Hardware encryption will not be used by default, no worries. There is no common vulnerability in hardware encryption present, it were just a few drive models that had problems. But software encryption will do, so leave it.
Without a PIN, an attacker that steals the machine might extract the key from RAM using a cold boot attack. That is not something the ordinary attacker would do, but who knows who is interested in your machines? https://www.youtube.com/watch?v=JDaicPIgn9U
Bitlocker most secure configuration
Folks - I'm setting up a new computer and want to make sure I'm using the most optimal and secure method for bitlocker given there have been so many vulnerabilities with it last few years. Can somebody take a look and advise? The data volume and OS volume look a little different at the end of each output. If there is something I should change to make it secure, I want to do it right now before installing applications onto the machine. My data drive will be solely used for a surveillance/VMS software but I need to guard against potential physical theft
[Data Volume]
Volume B: [data drive]
[Data Volume]
Size: 7452.02 GB
BitLocker Version: 2.0
Conversion Status: Fully Encrypted
Percentage Encrypted: 100.0%
Encryption Method: XTS-AES 128
Protection Status: Protection On
Lock Status: Unlocked
Identification Field: Unknown
Automatic Unlock: Enabled
Key Protectors:
External Key
Numerical Password
External Key (Required for automatic unlock)
Volume C: []
[OS Volume]
Size: 255.56 GB
BitLocker Version: 2.0
Conversion Status: Fully Encrypted
Percentage Encrypted: 100.0%
Encryption Method: XTS-AES 128
Protection Status: Protection On
Lock Status: Unlocked
Identification Field: Unknown
Key Protectors:
TPM
Numerical Password
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
7 answers
Sort by: Most helpful
-
MTG Marinetechnik 356 Reputation points
2020-10-05T06:45:18.267+00:00 -
Jake Sokol 106 Reputation points
2020-10-03T23:59:47.83+00:00 Also is the ssd hardware encryption vulnerability still present and should I configure group policy to use software encryption on all ssd drives (os and data drive)
Thx -
Jake Sokol 106 Reputation points
2020-10-03T22:26:41.963+00:00 how much security am I losing without a pre-boot authentication PIN? can an attacker somehow log into windows and access my data
given this is a surveillance machine, it's critical it boots up hands-free after a power loss
thx
-
Bagitman 596 Reputation points2020-10-03T19:03:57.337+00:00 You did not configure a pre-boot authentication PIN, so your config cannot be called optimal for security. However, with such a PIN set, the machine would not be able to start automatically (hands-free) after update installation reboots or crashes, so you need to decide if that matters or not.
-
Jake Sokol 106 Reputation points
2020-10-02T21:45:22.017+00:00 Can anybody kindly look into this? I'm hoping to start using this machine over the weekend - thanks!