.
               | Especially when willfully incompetence.
               | 
               | The same can be said of using "allies" to mutually snoop
               | on citizens then turning over data.
        
             | caminante wrote:
             | What are you talking about?
             | 
             |  _> I 'm sure there's some cryptographic way to avoid
             | Microsoft having direct access to the keys here._
             | 
             | FTA (3rd paragraph): don't default upload the keys to MSFT.
             | 
             |  _> If you design it so you don't have access to the data,
             | what can they do?_
             | 
             | You don't have access to your own data? If not, they can
             | compel you to reveal testimony on who/what is the next step
             | to accessing the data, and they chase that.
        
           | direwolf20 wrote:
           | "Good" companies in the old days would ensure they don't have
           | your data, so they don't have to give it to the police.
        
             | matheusmoreira wrote:
             | Plenty of companies would do that if they could. The
             | problem is it has become illegal for them to do that now.
             | KYC/AML laws form the financial arm of warrantless global
             | mass surveillance.
        
               | direwolf20 wrote:
               | KYC/AML is luckily still confined to the financial
               | sector. There's no law for operating system vendors to do
               | KYC/AML.
        
               | matheusmoreira wrote:
               | There is no law _yet_.
               | 
               | Where I live, government passed a similar law to the UK's
               | online identification law not too long ago. It creates
               | obligations for operating system vendors to provide
               | secure identity verification mechanisms. Can't just ask
               | the user if they're over 18 and believe the answer.
               | 
               | The goal is of course to censor social media platforms by
               | "regulating" them under the guise of protecting children.
               | In practice the law is meant for and will probably impact
               | the mobile platforms, but if interpreted literally it
               | essentially makes free computers illegal. The implication
               | is that only corporation owned computers will be allowed
               | to participate in computer networks because only they are
               | "secure enough". People with their own Linux systems need
               | not apply because if you own your machine you can easily
               | bypass these idiotic verifications.
        
               | direwolf20 wrote:
               | Which law is that?
        
               | matheusmoreira wrote:
               | Online Safety Act in the UK.
               | 
               | In Brazil, where I live, it's law 15.211/2025. It makes
               | it so that the tech industry must verify everyone's
               | identity in order to proactively ban children from the
               | harmful activities. It explicitly mentions "terminal
               | operating systems" when defining which softwares the law
               | is supposed to regulate.
        
           | thewebguyd wrote:
           | > I take it you've never worked at a company when law
           | enforcement comes knocking for data?
           | 
           | The solution to that is to not have the data in the first
           | place. You can't avoid the warrants for data if you collect
           | it, so the next best thing is to not collect it in the first
           | place.
        
             | scoofy wrote:
             | "But I forgot my password! You need to fix this!"
             | 
             | The technology exists to trivially encrypt your data if you
             | want to. That's not a product most people want, because the
             | vast majority of people (1) will forget their password and
             | don't want to lose their data, and (2) aren't particularly
             | worried about the feds barging in and taking their laptop
             | during a criminal investigation.
             | 
             | That's not what the idealists want, but that's the way the
             | market works. When the state has a warrant, and you've got
             | a backdoor, you're going to need to give the state the keys
             | to the backdoor.
        
             | amelius wrote:
             | Until the NSA knocks on your door and says encrypt it like
             | this.
        
           | morshu9001 wrote:
           | That's not the point. Microsoft shouldn't be silently taking
           | your encryption key in the first place. The law doesn't
           | compel them to do that.
        
             | smt88 wrote:
             | It's not silent. It tells you when you set up BitLocker and
             | it also allows you to recover the drive.
        
         | CodingJeebus wrote:
         | It's not about engineers being lazy, it's about money.
         | 
         | Trying to resist building ethically questionable software
         | usually means quitting or being fired from a job.
        
           | conception wrote:
           | No this is lazy. Microsoft shouldn't have access to your
           | keys. If they do, anyone who hacks Microsoft (again) also has
           | them.
        
           | kypro wrote:
           | I agree with you, but also think this is only true because we
           | as an industry have been so completely corrupted by money at
           | this point.
           | 
           | In the 90s and 00s people overwhelmingly built stuff in tech
           | because they cared about what they were building. The money
           | wasn't bad, but no one started coding for the money. And that
           | mindset was so obvious when you looked at the products and
           | cultures of companies like Google and Microsoft.
           | 
           | Today however people largely come into this industry and stay
           | in it for the money. And increasingly tech products are
           | reflecting the attitudes of those people.
        
