• frongt@lemmy.zip
    link
    fedilink
    arrow-up
    4
    ·
    16 days ago

    it is pretty much applicable to all devices using the default BitLocker “Device Encryption” setup, as this configuration relies solely on Secure Boot to automatically unseal the disk during boot.

    That is, only the default “transparent” bitlocker mode. If you have any other additional protection (pin, password) set it doesn’t affect you.

      • [object Object]@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        ·
        16 days ago

        The TPM takes “measurements” of the system and releases the decryption key only if they’re all correct. Files on the disk are encrypted, so booting into another OS with a bootable media doesn’t work (measurement picks up the fact that you booted into another OS). When the system does boot properly, the Windows lock screen prevents you from viewing the files.