How secure is bitlocker - Encryption Methods and Programs (2024)

#1How secure is bitlocker - Encryption Methods and Programs (1)andy220

andy220


  • How secure is bitlocker - Encryption Methods and Programs (2)
  • Members
  • 4 posts
  • OFFLINE
  • Local time:02:00 PM

Posted 01 September 2018 - 09:19 AM

Dear gents

I am exploring how secure are my data protected by bitlocker on Windows 10.

Based on article bellow there are methods how to crack bitlocker password.

https://blog.elcomsoft.com/2016/06/breaking-bitlocker-encryption-brute-forcing-the-backdoor-part-i/

But I am just wondering how is possible to boot protected windows 10 without knowing bitlocker password in order to get access to RAM and fetch keys.

Also veracrypt is not secured against brute force.

Any professional advice would be highly welcomed.

Kindest regards

Andy

  • Back to top

BC AdBot (Login to Remove)

#2How secure is bitlocker - Encryption Methods and Programs (5)Chiragroop

Chiragroop


  • How secure is bitlocker - Encryption Methods and Programs (6)
  • Members
  • 336 posts
  • OFFLINE
  • Gender:Male
  • Local time:06:00 AM

Posted 01 September 2018 - 10:16 AM

You wouldn't boot the computer to get the key. Instead, say if your computer is in sleep mode or hibernation mode, then the key is still in memory (so you don't have to type the password again and again to decrypt every file). This content of the memory can be extracted (since the key is in the memory), and used to decrypt the disk. A good advice is to shut down the computer instead, as that will prevent this type of attack.

-Chiragroop


  • Back to top

#3How secure is bitlocker - Encryption Methods and Programs (8)andy220

andy220

  • Topic Starter

  • How secure is bitlocker - Encryption Methods and Programs (9)
  • Members
  • 4 posts
  • OFFLINE
  • Local time:02:00 PM

Posted 01 September 2018 - 10:23 AM

All right. I can imagine if somebody would take snapshot of live RAM content and extract keys from registers even in hibernated mode. But as far as I know in order to get Windows to boot from encrypted partition - bitlocker volume I need to input bitlocker password first. Suppose somebody take my shut downed laptop protected by bitlocker and how he can pass initial password check in order to decrypt encrypted windows partition? This step is not clear for me how to overide bitlocker on black-boxed system.


  • Back to top

#4How secure is bitlocker - Encryption Methods and Programs (11)Chiragroop

Chiragroop


  • How secure is bitlocker - Encryption Methods and Programs (12)
  • Members
  • 336 posts
  • OFFLINE
  • Gender:Male
  • Local time:06:00 AM

Posted 01 September 2018 - 10:38 AM

There is this note in the article:

IMPORTANT: Use Elcomsoft Forensic Disk Decryptor to acquire volumes encrypted with BitLocker Device Protection. BitLocker Device Protection is a whole-disk encryption scheme that automatically protects certain Windows devices (such as tablets and ultrabooks equipped with TPM 2.0 modules) when the user logs in with their Microsoft Account. BitLocker Device Protection does NOT employ user-selectable passwords, and CANNOT be broken into by brute forcing anything. In certain cases, BitLocker escrow keys (BitLocker Recovery Keys) can be extracted by logging in to the user’s Microsoft Account via https://onedrive.live.com/recoverykey. The latest version of Elcomsoft Forensic Disk Decryptor (the one we’ve just released) has the ability to use these keys in order to decrypt or mount BitLocker volumes.

This method only mainly works on computers encrypted using TPM rather than requiring a Bitlocker separate password.

For the Bitlocker encryption where you have to type password to decrypt and continue the boot process, it is covered in their part 2:https://blog.elcomsoft.com/2016/07/breaking-bitlocker-encryption-brute-forcing-the-backdoor-part-ii/

Essentially, they try as many password combinations as they can to break it. If you have a strong password, that should deter this attack significantly (and length matters for the password).

I am not quite as familiar with Bitlocker, but other people on this forums are. As far as I have read, a strong password should be sufficient for the second attack.

