Share via

Bitlocker most secure configuration

Jake Sokol 106 Reputation points
2020-10-02T14:25:12.847+00:00

Folks - I'm setting up a new computer and want to make sure I'm using the most optimal and secure method for bitlocker given there have been so many vulnerabilities with it last few years. Can somebody take a look and advise? The data volume and OS volume look a little different at the end of each output. If there is something I should change to make it secure, I want to do it right now before installing applications onto the machine. My data drive will be solely used for a surveillance/VMS software but I need to guard against potential physical theft

[Data Volume]

Volume B: [data drive]

[Data Volume]

Size: 7452.02 GB

BitLocker Version: 2.0

Conversion Status: Fully Encrypted

Percentage Encrypted: 100.0%

Encryption Method: XTS-AES 128

Protection Status: Protection On

Lock Status: Unlocked

Identification Field: Unknown

Automatic Unlock: Enabled

Key Protectors:

External Key

Numerical Password

External Key (Required for automatic unlock)

Volume C: []

[OS Volume]

Size: 255.56 GB

BitLocker Version: 2.0

Conversion Status: Fully Encrypted

Percentage Encrypted: 100.0%

Encryption Method: XTS-AES 128

Protection Status: Protection On

Lock Status: Unlocked

Identification Field: Unknown

Key Protectors:

TPM

Numerical Password

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments

7 answers

Sort by: Most helpful
  1. MTG Marinetechnik 356 Reputation points
    2020-10-05T06:45:18.267+00:00

    Hardware encryption will not be used by default, no worries. There is no common vulnerability in hardware encryption present, it were just a few drive models that had problems. But software encryption will do, so leave it.
    Without a PIN, an attacker that steals the machine might extract the key from RAM using a cold boot attack. That is not something the ordinary attacker would do, but who knows who is interested in your machines? https://www.youtube.com/watch?v=JDaicPIgn9U

    Was this answer helpful?

    0 comments No comments

  2. Jake Sokol 106 Reputation points
    2020-10-03T23:59:47.83+00:00

    Also is the ssd hardware encryption vulnerability still present and should I configure group policy to use software encryption on all ssd drives (os and data drive)
    Thx

    Was this answer helpful?

    0 comments No comments

  3. Jake Sokol 106 Reputation points
    2020-10-03T22:26:41.963+00:00

    how much security am I losing without a pre-boot authentication PIN? can an attacker somehow log into windows and access my data

    given this is a surveillance machine, it's critical it boots up hands-free after a power loss

    thx

    Was this answer helpful?

    0 comments No comments

  4. Bagitman 596 Reputation points
    2020-10-03T19:03:57.337+00:00

    You did not configure a pre-boot authentication PIN, so your config cannot be called optimal for security. However, with such a PIN set, the machine would not be able to start automatically (hands-free) after update installation reboots or crashes, so you need to decide if that matters or not.

    Was this answer helpful?

    0 comments No comments

  5. Jake Sokol 106 Reputation points
    2020-10-02T21:45:22.017+00:00

    Can anybody kindly look into this? I'm hoping to start using this machine over the weekend - thanks!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.