Switch to full style
Data recovery and disk repair questions and discussions related to old-fashioned SATA, SAS, SCSI, IDE, MFM hard drives - any type of storage device that has moving parts
Post a reply

About Bitlocker decryption without password/recovery key

February 8th, 2020, 5:22

Hello,

I came through a blog post https://pulsesecurity.co.nz/articles/TPM-sniffing saying that it's possible to extract a Bitlocker key from a Trusted Platform Module (TPM) and decrypt it.

This needs some electronic knowledge.

@fzabkar: you are THE expert in electronics in this forum (my opinion), could you please confirm if it's true what this security expert is saying?

Did anyone test this method before and could decrypt the Bitlocker key?

Please share your knowledge.

Kind regards

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 3:35

No one interested in this topic? :roll: :roll: :roll:

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 4:25

Thanks for sharing the link.
Surely I can learn a lot from the post.

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 7:27

sosrecup wrote:Hello,

I came through a blog post https://pulsesecurity.co.nz/articles/TPM-sniffing saying that it's possible to extract a Bitlocker key from a Trusted Platform Module (TPM) and decrypt it.

This needs some electronic knowledge.

@fzabkar: you are THE expert in electronics in this forum (my opinion), could you please confirm if it's true what this security expert is saying?

Did anyone test this method before and could decrypt the Bitlocker key?

Please share your knowledge.

Kind regards


What is the point of this actions? Getting access to the data from stolen laptops?
Users who are willing to recovery their files in 99% cases provide us with pass/key .

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 8:46

What is the point of this actions? Getting access to the data from stolen laptops?
Users who are willing to recovery their files in 99% cases provide us with pass/key .


Not necessary. some clients encrypt their hard drives and forget the password and forget to save the recovery key or forget where they put it.

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 11:56

Why would anybody need to extract a key from TPM when they have access to TPM?

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 12:01

Why would anybody need to extract a key from TPM when they have access to TPM?


What if you forget the password and you don't remember where you put your recovery key (I had some clients in this situation), are you able to recover data from that drive?

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 12:10

"What if you forget the password and you don't remember where you put your recovery key (I had some clients in this situation), are you able to recover data from that drive?"
Billable hours, correct? Reading other discussion boards, I see a few threads about clients not having at the ready passwords or recovery keys.

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 12:10

sosrecup wrote:
Why would anybody need to extract a key from TPM when they have access to TPM?


What if you forget the password and you don't remember where you put your recovery key (I had some clients in this situation), are you able to recover data from that drive?

Per my understanding TPM holds a key that unlocks Bitlocker
Should be able to unlock Bitlocker, using TPM with a boot CD on the original laptop

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 13:09

Doomer wrote:Why would anybody need to extract a key from TPM when they have access to TPM?
Doomer, I'm a beginner, what has been your experience with TPM? I never knew that one could use just TPM to unlock BitLocker. I'd like to learn more!

Re: About Bitlocker decryption without password/recovery key

February 10th, 2020, 13:18

RolandJS wrote:
Doomer wrote:Why would anybody need to extract a key from TPM when they have access to TPM?
Doomer, I'm a beginner, what has been your experience with TPM? I never knew that one could use just TPM to unlock BitLocker. I'd like to learn more!

There are several types of protectors that can be used with Bitlocker, one of them is TPM only protector, which is old but sometimes can still be found on Bitlocker protected volumes

Re: About Bitlocker decryption without password/recovery key

February 12th, 2020, 3:36

Hi Guys
Pls. refer my post in this regard which is still unanswered unfortunately .
Bitlocker in some cases can be decrypted without key /password in pc3000. I have raised concerns as how AES128 key can be decrypted.
Can someone pls.look at it particularly senior members like Doomer , Dr-Kiev ,fzabkar , pepe to name few.


here is the post -
https://forum.hddguru.com/viewtopic.php ... er#p278195

Thanks

Re: About Bitlocker decryption without password/recovery key

February 12th, 2020, 11:22

terminator2 wrote:Hi Guys
Pls. refer my post in this regard which is still unanswered unfortunately .
Bitlocker in some cases can be decrypted without key /password in pc3000. I have raised concerns as how AES128 key can be decrypted.
Can someone pls.look at it particularly senior members like Doomer , Dr-Kiev ,fzabkar , pepe to name few.


here is the post -
https://forum.hddguru.com/viewtopic.php ... er#p278195

Thanks

Sometimes Bitlocker stores metadata called "clear key". Clear key can decrypt Bitlocker without a password
It has nothing to do with AES "crackability"

