3 ms·
Using Bitlocker with a PIN solves that. Anyways on many modern system the TPM is often just part of the firmware running on a secure part of the CPU and probin
by raron 2y ago
Using Bitlocker with a PIN solves that.
Anyways on many modern system the TPM is often just part of the firmware running on a secure part of the CPU and probing the signals in the chip is probably outsider of the budget of TikTok influencers.
- bri3d 2y ago> Using Bitlocker with a PIN solves that. At an enormous cost of having to remember and enter a PIN - not practical for corporate IT due to the propensity for forgetting and not practical for offline server use. > Anyways on many modern system the TPM is often just part of the firmware running on a secure part of the CPU On AMD this is almost 100% prevalent, yes. On Intel platforms a physical TPM is still common and PTT (firmware TPM) is usually disabled by default for some reason - a user/manager would usually have to re-select it in the BIOS. On desktop platforms I think PTT runs externally in the PCH, too, which is off-package and connected over DMI (I think on most mobile parts PCH is a separate on-package die). I don't think anyone has done research on how the fTPM part of PCH <-> CPU comms work on modern Intel platforms; this has always seemed like a fun topic for a deep dive and talk to me, but I've never had the time. I don't think either of these things excuses the lack of encrypted parameter support from BitLocker, though. I'd love to know why Microsoft continue not to use it. The only reason I've ever seen given is "it was deemed too complex / has an attack surface," which is an interesting idea but quite bunk when UEFI is already in the picture IMO.
- p_ing 2y agoThe Intel PCH is on-package exposed via [DMI] PCIe lane while AMD's fTPM is on-die. It would be unusual for any current device to have a discrete TPM, at least in the consumer space given current x86 processors have an fTPM.
- wat10000 2y agoI haven’t used Windows since the XP days. Does Windows not have a login password? Or does something make it require a separate disk PIN and not just encrypt the drive with the login password? macOS does the latter and it seems like an obvious approach.
- briHass 2y agoIn this case, they're talking about the Bitlocker disk encryption PIN, which is in _addition_ to the Windows password, or more common now, PIN. You can set them both to the same thing if you choose. The disk PIN on boot is uncommon/harder to do for home users, but it's a common setup in the corpo world. Enforced by AD, or Intune.
- wat10000 2y agoA disk PIN shouldn’t add much extra security, though, unless the login password isn’t actually used to key the encryption.
- BenjiWiebe 2y agoI'm not aware that Windows uses your login key to encrypt anything on the disk, but maybe Windows 11 does it differently than <=10. The disk password actually encrypts the disk, so you can't just pull the disk out and read it, or boot Linux from a flash drive and read it. You can do the above attacks when all that's set is a Windows password. In fact, you could even modify the OS at that point so it logs and exfiltrates passwords in the future.