         | smegger001 wrote:
         | it the natural results this site catter not just to tech nerds
         | but one chasing venture capital money. its an inudustry that
         | has never seen a dark patern it didn't like. we have gone from
         | "don't be evil" to "be evil if makes the stonks go up"
        
         | thinkingtoilet wrote:
         | Saying "of course" doesn't mean we agree with it or fail to try
         | to resist it. It's simply not surprising that this happened.
         | 
         | When you get high up in an org, choosing Microsoft is the
         | equivalent of the old "nobody ever got fired for buying IBM".
         | You are off-loading responsibility. If you ever get high up at
         | a fortune 500 company, good luck trying to get off of behemoths
         | like Microsoft.
        
         | egorfine wrote:
         | > This isn't an argument about law, it's about designing secure
         | systems
         | 
         | False. You can design truly end-to-end encrypted secure system
         | and then the state comes at you and says that this is not
         | allowed, period. [1]
         | 
         | [1] https://medium.com/@tahirbalarabe2/the-encryption-dilemma-
         | wh...
        
           | al_borland wrote:
           | I'd love to see companies stop service in countries that
           | request things like this, to put pressure on the governments
           | to not be scumbags.
        
           | direwolf20 wrote:
           | Another one: https://www.theguardian.com/australia-
           | news/2024/nov/05/sessi...
        
         | kccqzy wrote:
         | I don't see that at all. Instead, I think tech workers,
         | including the engineers and the product managers, are correctly
         | prioritizing user convenience over resistance to government
         | abuse. It's honestly the right trade off to make. Most users
         | worry about casual criminals, not governments. Say a criminal
         | snatching your laptop and accessing your files that way. If you
         | worry about governments you should already know what to do.
        
         | hmokiguess wrote:
         | I actually understood that as in "of course . . . because
         | Microsoft"
        
         | salawat wrote:
         | It's why tech loves young engineers who just do what their
         | told, of old engineers only as long as they can't say no. Once
         | you dig into the system and see how all the pieces fit
         | together, you can't ethically or morally continue to
         | participate any longer. Learned that the hard way. In the
         | middle of an attempt at midlife career change because of it to
         | maybe free myself to write software that needs to be written
         | instead of having to have a retained lawyer on hand to wrangle
         | employment contract clauses to keep my work belonging to me.
        
         | futuraperdita wrote:
         | > Too many tech workers decided to rollover for the government
         | and that's why we are in this mess now.
         | 
         | It has nothing to do with the state and has to do with getting
         | the RSUs to pay the down payment for a house in a HCOL area in
         | order to _maybe_ have children before 40 _and_ make the KPIs so
         | you don 't get stack-ranked into the bottom 30% _and_ fired at
         | big tech, or grinding 996 to make your investors richest _and_
         | you rich-ish in the process if you 're unlikely enough to exit
         | in the upper decile with your idea. This doesn't include the
         | contingent of people who fundamentally believe in the state,
         | too.
         | 
         | Most people are activists only to the point of where it begins
         | to impede on their comfort.
        
         | heresie-dabord wrote:
         | > Too many tech workers decided to rollover for the government
         | 
         | s/workers/Corporations/
        
         | p0w3n3d wrote:
         | yeah, every time someone says 'good, government must protect us
         | from terrorists', they need to remember that sometimes
         | govt := new_govt       terrorist := you
        
         | fzeroracer wrote:
         | Unfortunately there's a loud contingent of incredibly proud
         | idiots that post here as well that really like to pretend they
         | know what they're doing.
         | 
         | The people going 'well of course' or 'this is for the user'
         | drive me insane here because as said, there are secure ways you
         | can build a key escrow system so that your data and systems are
         | _actually_ secure. From a secure design standpoint it feels
         | more and more like we 're living in Idiocracy as people argue
         | insecure solutions are secure actually and perfectly
         | acceptable.
        
