Do not store your Bitlocker encryption keys on Microsoft's servers if your threat model includes governments or law enforcement. As this article points out, this is the result of a design choice Microsoft made. It didn't have to be this way.
reshared this
evacide
in reply to evacide • • •reshared this
cyplo, Irenes (many), webhat and FurballsNHairballs reshared this.
Kluthulhu' XOR 1=1--
in reply to evacide • • •René Mayrhofer 🇺🇦
in reply to evacide • • •Or, because this is Microsoft we are talking about, anyone who shows up virtually with a golden authentication ticket they got through an official API surface because Azure security is a mess...
Having encryption keys stored in plaintext on any cloud service is just a completely irresponsible and bonkers design.
Marius (windsheep)
in reply to evacide • • •Sveinn í Felli
in reply to evacide • • •🤔
Net Gremlin 🚴🏻 🐧 🇩🇪 🇪🇺
in reply to evacide • • •Kris Hardy
in reply to evacide • • •Asta McCarthy
in reply to Kris Hardy • • •VeraCrypt - Free Open source disk encryption with strong security for the Paranoid
veracrypt.ioAsta McCarthy
in reply to evacide • • •loStronzoRocco
in reply to Asta McCarthy • • •Todd Heberlein (social)
in reply to evacide • • •The Trump era has shown “government or law enforcement” should *always* be in your threat model.
The US is not alone in this. Lots of governments have been pushing boundaries.
Tommaso Gagliardoni
in reply to evacide • • •Shufflecake
shufflecake.netDan reshared this.
Byrnensorg🇮🇪🇺🇦🇵🇸🇬🇱🇩🇰
in reply to evacide • • •Drahflow
in reply to evacide • • •H.Lunke & Socke
in reply to evacide • • •Jamie :3 🏳️⚧️
in reply to H.Lunke & Socke • • •Jamie :3 🏳️⚧️
in reply to evacide • • •BoloMKXXVIII
in reply to evacide • • •Hordearius
in reply to evacide • • •Jona Joachim
in reply to evacide • • •Ameise
in reply to evacide • • •#FOSS
GhostOnTheHalfShell
in reply to evacide • • •`Da Elf
in reply to GhostOnTheHalfShell • • •@GhostOnTheHalfShell Whsat, I've been talking to myself for the last quarter century? (The answer is yes, it's always been yes. ... "Yes Elf, you're a grumpy old man shaking his fist ineffectually at Redmond (or in that shithole when I lived there) and none of us are listening to you ... even though there's overwhelming evidence you are correct, we just don't care. Now, what was my license key?"
I gave up years ago. Wanna shoot yourself with MS products? Go Ahead! No skin off my teeth.
GhostOnTheHalfShell reshared this.
GhostOnTheHalfShell
in reply to `Da Elf • • •There are a great number of people who resemble that statement (old bitter cassandras)
`Da Elf
in reply to GhostOnTheHalfShell • • •@GhostOnTheHalfShell Nobody listens to them either.
Just a bunch of old grumps.
But now I can add "I told you so" to my grumpy old man shtick.
GhostOnTheHalfShell
in reply to `Da Elf • • •One more for the bucket list
PKs Powerfromspace1
in reply to evacide • • •gunstick
in reply to evacide • • •dragonfrog
in reply to evacide • • •In principle that would also include anyone who knows my email address and can set up a phishing website, right?
Government agencies need whatever a valid warrant is in their jurisdiction, but a user just has to log in to their account and click through the "I forget my Bitlocker password" workflow.
So someone who knows me, or stole my laptop bag with my business cards in it, knows who to phish to get into an account likely to have my recovery key, right?
Quinn9282 🖥️🌙✌️
in reply to evacide • • •Jeff Turner ⛵
in reply to Quinn9282 🖥️🌙✌️ • • •fuzzyfuzzyfungus
in reply to evacide • • •MyView
in reply to evacide • • •mikeTesteLinuxQlub
in reply to evacide • • •Simply deactivate Bitlocker. Bad by design and a gate wide open to lock YOU OUT.
Just use Veracrypt or something like that on a second drive ou usb stick to protect the very sensible data......and at least, deactivate Bitlocker, that force windows recall or whatever is name to deactivate too.
Tanquist reshared this.
Paco (2026: New) Hope
in reply to evacide • • •“#Microsoft says it will provide encryption keys for Windows PC data protected by BitLocker where it has access to them and it's received a valid warrant.”
The word “valid” sure is doing a lot of work there. This is the most corrupt DoJ and FBI in generations. One that ignores court rulings that it disagrees with. So what way is the warrant “valid”? Syntactically? Grammatically? Because if we get any deeper, like morally or ethically, the argument gets harder to make.
x41h
in reply to evacide • • •Oliver
in reply to evacide • • •Natalie Esmerelda
in reply to evacide • • •Yan
in reply to evacide • • •reindeerphoto
in reply to evacide • • •Do not use software from a fascist regime.
Paolo Redaelli
in reply to evacide • • •DFX4509B (Joshua Mason)
in reply to evacide • •