Recommended Posts

Hi,

 

I've come across a friend's setup where he has secured his boot/system hard drive using Windows 7 Bitlocker using a key stored on a USB drive that he always leaves in the computer (with no startup PIN). If his PC was stolen how secure would it actually be?

 

We've discussed it at length as I'm pretty sure that it is the equivalent of locking your house but leaving the keys in the door. Do any of you know for a fact how secure this actually is? I'd also appreciate any articles or references that state the facts about this?

 

Any help greatly appreciated!

Well if you always leave the usb key in, what exactly is the point?

I am going to have to agree with you, but if someone didn't know and they inadvertently took it out and wiped the usb then the information on the hard drive would be useless, but common theft really aren't after what is on the hard drive,.... They want the hardware.

  • Like 1

Well if you always leave the usb key in, what exactly is the point?

I am going to have to agree with you, but if someone didn't know and they inadvertently took it out and wiped the usb then the information on the hard drive would be useless, but common theft really aren't after what is on the hard drive,.... They want the hardware.

 

Well the Windows install does have password protected users so if a thief powered it on they would see a logon prompt. I'm not 100% sure of how the PC would operate if the thief tried a basic recovery disk or even just reinstalled Windows over the top. Would it just find the key on the USB drive and allow access to all the PC's files as though it was not even encrypted for example or is it better than that?

The windows password can be easily cracked it is about as secure as a twisty tie keeping thieves away. There are plenty of password reset utilities available by a Google search.

 

But would Bitlocker block them being able to do the pw reset though (at least the typical/mainstream ones)? Or would the PC boot into password reset utility and access the Bitlocker'd drive using the USB drive's encryption key?

Bitlocker uses a logical partition that's encrypted. It's theoretically impossible to break into without the key. If you leave the key plugged in all of the time, that's another story, but the implementation of bitlocker should be very secure.

 

More: http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption

If he leaves it in all the time it's completely useless. If nothing else, the thief could just boot into Windows To Go, and then decrypt the C:\ drive and take all the data that way.

I know you're not talking about the FBI and stuff, but it's legally safer to have a password instead of a USB key, since the government can force you to hand over a physical key, while they can't force you to incriminate yourself by telling them the encryption password.

But would Bitlocker block them being able to do the pw reset though (at least the typical/mainstream ones)? Or would the PC boot into password reset utility and access the Bitlocker'd drive using the USB drive's encryption key?

Yes and no. If you can uninstall bit locker with the usb installed that is moot, uninstalling bit locker will negate the security bit locker provides

The way he has it setup is like putting your car in a vault, but leaving the vault door open. The only real defense left is the car's door locks (Windows Password), the vault itself (Bitlocker) is totally useless unless you lock the door.

  • Like 1

All of the above pretty much mirrors my thoughts on it. I was hoping for some clear cut reference though that demonstrates it's a futile step without having to resort to testing it in practice. Does anyone know of any or is it so bad that nobody has given it any serious consideration?

I would say don't bother unless its on a HDD that in a system supports TPM. What I see happening a lot is for BL is doing it for a USB key the data does get corrupted easy. I have had 5 of these to get corrupted in this past year alone. I am not sure what it is about usb keys but not HDDs.

 

?When BitLocker is suspended, BitLocker keeps the data encrypted but encrypts the BitLocker volume master key with a clear key.? ? Is that so? 

More digging around the documentation did finally reveal that yes, Microsoft knows that the system must be logged out "gracefully" for encryption to work.

Source

 

Unlock BitLocker under Windows PE

 

 

To unlock a BitLocker encrypted drive from the command prompt, you need the Windows command manage-bde. However, if you only have a common bootable Windows PE USB stick, your heroic deed will miserably fail with this error message:

ERROR: An error occurred (code 0?80040154):

Class not registered

Actually, if he has this set up properly it is secure, as you'd need to log in to make use of the bit locker locked files, and while windows passwords can be "easily" broken, that doesn't apply when the profile is protected by bit locker.

So basically without knowing his windows password you're getting nowhere, and with a bit locker protected profile you can't get it.

