4 ms·
The point of this kind of encryption is that a removed hardrive can be sold or repurposed without data risk. Anyone can boot the laptop and get to the decrypte
by psychphysic 3y ago
The point of this kind of encryption is that a removed hardrive can be sold or repurposed without data risk.
Anyone can boot the laptop and get to the decrypted hard drive, what does it matter if they sniff the key first? They always had access to the end result of they can boot the laptop.
- brohee 3y agoWell you will boot the laptop but still have to get past the login screen. Intercepting the key permits to read/write whatever you want on the disk, and thus backdoor the OS (as he does).
- withinboredom 3y agoDude. Bypassing the login screen is as simple as pressing shift five times. That’s like some kindergarten stuff.
- sznio 3y agoIf I remember correctly, you needed to replace the accessibility executable with cmd.exe for that to work. Can't do that if the machine is encrypted. And if it's unencrypted there are better ways to reset the passwords.
- gquere 3y agoWell that's what I described. The drive was encrypted but there was no PIN so I just snooped the key, decrypted the drive and mounted it on another machine where I replaced sethc with cmd.
- cafeinux 3y agoDoesn't this method imply booting from an external disk, thus not decrypting the HDD, thus not being able to modify what needs to be modified in order to bypass the login screen?
- withinboredom 3y agoIf you can trick the computer into decrypting the disk, why does it matter which disk you actually boot from?
- cafeinux 3y agoThe point made earlier was that if you boot Windows, it automatically decrypts the disk, but if you boot from another disk, it doesn't. I don't know much in this, except that I think I know that the TPM has an "owner" and that only that owner can read and modify the content of the TPM. If you could just plug your USB drive, boot from it and automatically decrypt the Windows partition to edit CMD.exe, I just see this whole Bitlocker and TPM thing as completely moot.
- withinboredom 3y agoI really hate to be the one to point this out, but its clear you didn't read the article since this is exactly what they did: boot windows, steal the key from the TPM, boot into different OS entirely, inject the key to decrypt the disk, replace sethc, reboot into windows and push shift five times ... and there you go.
- cafeinux 3y agoI read the article (and skimmed some parts, as I'm not interested in the technical details of how the signals were decoded). As I understood the conversation thread we're in, we were talking in the context of someone simply booting up the laptop, not someone opening it and plugging wires to tap the TPM bus. Of course, once you've tapped the TPM with the technique described in the article you can do whatever you want with the disk, but in this case I don't see why you would bother bypassing the login, just mount the partition and get the data you need. Edit: specifically in this case, my comment was a reaction to this but from psychphysic : > what does it matter if they sniff the key first? They always had access to the end result of they can boot the laptop => if you didn't sniff the key first, you can't decrypt the disk offline, and can't have access to CMD on the login screen. That's why it matters.
- gquere 3y agoCan't do this attack if BitLocker is protected by PIN/passphrase, which is rarely the case.