Topic: encryption keys
-
Microsoft Enables Federal Access to BitLocker Encryption
Microsoft can provide BitLocker recovery keys to law enforcement when users store them in the company's cloud, as demonstrated in a 2024 fraud case, highlighting a trade-off between convenience and user control. The system's default setup encourages key backup to Microsoft servers for easy recove...
Read More » -
Microsoft Gave Government Access to Customer Encryption Keys
Microsoft complied with a federal warrant by providing customer BitLocker encryption keys for a fraud investigation, marking a notable shift from typical industry resistance to such legal demands. This action contrasts with precedents like Apple's 2016 refusal to unlock a device, as Microsoft ass...
Read More » -
Zscaler Boosts Data Sovereignty with Regional Processing & Logging
Zscaler enhances its Zero Trust Exchange platform with regional processing and logging to help global businesses comply with data sovereignty laws without compromising security or collaboration. Its decentralized cloud architecture allows sensitive data to be processed and inspected within specif...
Read More » -
Signal Founder Tackles AI's Privacy Challenge
Moxie Marlinspike, founder of Signal, has launched **Confer**, an open-source, end-to-end encrypted AI chatbot designed to ensure user conversations remain completely confidential, addressing privacy concerns with mainstream AI. The initiative is driven by the unique risk that large language mode...
Read More » -
Humanoid Robot Hacked via Bluetooth, Data Sent to China
The Unitree G1 humanoid robot has critical Bluetooth vulnerabilities that allow unauthorized root access and remote code execution due to shared hardcoded encryption keys and improper data validation during setup. Weak encryption in the robot's configuration files and unsecured communication prot...
Read More » -
Firezone: Open-Source Remote Access Made Secure
Firezone is an open-source platform offering secure remote access through a least-privilege model, distinguishing it from traditional VPNs by granting only necessary permissions. It utilizes the WireGuard protocol for speed and security, with features like short-lived keys and a simplified Policy...
Read More » -
WhatsApp API Flaw Exposed 3.5 Billion User Accounts
A security vulnerability in WhatsApp's API allowed researchers to compile a list of 3.5 billion active user accounts by exploiting a contact-discovery feature lacking rate-limiting safeguards. The researchers, using a single server and minimal resources, identified global usage patterns, with Ind...
Read More » -
Secure Your WhatsApp Backups with Passkeys
WhatsApp is introducing a password-free method to encrypt chat backups using device authentication like facial recognition, fingerprint, or screen lock PIN. This update eliminates the previous need for a 64-digit key or separate password, simplifying the process and enhancing security for stored ...
Read More »