frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Microsoft Gave FBI Keys to Unlock Encrypted Data, Exposing Major Privacy Flaw

https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/
62•_____k•2w ago

Comments

fuzzfactor•2w ago
You all did know that the idea of a Microsoft account was a security & privacy compromise from day zero of its conception, right?
jqpabc123•2w ago
Yes; and none of my computers have one. Contrary to popular myth, it is relatively easy to install Win11 Pro without one.
josephcsible•2w ago
A constant cat-and-mouse game of Microsoft disabling every method to do so as soon as they become somewhat popular is not "relatively easy".
jqpabc123•2w ago
Really? I haven't had any problems, even with computers that don't meet the official hardware requirements.

Download the Win11 Pro ISO, extract it to a USB drive and then execute the command below from it for a totally automated install that bypasses all the BS.

.\setup.exe /product server /auto upgrade /EULA accept /migratedrivers all /ShowOOBE none /Compat IgnoreWarning /Telemetry Disable

You're welcome!

PS: I know it says "server" but when upgrading a desktop machine, desktop is what you will get --- minus a lot of BS.

josephcsible•2w ago
I believe you that that way works today, but once knowledge of it starts to spread, I expect Microsoft to break it, just like they previously broke Shift+F10 "oobe\bypassnro" and "start ms-cxh:localonly".
jqpabc123•2w ago
It has worked all along and MS can't break it because I have the ISO that it works with.

It's unlikely it can be broken without totally abandoning the server market and disrupting a lot of existing installations --- which would be a marketing disaster.

alt227•2w ago
There will always be a way to create local accounts in Windows because they are intrinsic to how windows actually works.
josephcsible•2w ago
There may always be a way, but every few months the existing way will stop working and people will need to discover a new way.
alt227•1w ago
Thats exactly my point, they will keep closing loopholes but they will never truly stop people doing it without removing local accounts completely, which they cant do.
jmclnx•2w ago
Well I would say this should be true for most people here. I expect the same for Apple too. The big question is, when will these keys hit the wild ? Since they exist, eventually they will get out there.

We all know, if you want real security, there are much better OSs.

dagmx•2w ago
Why would you expect Apple to have the keys? They famously fought the FBI on the grounds of not having access to the keys themselves.

Good engineering practices say that you shouldn’t even find yourself in the position of having the keys.

And what “better OS” pushes you to encrypted drives on setup? Most Linux distros don’t.

jqpabc123•2w ago
... does not possess the forensic tools to break into devices encrypted with Microsoft BitLocker

Nice intel to have. Now, all that is needed for reasonable security is to avoid storing the key in the cloud. Duhhh.

Basic rule: Not your hardware (computer/drive), not your data.

Never store anything on someone else's hardware that you need to maintain full control over.

But, but, but encryption? It helps but encryption does not guarantee full access when you don't control the hardware.

OptionOfT•2w ago
They don't have the tools but for 99% of the people who have laptop with device encryption, they mandate Microsoft Accounts, and guess where the keys are uploaded to? Thats right, https://aka.ms/recoverykey.

You don't need to build backdoors when you store a copy of the key.

jqpabc123•2w ago
they mandate Microsoft Accounts

I don't use these. See post below.

general1465•2w ago
> Nice intel to have. Now, all that is needed for reasonable security is to avoid storing the key in the cloud. Duhhh.

You can go one step further. Encrypt your computer, store keys on the cloud, then encrypt your computer again but store keys into a file. You can see key ID on Microsoft Live account. Now you won't even look suspicious.

romanovcode•2w ago
The flaw is that they had those keys to begin with. What's the point of encryption if key is available and free to use? Same with iCloud Email.

Privacy cannot come from human-made laws and regulations because they get abused on they change. Privacy comes from mathematics which do not care for laws and regulations.

dogma1138•2w ago
The main threat model here is a stolen/lost device or an unscrupulous repair shop not a government agency with a warrant.

You also do not have to backup keys in the cloud, however for most users it’s the best solution since for them data recovery in case of a hardware failure is more important than resiliency against state level adversaries.

toomuchtodo•2w ago
I am an Apple ecosystem lifetime participant. I have recovery and legacy contacts. What I would love is for those contacts to have the encryption key(s) for my data shared with them so they can provide me with recovery options if needed, but Apple cannot.

Certainly, nation state actors could pursue those people to obtain access to key material, but that is a different hill to climb than simply sending requests to Apple, especially for contacts outside of the jurisdiction or nation state reach. Perhaps Shamir's secret sharing would be a component of such an option (you need X out of Y trusted contacts to recover, 2 out of 3 for easy mode, 3 out of 5 for hard mode).

eddyg•2w ago
Don't include iCloud in this.

https://www.youtube.com/watch?v=BLGFriOKz6U&t=1993s

dogma1138•2w ago
Apple can recover your keys also unless you enable ADP.

With MSFT cloud backup of keys is an opt-in. With Apple it’s an opt-out.

romanovcode•2w ago
I will include iCloud in this because their email has nothing to do with ADP and is accessible by any agency that would ask.
dogma1138•2w ago
Mailbox encryption is near pointless since at the least it needs to be encrypted at both ends not to mention relays.

For email each individual message should be encrypted if you want any confidentiality and even then the meta data is in the clear.

And this is because in order to send or receive an email the provider needs to access it. If they put it into a box later on to which they do not hold the key that is just security theater at that point.

alt227•2w ago
Dude thats from 9 years ago.

A lot has changed since then and it is common knowledge that Apple regularly give government agencies access to their systems and hides it from the public until a whistleblower leaks it.

https://www.reuters.com/technology/cybersecurity/governments...

