you are viewing a single comment's thread
view the rest of the comments
[–] 53 points 2 years ago (13 children)

uhoh, and wait for the time when the user will update his BIOS, that resets TPM2, and at reboot bitlocker asks for the 48 digits key to decrypt hard drive, that the user never saved...

  • source
  • hideshow 13 child comments
  • [–] 13 points 2 years ago (7 children)

    What can you do when this happens... Asking for a friend...

  • source
  • parent
  • hideshow 7 child comments
  • [–] 14 points 2 years ago (5 children)

    it should be in your MS online account as someone wrote, but in case of, I always save it on a USB key, hidden somewhere. You can also print it, or take a picture of it with your phone. Because there is no way to get it back.

  • source
  • parent
  • hideshow 5 child comments
  • [+] 2 points 2 years ago* (last edited 1 year ago) (4 children)
  • [+] 4 points 2 years ago* (last edited 1 year ago) (3 children)
  • [–] 5 points 2 years ago (1 child)

    Wait? My Lenovo laptop did exactly this. It first encrypted the SSD without telling me, then it updated the bios via windows update (or via Lenovo assistant, but still it was unattended)

    Luckily I was using a Microsoft account (usually I don't because fuck that) so the keys were automatically backupped

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 2 years ago (2 children)

    I updated my BIOS few days ago and on reboot got a warning about bitlocker and resetting fTPM, but I'm on linux. I dumped luks headers, and master priv keys before resetting just in case but everything worked as usual. Do you know if I just got lucky or if luks dosn't use TPM? Should I hold on to the luks headers and master priv key backup?

  • source
  • parent
  • hideshow 2 child comments