lemmy.mlaga97.space
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Lee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year ago

BitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM

www.tomshardware.com

external-link
message-square
68
fedilink
0
external-link

BitLocker encryption broken in less than 43 seconds with sub-$10 Raspberry Pi Pico — key can be sniffed when using an external TPM

www.tomshardware.com

Lee Duna@lemmy.nz to Technology@lemmy.worldEnglish · 1 year ago
message-square
68
fedilink
BitLocker's reliance on a TPM for security is its own downfall in this specific exploit.
  • smileyhead@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 year ago

    Solution: Just encrypt it with a password.

    • BaroqueInMind@kbin.social
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      Bit locker is a password controlled drive encryption. Am I being dumb or are you seriously saying that?

      • Kraven_the_Hunter@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 year ago

        Yes.

      • tias@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        1 year ago

        I guess they mean use the password as part of the encryption key, or encrypt the key with the password. Bitlocker doesn’t use the user’s password in that way, which is why it can boot an encrypted system without user interaction. That part always seemed very sketchy to me.

        • d3Xt3r@lemmy.nz
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 year ago

          FYI: You can set it to require a PIN + TPM, or even just a password eg using manage-bde -on c: -password.

          https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/manage-bde-on

          • tias@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 year ago

            Thanks, that sounds really useful. I’m guessing it won’t work unless you’re local admin though.

            • d3Xt3r@lemmy.nz
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 year ago

              Yep, you’ll need local admin of course.

              • tias@discuss.tchncs.de
                link
                fedilink
                English
                arrow-up
                0
                ·
                edit-2
                1 year ago

                Which kind of makes it useless in many corporate environments where it’s most needed, since the users won’t be able to set their own password.

                • d3Xt3r@lemmy.nz
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  1 year ago

                  I mean, if it’s a corporate device then it’s really a policy IT should be setting - this can be easily be done via a GPO or Intune policy, where an elevated script can prompt the end-user for a password.

                  • LifeInMultipleChoice@lemmy.world
                    link
                    fedilink
                    English
                    arrow-up
                    0
                    ·
                    edit-2
                    1 year ago

                    Yarp. And when they forget it we use the 48 numerical recovery key found using the recovery ID that shows on the screen when you hit escape (from the bitlocker screen)

                  • lud@lemm.ee
                    link
                    fedilink
                    English
                    arrow-up
                    0
                    ·
                    1 year ago

                    It would be insane to let non admin change settings like this.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 387 users / day
  • 1.95K users / week
  • 5.04K users / month
  • 13.2K users / 6 months
  • 0 local subscribers
  • 69.9K subscribers
  • 12.6K Posts
  • 398K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org