Also windows passwords aren't that easy to break in windows 7 and 8 either even without encryption. And if the password is long enough you can't break it anyway. You can only remove it, which again isn't possible in this situation.

It isn't just the profile that would have to be locked, it would have to be the Sam too. If the Sam is left unlocked the password can be reset and the encrypted profile would be useless to password hacks. I don't think windows did away with the Sam database.

I believe it was said that if you used bitlocker it would be encrypted as well.

 

even if you managed to wipe that password though, you still wouldn't get access to any of the data or the actual profile since it would still be encrypted and you wouldn't have the password. 

If you do not have a Trusted Platform Module, usage of a PIN in conjunction with a USB drive is advised.

The USB drive will not prevent thieves from accessing data if both the laptop and its USB drive were stolen. Bitlocker would be useless.

Despite the helpful replies I didn't quite get the definite confirmation I was looking for so I decided to take the time and test it myself.

 

I setup a PC with bit locker and the startup key on the USB drive (not the recovery key). I took out the hard drive, connected via a USB SATA connector. I then used the USB's key filename.bek file and unlocked the drive using the manage-bde command. Took less than 2 minutes and I could see all the files on the drive so it was absolutely owned!

 

I'm not going to bother trying an ERD disc but I'm sure the principle the same.

 

End result: encrypting with a USB drive that you leave in the computer is just like locking your car but leaving the keys in the lock. It's technically locked but might as well not be!

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I doubt that Google will keep the same price... it may go up from that list published.
    • Sennheiser's audiophile grade HD 600 hits lowest ever price on Amazon Prime Day 2026 by Sayan Sen If you are in the market for high-quality audiophile-grade over-ear headphones then Sennheiser's HD 600 are a great choice for sure, especially today on Prime Day 2026 as the product has hit its lowest ever price (purchase link under the specs table down below). The Sennheiser HD 600 has long been regarded as a reference headphone for listeners seeking a detailed and natural listening experience. It is an open-back design that is built around the idea of acoustic transparency which is essentially said to allow sound waves to move freely for a more spacious and accurate presentation by reducing turbulence and the type of distortion that can result from it. At the heart of the product is Sennheiser’s proprietary driver system featuring a 42 mm driver paired with a lightweight diaphragm and aluminum voice coils. The company says this design helps deliver fast response times and better articulate sound across the audible frequency range. Comfort and durability are also key aspects of the HD 600 as the headphones feature soft velour ear pads designed for extended listening sessions. The HD 600 comes with a detachable 3-meter cable, a 6.3 mm stereo connector, and a 3.5 mm adapter for compatibility with a wide range of audio equipment. The technical specs of the Sennheiser HD 600 are given in the table below: Specification Value Transducer Principle Dynamic, Open-Back Ear Coupling Circumaural (Over-Ear) Frequency Response 12 Hz – 40,500 Hz Sound Pressure Level (SPL) 97 dB (1 V) Impedance 300 Ω Total Harmonic Distortion (THD) < 0.1% (1 kHz, 1 V) Cable Length 3 m (9.8 ft) Connector 3.5 mm Stereo Jack Plug Included Adapter 6.3 mm (1/4") Stereo Jack Adapter Weight 260 g Magnetic Field Strength 1.8 mT Driver Size 42 mm Dynamic Driver Diaphragm Size 38 mm Get it at the link below: Sennheiser HD 600: $237.00 (Sold by Electronics Expo, Shipped by Amazon US) (Was: $449.95) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases
    • So the card is targeted at headphone users - so the review should be from someone that uses this - maybe I can review a card next time.
    • I have a older F4-210 NAS, it is pretty basic, the CPU is not the fastest by a long way and only 1GB of ram, but it works fine. I don't understand the need for A.I in a NAS. It seems like A.i is being shoved into everything, if we like it or not. i will stick to my old Terramsater NAS, thankfully the OS is not being updated. Also, got myself a small NAs built using a Raspberry Pi 5. iy usesd less energy, so stays on all the time. As for the unit above, if it is as reliable as my old Terramaster Nas, then it will be a good unit.
  • Recent Achievements

    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      476
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      104
    4. 4
      Michael Scrip
      88
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!