<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx</link><description>Got an email today from a customer asking about how BitLocker will affect the ability of law enforcement to conduct forensic analysis of a protected hard drive. Specifically, the person was asking about any back doors that law enforcement could use to</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1542436</link><pubDate>Tue, 17 Jul 2007 20:16:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1542436</guid><dc:creator>Terence</dc:creator><description>&lt;p&gt;i totally agree with you steve. the feature benefits much more people than compared with the baddies. anyway, nothing if perfect in this world. &amp;nbsp;that means technology too! :&amp;gt;&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1558678</link><pubDate>Thu, 19 Jul 2007 18:34:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1558678</guid><dc:creator>Samuel</dc:creator><description>&lt;p&gt;I work in IT for a sheriff's dept. &amp;nbsp;There's definitely a lot of objection to the right of citizens to protect their properties, at least by the folks I work with. &amp;nbsp;It'd take a para-digg-'em shift to have people and law enforcement realize that when it concerns good/bad, then by definition there will be two sides in opposition to any argument posed...except for guns...we just need more guns...leave them guns alone...unless you're bringing more...&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1576171</link><pubDate>Sat, 21 Jul 2007 22:55:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1576171</guid><dc:creator>kai axford</dc:creator><description>&lt;p&gt;As Steve mentions, there is absolutely no back door for anyone in BitLocker. However, good investigatory and digital forensic procedures are certainly still very important when working with a Windows Vista computer. I'd suggest that any law enforcement agencies with concerns should have their department contact Microsoft directly. &lt;/p&gt;
&lt;p&gt;- Kai&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1578514</link><pubDate>Sun, 22 Jul 2007 08:24:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1578514</guid><dc:creator>Steve Riley</dc:creator><description>&lt;p&gt;Samuel -- the right of citizens to protect their own property is the foundation of American democracy and indeed is a requirement for any democracy to function, along with transparency in government. It's really quite disheartening when I read that segments of our society are opposed to these very necessary fundamentals.&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1619594</link><pubDate>Thu, 26 Jul 2007 19:03:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1619594</guid><dc:creator>slagmi</dc:creator><description>&lt;p&gt;Don't think for a moment that Microsoft won't provide the BitLocker Password Recovery Tool to any verifiable Law Enforcement entity that asks for it! &lt;/p&gt;
&lt;p&gt;(800) 936-5700&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1619993</link><pubDate>Thu, 26 Jul 2007 19:55:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1619993</guid><dc:creator>Watches</dc:creator><description>&lt;p&gt;I agree! There are tools such as truecrypt that offer the same services and making it fool proof encryption is what is needed!&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1620579</link><pubDate>Thu, 26 Jul 2007 21:12:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1620579</guid><dc:creator>Steve Riley</dc:creator><description>&lt;p&gt;slagmi-- What evidence do you have that such a tool exists? Do you work for Microsoft? I can promise you, there is no such tool. There is a Recovery Password Viewer (&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/928202"&gt;http://support.microsoft.com/kb/928202&lt;/a&gt;), but this is for displaying recovery passwords stored in computer accounts in Active Directory. It will not work if you don't have admin-level access to the domain. It's a pretty safe assumption that bad guys won't be joining their computers to any domains.&lt;/p&gt;
&lt;p&gt;Watches-- there is no such thing as &amp;quot;fool-proof encryption.&amp;quot; Given sufficient time and resources, all encryption is ultimately defeatable.&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1729436</link><pubDate>Thu, 09 Aug 2007 23:22:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1729436</guid><dc:creator>I agree</dc:creator><description>&lt;p&gt;I just read your article on Tech ED (link posted at slashdot) and totally agree with you. It is really good to know that IT security in big companies has not completely sold itself to the &amp;quot;Big Brother&amp;quot;.&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1744289</link><pubDate>Mon, 13 Aug 2007 07:39:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1744289</guid><dc:creator>Ravi</dc:creator><description>&lt;p&gt;yeah, its true.....certainly for the organizations in the initial stages thinkin about security can go for bitlocker. But dont you agree with that, there comes some things like TPM, if your motherboard is gone then you have to kiss goodbye to your valueable information. &lt;/p&gt;
&lt;p&gt;Reply to ravi.rawal@gatewaynintec.in&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1757954</link><pubDate>Wed, 15 Aug 2007 15:04:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1757954</guid><dc:creator>Slav Pidgorny</dc:creator><description>&lt;p&gt;Amazingly, many corporations decide implementing HD encryption recovery procedures that degrade level of protection given by BitLocker using TPM to that of a helpdesk guy's password.&lt;/p&gt;
&lt;p&gt;Re. governments having access to backdoors and such: the government agencies _know_ that there's no backdoor. Besides having Steve's and Steve's word, they have access to Windows sources.&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1761727</link><pubDate>Thu, 16 Aug 2007 04:24:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1761727</guid><dc:creator>Steve Riley</dc:creator><description>&lt;p&gt;Ravi-- this is why BitLocker (and any good enterprise-grade encryption product) includes a recovery mechanism. It's all very well documented on Microsoft.com.&lt;/p&gt;
</description></item><item><title>Cellphones in movie theatres</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1805237</link><pubDate>Thu, 23 Aug 2007 02:39:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1805237</guid><dc:creator>Craig Beere</dc:creator><description>&lt;p&gt;I think cellphones should be banned in movie theatres because they are annoying. If a movie threatre agrees with me then they should be honest about their reason rather than hiding behind a &amp;quot;security&amp;quot; argument. Saying they are doing something for &amp;quot;security purposes&amp;quot; is a strange kind of &amp;quot;reverse security theatre&amp;quot;.&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Craig&lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#1988735</link><pubDate>Wed, 19 Sep 2007 01:45:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1988735</guid><dc:creator>Orin</dc:creator><description>&lt;p&gt;Generally speaking, a smart criminal (the sort that would know about Bitlocker and use it in the right way) wouldn't keep records of their criminal activity on their computer anyway.&lt;/p&gt;
&lt;p&gt;Alternatively they could use &amp;quot;one time pads&amp;quot; to effectively encrypt stuff that they want to keep secret without worrying about whatever secrecy features their operating system has.&lt;/p&gt;
&lt;p&gt;You don't need a computer to keep things secret. Stuff like bitlocker just makes it a little easier. &lt;/p&gt;
</description></item><item><title>re: The bad guys will use BitLocker, too</title><link>http://blogs.technet.com/steriley/archive/2007/07/13/the-bad-guys-will-use-bitlocker-too.aspx#2131071</link><pubDate>Sun, 07 Oct 2007 23:57:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2131071</guid><dc:creator>c#guy</dc:creator><description>&lt;p&gt;&amp;lt;strike&amp;gt;Communications tools&amp;lt;/strike&amp;gt; Firearms are far more beneficial to the millions of good guys who use them every day (perhaps to save lives?) than to the few bad guys who also use them. Why destroy beneficial utility for everyone just because someone might misuse &amp;lt;strike&amp;gt;the technology&amp;lt;/strike&amp;gt; them?&lt;/p&gt;
</description></item></channel></rss>