An attacker with physical access can abruptly restart the device and dump RAM, as analysis of this memory may reveal FVEK keys from recently running Windows instances, compromising data encryption.

The effectiveness of this attack is, however, limited because the data stored in RAM degrades rapidly after the power is cut off.

  • optional
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    2 days ago

    What’s the advantage of disk encryption if you don’t require a password to boot? Couldn’t you just boot the device and extract the data using Explorer anyway?

    • cheet@infosec.pub
      link
      fedilink
      English
      arrow-up
      11
      ·
      2 days ago

      Its kinda useful for devices where userland is also protected against exfil, like a kiosk or windows lock screen.

      If the bios is hardened, secure boot on, bitlocker on, and windows is locked with a password, you can’t simply take the disk out and manipulate it cause bitlocker with TPM means only that specific hardware profile will decrypt the disk automatically.

      You can’t get to explorer cause the system is locked with windows auth, and you can’t reset the PW cause bitlocker is on, and you cant remove the disk cause the TPM protects against that with bitlocker.

      Its really not perfect, and I’m not advocating for it, but its a decent protection in systems where adding another pin/password isn’t practical.

      Even Microsoft recommends at least also using a pin with bitlocker.

    • Limonene@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      I assume they think the Windows login password will keep them safe. I don’t know. But many corporate computers (several I’ve been forced to use) do use Bitlocker without a password.

      • sugar_in_your_tea
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Yeah, that’s only going to protect from drive theft, which I guess makes disposal easier?