4 ms·
If you have physical access to the harddrive and can turn it on or off legitimately, then can you not just image the harddrive to a backup (While its running) t
by DanBlake 12y ago
If you have physical access to the harddrive and can turn it on or off legitimately, then can you not just image the harddrive to a backup (While its running) then modify whatever files you want and restore the new modified backup back to the harddrive? Sounds to me like you would be off to the races then.
Bottom line is, if you let people have physical access to the machine, they can always own it.
- discreditable 12y ago> an you not just image the harddrive to a backup (While its running) The disk contents are fully encrypted, and Windows will only boot when the system is in an untampered state (via TPM unlock). A student would have to compromise Windows in a way that escalates their privileges. From there they could turn BitLocker off if they liked. This is far from impossible, but we also use AppLocker to prevent students from running any software that has not be explicitly approved--so they would have to compromise some software which is already installed. I won't delude myself and say it's impossible to compromise all of this, but for my goal of keeping 13-18 year-olds from resetting the local admin password it is quite sufficient.
- stevecalifornia 12y agoTPM is a chip on the motherboard that stores the keys for the encrypted hard-drive. You can't move the hard disk to another machine or use a backup to go elsewhere because it won't have the correct key on the TPM to decrypt the hard drive.
- rilita 12y agoIf you have physical access, just reset the bios and reinstall windows on the box from scratch. If the bios cannot be reset ( is such a thing possible ) then remove, clip, or melt the tpm chip in order to force the system to forget it's tpm info?
- Klathmon 12y agoIt's not that the TPM chip is "enforcing" the encryption, it actually contains the "password" to it. So if you remove, clip, or melt the TPM chip the hard drives' data is forever lost, as that key is now destroyed.
- rilita 12y agoThe discussion was whether students could force the machine ( a laptop they could take home with them ) into a state where they could use it to cheat during tests. TPM chips generally provide the following: 1. An encrypted store that can only be accessed by an authorized portion of code ( such as booting an encrypted drive ). Checks are done to ensure the code being run is signed. 2. Secure RNG ( random number generation ) 3. Various other public/private key stuff Typically you can enable/disable TPM from the BIOS. ( whether it is a physically removeable TPM chip or not ) Obviously removing/destroying the TPM chip will cause a loss of data, but that is irrelevant if you don't care about that data and are willing to reinstall the OS. It isn't hard to install a clean OS on a wiped drive. Even supposing somehow you couldn't reset the BIOS to shut off the TPM and force a normal clean drive boot process, I was speculating if removing/destroying the TPM would revert to booting normally. Note there was a lot of anger when TPMs were initially introduced, because they could effectively be used to force a system to only ever boot a signed OS. ( removing the ability to run Linux ) This is my curiosity; if on normal systems this can be forced or not.
- halfcat 12y ago>If you have physical access to the harddrive and can turn it on or off legitimately, then can you not just image the harddrive to a backup (While its running) How would one complete an image level backup of an encrypted hard drive without admin rights?