logoalt Hacker News

DANmodetoday at 5:19 AM1 replyview on HN

> Mitigation: Use Bitlocker with a PIN.

> (Note: The YellowKey author disagrees that PIN is a protection


Replies

jackjefftoday at 5:50 AM

That’s the most puzzling part to me. What’s the point of the PIN then? I was assuming it was mixed with the TPM secret somehow but if it can be bypassed then it shows it just an IF statement somewhere. Dang…

God I hate this stupid design of burying the decryption key in the TPM and hoping the software does not get fooled to reveal it.

Microsoft always sucks. Why don’t you ask for the password at boot time and derive the key from it. So much simpler and makes this kind of attacks impossible. Nobody is going to bypass LUKS or FileVault like this.

show 4 replies