this post was submitted on 02 May 2024
52 points (98.1% liked)

Technology

2037 readers
122 users here now

Post articles or questions about technology

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 22 points 6 months ago* (last edited 6 months ago) (6 children)

In a healthy marketplace, these would be fireable offenses. Regrettably, the marketplace is far from healthy — Microsoft has the government locked in as a customer, so the government’s options for forcing change at Microsoft are limited, at least in the short term.

And that's why nothing will happen to MS, except maybe line go down a bit. But then line will go up again so it's all good.

Kinda annoyed by articles like this making it sound like security wasn't always an afterthought at MS though. It's just that it's even worse with everything being forced online to push SaaS revenue.

Them just quietly throwing the towel when it comes to Bitlocker getting circumvented on Windows 10 because the recovery partition is too small is only the tip of that shitberg.

As long as decision makers will flip their shit when they can't have PowerPoint and Outlook the company will just keep on trucking'

[–] [email protected] 6 points 6 months ago (2 children)

Bitlocker getting circumvented on Windows 10 because the recovery partition is too small

What's this about?

[–] [email protected] 14 points 6 months ago* (last edited 6 months ago) (1 children)

Current Win11 update fails if the recovery partition doesn’t have enough space. Microsoft says it won’t fix the problem, users have to resize their own partition first.

That’s fine for nerds. Grandma doesn’t know what the fuck a hard disk even is.

(Edit: not sure what the bitlocker problem is in relation to this)

[–] [email protected] 1 points 6 months ago

@[email protected] already explained most of it, Bitlocker comes into play because the recovery environment can be booted without needing to provide the recovery key for Bitlocker, the vulnerability that is being patched additionally allows bypassing the need to log into it.

That said, Microsoft frequently disables Bitlocker anyway to do OS updates, it really only works if you enable the additional pin feature.

load more comments (3 replies)