October 4th, 2021, 6:50
terminator2 wrote:Is there any way to read key from TPM directly ? I have asked customer to give his microsoft account details as well.
It seems protectors are not weak or "clear key" metadata is not present.
I am also sending it to one of my friend who is having updated DE.
October 4th, 2021, 9:09
DR-Kiev wrote:terminator2 wrote:Is there any way to read key from TPM directly ? I have asked customer to give his microsoft account details as well.
It seems protectors are not weak or "clear key" metadata is not present.
I am also sending it to one of my friend who is having updated DE.
In your case key is not empty. Solution with "clear key" won't work.
Ask your client about his Microsoft account.
Specify model of your ThinkPad laptop.
October 4th, 2021, 9:29
DR-Kiev wrote:terminator2 wrote:Is there any way to read key from TPM directly ? I have asked customer to give his microsoft account details as well.
It seems protectors are not weak or "clear key" metadata is not present.
I am also sending it to one of my friend who is having updated DE.
In your case key is not empty. Solution with "clear key" won't work.
Ask your client about his Microsoft account.
Specify model of your ThinkPad laptop.
October 5th, 2021, 0:43
terminator2 wrote:DR-Kiev wrote:terminator2 wrote:Is there any way to read key from TPM directly ? I have asked customer to give his microsoft account details as well.
It seems protectors are not weak or "clear key" metadata is not present.
I am also sending it to one of my friend who is having updated DE.
In your case key is not empty. Solution with "clear key" won't work.
Ask your client about his Microsoft account.
Specify model of your ThinkPad laptop.
Is it anyway possible to access TPM & extract key from TPM ?
October 5th, 2021, 2:05
October 5th, 2021, 8:14
digisupport wrote:Did use LPC sniffing in a BitLocker TPM-only mode case. SSD had a lot of reading errors, windows could not boot but TPM still unlocking the drive.
Sniffing worked fine and VMK was found and used in DE to decrypt. In this case it was useful to get the SSD moved to DE for imaging. Could probably have used a live CD to boot the pc and made a image that way, but without power control imaging would not have been successful. Drive hang itself on every reading error.
In your case terminator2, as i understand it, TPM is not decrypting the drive and there is no "clear key" in meta. To sniff VMK TPM encryption needs to work, so i cant see how sniffing will solve your case.
October 10th, 2021, 0:43
October 11th, 2021, 5:43
October 11th, 2021, 6:16
alpy wrote:Hi,
If the required key can be sniffed (i.e. LPC communication is not encrypted) then it should be possible to be extracted by booting a linux and accessing TPM with trousers/tpm-tools (in case secure boot is not enabled). If it's still not working, then you can still try to throw the windows installation under a virtual machine which emulates the TPM, so you can basically sniff the TPM in a 'soft' way, without having to actually solder wires on TPM chip.
Powered by phpBB © phpBB Group.