I was wondering when a reporter would uncover this.
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog @zzt Don't worry, soon copilot will upload EVERYTHING to the cloud anyway, so law enforcement won't need those keys!
-
@GossiTheDog Unfortunately, not *just* valid ones.
@shelldozer @GossiTheDog Wouldn't it be crazy if someone generated a million keys for LE to try?
-
@GossiTheDog is it not the case that the only way to avoid this is to use Windows Professional, or have they changed that with Windows 11 as well?
@gwire @GossiTheDog I believe you only get the GUI on Professional, but you can set up bitlocker manually with local protectors on Home using the command-line. At least in Windows 10.
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@bert_hubert @barbarakathmann Zelfs je bitlocker key is niet veilig in #amerika #usa #microsoft willing to engance in support #fascism
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog No, I don't consider BitLocker to be super secure at all, frankly. 🐻 😅
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog SO many parts of bitlocker setup just screamed "dark pattern" and "we can access your data, but lol no we won't help you recover it", last time I tried to set it up. and then they locked a ton of the actually-decent stuff away from Home users, because consumers don't deserve safety.
Microsoft is a vile company.
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@serrebi @GossiTheDog If the FBI has a warrent and they sapena a company for access to data, microsoft feels it's obligated.
-
@GossiTheDog I don’t understand putting your trust in black box proprietary encryption software when TrueCrypt/VeraCrypt exist and are older than BitLocker by 3 years, stupid doesn’t even begin to describe it.
@gsprs @GossiTheDog they also work on ALL hardware, not just ones that Microsoft feels like supporting / have specific TPM features.
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/From my knowledge, the following is true: sign in with MS account will store encryption key. It can be deleted. But is anything cloud really deleted?
Setting up computer as a local machine, from what I know, does not sync encryption keys. They change things frequently and I don’t trust MS, so still use caution.
Setting up a machine on Active Directory in an enterprise setting allows bit locker keys to be written to Active Directory, but I don’t believe it is enabled OOB.
-
It's not just the FBI, btw - MS accepts valid law enforcement request internationally. Also it's not just BitLocker.
@GossiTheDog Time to get a Yubikey and see if they can get around that as a last line of defense. That's if you have admin and can install it yourself. No Yubikey? Good Luck with trying to enter that stupid bit -ocker recovery code. Ask me how I know. I FAFO'D
-
@GossiTheDog SO many parts of bitlocker setup just screamed "dark pattern" and "we can access your data, but lol no we won't help you recover it", last time I tried to set it up. and then they locked a ton of the actually-decent stuff away from Home users, because consumers don't deserve safety.
Microsoft is a vile company.
@groxx @GossiTheDog what?? Apple does the same thing which is why nobody should be using cloud accounts on their devices.
-
@groxx @GossiTheDog what?? Apple does the same thing which is why nobody should be using cloud accounts on their devices.
@x41h @GossiTheDog you don't need an Apple account to set up a Mac.
(at least, last I did it, and still true as far as I can find from a brief search)
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog shocking..
-
@GossiTheDog Time to get a Yubikey and see if they can get around that as a last line of defense. That's if you have admin and can install it yourself. No Yubikey? Good Luck with trying to enter that stupid bit -ocker recovery code. Ask me how I know. I FAFO'D
@carpetbomberz @GossiTheDog yubi for what?
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog Isn't bitlocker flawed, though? I remember hackers demonstrating bitlocker bypass when recovering Windows.
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog@cyberplace.social Rob Braxman Tech covered this a few months ago.
-
@GossiTheDog You can save Key as a file.
@niknukem @GossiTheDog Which most average users will not. Or if they do, they lose the file before need arises. I mean I hate Microsoft and all the forced cloud stuff, but recovery is a hard problem to solve user-friendly.
-
@niknukem @GossiTheDog Which most average users will not. Or if they do, they lose the file before need arises. I mean I hate Microsoft and all the forced cloud stuff, but recovery is a hard problem to solve user-friendly.
@niknukem @GossiTheDog To put it other way around, having recovery keys automatically stored in Microsoft cloud has probably made A LOT of people happy they could recover their data. A much smaller group is unhappy that Microsoft shared their keys with the spooks.
-
@GossiTheDog
How to cancel bitlocker on Linux?@beastfellow @GossiTheDog remove cryptsetup package
-
I was wondering when a reporter would uncover this.
So BitLocker is super secure, right? Well... BitLocker recovery keys are backed up to Microsoft's Cloud - and they give them out to law enforcement on request. Using the BitLocker recovery key, you can just unlock the device without a PIN etc.
https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/@GossiTheDog Isn't this the default-on-consumer-devices "Device Encryption" branded BitLocker which syncs the recovery key to your MS account and you can view it there if you need it, rather than BitLocker-branded BitLocker that you enable in the legacy control panel and/or with group policies (the latter including options to sync keys to AD and whatever)?
Not that they couldn't grab the key in the latter case too since stealing all the data is totally fine in the AI era, but I think the latter would be somewhat more scandalous than giving the feds the key that you kinda-knowingly already sent to Microsoft.