Automatically translated.View original post

You have the right not to speak, but we have the right to open it.

Many people already know BitLocker. The encryption feature on the Windows operating system prevents other people from connecting our hard disk or SSD to another machine and viewing the data without the correct decryption code. BitLocker uses a 48-digit Recovery Key, which is considered to be a highly secure encryption system, so that in some cases, if a user loses a key or a system crashes, it may not recover the data again.

.

Most recently, there were reports that brought BitLocker's "super secure" image into question, when it was revealed that Microsoft had stored some of its user's Recovery Keys on the cloud and could hand over such keys to law enforcement if it had a legitimate court order or search warrant, meaning that BitLocker encryption may not always be accessible to the owner of the machine.

.

The issue became a hot trend in IT and cybersecurity; the latter was revealed that the FBI was able to successfully unlock a Windows laptop encrypted with BitLocker, using a Recovery Key handed over by Microsoft as a subpoena, marking the first time a case of this nature had been explicitly confirmed publicly.

.

According to a Forbes report, the incident was triggered by a COVID-19 unemployed subsidy fraud case in Guam, with the FBI gaining access to information on three suspected laptops that government digital forensics experts previously determined could not crack BitLocker without a direct Recovery Key.

.

Microsoft has confirmed that it cooperates with law enforcement when it receives a valid court order and has revealed that it receives about 20 BitLocker Recovery Key requests per year. BitLocker is a feature that is enabled by default on newer Windows PCs and often recommends that users reserve their keys to Microsoft accounts on the cloud. Experts recommend that users concerned with privacy should check and keep the Recovery Key offline to control data security more manually.

.

Unlike Apple and Meta, which use zero-knowledge or end-to-end encryption structures, the company cannot access the user's decryption key despite a subpoena.

.

Source: neowin

# IT News # Includes IT matters # Cough to know # IT

1/28 Edited to

... Read moreจากประสบการณ์การใช้งาน BitLocker มาอย่างต่อเนื่อง ผมเห็นว่าฟีเจอร์นี้ช่วยปกป้องข้อมูลในเครื่องเราได้ดีมากเมื่อใช้งานตามคำแนะนำ เช่น การสำรอง Recovery Key ไว้ในบัญชี Microsoft หรือเก็บไว้ในรูปแบบออฟไลน์ อย่างไรก็ตามข่าวล่าสุดที่ Microsoft สามารถส่งมอบ Recovery Key ให้กับหน่วยงานบังคับใช้กฎหมายนั้น ทำให้ผมเริ่มทบทวนเรื่องความเป็นส่วนตัวในการเข้ารหัสข้อมูลครั้งนี้ ผมเองก็เคยเจอบางสถานการณ์ที่ระบบ BitLocker แจ้งให้ใส่ Recovery Key เพราะเครื่องตรวจพบความผิดปกติ เช่น การเปลี่ยนฮาร์ดแวร์หรืออัพเดตไบออส ซึ่งในกรณีเหล่านี้ หากไม่มี Recovery Key ก็จะไม่สามารถเข้าใช้งานข้อมูลได้เลย การที่ Microsoft มีสำเนากุญแจในระบบคลาวด์จึงช่วยให้ผู้ใช้บางกลุ่มสามารถกู้ข้อมูลได้เมื่อเกิดปัญหา แต่ในอีกมุมหนึ่งก็ต้องแลกมาด้วยความเสี่ยงที่หน่วยงานภายนอกจะเข้าถึงข้อมูลได้โดยได้รับคำสั่งศาล เพื่อนๆ ที่กังวลเรื่องความเป็นส่วนตัวและความปลอดภัยของข้อมูล ผมแนะนำให้เก็บสำรอง Recovery Key ในรูปแบบออฟไลน์ เช่น บันทึกลงในแฟลชไดรฟ์หรือพิมพ์ออกมาเก็บไว้กับตัว และปิดการสำรองกุญแจไว้ในบัญชี Microsoft โดยตรง เพื่อให้เรามั่นใจว่าสามารถควบคุมกุญแจถอดรหัสได้ด้วยตัวเอง นอกจากนี้ อย่าลืมว่าการเข้ารหัสแบบ BitLocker นั้นยังแตกต่างจากระบบเข้ารหัสของบริษัทอื่นๆ เช่น Apple หรือ Meta ที่ใช้เทคโนโลยี zero-knowledge encryption ทำให้บริษัทไม่สามารถเข้าถึงข้อมูลผู้ใช้ได้เลยแม้จะมีคำสั่งศาล เรื่องนี้ชี้ให้เห็นว่าการเลือกเครื่องมือและฟีเจอร์เข้ารหัสข้อมูล ควรคำนึงถึงนโยบายความเป็นส่วนตัวของผู้ให้บริการด้วย โดยส่วนตัวผมคิดว่า BitLocker เหมาะกับผู้ใช้ส่วนใหญ่ที่ต้องการความปลอดภัยจากการโจรกรรมข้อมูลพื้นฐาน แต่ถ้าเป็นข้อมูลที่มีความสำคัญสูงมาก ควรพิจารณาวิธีเข้ารหัสเพิ่มเติมหรือตรวจสอบนโยบายการเก็บข้อมูล Recovery Key อย่างละเอียดก่อนใช้งานจริง เพื่อความมั่นใจว่าข้อมูลของเราจะปลอดภัยตามความต้องการจริงๆ