-Chiragroop


  • Back to top

#5How secure is bitlocker - Encryption Methods and Programs (14)andy220

andy220

  • Topic Starter

  • How secure is bitlocker - Encryption Methods and Programs (15)
  • Members
  • 4 posts
  • OFFLINE
  • Local time:02:00 PM

Posted 01 September 2018 - 10:47 AM

I am not certain but method described here https://blog.elcomsoft.com/2016/07/breaking-bitlocker-encryption-brute-forcing-the-backdoor-part-ii/ is bruteforce attack assuming that bitlocker password is weak not strong?

How works there probing of brute force passwords? Is there some live USB utility with cracks bitlocker protected windows partition offline? For instance some script is inputting brute force password repeatedly until it crack real bit locker password and decrypt bitlocker protected partition by brute force method?

Gents on other hands what is the strong, hack-proof password? Suppose I am using 10 character password including capital letter, numbers and special character. Can we say that such password combination is proof against brute force method and even brute force attack is accelerated by GPU CUDA hardware it would take ages to break such password combination?

Anyway my laptop is equipped just by older TPM 1.2. Is it enough to support bitlocker protection togheter with strong password described hereby?

Status of my TPM is TPM autorization is not stored properly and saying reset TPM. Does it mean problem with lowered TPM security?

https://ibb.co/gMeaSz

P.S. I have found way how to enable passphrase instead of PIN here https://community.spiceworks.com/topic/2020155-bitlocker-with-a-password-instead-of-pin

Now I reverted bitlocker off and doing TPM sync then re-enable bitlocker with stronger passphrase.


Edited by andy220, 01 September 2018 - 10:05 PM.

  • Back to top

#6How secure is bitlocker - Encryption Methods and Programs (17)Chris Cosgrove

Chris Cosgrove


  • How secure is bitlocker - Encryption Methods and Programs (18)
  • Global Moderator
  • 23,611 posts
  • OFFLINE
  • Gender:Male
  • Location:Scotland
  • Local time:02:00 PM

Posted 01 September 2018 - 05:40 PM

Before deciding on the level of security you need you have to consider the threat level you face.

If you are worried about your kid sister, partner or a caual thief reading your files then bitlocker is almost certainly adequate. If you are worried because GCHQ or the NSA might attack them you either need the highest level of encryption you can afford or you might as well keep everything in clear text and save all the complications.

Chris Cosgrove


  • Back to top

#7How secure is bitlocker - Encryption Methods and Programs (20)andy220

andy220

  • Topic Starter

  • How secure is bitlocker - Encryption Methods and Programs (21)
  • Members
  • 4 posts
  • OFFLINE
  • Local time:02:00 PM

Posted 01 September 2018 - 08:27 PM

Allright thanks.I am maybe a bit paranoid so I am looking for higher level of security not just ordinar thief.I have sensitive business data which I signed nda there.

Basically I was scared by article above describing how it is possible crack bitlocker a such.

Gents nobody can advise about TPM issue above saying that tpm chip is just partly ready?

Shall I reset tpm? If so what precaution or care I shall take to avoid data loss on encrypted file system.
I got idea to disable bitlocker a such and decrypt protected partition and then to do tpm sync and encypt partition again.

Any advice would be highly welcomed.

  • Back to top
How secure is bitlocker - Encryption Methods and Programs (2024)

FAQs

How secure is bitlocker - Encryption Methods and Programs? ›

For general information and file encryption, BitLocker is a secure option. As the built-in full-disk encryption on Windows, it is able to safeguard your data by encrypting the entire volume.

How strong is BitLocker encryption? ›

BitLocker uses Advanced Encryption Standard (AES) as its encryption algorithm with configurable key lengths of 128 bits or 256 bits. The default encryption setting is AES-128, but the options are configurable by using Group Policy.

Is BitLocker 100% safe? ›

BitLocker encryption is not the be-all and end-all type of protection. While BitLocker securely encrypts your data with industry-standard AES encryption, it can only protect your data against a set of very specific threats.

