Apple wants its users' secrets to be secret.
The UK wants the fact it wants Apple to reveal anyone's secrets to be secret.
Apple wants its users' secrets to be secret.
The UK wants the fact it wants Apple to reveal anyone's secrets to be secret.
Yes I hate that they do that without prompting, but in theory that solution offers that balance that OP talks about - if there are no backdoors in Bitlocker(let's assume that there aren't), then your encrypted data is perfectly secure. But if a judge issues a warrant for your data, then Microsoft can provide them with a key to unlock your device.
To me, that's an acceptable compromise - it means that someone stealing my laptop won't get my data, but if a warrant is produced then bitlocker drives can be unlocked for a criminal investigation.
Couldn't Apple create a solution where all your communication is end to end encrypted with a key that they just have a copy of? No backdoors necessary.
But that is a backdoor!
Especially, it's a backdoor that's inside a foreign country and subject to their intelligence services! It might be valid for a hypothetical autochthonous UKphone, but having a system where the US can secretly crack all UK comms is .. not ideal.
Given the tendency of UK ministers to use Whatsapp for private government communications, should we allow the US to have a backdoor into all of that via Meta? (in practice, they tend to leak to newspapers themselves, but it's the principle)
> then Microsoft can provide them with a key to unlock your device.
This is a quote from parent. That renders the key and encryption itself pretty useless if it has been given to someone other than you.
I want my devices to be secure from thieves who might steal them, and I want my communications to be secure from someone intercepting internet traffic at various locations I might visit - that is still achieved in that scenario, even if MS/Apple hold the copy of the key. That doesn't make the encryption useless - just ineffective if your attack vector is defending yourself against state-level actors.
Someone has to physically come to your house to access your front door. Computers and other computer equipment is accessible by anyone anywhere. A Russian hacker outfit can attempt to access your phone from Vladivostok in a way they can't with your front door.
Sticking with front door analogy, what if there were a master key that could open up all door locks that the police held. What if that key was leaked and now you knew that multiple gangs and criminals had the key and were breaking into houses. Would you feel secure with your front door then? Data breaches happen and a company with the keys to everyone's computer front door is a huge target. I don't trust my bitlocker key to Microsoft. There is no such thing as a magical backdoor that only good guys can use but is secure against everyone else. A backdoor is a vulnerability that puts everyone using it at risk.
That's exactly what I said I don't want Apple/Google/MS to have - a master key that opens all locks is unacceptable imho.
>> What if that key was leaked and now you knew that multiple gangs and criminals had the key and were breaking into houses.
I'm sure I used this exact analogy in another comment, that's why no one should have a master key.
>>I don't trust my bitlocker key to Microsoft.
And neither do I - but overall on balance I think this is a good thing. I do like that my mum's laptop is automatically encrypted, if it gets stolen her data is safe, and if she forgets her password there is some pathway to recovering it. I like that. It's nice convenience for "regular" people. I don't do it myself because I have an alternative backup of my encryption keys. And yes, I do like that if someone is under criminal investigation that the key can be obtained from MS when a valid warrant is produced. I see that as a good thing personally.
>> There is no such thing as a magical backdoor that only good guys can use but is secure against everyone else.
Well, good thing it's not a backdoor then.
>>A backdoor is a vulnerability that puts everyone using it at risk.
Again, MS having a copy of your bitlocker key is not a backdoor.