         | Spivak wrote:
         | This is such a lazy take and ignores that this is the only
         | system that has the property of not losing data when users
         | forget their passwords and lose (or likely never write down)
         | their recovery key.
         | 
         | That's it. That's the whole thing. Whatever "secure system" you
         | build will not have this property and users will lose their
         | data, be mad at you, and eventually you'll have to turn it off
         | by default leaving everyone's data in plaintext. It's a
         | compromise that improves security for people who previously
         | left their disk unencrypted. It changes nothing for people who
         | previously did their own key management.
         | 
         | You won't be able to turn the first group into the second
         | group. That's HN's "Average Familiarity" fallacy. The fact that
         | basically every 2FA system has a means of recovering your
         | account by removing it should tell you that even technical
         | people are shit at key management.
        
         | mihaaly wrote:
         | And too many tech workers decided to rollover for the big
         | companies too. Accepting and advocating whatever they do. Even
         | when it is tricky, can find the way to defend the big names,
         | because they are big names, they know the way, they became big!
        
         | PlatoIsADisease wrote:
         | I used to be a principled freedom fighter. But others
         | defected(thinking mostly about Apple users...). I promoted open
         | source software, even dealing with the pains.
         | 
         | So now I just use whatever I want. Someone else can be a tech
         | moralist.
        
         | raincole wrote:
         | The resistance is to switch to Linux.
        
         | pessimizer wrote:
         | > Too many tech workers decided to rollover for the government
         | and that's why we are in this mess now.
         | 
         | It isn't really about the government. It's about a bunch of
         | people trying to convince you that the locked-down proprietary
         | closed source corporate crap that they use isn't _in and of
         | itself_ a security risk, no matter what the quality of the code
         | _that you 've never seen_ is. Apple, Microsoft, Google etc.
         | aren't your friends; no matter how brand loyal you are, they'll
         | never care whether you're alive or dead.
         | 
         | FOSS isn't your friend either, but they're not asking you to
         | trust them. Any exposure to these world spanning juggernaut
         | military and intelligence contractor companies is a security
         | hole. It's insane that people (thinking of Europeans now) get
         | fired up to switch from this stuff because _Trump_ but not
         | because _of course you should._ Instead they 're busy calling
         | being suspicious of Microsoft _old_ and hatred of Apple 's
         | customer corral _stuck up_ and the desire to own your own
         | machine _fanatical_ and _judgemental_. Have you ever considered
         | that you 've been programmed to say and encourage dumb stuff
         | that is completely against your own interests and supports the
         | interests of the people who sell things to you?
         | 
         | You're convinced by the argument that people dumber than you
         | have to be protected from their own machines (by corporations
         | who have no interest in or obligation to protect them) - have
         | you ever thought that people are saying the same thing about
         | you? That you have to be protected from writing things you
         | shouldn't write or talking to people you shouldn't be talking
         | to? And the world isn't a meritocracy: the people on the top
         | are inbred creeps. You've given up your freedom to dummies with
         | marketing departments.
        
         | concinds wrote:
         | The median user's threat model doesn't include the government,
         | but does include data loss, forgetting the password, or a thief
         | stealing your laptop. Microsoft struck the right balance.
         | 
         | I'm glad the knee-jerk absolutists are marginal, for one. A
         | world run by you people would be much worse for anyone who
         | isn't you.
        
           | ok_dad wrote:
           | Today the median users threat model absolutely includes the
           | government! They are snatching people up left and right,
           | including their electronics.
           | 
           | I don't get how people like you trust the corporation or the
           | government that much. If we were all more cognizant of
           | security and privacy, it would be much harder for large orgs
           | to break our society the way they are doing today.
        
           | beeflet wrote:
           | The median user would be better off in a society where
           | computers are not needed for daily life. The median user
           | doesn't understand computers. In their life, computers only
           | manfiest as a tool of control imposed by the people who
           | understand computers over those that don't.
           | 
           | This is one such example.
           | 
           | This sort of utilitarian nitpicking over the convenience of a
           | "median" user is like maximizing the happiness of a cow on a
           | factory farm. The cow would be better off if it did not exist
           | at all. It is a matter of freedom and dignity.
        
       | aeternum wrote:
       | Not your keys not your {thing}
        
       | observationist wrote:
       | Hear that? It's the sound of the year of the Linux desktop.
       | 
       | It's time - it's never been easier, and there's nothing you'll
       | miss about Windows.
        
