Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  Other than that, I've yet to hear any 
  substantive reason why I wouldn't use 
  BitLocker.
The thinking goes like this:

1. RSA released software with backdoors, at the behest of the NSA.

2. Therefore, the NSA has the ability to make companies release software with backdoors.

3. The FBI and British governments are known to have asked for backdoors to be included in BitLocker.

4. Therefore, the NSA has the motive to have a backdoor put in.

5. Microsoft have not proved BitLocker /does not/ contain backdoors.



But you have to run Windows on bitlocker.

so you've already handed over your machine no matter what FDE you use.

certainly trusting less people is better than trusting more, since _any_ nefarious third party in this scenario already has the keys to the kingdom.


Full-disk encryption is primarily used to protect offline volumes. If no one can boot your disk, it doesn't matter if Microsoft can upload its entire contents to the NSA once Windows is started. The concern is that a flaw in BitLocker's FDE would make it vulnerable to attacks while the volume is offline.

FDE doesn't really protect online volumes. Yes, the disk is still encrypted, but the OS transparently decrypts any requested sector, so other security measures are necessary to protect mounted volumes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: