Jump to content

Can someone explain the practical use of bitlocker?

Necro compute

From my understanding bitlocker encrypts your data with a secure key stored in your system's TPM.

However your PC with said can access that data just fine; malware would equally be able to read the data along with the rest of the OS.
Someone with access to your computer would be able to copy files on and off as well. If someone stole the computer, they'd have the key because it's stored in said computer.

 

So really bitlocker is only able to protect your data if someone steals your internal hard drive but not the rest of the system... Or am I missing something ?

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, Necro compute said:

If someone stole the computer, they'd have the key because it's stored in said computer.

 

So really bitlocker is only able to protect your data if someone steals your internal hard drive but not the rest of the system... Or am I missing something ?

Your user account is supposed to be secured enough that if they get the computer, power it on and that unlocks the drive they can't actually log in and access data. So to get at the data they'd have to either boot another OS or take the drive out and put it in another machine, both of which would require the bitlocker recovery key.

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
Share on other sites

Link to post
Share on other sites

50 minutes ago, Kilrah said:

Your user account is supposed to be secured enough that if they get the computer, power it on and that unlocks the drive they can't actually log in and access data. So to get at the data they'd have to either boot another OS or take the drive out and put it in another machine, both of which would require the bitlocker recovery key.

So where is the key stored? in the MB, or the OS-drive? if so, and those fail, then my data will be forever locked? 

AMD 9 7900 + Thermalright Peerless Assassin SE

Gigabyte B650m DS3H

2x16GB GSkill 60000 CL30

Samsung 980 Pro 2TB

Fractal Torrent Compact

Seasonic Focus Plus 550W Platinum

W11 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

not 100% sure as it was a while back but our it guy used an encyption for our company PC laptops etc. but if something happened as PC failure he had access to keys that could unlock the drives. I would imagine that your agreement with bitlocker would also have this as you the user need to register etc. So moving you hard drive to a working computer only you would have access to your data and the key would be applied to your new shiny PC .

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, Lurking said:

So where is the key stored? in the MB, or the OS-drive? if so, and those fail, then my data will be forever locked? 

Bitlocker keys are backed up in the cloud. You can access it online on your Microsoft Account

https://support.microsoft.com/en-us/windows/finding-your-bitlocker-recovery-key-in-windows-6b71ad27-0b89-ea08-f143-056f5ab347d6

AMD Ryzen 5 3600 | AsRock B450M-Pro4 | Zotac GTX 3070 Ti

Shure SRH840A | Sennheiser Momentum 2 AEBT | LG C9 55"

Link to comment
Share on other sites

Link to post
Share on other sites

36 minutes ago, Lurking said:

So where is the key stored? in the MB, or the OS-drive? if so, and those fail, then my data will be forever locked? 

TPM and no, you can always use the recovery key you'll have been given when enabling bitlocker. Or the MS account as mentioned if tied. 

F@H
Desktop: i9-13900K, ASUS Z790-E, 64GB DDR5-6000 CL36, RTX3080, 2TB MP600 Pro XT, 2TB SX8200Pro, 2x16TB Ironwolf RAID0, Corsair HX1200, Antec Vortex 360 AIO, Thermaltake Versa H25 TG, Samsung 4K curved 49" TV, 23" secondary, Mountain Everest Max

Mobile SFF rig: i9-9900K, Noctua NH-L9i, Asrock Z390 Phantom ITX-AC, 32GB, GTX1070, 2x1TB SX8200Pro RAID0, 2x5TB 2.5" HDD RAID0, Athena 500W Flex (Noctua fan), Custom 4.7l 3D printed case

 

Asus Zenbook UM325UA, Ryzen 7 5700u, 16GB, 1TB, OLED

 

GPD Win 2

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×