4 ms·
Another write up from 2021 https://arstechnica.com/gadgets/2021/08/how-to-go-from-stolen-pc-to-network-intrusion-in-30-minutes/ https://arstechnica.com/gadgets
by controversial97 3y ago
Another write up from 2021
https://arstechnica.com/gadgets/2021/08/how-to-go-from-stolen-pc-to-network-intrusion-in-30-minutes/ https://arstechnica.com/gadgets/2021/08/how-to-go-from-stole...
One aspect of this is that some laptop manufacturers provide a setting to erase the TPM if the laptop is opened. You opened that laptop to see if you can add more RAM? Better hope you can access the bitlocker key or have a good backup.
- layer8 3y agoIt’s good practice to have a copy of the recovery key somewhere.
- controversial97 3y agoLots of people and small companies just buy a windows laptop and are unaware that the harddrive/ssd is encrypted with bitlocker. People who avoid making a Microsoft account to log on to a windows computer, or who don't have access to the email address they used can find themselves in difficulty later when windows won't boot or it wants the bitlocker key for some reason. You can't get their files off the drive by connecting it to another machine because the bitlocker key is not available. Yes, people should have backups and copies of their keys but they very commonly don't.
- Crontab 3y agoI was under the impression that BitLocker does not default to being on, even with a Microsoft account. That's kind of dangerous if they have changed that without at least a warning.
- withinboredom 3y agoIf you do a volume order, I think you can ask for it to be turned on by default.
- gambiting 3y agoI recently got a new MSI laptop, came with Windows 11 - I immediately wiped the drive and installed Windows 10(Home edition), few days later installed a new BIOS update and the laptop asked me for a bitlocker key......but I never encrypted the drive??? What's even weirder is that I logged into the Microsoft recovery thing and it had the recovery key for it????? So it does seem to be the default behaviour now.
- ixwt 3y agoThis makes absolutely 0 sense. Bitlocker cannot be setup on Windows 10 Home edition.
- gambiting 3y agoWell I upgraded to Pro about two days later, so maybe the upgrade did it? But either way, there was absolutely zero indication that the drive is getting encrypted or that it's going to save my recovery key to my Microsoft account.
- wbkang 3y agoIt's called "device encryption" which seems to do the same thing and they allow it for Windows 10 home. It's confusing.
- ysleepy 3y agoWindows marks the device as bitlocker enables somewhere in the EFI partition or GPT disklabels. I needed to wipe the whole disk to have windows cease with bitlocker bootscreens.
- controversial97 3y agoI can say from personal experience that for at least five years it has been common for small companies to buy a laptop direct from Dell and for it to have a bitlocker encrypted drive without anyone choosing that.
- vladvasiliu 3y agoIME with win 11 pro, it won't encrypt the drive if you (jump through hoops to) create a local account. But as soon as you link it to MS, it will encrypt it.
- bootsmann 3y agoIt is default on in win 11, which is probably a huge privacy improvement for a majority of users. The recovery is sent to microsoft with your microsoft account, but against 99% of attacks (petty criminals stealing your laptop) this suffices. If you fall into the category of users that distrust microsoft with their key, you can take active action and configure bitlocker yourself.
- gnopgnip 3y agoMost small companies will login with a microsoft account and have the key saved by default to https://myaccount.microsoft.com/ https://myaccount.microsoft.com/ If you don't sign in with a microsoft account bitlocker isn't enabled by default. When you setup bitlocker it "forces" you to make a backup of the key
- replwoacause 3y agoWell no kidding
- brunoqc 3y ago> One aspect of this is that some laptop manufacturers provide a setting to erase the TPM is the laptop is opened. Do you mean like if you remove the screws and get inside a laptop? Could they gain access by cutting the plastic instead (maybe Matrix parasite extraction style).
- Ian678 3y agoCould also use a light sensor or check if a circuit that runs on the inside of the case is broken.
- michaelmior 3y agoStill seems not to difficult to bypass (if you know it's there).
- redox99 3y agoChassis intrusion is almost always just a small switch pushing against the side panel of the case. And yes there's a million ways you could bypass that.
- sublinear 3y agoWhich sounds potentially unreliable on a laptop. Seems like a hard knock or even just normal material fatigue might be enough to release the switch.
- hutzlibu 3y agoOne laptop of mine has such a sensor, but not for bitlocker. After I opened it, it would just refuse to turn on, probably a safeguard when repairing and not wanting it to run anything. But I did not know and thought I broke it, but after closing it again and tightening one screw in the middle, it worked and so I found that sensor. It is a very simple, but reliable push button and before it breaks, the screen will be broken long before that.
- ComputerGuru 3y agoI’ve never seen a consumer device with chassis intrusion enabled by default. Were these maybe volume orders for a business account? Those can come with whatever configuration IT wants.
- ixwt 3y agoFrom all the computers that I've seen with intrusion detection on by default, they only give you a warning from what I've seen.
- morpheuskafka 3y agoThat's probably just relying on a push-button tamper switch which could be easily bypassed by cutting the back plastic instead. I doubt they are doing anything very fancy like running wires over the whole case.
- o1y32 3y agoOff topic -- The joke is that you can hardly find a laptop with upgradable RAM these days. Not even on some ThinkPad lines. Gaming laptops often do.
- yencabulator 3y agohttps://frame.work/ https://frame.work/ is there for you.