• RainbowBlite@piefed.ca
      link
      fedilink
      English
      arrow-up
      41
      ·
      2 months ago

      The connection is that Windows records everything you do. So the FBI asks for every Windows user who accessed a specific site around a date/time and Microsoft can provide that.

      You accessed a site over VPN? Your ISP has no idea it was you, , and the VPN didn’t keep records, but Windows recorded that and sent it back to the mothership with your unique identifier.

      • angband@lemmy.world
        link
        fedilink
        arrow-up
        17
        ·
        2 months ago

        Exactly it, and their claim that it is stored with bitlocker level encryption is obviously meaningless if they have the keys.

        • 4am@lemmy.zip
          link
          fedilink
          arrow-up
          35
          ·
          2 months ago

          Fun fact, windows 11 backs up your bitlocker private key with Microsoft if you sign in with a Microsoft Account.

          There’s a database somewhere with every bitlocker key to almost every Windows 11 device on earth.

          I’m sure they let the NSA and the FBI right in. The CIA probably has sleeper agents working devops at Microsoft so they don’t even need to access it procedurally. $10 says Israel can access it too, because why the fuck not.

    • ExLisperA
      link
      fedilink
      arrow-up
      8
      ·
      2 months ago

      My guess is oauth. He basically used fake Microsoft account to access services during the hack and them used his actual microsoft account to access something else. He used VPN for the hack but he connected from his actual IP to the second service. The only thing linking those was the GID. So they figured out his actual IP address and checked other logins from this IP around the same time and found out his other accounts.