3 ms·
With Bitlocker it is still possible to have single password-based key. But enabling that requires to enter a few commands on the command line.
by fpoling 9mo ago
With Bitlocker it is still possible to have single password-based key. But enabling that requires to enter a few commands on the command line.
- lazide 9mo agoAnd you can be sure it didn’t add a ‘recovery’ key, how?
- nerdile 9mo agoUsing the same CLI, which shows all the alternative "protectors".
- lazide 9mo agoAgain, that is a lot of trust since it could trivially just… not show it. Which is already the default for most FDE systems for intermediate/system managed keys.
- smileybarry 9mo agoIt could also just pretend to encrypt your drive with a null key and not do anything, either. You need some implicit trust in a system to use it. And at worst, you can probably reverse engineer the (unencrypted) BitLocker metadata that preboot authentication reads.
- lazide 9mo agoNo, that would be trivial to verify with any other operating system. Key ring contents (and what is done with them) are typically much harder to verify as they’re encrypted.
- Krssst 9mo agoIt requires the Pro edition of Windows too.