Re: About Bitlocker decryption without password/recovery key

February 13th, 2020, 9:42

Thanks Doomer :good: :-D

Re: About Bitlocker decryption without password/recovery key

February 14th, 2020, 2:08

terminator2 wrote:Thanks Doomer :good: :-D


Hi,
Many Dell Laptops Use Bitlocker and TPM i have recovered a few of these combos in india for my clients and i have also done that magic were key is not required as explained by doomer [ Were key is stored and the app finds it ]

Re: About Bitlocker decryption without password/recovery key

October 2nd, 2021, 7:39

Doomer wrote:
terminator2 wrote:Hi Guys
Pls. refer my post in this regard which is still unanswered unfortunately .
Bitlocker in some cases can be decrypted without key /password in pc3000. I have raised concerns as how AES128 key can be decrypted.
Can someone pls.look at it particularly senior members like Doomer , Dr-Kiev ,fzabkar , pepe to name few.


here is the post -
https://forum.hddguru.com/viewtopic.php ... er#p278195

Thanks

Sometimes Bitlocker stores metadata called "clear key". Clear key can decrypt Bitlocker without a password
It has nothing to do with AES "crackability"

hi Doomer
Is there any other software other than pc3000 DE which will sniff "clear key " password from Bitlocker metadata and decrypt it ?
My pc3000 is not updated and does not support this function.

Re: About Bitlocker decryption without password/recovery key

October 2nd, 2021, 9:36

terminator2 wrote:
Doomer wrote:
terminator2 wrote:Hi Guys
Pls. refer my post in this regard which is still unanswered unfortunately .
Bitlocker in some cases can be decrypted without key /password in pc3000. I have raised concerns as how AES128 key can be decrypted.
Can someone pls.look at it particularly senior members like Doomer , Dr-Kiev ,fzabkar , pepe to name few.


here is the post -
https://forum.hddguru.com/viewtopic.php ... er#p278195

Thanks

Sometimes Bitlocker stores metadata called "clear key". Clear key can decrypt Bitlocker without a password
It has nothing to do with AES "crackability"

hi Doomer
Is there any other software other than pc3000 DE which will sniff "clear key " password from Bitlocker metadata and decrypt it ?
My pc3000 is not updated and does not support this function.


UFS Explorer Pro, can do the same "trick" with "clear key" for Bitlocker encryption

Re: About Bitlocker decryption without password/recovery key

October 3rd, 2021, 4:22

DR-Kiev wrote:
terminator2 wrote:
Doomer wrote:
terminator2 wrote:Hi Guys
Pls. refer my post in this regard which is still unanswered unfortunately .
Bitlocker in some cases can be decrypted without key /password in pc3000. I have raised concerns as how AES128 key can be decrypted.
Can someone pls.look at it particularly senior members like Doomer , Dr-Kiev ,fzabkar , pepe to name few.


here is the post -
https://forum.hddguru.com/viewtopic.php ... er#p278195

Thanks

Sometimes Bitlocker stores metadata called "clear key". Clear key can decrypt Bitlocker without a password
It has nothing to do with AES "crackability"

hi Doomer
Is there any other software other than pc3000 DE which will sniff "clear key " password from Bitlocker metadata and decrypt it ?
My pc3000 is not updated and does not support this function.


UFS Explorer Pro, can do the same "trick" with "clear key" for Bitlocker encryption


Thank you so much Dr-kiev :good:

I have got a case of 512GB M.2 SSD from Thinkpad laptop. After windows updates suddenly Bitlocker has started to appear and asking for key.
Customer has not enabled it earlier ( by default it was enabled ). In fact customer was not aware of what is Bitlocker.

manage-Bde shows numeric key +TPM protectors.
I will give it a try using UFS explorer.
Thanks again.
Attachments
Screenshot 2021-10-02 164207.png
Screenshot 2021-10-02 164207.png (8.25 KiB) Viewed 13084 times

Re: About Bitlocker decryption without password/recovery key

October 3rd, 2021, 7:46

I tried UFS explorer but it failed to decrypt the volume. What should I do now ?
Attachments
bitlocker.jpg

Re: About Bitlocker decryption without password/recovery key

October 3rd, 2021, 23:23

Is there any way to read key from TPM directly ? I have asked customer to give his microsoft account details as well.
It seems protectors are not weak or "clear key" metadata is not present.
I am also sending it to one of my friend who is having updated DE.
Post a reply