Is there a downside for using BitLocker? ›

Cons of BitLocker

First, BitLocker is only available for Windows 10 Pro, Enterprise, and Education editions, so if you have Windows 10 Home, you cannot use it. Second, BitLocker may slow down your system, especially if you have an older or low-end device, as it uses CPU and disk resources to encrypt and decrypt data.

Which BitLocker encryption method is best? ›

Block write access to fixed data-drives not protected by BitLocker is recommended as it prevents saving data on unencrypted drives, and may be important for compliance reasons. Finally, it's recommended that AES-256-XTS is used as the encryption method.

How hard is BitLocker to crack? ›

What makes this any special? Well, no algorithm is indeed 100% foolproof but, algorithms used in BitLocker are much smarter. So far, the only known way to crack the encryption algorithms in BitLocker is to brute force your way into it.

Is it possible to crack BitLocker? ›

The answer is “Yes”. Usually, the BitLocker drive encryption doesn't ask for the recovery key on a normal startup. However, the Windows system may ask for BitLocker recovery key in some cases, such as motherboard hardware changes, a system crash, or if your program believes the data is under attack.

How long does it take to crack BitLocker? ›

Factors affecting attack speeds: password length, complexity, data format and hardware
6 characters, lower-case8 alphanumeric, both cases
RAR5, CPU56 daysEternity
RAR5, GPU2 hours273 years
BitLocker, CPU5 yearsEternity
BitLocker, GPU4 daysEternity
2 more rows
Apr 4, 2017

What software cracks BitLocker passwords? ›

Thegrideon Software: It is an advanced password recovery utility for BitLocker encrypted drives as well as BitLocker to Go protected removable devices. This tool uses several password search attacks to get its job done, including dictionary attacks with modifications, brute-force attacks, and advanced mixed attacks.

Does BitLocker decrypt on the fly? ›

No, BitLocker doesn't encrypt and decrypt the entire drive when reading and writing data. The encrypted sectors in the BitLocker-protected drive are decrypted only as they're requested from system read operations. Blocks that are written to the drive are encrypted before the system writes them to the physical disk.

What is more secure than BitLocker? ›

We have compiled a list of solutions that reviewers voted as the best overall alternatives and competitors to Microsoft BitLocker, including Kaspersky Endpoint Security for Business, VeraCrypt, Symantec Encryption, and FileVault. Have you used Microsoft BitLocker before?

Why should I turn off BitLocker? ›

BitLocker is a discrete method of protecting your data from unauthorized access. Turning off the feature won't erase any of your files, but it's still good practice to keep backup copies of your files.

Is it worth turning on BitLocker? ›

If you are going to store sensitive, private, and important files on your home PC, you should turn on BitLocker to protect your data from potential theft and a common criminal. If there is nothing on your computer that needs to be protected from leaks, you don't need to enable BitLocker drive encryption.

What is the most secure encryption system? ›

AES 256-bit encryption is the strongest and most robust encryption standard that is commercially available today. While it is theoretically true that AES 256-bit encryption is harder to crack than AES 128-bit encryption, AES 128-bit encryption has never been cracked.

Which is the safest encryption method? ›

AES. The Advanced Encryption Standard (AES) is the algorithm trusted as the standard by the U.S. Government and numerous organizations. Although it is highly efficient in 128-bit form, AES also uses keys of 192 and 256 bits for heavy-duty encryption purposes.

Which encryption mode is most secure? ›

Although extremely efficient in the 128-bit form, AES also uses 192- and 256-bit keys for very demanding encryption purposes. AES is widely considered invulnerable to all attacks except for brute force.

Can a hacker bypass BitLocker? ›

There is no way to bypass the BitLocker recovery key when you want to unlock a BitLocker encrypted drive without a password.

How long does BitLocker take to encrypt 1tb? ›

So how long will encryption take?
New disk1-5 minutes
1 TB / 300 GB used10 hours
2 TB / 1.5 TB used50 hours

Is there a master key for BitLocker? ›

The volume master key is encrypted by the appropriate key protector and stored in the encrypted drive. If BitLocker has been suspended, the clear key that is used to encrypt the volume master key is also stored in the encrypted drive, along with the encrypted volume master key.

