This attack reads the key from RAM, so I don't see how a TPM PIN would mitigate it.
This attack reads the key from RAM, so I don't see how a TPM PIN would mitigate it.
If the TPM doesn't have a PIN, this attack works even if the attacker obtains the system when it's powered off. They can start the computer, proceed to the Windows logon screen (that they can't get past and that hence prevents them from exfiltrating data from the running system), then just reset the computer and perform this attack to obtain the encryption key. This obviously doesn't work if the PIN prevents Windows from ever even starting.
Even on Win11 it's still possible to do the old utilman (or other suitable module) replacement hack from Windows repair (trigger by interrupting boot), from there you can change account passwords at will.
Can you elaborate on this?
> Changes the default setting for BitLocker when encrypting a self-encrypting hard drive. Now, the default is to use software encryption for newly encrypted drives. For existing drives, the type of encryption will not change.
https://support.microsoft.com/en-us/topic/september-24-2019-...
https://threadreaderapp.com/thread/1059435094421712896.html
This is amazing.
> The encrypted SSD has a master password that’s set to “”
HN discussion here: https://news.ycombinator.com/item?id=18382975
Original paper here: https://cs.ru.nl/~cmeijer/publications/Self_Encrypting_Decep...
You can then go further up the chain with a UEFI settings password and no usb booting. If the password is hard to decrypt, then that's a pretty good approach.
Then there's custom Secure Boot certificates that replaces the ones from MS. It'll work for Linux, not sure about BitLocker. But my Surface tablet doesn't even support custom sb certs.
Having said that a number of laptops can still be opened without being powered-off if you do it carefully.