I’m pretty sure all tpms can be read with an electric interference reader when they’re probed, as an intended loophole
Your computer generate a random key using (hopefully) a trusted PRNG with good enough sources. This key is then used to encrypt your data. This key is stored in your computer’s TPM module, and provided to the OS only if the chip approves all the checks in places. In addition, you get that key displayed to you, so you can write it down (or alternatively save the key file somewhere of your convenience). This is relatively good as far as security goes (unless the TPM is broken, which can happen).
And then, unless you jumped through hoops to disable it, your PC sends the key to Microsoft so they can just keep it linked to your account. That’s the part that sucks, because then, they have the key, can unlock your drive on your behalf, and have to produce it if asked by a judge or something.
Note that there are relatively safe way to protect these keys even if they are backed up in “the cloud”, by encrypting them beforehand using your actual password. It’s not absolutely perfect, but can make it very hard/costly/impossible to retrieve, depending on the resources of the attacker/government agency. But MS didn’t chose this way. I don’t know if it’s because of sheer incompetence, inattention, or because this feature is claimed to be here to “help” people that lose their key, and as such are likely to lose their password too, but it is what it is.
jnod4@lemmy.ca 11 hours ago
French75@slrpnk.net 7 hours ago
And then, unless you jumped through hoops to disable it, your PC sends the key to Microsoft so they can just keep it linked to your account.
You’d probably also have to jump through the hoops to disable windows recall too.
DeathByBigSad@sh.itjust.works 11 hours ago
Funny enough, people have lost access to their bitlocker encrypted drive because of some weird issues that triggered the windows intallation to revert to asking for the full bitlocker encryption key (I think if you disable secure boot or mess with CPU upgrades or the TPM, or some weird update broke, that can happen), which they didn’t have and forgot the microsoft account. But microsoft can’t help because they forgot about their acount credentials.
They should’ve asked the FBI for help lolz
Wispy2891@lemmy.world 7 hours ago
It happened TWICE on my Lenovo laptop, when it automatically installed a firmware update from windows update