logoalt Hacker News

bombcartoday at 3:55 AM2 repliesview on HN

How is this even possible, backdoor or no? Isn't the whole point of this type of encryption that even a compromised machine can't decrypt without the passphrase? If this works it means that the key is stored unencrypted somewhere?


Replies

majorchordtoday at 4:23 AM

Most setups only have the key stored in the TPM, so all you need to get it back is a signed/trusted bootloader.

Ideally you'd want that key to be further protected with a password or some other mechanism because it's not impossible to extract TPM keys.

andrecarinitoday at 4:18 AM

Presumably the key is stored in the TPM