3 ms·
I would like to take the chance to ask about something that I never understood from Bitlocker and this kind of encryption, in general, where the decryption key
by Octabrain 3y ago
I would like to take the chance to ask about something that I never understood from Bitlocker and this kind of encryption, in general, where the decryption key is provided automatically by the system. Let's say, if my laptop (I mean, the whole device) is stolen, which security does Bitlocker provide? From an attacker POV, the system will boot and it will ask for my user account password. So, to my understanding, it will protect my data if my hard disk is extracted from the laptop and attempted to run it from a different system.
Worth mentioning that this probably silly misconception is what makes me to always set a password for Bitlocker that I have to type manually which is what I've always done on LUKS.
Am I totally wrong?
- Rygian 3y agoMy guess: if you didn't set a password for the disk encryption, you have no protection for that scenario.
- itscrush 3y agoNot entirely wrong, but may be missing how the key is now exportable adding risk to the scenario. As you mention decryption key is provided automatically to the system. This means it's in RAM ready for export and re-use by bad actor against your encrypted disk. Cold boot attacks[1] are one of the attack vectors you'd want to read more on to figure out if this is valid for your threat model. [1] https://en.wikipedia.org/wiki/Cold_boot_attack https://en.wikipedia.org/wiki/Cold_boot_attack
- tedunangst 3y agoWindows is not supposed to let anyone access the files until they enter the correct account password. So the disk will decrypt in this computer, but then Windows prevents access.
- vel0city 3y agoIt requires the attacker to bypass the login, extract the key from memory from the system, or potentially with a physical TPM this style of attack. This is probably a lot more sophisticated of an attack than a random thief trying to make a quick buck stealing an expensive computer. Chances are they'll just end up wiping the drive and try to sell it rather than actually try a cold boot attack, but it all depends on your threat profile. Personally I mostly use FDE on personal machines so I don't have to care much about physical destruction when I need to get rid of storage devices. If a hard drive fails I don't need to actually tear it apart to make sure my data is gone. My device is usually in sleep mode when I'm out and about so if they were going to do a cold boot attack they could do it anyways.