halubilo.social
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Lee Duna to [email protected]English • 2 years ago

BitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM

www.tomshardware.com

external-link
message-square
68
fedilink
735
external-link

BitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM

www.tomshardware.com

Lee Duna to [email protected]English • 2 years ago
message-square
68
fedilink
BitLocker's reliance on a TPM for security is its own downfall in this specific exploit.
  • @[email protected]
    link
    fedilink
    English
    12•2 years ago

    FYI: You can set it to require a PIN + TPM, or even just a password eg using manage-bde -on c: -password.

    https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/manage-bde-on

    • @[email protected]
      link
      fedilink
      English
      3•2 years ago

      Thanks, that sounds really useful. I’m guessing it won’t work unless you’re local admin though.

      • @[email protected]
        link
        fedilink
        English
        4•2 years ago

        Yep, you’ll need local admin of course.

        • @[email protected]
          link
          fedilink
          English
          -2•
          edit-2
          2 years ago

          Which kind of makes it useless in many corporate environments where it’s most needed, since the users won’t be able to set their own password.

          • @[email protected]
            link
            fedilink
            English
            5•2 years ago

            I mean, if it’s a corporate device then it’s really a policy IT should be setting - this can be easily be done via a GPO or Intune policy, where an elevated script can prompt the end-user for a password.

            • @[email protected]
              link
              fedilink
              English
              2•
              edit-2
              2 years ago

              Yarp. And when they forget it we use the 48 numerical recovery key found using the recovery ID that shows on the screen when you hit escape (from the bitlocker screen)

            • @[email protected]
              link
              fedilink
              English
              1•
              edit-2
              9 months ago

              deleted by creator

              • @[email protected]
                link
                fedilink
                English
                1•2 years ago

                I’m talking about letting the user change their own password. I’m honestly not sure how that would be technically accomplished in this situation without having to contact IT each time. It seems like something Microsoft should provide a no-frills GUI for that doesn’t require elevation.

                • @[email protected]
                  link
                  fedilink
                  English
                  1•
                  edit-2
                  9 months ago

                  deleted by creator

[email protected]

[email protected]

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @[email protected]
  • @[email protected]
  • @[email protected]
  • @[email protected]
  • 5.41K users / day
  • 9.74K users / week
  • 17.3K users / month
  • 30.4K users / 6 months
  • 83.3K subscribers
  • 18.4K Posts
  • 792K Comments
  • Modlog
  • mods:
  • @[email protected]
  • enu
  • Technopagan
  • L4sBot
  • L3s
  • BE: 0.19.3
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org