BitLocker? More like ShitLocker.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
BitLocker provides for a recovery key. This is to allow someone to regain access to an encrypted device in the event that they lose their PIN, any one of these scenarios happen, OR when suspects do not want to cooperate with LEOs.
Find your BitLocker recovery key
If the target device is part of an enterprise and managed with EntraId/Intune this is the option. Escrowed keys.
Just as I expected how security in Microsoft products works.
Remember when Truecrypt got suspiciously terminated? That was the goal
Microslop is openly anti consumer. Why would you hand them your encryption keys?
Well, since you don't actually enter a password to decrypt a bitlocker device, you can intercept the key data with physical connectors to the TPM
Bitlocker just makes it slightly more tedious to retrieve data. As long as you have all other components intact aswell.
I'm just wondering how many devices still use dedicated TPMs, instead of the ones integrated in the SoC by AMD and Intel. Sniffing a bus inside the SoC must be significantly harder or impossible.
Regular old ZIP with AES-256 should do the trick for anything truly important you want to keep locked down.
You could always do sly stuff like Hidden volumes with Veracrypt as well. Leave the crumb trail for the low key shit or old nudes of gfs you have permission to keep.
So how did Microsoft have the keys in the first place? The article says they are automatically uploaded to the cloud. What does that mean? They're uploaded to the user's on drive or something else? Because whatever that user account is shouldn't be accessible by Microsoft, even if they run the service. I'm not saying aim surprised they do have it, but would be nice to be a little clearer about what features of Bitlocker to avoid. Is it the Microsoft account associated with the windows key? Probably.
Did you read the news about how nowadays is almost impossible to use Windows 11 without a Microsoft account?
When/if any user uses the computer with a Microsoft account, then the bitlocker decryption key is silently and automatically uploaded to Microsoft servers as a "safe backup" 😉
