{"id":50821,"date":"2026-01-26T15:51:04","date_gmt":"2026-01-26T20:51:04","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=50821"},"modified":"2026-01-26T15:51:04","modified_gmt":"2026-01-26T20:51:04","slug":"microsoft-sharing-bitlocker-keys-with-fbi","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/01\/26\/microsoft-sharing-bitlocker-keys-with-fbi\/","title":{"rendered":"Microsoft Sharing BitLocker Keys With FBI"},"content":{"rendered":"<p><a href=\"https:\/\/www.windowscentral.com\/microsoft\/windows-11\/microsoft-bitlocker-encryption-keys-give-fbi-legal-order-privacy-nightmare\">Zac Bowden<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=46743154\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.windowscentral.com\/microsoft\/windows-11\/microsoft-bitlocker-encryption-keys-give-fbi-legal-order-privacy-nightmare\">\n<p><a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2026\/01\/22\/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data\/\">Microsoft has confirmed in a statement to Forbes<\/a> that the company will provide the FBI access to <a href=\"https:\/\/www.windowscentral.com\/microsoft\/windows-11\/microsoft-is-making-a-major-change-to-bitlocker-encryption-in-2026-heres-what-you-need-to-know\">BitLocker <\/a>encryption keys if a valid legal order is requested. These keys enable the ability to decrypt and access the data on a computer running Windows, giving law enforcement the means to break into a device and access its data.<\/p>\n<p>The news comes as Forbes reports that Microsoft gave the FBI the BitLocker encryption keys to access a device in Guam that law enforcement believed to have &ldquo;evidence that would help prove individuals handling the island&rsquo;s Covid unemployment assistance program were part of a plot to steal funds&rdquo; in early 2025.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/techcrunch.com\/2026\/01\/23\/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports\/\">Lorenzo Franceschi-Bicchierai<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=46735545\">Hacker News<\/a>, <a href=\"https:\/\/it.slashdot.org\/story\/26\/01\/23\/1910235\/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"https:\/\/techcrunch.com\/2026\/01\/23\/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports\/\">\n<p>But, by default, BitLocker recovery keys are uploaded to Microsoft&rsquo;s cloud, allowing the tech giant &mdash; and by extension law enforcement &mdash; to access them and use them to decrypt drives encrypted with BitLocker, as with the case reported by Forbes.<\/p>\n<p>[&#8230;]<\/p>\n<p>Apart from the privacy risks of handing recovery keys to a company, Johns Hopkins professor and cryptography expert Matthew Green <a href=\"https:\/\/bsky.app\/profile\/matthewdgreen.bsky.social\/post\/3md3vciumvk2s\">raised the potential scenario<\/a> where malicious hackers compromise Microsoft&rsquo;s cloud infrastructure &mdash; something that <a href=\"https:\/\/techcrunch.com\/2023\/07\/17\/microsoft-lost-keys-government-hacked\/\">has happened<\/a> <a href=\"https:\/\/techcrunch.com\/2024\/01\/19\/hackers-breached-microsoft-to-find-out-what-microsoft-knows-about-them\/\">several times<\/a> in recent years &mdash; and get access to these recovery keys.<\/p>\n<\/blockquote>\n\n<p>It&rsquo;s not surprising or improper that Microsoft would cooperate with law enforcement, but it may be surprising to many users that they had shared their recovery keys with Microsoft.<\/p>\n\n<p><a href=\"https:\/\/schwarztech.net\/snippets\/microsoft-gave-fbi-keys-to-unlock-encrypted-data-exposing-major-privacy-flaw\">Eric Schwarz<\/a>:<\/p>\n<blockquote cite=\"https:\/\/schwarztech.net\/snippets\/microsoft-gave-fbi-keys-to-unlock-encrypted-data-exposing-major-privacy-flaw\">\n<p>Microsoft has made it increasingly harder for individual consumers to set up a new PC without creating a Microsoft account. Between closing loopholes and fighting users who want to make local accounts, this means most people are unknowingly uploading their BitLocker keys to Microsoft&rsquo;s servers. Whether intentional or not, the fact that Microsoft hasn&rsquo;t designed a way to be out of the encryption key business is concerning.<\/p>\n<\/blockquote>\n\n<p>Apple also strongly and repeatedly encourages users to store the FileVault recovery key on Apple&rsquo;s servers. I was not able to find information about this in their <a href=\"https:\/\/support.apple.com\/guide\/security\/welcome\/web\">security guide<\/a>, but the situation should be better than with Windows because the recovery key is now stored in iCloud Keychain, which is end-to-end encrypted.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/09\/22\/tahoe-filevault-icloud-keychain-and-ssh\/\">Tahoe FileVault: iCloud Keychain and SSH<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/06\/24\/macos-tahoe-beta-forces-sharing-filevault-key\/\">macOS Tahoe Beta Forces Sharing FileVault Key<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2012\/08\/07\/filevault-2s-apple-id-backdoor\/\">FileVault 2&rsquo;s Apple ID Backdoor<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Zac Bowden (via Hacker News): Microsoft has confirmed in a statement to Forbes that the company will provide the FBI access to BitLocker encryption keys if a valid legal order is requested. These keys enable the ability to decrypt and access the data on a computer running Windows, giving law enforcement the means to break [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-01-26T20:51:10Z","apple_news_api_id":"f4e51616-c5bf-48b1-87e9-2952a1754f94","apple_news_api_modified_at":"2026-01-26T20:51:10Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/A9OUWFsW_SLGH6SlSoXVPlA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1347,706,16,1417,30,2742,37,355,219,2099],"class_list":["post-50821","post","type-post","status-publish","format-standard","hentry","category-technology","tag-federal-bureau-of-investigation-fbi","tag-filevault","tag-icloud","tag-icloud-keychain","tag-mac","tag-macos-tahoe-26","tag-microsoft","tag-privacy","tag-windows","tag-windows-11"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/50821","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=50821"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/50821\/revisions"}],"predecessor-version":[{"id":50822,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/50821\/revisions\/50822"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=50821"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=50821"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=50821"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}