• empireOfLove2@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    18 days ago

    So, this means Microsoft has copies of every single bitlocker key, meaning that a bad actor could obtain them… Thereby making bitlocker less than worthless, it’s an active threat.
    MS really speedrunning worst possible software timeline

    • dual_sport_dork 🐧🗡️@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 days ago

      They don’t have a copy of every single Bitlocker key. They do have a copy of your Bitlocker key if you are dumb enough to allow it to sync with your Microsoft account, you know, “for convenience.”

      Don’t use a Microsoft account with Windows, even if you are forced to use Windows.

      • tabular@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 days ago

        To use Windows without a Microsoft account requires tech literacy these days, I thought. I would not be suprised if users didn’t choose to sync with a MS account but it’s doing it anyway, if that’s what MS want.

    • x0x7@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 days ago

      Microsoft is already a bad actor and they have them. Or a bad actor could threaten microsoft physically and microsoft will hand them over. Wait, that already happened.

    • bw42@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      18 days ago

      No they do not have copies of every Bitlocker key.

      Bitlocker by default creates a 48-bit recovery code that can be used to unlock an encrypted drive. If you run Windows with a personal Microsoft account it offers to backup that code into your Microsoft account in case your system needs recovered. The FBI submitted a supoena to request the code for a person’s encrypted drive. Microsoft provided it, as required by law.

      Bitlocker does not require that key be created, and you don’t have to save it to Microsoft’s cloud.

      This is just a case of people not knowing how things work and getting surprised when the data they save in someone else’s computer is accessed using the legal processes.

      • user28282912@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        18 days ago

        Except that Microsoft basically puts a gun to every users head to login with a Microsoft account which can/does backup the recovery keys.