Recommended Posts

Hi,

 

I've come across a friend's setup where he has secured his boot/system hard drive using Windows 7 Bitlocker using a key stored on a USB drive that he always leaves in the computer (with no startup PIN). If his PC was stolen how secure would it actually be?

 

We've discussed it at length as I'm pretty sure that it is the equivalent of locking your house but leaving the keys in the door. Do any of you know for a fact how secure this actually is? I'd also appreciate any articles or references that state the facts about this?

 

Any help greatly appreciated!

Well if you always leave the usb key in, what exactly is the point?

I am going to have to agree with you, but if someone didn't know and they inadvertently took it out and wiped the usb then the information on the hard drive would be useless, but common theft really aren't after what is on the hard drive,.... They want the hardware.

  • Like 1

Well if you always leave the usb key in, what exactly is the point?

I am going to have to agree with you, but if someone didn't know and they inadvertently took it out and wiped the usb then the information on the hard drive would be useless, but common theft really aren't after what is on the hard drive,.... They want the hardware.

 

Well the Windows install does have password protected users so if a thief powered it on they would see a logon prompt. I'm not 100% sure of how the PC would operate if the thief tried a basic recovery disk or even just reinstalled Windows over the top. Would it just find the key on the USB drive and allow access to all the PC's files as though it was not even encrypted for example or is it better than that?

The windows password can be easily cracked it is about as secure as a twisty tie keeping thieves away. There are plenty of password reset utilities available by a Google search.

 

But would Bitlocker block them being able to do the pw reset though (at least the typical/mainstream ones)? Or would the PC boot into password reset utility and access the Bitlocker'd drive using the USB drive's encryption key?

Bitlocker uses a logical partition that's encrypted. It's theoretically impossible to break into without the key. If you leave the key plugged in all of the time, that's another story, but the implementation of bitlocker should be very secure.

 

More: http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption

If he leaves it in all the time it's completely useless. If nothing else, the thief could just boot into Windows To Go, and then decrypt the C:\ drive and take all the data that way.

I know you're not talking about the FBI and stuff, but it's legally safer to have a password instead of a USB key, since the government can force you to hand over a physical key, while they can't force you to incriminate yourself by telling them the encryption password.

But would Bitlocker block them being able to do the pw reset though (at least the typical/mainstream ones)? Or would the PC boot into password reset utility and access the Bitlocker'd drive using the USB drive's encryption key?

Yes and no. If you can uninstall bit locker with the usb installed that is moot, uninstalling bit locker will negate the security bit locker provides

The way he has it setup is like putting your car in a vault, but leaving the vault door open. The only real defense left is the car's door locks (Windows Password), the vault itself (Bitlocker) is totally useless unless you lock the door.

  • Like 1

All of the above pretty much mirrors my thoughts on it. I was hoping for some clear cut reference though that demonstrates it's a futile step without having to resort to testing it in practice. Does anyone know of any or is it so bad that nobody has given it any serious consideration?

I would say don't bother unless its on a HDD that in a system supports TPM. What I see happening a lot is for BL is doing it for a USB key the data does get corrupted easy. I have had 5 of these to get corrupted in this past year alone. I am not sure what it is about usb keys but not HDDs.

 

?When BitLocker is suspended, BitLocker keeps the data encrypted but encrypts the BitLocker volume master key with a clear key.? ? Is that so? 

More digging around the documentation did finally reveal that yes, Microsoft knows that the system must be logged out "gracefully" for encryption to work.

Source

 

Unlock BitLocker under Windows PE

 

 

To unlock a BitLocker encrypted drive from the command prompt, you need the Windows command manage-bde. However, if you only have a common bootable Windows PE USB stick, your heroic deed will miserably fail with this error message:

ERROR: An error occurred (code 0?80040154):

Class not registered

Actually, if he has this set up properly it is secure, as you'd need to log in to make use of the bit locker locked files, and while windows passwords can be "easily" broken, that doesn't apply when the profile is protected by bit locker.

So basically without knowing his windows password you're getting nowhere, and with a bit locker protected profile you can't get it.

Also windows passwords aren't that easy to break in windows 7 and 8 either even without encryption. And if the password is long enough you can't break it anyway. You can only remove it, which again isn't possible in this situation.

It isn't just the profile that would have to be locked, it would have to be the Sam too. If the Sam is left unlocked the password can be reset and the encrypted profile would be useless to password hacks. I don't think windows did away with the Sam database.

I believe it was said that if you used bitlocker it would be encrypted as well.

 

even if you managed to wipe that password though, you still wouldn't get access to any of the data or the actual profile since it would still be encrypted and you wouldn't have the password. 

If you do not have a Trusted Platform Module, usage of a PIN in conjunction with a USB drive is advised.

The USB drive will not prevent thieves from accessing data if both the laptop and its USB drive were stolen. Bitlocker would be useless.

Despite the helpful replies I didn't quite get the definite confirmation I was looking for so I decided to take the time and test it myself.

 

I setup a PC with bit locker and the startup key on the USB drive (not the recovery key). I took out the hard drive, connected via a USB SATA connector. I then used the USB's key filename.bek file and unlocked the drive using the manage-bde command. Took less than 2 minutes and I could see all the files on the drive so it was absolutely owned!

 

I'm not going to bother trying an ERD disc but I'm sure the principle the same.

 

End result: encrypting with a USB drive that you leave in the computer is just like locking your car but leaving the keys in the lock. It's technically locked but might as well not be!

