Anyone can boot the laptop and get to the decrypted hard drive, what does it matter if they sniff the key first? They always had access to the end result of they can boot the laptop.
Anyone can boot the laptop and get to the decrypted hard drive, what does it matter if they sniff the key first? They always had access to the end result of they can boot the laptop.
Can't do that if the machine is encrypted. And if it's unencrypted there are better ways to reset the passwords.
If you could just plug your USB drive, boot from it and automatically decrypt the Windows partition to edit CMD.exe, I just see this whole Bitlocker and TPM thing as completely moot.
As I understood the conversation thread we're in, we were talking in the context of someone simply booting up the laptop, not someone opening it and plugging wires to tap the TPM bus.
Of course, once you've tapped the TPM with the technique described in the article you can do whatever you want with the disk, but in this case I don't see why you would bother bypassing the login, just mount the partition and get the data you need.
Edit: specifically in this case, my comment was a reaction to this but from psychphysic : > what does it matter if they sniff the key first? They always had access to the end result of they can boot the laptop => if you didn't sniff the key first, you can't decrypt the disk offline, and can't have access to CMD on the login screen. That's why it matters.