How many BitLocker attempts do you get? ›

For each of the 32 attempts, the TPM records if the authorization value was correct or not. This inadvertently causes the TPM to enter a locked state after 32 failed attempts.

Can a BitLocker key be recovered? ›

In your Microsoft account: Open a web browser on another device and Sign in to your Microsoft account to find your recovery key. This is the most likely place to find your recovery key. Tip: You can sign into your Microsoft account on any device with internet access, such as a smartphone.

How do I know when BitLocker is decrypted? ›

Checking BitLocker Status (Command Line)

Right-click Command Prompt and select "Run as Administrator." In command prompt, type manage-bde -status and press Enter. View the status of BitLocker on the drives in the computer.

Does turning off BitLocker decrypt the drive? ›

Click Start, click Control Panel, click System and Security, and then click BitLocker Drive Encryption. Look for the drive on which you want BitLocker Drive Encryption turned off, and click Turn Off BitLocker. A message will be displayed, stating that the drive will be decrypted and that decryption may take some time.

How long does BitLocker take to encrypt 256gb? ›

BitLocker supports encrypted hard drives with onboard encryption hardware built in, which allows administrators to use the familiar BitLocker administrative tools to manage them. Encrypting a new flash drive can take more than 20 minutes.

Who can decrypt BitLocker? ›

Computers encrypted with BitLocker cannot be decrypted automatically. Decryption can be carried out using either the BitLocker Drive Encryption item in the Control Panel or the Microsoft command-line tool "manage-bde".

What will trigger BitLocker? ›

Bitlocker recovery mode can be triggered by a number of situations, including:
  • A malicious attempt by a person or software to change the startup environment. ...
  • Moving the BitLocker-protected drive into a new computer.
  • Installing a new motherboard with a new TPM.
  • Turning off, disabling, or clearing the TPM.
Jan 30, 2023

How to hack BitLocker without password and recovery key? ›

If you lost not only the BitLocker password, but also the Recovery Key, there will be no way to unlock the BitLocker drive without losing all the data. You need to format the encrypted drives to remove the BitLocker. Learn more: How to Find BitLocker Recovery Key?

How to tell if BitLocker is using hardware or software encryption? ›

If the "Encryption Method" starts with "Hardware Encryption", then BitLocker is using the self-encrypting disk's hardware-based encryption implementation. If the "Encryption Method" states something other than "Hardware Encryption", such as "AES-128" or "XTS AES-256", then BitLocker is using software-based encryption.

Which encryption is least secure? ›

Using some encryption is always better than using none, but WEP is the least secure of these standards, and you should not use it if you can avoid it. WPA2 is the most secure of the three.

Which encryption type is least secure? ›

WEP is the least secure type of encryption and should only be used if necessary. WPA and WPA2 are more secure, and WPA2 is the most secure type of encryption available. When configuring wireless security, you should always use WPA2 if possible.

How much does BitLocker cost? ›

BitLocker is free with Microsoft Windows: Microsoft BitLocker is free to use and very easy to set up.

Why is my computer asking for BitLocker key every time? ›

BitLocker monitors the computer for changes to the boot configuration. When BitLocker sees a new device in the boot list or an attached external storage device, it prompts you for the key for security reasons. This is normal behavior.

Why does my PC keep asking for BitLocker? ›

Some changes to hardware, firmware, or software may have conditions that BitLocker cannot distinguish from a possible attack. In these cases, Windows will ask for your BitLocker recovery key. This is to be sure that it is really an authorized user of the device who is trying to unlock it.

Why do companies use BitLocker? ›

BitLocker Can be used to mitigate unauthorized data access on lost or stolen computers by encrypting all user files and system files on the operating system drive, including the swap files and hibernation files, and checking the integrity of early boot components and boot configuration data.

Does BitLocker reduce SSD life? ›

(For Software Based Encryption eg Bitlocker): Even when you change a single bit in file, due to the re-encryption of the file, the whole file will be written back to the SSD and not only the changed block of data. This will incur additional wear-and-tear of the SSD, reducing the performance exponentially.