In a statement, Apple said that Wyden's letter gave them the opening they needed to share more details with the public about how governments monitored push notifications. "In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests."

OutOfHere•2w ago
The part that I was shocked to read is that Apple is equally unsafe.
jqpabc123•2w ago
Just wait until you discover that Apple is not so private either.

https://appleinsider.com/articles/22/11/12/apple-getting-sue...

https://slnt.com/blogs/insights/is-apple-selling-data-find-o...

dogma1138•2w ago
You can enable ADP (unless you’re in the UK) and then they can’t recover the key either. But the risk then is that if you lose the device your data is gone for good (unless you have a backup and that opens you up for a whole other list of potential threats).
OutOfHere•2w ago
Oh I would never use iCloud. The concern is more about Apple's full disk encryption.

Regarding my own encrypted backups, the choices there are so diverse that Apple doesn't factor in.

cf100clunk•2w ago
https://archive.ph/0OaJ9

We Mourn Our Craft

https://nolanlawson.com/2026/02/07/we-mourn-our-craft/
185•ColinWright•1h ago•168 comments

I Write Games in C (yes, C)

https://jonathanwhiting.com/writing/blog/games_in_c/
22•valyala•2h ago•6 comments

Hoot: Scheme on WebAssembly

https://www.spritely.institute/hoot/
124•AlexeyBrin•7h ago•24 comments

SectorC: A C Compiler in 512 bytes

https://xorvoid.com/sectorc.html
17•valyala•2h ago•1 comments

Stories from 25 Years of Software Development

https://susam.net/twenty-five-years-of-computing.html
65•vinhnx•5h ago•9 comments

OpenCiv3: Open-source, cross-platform reimagining of Civilization III

https://openciv3.org/
833•klaussilveira•22h ago•250 comments

U.S. Jobs Disappear at Fastest January Pace Since Great Recession

https://www.forbes.com/sites/mikestunson/2026/02/05/us-jobs-disappear-at-fastest-january-pace-sin...
155•alephnerd•2h ago•106 comments

The AI boom is causing shortages everywhere else

https://www.washingtonpost.com/technology/2026/02/07/ai-spending-economy-shortages/
119•1vuio0pswjnm7•8h ago•149 comments

Al Lowe on model trains, funny deaths and working with Disney

https://spillhistorie.no/2026/02/06/interview-with-sierra-veteran-al-lowe/
57•thelok•4h ago•8 comments

The Waymo World Model

https://waymo.com/blog/2026/02/the-waymo-world-model-a-new-frontier-for-autonomous-driving-simula...
1061•xnx•1d ago•613 comments

Reinforcement Learning from Human Feedback

https://rlhfbook.com/
79•onurkanbkrc•7h ago•5 comments

Brookhaven Lab's RHIC Concludes 25-Year Run with Final Collisions

https://www.hpcwire.com/off-the-wire/brookhaven-labs-rhic-concludes-25-year-run-with-final-collis...
4•gnufx•57m ago•1 comments

Start all of your commands with a comma (2009)

https://rhodesmill.org/brandon/2009/commands-with-comma/
489•theblazehen•3d ago•177 comments

Vocal Guide – belt sing without killing yourself

https://jesperordrup.github.io/vocal-guide/
212•jesperordrup•12h ago•72 comments

France's homegrown open source online office suite

https://github.com/suitenumerique
567•nar001•6h ago•259 comments

Coding agents have replaced every framework I used

https://blog.alaindichiappari.dev/p/software-engineering-is-back
226•alainrk•6h ago•354 comments

A Fresh Look at IBM 3270 Information Display System

https://www.rs-online.com/designspark/a-fresh-look-at-ibm-3270-information-display-system
40•rbanffy•4d ago•7 comments

Show HN: I saw this cool navigation reveal, so I made a simple HTML+CSS version

https://github.com/Momciloo/fun-with-clip-path
10•momciloo•2h ago•0 comments

History and Timeline of the Proco Rat Pedal (2021)

https://web.archive.org/web/20211030011207/https://thejhsshow.com/articles/history-and-timeline-o...
19•brudgers•5d ago•4 comments

Selection Rather Than Prediction

https://voratiq.com/blog/selection-rather-than-prediction/
8•languid-photic•3d ago•1 comments

72M Points of Interest

https://tech.marksblogg.com/overture-places-pois.html
29•marklit•5d ago•3 comments

Unseen Footage of Atari Battlezone Arcade Cabinet Production

https://arcadeblogger.com/2026/02/02/unseen-footage-of-atari-battlezone-cabinet-production/
114•videotopia•4d ago•33 comments

Where did all the starships go?

https://www.datawrapper.de/blog/science-fiction-decline
77•speckx•4d ago•82 comments

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox

https://github.com/valdanylchuk/breezydemo
275•isitcontent•22h ago•38 comments

Learning from context is harder than we thought

https://hy.tencent.com/research/100025?langVersion=en
201•limoce•4d ago•112 comments

Monty: A minimal, secure Python interpreter written in Rust for use by AI

https://github.com/pydantic/monty
288•dmpetrov•22h ago•155 comments

Show HN: Kappal – CLI to Run Docker Compose YML on Kubernetes for Local Dev

https://github.com/sandys/kappal
22•sandGorgon•2d ago•12 comments

Hackers (1995) Animated Experience

https://hackers-1995.vercel.app/
557•todsacerdoti•1d ago•269 comments

Making geo joins faster with H3 indexes

https://floedb.ai/blog/how-we-made-geo-joins-400-faster-with-h3-indexes
155•matheusalmeida•2d ago•48 comments

Sheldon Brown's Bicycle Technical Info

https://www.sheldonbrown.com/
427•ostacke•1d ago•111 comments