         | tombert wrote:
         | I've been trying to get my parents to move, but until Microsoft
         | Office _desktop_ is able to be run natively on there my parents
         | won 't entertain the subject.
         | 
         | I've tried to get them to use the web version of office, I've
         | tried to get them to use OnlyOffice and LibreOffice, I've even
         | tried showing them LaTeX as a last ditch effort, but no, if it
         | isn't true Microsoft Branded Office 2024, the topic isn't even
         | worth discussing [1].
         | 
         | I'm sure there are technical reasons why Wine can't run Office
         | 2024, and I am certainly not trying to criticize the wine
         | developers at all, but until I can show Wine running full-fat
         | MS Office, my parents will always "miss" Windows.
         | 
         | To be clear, I _hate_ MS Office. _I_ do not miss it on Linux. I
         | 'm pretty sure my parents could get by just fine with
         | LibreOffice or OnlyOffice or Google Docs, but they won't hear
         | it.
         | 
         | I've also tried to get them to use macOS, since that does have
         | a full-fat MS Office, I've even offered to buy them Macbooks so
         | they can't claim it's "too expensive", and they still won't
         | hear it. I love my parents but they can be stubborn.
         | 
         | [1] Before you accuse me of pushing for "developer UI", LaTeX
         | was _not_ something I led with. I tried the more  "normy-
         | friendly" options first.
        
           | rz2k wrote:
           | I use macOS most of the time, but switch to a Windows VM for
           | Excel. Without the same keyboard shortcuts, the macOS version
           | ends up having a fraction of the power available to
           | experienced users of the Windows version. For people who use
           | Excel extensively, LibreOffice or Google Sheets would have to
           | offer some remarkable new killer features to make it worth
           | the switch. I don't think feature parity alone would make the
           | benefits of Linux outweigh the significant transition costs.
        
           | observationist wrote:
           | Is your last name Segurakreischer? Have them try - leave the
           | Windows computer online and accessible, give your parents a
           | linux box and have them use it exclusively unless they
           | absolutely 100% need to get back on the Windows machine for
           | some reason, and talk with you about it. Set up a NAS with an
           | external HD and a shared folder on both the windows and linux
           | box, so if they actually do need to go back to Windows, they
           | aren't leaving anything stuck on the Linux box.
           | 
           | That's a 100% easy peasy safe mode, the worst they're likely
           | to encounter is a brief 2 minute call with you, and in the
           | worst case scenario, they get to go back to Windows without
           | having to be scared of losing anything.
        
         | PlatoIsADisease wrote:
         | Just remember, never use or recommend Debian-
         | family(Ubuntu/Mint) or you will be back to windows. Do not fall
         | for the marketing term Stable, which means outdated and
         | contains bugs that are fixed.
         | 
         | Fedora is my recommendation. I remind people Fedora is _not_
         | Arch. Fedora is a consumer grade OS that is so good, I don 't
         | lump it in with the word Linux.
        
           | observationist wrote:
           | Once you've got a bit of savvy, do Arch. But if you're
           | looking for "good" and "just works" and you don't want to
           | tinker and/or occasionally scream at your computer in
           | inchoate fury, Fedora is the way.
           | 
           | You can build your ideal fantasy setup piecewise, and I
           | definitely recommend getting there, but Fedora is nice, and
           | clean, and has plenty of "just works", and 99.999% of the
           | problems you might run into, someone else has, too, and they
           | wrote a treatise and tutorial on how to fix it and why it
           | happened.
        
       | g947o wrote:
       | So, forcing user to connect to Internet and log in to Microsoft
       | account has more to do than tracking you and selling ads --
       | Microsoft may be intentionally helping law enforcement unlocking
       | your computer -- and that's not a conspiracy.
        
       | ChrisArchitect wrote:
       | [dupe] Discussion on source:
       | https://news.ycombinator.com/item?id=46731694
        
       | axus wrote:
       | Here's a story about what the FBI may do when they don't unlock
       | the laptop:
       | 
       | https://cointelegraph.com/news/fbi-cant-be-blamed-for-wiping...
       | 
       | Perhaps next time, an agent will copy the data, wipe the drive,
       | and say they couldn't decrypt it. 10 years ago agents were
       | charged for diverting a suspect's Bitcoin, I feel like the
       | current leadership will demand a cut.
        