Can BitLocker encrypt a USB drive? ›

Insert the USB drive you want to encrypt - this can be a new drive, or one that already has data stored on it. Open File Explorer, right-click on the USB drive then select Turn on BitLocker… from the pop-up menu. The BitLocker wizard launches and BitLocker prepares the USB drive for encryption.

Is there any encryption method that Cannot be broken? ›

In cryptography, the one-time pad (OTP) is an encryption technique that cannot be cracked, but requires the use of a single-use pre-shared key that is not smaller than the message being sent.

What is more secure than software encryption? ›

Hardware encryption is safer than software encryption because the encryption process is separate from the rest of the machine. This makes it much harder to intercept or break. The use of a dedicated processor also relieves the burden on the rest of your device, making the encryption and decryption process much faster.

What encryption does Tesla use? ›

TESLA is a symmetric cryptographic algorithm that creates asymmetry by the delayed release of keys used to authenticate signatures called Message Authentication Codes (MACs). A message is sent appended with the MAC that authenticates it, or a series of messages.

What are the four 4 most secure encryption techniques? ›

Now let's look at seven common methods of encryption that you can use to safeguard sensitive data for your business.
  1. Advanced Encryption Standard (AES) ...
  2. Triple Data Encryption Standard (TDES) ...
  3. Rivest Shamir Adleman (RSA) ...
  4. Blowfish. ...
  5. Twofish. ...
  6. Format-Preserving Encryption (FPE) ...
  7. Elliptic Curve Cryptography (ECC)
Nov 29, 2022

How long would it take to break a BitLocker encryption? ›

Factors affecting attack speeds: password length, complexity, data format and hardware
6 characters, lower-case8 alphanumeric, both cases
RAR5, CPU56 daysEternity
RAR5, GPU2 hours273 years
BitLocker, CPU5 yearsEternity
BitLocker, GPU4 daysEternity
2 more rows
Apr 4, 2017

How long would it take to break BitLocker? ›

Assuming we could somehow process 500 trillion passwords an hour (which would be 3,623 times more than the ~138 billion passwords per hour capability of a desktop computer in 2008 under 10% load), it would still take us ~7.7 x 10^19 years to brute force crack this 48 character numerical recovery password.

What is the strongest bit encryption? ›

AES 256-bit encryption is the strongest and most robust encryption standard that is commercially available today.

How many password attempts on BitLocker? ›

For each of the 32 attempts, the TPM records if the authorization value was correct or not. This inadvertently causes the TPM to enter a locked state after 32 failed attempts.

How long does BitLocker take to encrypt 4tb? ›

How long will the encryption take? The length of time will depend on the size and speed of the hard drive in your computer. In our testing, the process has taken anywhere from 20 minutes to three hours.

How do I know if BitLocker encryption is completed? ›

Checking BitLocker Status (Command Line)

Right-click Command Prompt and select "Run as Administrator." In command prompt, type manage-bde -status and press Enter. View the status of BitLocker on the drives in the computer.

What is the safest encryption method? ›

AES. The Advanced Encryption Standard (AES) is the algorithm trusted as the standard by the U.S. Government and numerous organizations. Although it is highly efficient in 128-bit form, AES also uses keys of 192 and 256 bits for heavy-duty encryption purposes.

What is the most secure key encryption? ›

AES encryption

One of the most secure encryption types, Advanced Encryption Standard (AES) is used by governments and security organizations as well as everyday businesses for classified communications. AES uses “symmetric” key encryption. Someone on the receiving end of the data will need a key to decode it.

Top Articles
Latest Posts
Article information

Author: Kareem Mueller DO

Last Updated:

Views: 5993

Rating: 4.6 / 5 (46 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Kareem Mueller DO

Birthday: 1997-01-04

Address: Apt. 156 12935 Runolfsdottir Mission, Greenfort, MN 74384-6749

Phone: +16704982844747

Job: Corporate Administration Planner

Hobby: Mountain biking, Jewelry making, Stone skipping, Lacemaking, Knife making, Scrapbooking, Letterboxing

Introduction: My name is Kareem Mueller DO, I am a vivacious, super, thoughtful, excited, handsome, beautiful, combative person who loves writing and wants to share my knowledge and understanding with you.