Jump to content
  • FBI bypasses "impenetrable" encryption using BitLocker keys supplied by Microsoft

    Karlston

    • 2 comments
    • 491 views
    • 2 minutes
     Share


    • 2 comments
    • 491 views
    • 2 minutes

    Microsoft has confirmed that it works with law enforcement agencies when it gets a valid court order or warrant, even to the extent of providing BitLocker recovery keys to law enforcement agencies. Forbes uncovered this disclosure following a federal fraud investigation in Guam where the FBI successfully used keys supplied by Microsoft to unlock three encrypted laptops linked to a COVID-19 unemployment assistance scheme.

     

    The Redmond giant revealed that it receives around 20 requests for BitLocker keys annually. It is not new information that Microsoft complies with lawful government requests and hands over keys that are within its cloud infrastructure. However, this is the first publicly confirmed instance that the company has surrendered keys to federal investigators.

     

    For those not familiar, BitLocker encryption is turned on by default on most modern Windows PCs and encrypts drives to keep data safe. However, Windows frequently tells users to backup their 48-digit recovery keys to a Microsoft cloud account. This choice allows Microsoft to retain technical access to the keys, making them accessible if law enforcement comes knocking.

     

    In the Guam case the FBI used the keys it received from Microsoft to bypass encryption that federal forensic experts previously said were “impenetrable.” The court documents said that agencies like Homeland Security Investigations (HSI) lacked the tools to break BitLocker without the specific recovery keys.

     

    Microsoft’s decision to hand over keys to law enforcement contrasts with its competitors like Apple and Meta which use zero-knowledge architectures where recovery keys are end-to-end encrypted or stored on the user’s device, meaning the company can’t comply with requests, even under subpoena.

     

    Legal experts are now anticipating more law enforcement requests for BitLocker keys now that Microsoft’s compliance has been reported. Users that do not want to allow Microsoft to store their keys can audit their accounts at account.microsoft.com/devices/recoverykey. From there, you can see if keys are stored in the cloud. If you want more security, it is recommended to move to local-only key storage, such as a physical USB drive or a printed document, to regain full control over encrypted data.

     

    Source


    Hope you enjoyed this news post. Feedback welcome.

    Posted Sunday 25 January 2026 at 4:17 am AEST (my time).

    News posts... 2023: 5,800+ | 2024: 5,700+ | 2025: 5,700+

    RIP Matrix


    User Feedback

    Recommended Comments

    8 hours ago, The Boca Deb said:

    DAMN YOU NADELLA!  (Yes, I meant to shout.)

    It is not only Nadella it is all of them, google, Meta and Apple. Bearing in mind that the "law enforcement agencies" is able to issue a court order anytime and for any reason whatsoever including political, that your personal info and data are widely opened to them, thanks to the tech giants, whom we trust with our info.

    • Like 2
    Link to comment
    Share on other sites




    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...