       | alexfromapex wrote:
       | I don't know how many bad things Microsoft has to do before
       | consumers realize they are a terrible company and you should stop
       | buying their stuff.
        
       | uriegas wrote:
       | The problems of centralization. Some economic sectors are
       | centralized by nature, IT is not.
        
       | MattSteelblade wrote:
       | Based on the comments in the thread, I sense I will be in the
       | minority, but for most consumers this is a reasonable default.
       | Broadly speaking, the threat model most users are concerned with
       | doesn't account for their government. The previous default is no
       | encryption at rest, which doesn't protect from the most common
       | threats, like theft or tampering. With BitLocker on, a new risk
       | for users is created: loss of access to their data because they
       | don't have their recovery key. You are never forced to keep your
       | recovery keys in Microsoft's servers and it's not a default for
       | corporate users.
        
         | nancyminusone wrote:
         | I'll always remember - when I was first learning about it, one
         | of the interesting counter-arguments to ignoring privacy was
         | "what if the Nazis come back, would you want them to have your
         | data?". I suppose there's some debate these days, but hostile
         | governments seem a lot closer than they were 10-15 years ago.
         | 
         | Will this make people care? Probably not, but you never know.
        
           | burnt-resistor wrote:
           | "Closer"? They're already here. Trusting corporations or
           | governments is inherently moronic.
        
             | pessimizer wrote:
             | Even in the best of times. Why widen your attack surface
             | unnecessarily? Do you tell people your passwords and PINs
             | at parties?
             | 
             | What governments and corporations (and plenty of bad actors
             | in the FOSS world) have done is make this the default; made
             | it easy to mindlessly hand people your privacy without even
             | knowing. Opt-out, if you know the setting exists, and can
             | find it.
        
         | Avamander wrote:
         | It's certainly a reasonable default. People lose or have their
         | laptops stolen much more often than they get targeted by their
         | governments.
         | 
         | Though that doesn't mean Microsoft couldn't implement a way of
         | storing these keys so that they can't be accessed by Microsoft.
         | Still better than nothing though.
        
       | t1234s wrote:
       | If you use a local windows account does it still upload your
       | bitlocker key to M$?
        
         | masfuerte wrote:
         | No, and by default the keys are stored on the disk so it's not
         | actually secure.
         | 
         | If you open the BitLocker control panel applet your drive(s)
         | will be labelled as "Bitlocker waiting for activation".
        
           | mmmlinux wrote:
           | Oh? Do tell how to retrieve those insecure keys. I have an
           | old laptop I would love to get access to again.
        
       | diego_moita wrote:
       | This isn't even about Microsoft or BitLocker. This is about the
       | U.S.A.: anyone who thrusts the rule of law in the U.S. is a fool.
       | 
       | Yes, the American government retrieves these keys "legally". But
       | so what? The American courts won't protect foreigners, even if
       | they are heads of state or dictators. The American government
       | routinely frees criminals (the ones that donate to Republicans)
       | and persecutes lawful citizens (the ones that cause trouble to
       | Republicans). The "rule of law" in the U.S. is a farce.
       | 
       | And this is not just about the U.S. Under the "five eyes"
       | agreement, the governments of Canada, UK, Autralia and New
       | Zealand could also grab your secrets.
       | 
       | Never trust the United States. We live in dangerous times. Ignore
       | it at your own risk.
        
       | gethly wrote:
       | it's like microsoft has nothing better to do other than keep
       | digging the hole to burry windows as mainstay operating system
       | deeper and deeper with every new day.
        
       | AmazingTurtle wrote:
       | I have opted out of all cloud services in my windows
       | installation; I use a passphrase, too (it is even before booting
       | the computer). I feel like this is pretty safe
        
         | knowitnone3 wrote:
         | except MS could easily turn something on without you knowing
         | and be uploading your files to their cloud. Yes, I believe they
         | would stoop that low and even lower.
        
       | mmooss wrote:
       | > Johns Hopkins professor and cryptography expert Matthew Green
       | raised the potential scenario where malicious hackers compromise
       | Microsoft's cloud infrastructure -- something that has happened
       | several times in recent years -- and get access to these recovery
       | keys.
       | 
       | Bitlocker isn't serious security. What is the easiest solution
       | for non-technical users? Does FDE duplicate Bitlocker's
       | funcationality?
        
