3 ms·
BitLocker can be used without TPM, for example with a password or a key file on a USB drive. And those are probably safer options if your whole computer gets st
by whyoh 4y ago
BitLocker can be used without TPM, for example with a password or a key file on a USB drive. And those are probably safer options if your whole computer gets stolen.
- vel0city 4y agoThe experience of doing it with a password is pretty poor compared to using a TPM. Every time the computer reboots, I need to type in the password. If it is a remote machine, I have to physically be at the station to type in the password. Keeping the key file on a USB drive isn't exactly safe either, as there's a high likelihood that flash drive is probably going to be near my computer when stolen. Also, that flash drive may be active and plugged when the system is running, exposing it to the machine directly. Having that key material easily accessible on a flash drive makes it less protected than using the TPM. Using the TPM gives me a better experience and depending on how things are handled a far more secure way of handling the key. Its way easier to grab the key file off the flash drive than coaxing it out of the TPM without booting the trusted boot process.
- gambiting 4y agoThey are only safer if you always unplug the USB drive and take it with you. Which I know I would never do reliably enough to offer protection(and I would probably lose the drive eventually which is then actually a complete loss of data unless you have a backup, but if you have a backup then that's yet another weakness in the system). A built in TPM module might have some unknown fault that hasn't been disclosed yet, but I think that's about 10000x less likely than the chance of me forgetting/losing the USB drive with encryption key.