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Speaking of right, right dominant only which, as with most, makes this meaningless to me.
    • No, size is not the only selling point. I did not even remotely say that. Your claim was that "building your own will be faster and cheaper". This is false. You cannot build something close to that form factor with off-the-shelf parts. You can build a Mini-ITX PC and pay more, or something larger and pay less. But these are different market segments. It's apples and oranges.
    • There is a default resolution setting in Settings > Display that can be changed with a click. You can also change the settings on a per-game basis. No CLI needed. Also, Steam has countless games that are not "[perpetual] alpha/beta games", so no need for the straw man. Plus you can use other stores as well. And console games (e.g. PS5) cost a fortune, which itself more than negates the price subsidy on the system, unless you plan on exclusively playing 1 or 2 games. It's true that you shouldn't buy a system that doesn't support the game(s) you want to play, but I think that's kinda obvious, and applies to every console as well as PC. I don't game in the living room and have no need of a Steam Machine, but there is a clear market segment that would find it useful.
    • RSS Guard 5.2.0 by Razvan Serea RSS Guard is a simple (yet powerful) feed reader. It is able to fetch the most known feed formats, including RSS/RDF and ATOM. It's free, it's open-source. RSS Guard currently supports Czech, Dutch, English, French, German, Italian. RSS Guard will never depend on other services - this includes online news aggregators like Feedly, The Old Reader and others. RSS Guard is developed on top of the Qt library and it supports these operating systems: Windows GNU/Linux OS/2 (eComStation) Mac OS X xBSD (possibly) Android (possibly) other platforms supported by Qt The core features of RSS Guard are: support for online feed synchronization via plugins, Tiny Tiny RSS (from RSS Guard 3.0.0). multiplatform, support for all feed formats, simplicity, import/export of feeds to/from OPML 2.0, downloader with own tab and support for up to 6 parallel downloads, message filter with regular expressions, feed metadata fetching including icons, simple Adblock functionality, customized popup notifications, Google-based auto-completion for internal web browser location bar, ability to cleanup internal message database with various options, enhanced feed auto-updating with separate time intervals, multiple data backend support, SQLite (in-memory DBs too), MySQL. is able to specify target database by its name (MySQL backend), “portable” mode support with clever auto-detection, feed categorization, drap-n-drop for feed list, automatic checking for updates, ability to discover existing feeds on websites, full support of podcasts (both RSS & ATOM), ability to backup/restore database or settings, fully-featured recycle bin, printing of messages and any web pages, can be fully controlled via keyboard, feed authentication (Digest-MD5, BASIC, NTLM-2), handles tons of messages & feeds, sweet look & feel, fully adjustable toolbars (changeable buttons and style), ability to check for updates on all platforms + self-updating on Windows, hideable main menu, toolbars and list headers, KFeanza-based default icon theme + ability to create your own icon themes, fully skinnable user interface + ability to create your own skins, “newspaper” view, plenty of skins, support for "feed://" URI scheme, ability to hide list of feeds/categories, open-source development model based on GNU GPL license, version 3, tabbed interface, integrated web browser with adjustable behavior + external browser support, internal web browser mouse gestures support, desktop integration via tray icon, localizations to some languages, Qt library is the only dependency, open-source development model and friendly author waiting for your feedback, no ads, no hidden costs. RSS Guard 5.2.0 changelog: Added: Feed auto-fetch can now also be delayed while Feral GameMode is active on Linux and startup auto-fetch is skipped when GameMode is already active. (#2265) WebEngine builds can now use RSS Guard generated proxy auto-config (PAC) rules so article/web browsing follows per-account and per-feed proxy settings more closely. (#2273) Generated PAC rules now also cover related subdomains and use Public Suffix List data, so feeds such as feeds.bbc.co.uk can also proxy resources from images.bbc.co.uk. (#2273) Standard feeds can now define extra proxy domains, useful when article images, stylesheets or other page resources are loaded from a CDN or another domain that should use the same feed proxy. (#2273) RSS Guard now asks for proxy credentials when a WebEngine page needs proxy authentication and can fill credentials from the current feed proxy when available. (#2273) Network settings again include an option to ignore all cookies, which clears stored cookies and prevents new cookies from being accepted. Standard RSS/ATOM feeds can now individually ignore cookies while downloading feed data. Stored cookies can now be deleted from the Tools menu. Custom skin colors can now override the feed list article count color separately from feed titles, including a separate highlighted color. (#2275) Settings dialog can now search across available settings and highlight matching controls. (#1754) Standard RSS/ATOM feeds can now optionally be reported as broken when they are valid but contain no articles. (#2039) Standard RSS/ATOM feeds can now override the application-wide feed connection timeout per feed. (#1023) Tray icon can now use a custom background color and unread-count text color, with an option to reuse the generated icon as the application icon. (#1973) Support for more benevolent parsing of Gemlog entries (#2295). Article list can now show when an article was received by RSS Guard. (#947) Feed deep discovery now actually scrapes all links found in the website and checks if they are feeds or not. This greatly enhances usability of the deep discovery mode and discovers many more feeds than before. (#2306) Search boxes now show a small dot when the feed or article list is hiding some items because of active filtering. (#873) Articles now have a shortcut-assignable action to open the homepage of the feed they belong to. (#2060) Fixed: Parallel feed updates no longer crash when multiple update results are processed at the same time. (64cf521) Links in WebEngine articles opened from feeds such as Kill the Newsletter now open correctly instead of being swallowed by the embedded page. (#2272) Relative article URLs resolution was kinda broken. (#2282) Clicking article URL did not work when the URL had "fragment" set. (#2293) The default proxy setting now uses Qt/system default proxy behavior instead of forcing no proxy. (e0263ad) WebEngine article loading now keeps the current feed context, so feed-specific proxy credentials remain available while the article page loads. (fdd0f00) Download: RSS Guard 5.2.0 (64-bit) | Portable | ~ 130.0 MB (Open Source) Link: RSS Guard Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      461
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      110
    4. 4
      Michael Scrip
      83
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!