       | estimator7292 wrote:
       | My Linux drives are all encrypted, and one of the wonderful
       | features of this is that there is no entity or force on this
       | planet that can decrypt them.
       | 
       | What happens if I forget my keys? Same thing that happens if my
       | computer gets struck by a meteor. New drive, new key, restore
       | contents from backups.
       | 
       | It's simple, secure, set-and-forget, and absolutely nobody but me
       | and your favored deity have any idea what's on my drives.
       | Microsoft and the USGov don't have any business having access to
       | my files, and it's completely theoretically impossible for them
       | to gain access within the next few decades.
       | 
       | Don't use Windows. Use a secure operating system. Windows is not
       | security for you, it's security for a hostile authoritarian
       | government.
        
         | deejaaymac wrote:
         | I wish there was more people like you and me.
         | 
         | Privacy is not a crime.
        
           | NegativeK wrote:
           | I wish people didn't have to be like us to have privacy.
        
         | tombert wrote:
         | Yeah, if the drive can be encrypted by an external party that
         | you didn't give permission, I'm not sure how it's really
         | "encryption" other than burning cycles when doing writes.
        
         | digiown wrote:
         | It's a good start, but FDE alone is still fairly easy to
         | compromise in many cases. If you ever type the password under a
         | camera, it may be leaked. If the device ever leaves your
         | possession and you don't have secure boot, your bootloader can
         | be trivially altered to leak the password. Then there are
         | keyloggers. And cold boot attacks can often be done if your
         | system is running.
        
       | exabrial wrote:
       | The US Government has quickly realized the utility of monopolies
       | and no longer goes after them.
        
       | mawise wrote:
       | I consider myself pretty pro-privacy, but there is so much
       | dragnet surveillance and legitimate breaches of the fourth
       | amendment that I have a hard time getting up in arms over a
       | company complying with a valid search warrant that is scoped to
       | three hard drives (and which required law enforcement to have
       | physical possession of the drives to begin with).
       | 
       | This is so much more reasonable than (for example) all the EU
       | chat control efforts that would let law enforcement ctrl+f on any
       | so-called private message in the EU.
        
       | gdevenyi wrote:
       | What was the point of mandatory TPM then? I thought they were
       | storing the keys securely there!
        
         | layer8 wrote:
         | Keys are stored securely in a TPM in the sense that a random
         | program has no access to it. They are not stored safely there
         | in the sense that they couldn't possibly get destroyed. TPM
         | hardware, or the motherboard that hosts it, occasionally fails.
         | Or you might want to migrate your physical hard drive to a
         | different PC. That's the purpose of backing up the keys to the
         | cloud. Alternatively, you can write down a recovery key and put
         | it in your safe. Personally, I put it in my password vault that
         | also happens to be backed up to the cloud (though not
         | Microsoft's).
        
       | kmoser wrote:
       | > The hackers would still need physical access to the hard drives
       | to use the stolen recovery keys.
       | 
       | Or remote access to the computer. Or access to an encrypted
       | backup drive. Or remote access to a cloud backup of the drive. So
       | no, physical access to the original hard drive is not
       | _necessarily_ a requirement to use the stolen recovery keys.
        
       | cmurf wrote:
       | I'm certain I should encrypt my data, backup all LUKS headers,
       | and backup all data.
       | 
       | But what about unsophisticated users? In aggregate it might be
       | true data exfiltration is worse than data loss? I don't know if
       | that's true.
       | 
       | But what is true is enabling encryption by default without
       | automated backup and escrow will lead to some data loss.
       | 
       | It's difficult for me to separate the aggregate scenarios from
       | individual scenarios. The individual penalty of data loss can be
       | severe. Permanent.
        
       | aeon_ai wrote:
       | Hello there!
       | 
       | Have you heard of our lord and savior, Linux?
        
       | tamimio wrote:
       | In the year of 2026, the rule of thumb is if you can get your
       | work done without touching windows, then you should. It goes
       | without saying you should never trust any third party let alone a
       | big corp.
        
       | citizenpaul wrote:
       | Relevant XKCD
       | 
       | https://xkcd.com/538/
        
       ___________________________________________________________________
       (page generated 2026-01-23 23:00 UTC)