• bw42@lemmy.world
    link
    fedilink
    English
    arrow-up
    51
    arrow-down
    5
    ·
    2 days ago

    No they do not have copies of every Bitlocker key.

    Bitlocker by default creates a 48-bit recovery code that can be used to unlock an encrypted drive. If you run Windows with a personal Microsoft account it offers to backup that code into your Microsoft account in case your system needs recovered. The FBI submitted a supoena to request the code for a person’s encrypted drive. Microsoft provided it, as required by law.

    Bitlocker does not require that key be created, and you don’t have to save it to Microsoft’s cloud.

    This is just a case of people not knowing how things work and getting surprised when the data they save in someone else’s computer is accessed using the legal processes.

    • user28282912@piefed.social
      link
      fedilink
      English
      arrow-up
      44
      arrow-down
      3
      ·
      2 days ago

      Except that Microsoft basically puts a gun to every users head to login with a Microsoft account which can/does backup the recovery keys.

      • Agent641@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        5
        ·
        2 days ago

        This is why we Jason Bourne style snatch the gun out of their holster before they can draw it and beat them unconcious with it, I mean oobe\bypassnro

          • Creat@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 days ago

            It no longer works as a shortcut, but the actual bypass still works. In practice the command line you have to enter just got a bit longer is all.

            At least last time I needed it, to that still worked fine. It’s been a few months.

    • greybeard@feddit.online
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 days ago

      If you sign into a Microsoft account during setup, Microsoft automatically turns on bitlocker and sends the key off to Microsoft for safe keeping. You are right, there are other ways to handle bitlocker, but that’s way beyond most people, and I don’t think Microsoft even tells you this during setup. It’s honestly a lifesaver for when bitlocker breaks(and it does), but it comes at a cost. In the business world, this is seen as a huge benefit, as we aren’t trying to protect from the US government, mostly petty theft and maybe some corporate espionage.

      As is often the case, the real solution is Linux, but that, too, is far beyond most people until manufacturers start shipping Linux machines to big box stores and even then they’d probably not enable any encryption.