Windows 10: Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install

Discus and support Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install in Windows 10 Ask Insider to solve the problem; I run latest and greatest Win10 on an external SSD connected to a USB3 adapter, everything installed and encrypted with Bitlocker without any hacks.... Discussion in 'Windows 10 Ask Insider' started by /u/AaronCompNetSys, Jun 25, 2020.

  1. Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install


    I run latest and greatest Win10 on an external SSD connected to a USB3 adapter, everything installed and encrypted with Bitlocker without any hacks. Installing 2004 update halted at a point where it looked like recovery environment and prompted if I wanted to boot into the OS. Then I got the "couldn't start properly" and prompt to recover startup. The startup tools could not detect the volume and would not prompt me to enter my decryption key.

    Plugging the drive into an unencrypted PC that already had 2004, prompted me to continue decryption of a bitlocker volume was not complete, which it then did so without entering a key. I could read the files from the volume, but nothing would make it bootable.

    I'm now typing this on a fresh install on the same hardware, encrypted after 2004 was installed. I had to put the SATA SSD in a temporary laptop to get past the first step, because the new creation tool setup version no longer allows installing to a drive that detects USB.

    submitted by /u/AaronCompNetSys
    [link] [comments]

    :)
     
    /u/AaronCompNetSys, Jun 25, 2020
    #1

  2. bitlocker decryption

    After the last win10 update OS version : 10.0.15063.414 ,my SD card encrypted by bitlocker without my knowledge.

    So, How i can decrypt bitlocker??

    ***Post moved by the moderator to the appropriate forum category.***
     
    satya prakash shukla, Jun 25, 2020
    #2
  3. chriad Win User
    Decrypting bitlocker encrypted OS volume with .pfx certificate

    I have a windows 10 operating system partition that is encrypted with bitlocker.
    Unfortunately I don't remember ever having activated bitlocker encryption nor can find and
    .bek file or numeric pin or password.

    My first uncertainty is in why my device is encrypted in the first place and who encrypted it. There are two possibilities: I have encrypted it myself and forgotten about it. The manufacturer that shipped the laptop has encrypted the device
    when installing the operating system (which I don't think is the case). I contacted the manufacturer and they do not have knowledge of any key.

    My second uncertainty is in why the bitlocker lockout was triggered at this time when it worked fine for the last year or so. It says
    Boot policy has unexpectedly changed. From what I have red so far, there are a lot of reasons why this can happen. Probably it happened because I did not properly remove a external USB harddrive or I changed some BIOS settings without knowing what
    I was doing. The only important question is if it is it in principle possible to roll back the boot policy to its initial state and thus circumvent the necessity to enter the bitlocker code?

    My third uncertainty is concerning the unlock key. I found a
    .pfx certificate file that I might have exported during the encryption procedure, I just don't remember. I found a post

    https://www.einfaches-netzwerk.at/teil-20b-bitlocker-dra/
    where a drive is indeed decrypted with the
    sha1 certificate thumbprint like this:

    manage-bde -unlock i: -cert -ct "46 4f 75 9b f9 67 7a d2 44 d0 7b 64 61 63 16 80 df dc 0b a2"

    which I can easily retrieve from the .pfx file.

    My question is now, assuming this .pfx certificate indeed contains the key to do the decryption, how can I export this certificate to the certificate store so that the above command will work?

    How can I install the .pfx certificate from the elevated command prompt (I cannot do it from within the GUI because it is my OS volume that is locked so I only can access it with the recovery console)?

    I tired:

    certutil -f -p somePassword -importpfx "somePfx.pfx"

    as outlined here
    https://stackoverflow.com/questions/5171117/import-pfx-file-into-particular-certificate-store-from-command-line?noredirect=1
    , but
    certutil command is not found.

    Here is the output of the manage-bde -status command

    Can someone give a hint on how to decrypt a bitlocker encrypted OS partition with a
    .pfx file and clarify if the steps outlined are in principle correct and should work if the certificate is the right one?

    I would appreciate any your comments.
     
    chriad, Jun 25, 2020
    #3
  4. Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install

    BitLocker Decryption Paused..

    Hi Hans,

    Thanks for your immediate response.

    I have followed the steps for my device (DFeature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install :) in Windows PowerShell as mentioned by you but I got the following result mentioning "the device is not ready". Please help with any alternate solution.

    Thanks

    C:\WINDOWS\system32> manage-bde -status

    BitLocker Drive Encryption: Configuration Tool version 10.0.16299

    Copyright (C) 2013 Microsoft Corporation. All rights reserved.

    Disk volumes that can be protected with

    BitLocker Drive Encryption:

    Volume C: [Windows]

    [OS Volume]

    Size: 464.15 GB

    BitLocker Version: 2.0

    Conversion Status: Used Space Only Encrypted

    Percentage Encrypted: 100.0%

    Encryption Method: XTS-AES 128

    Protection Status: Protection On

    Lock Status: Unlocked

    Identification Field: Unknown

    Key Protectors:

    Numerical Password

    TPM

    Volume D: [comicider]

    [Data Volume]

    Size: 931.51 GB

    BitLocker Version: 2.0

    Conversion Status: Decryption Paused

    Percentage Encrypted: 0.1%

    Encryption Method: AES 128 with Diffuser

    Protection Status: Protection Off

    Lock Status: Unlocked

    Identification Field: Unknown

    Automatic Unlock: Disabled

    Key Protectors:

    Numerical Password

    Password

    PS C:\WINDOWS\system32> Disable-BitLocker -MountPoint "D:"

    Disable-BitLocker : The device is not ready. (Exception from HRESULT: 0x80070015)

    At line:1 char:1

    + Disable-BitLocker -MountPoint "D:"

    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    + CategoryInfo : NotSpecified: Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install :)) [Write-Error], FileNotFoundException

    + FullyQualifiedErrorId : System.IO.FileNotFoundException,Disable-BitLocker

    PS C:\WINDOWS\system32> manage-bde -off D:

    BitLocker Drive Encryption: Configuration Tool version 10.0.16299

    Copyright (C) 2013 Microsoft Corporation. All rights reserved.

    ERROR: An error occurred (code 0x80070015):

    The device is not ready.
     
    Subhradeep Ghosh, Jun 25, 2020
    #4
Thema:

Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install

Loading...
  1. Feature update 2004 seems to decrypt your Bitlocked OS volume and may brick your install - Similar Threads - Feature update 2004

  2. Windows 10's PIN feature can brick your device!

    in AntiVirus, Firewalls and System Security
    Windows 10's PIN feature can brick your device!: Hello, I am done with Windows. I see it has some of the worst flaws out there regarding security and performance. No one should depend on a single company when dumb things like this can happen:1. Set up a PIN and/or Microsoft Password to sign in your PC's account. 2. Done?...
  3. Problem installing Feature update 2004

    in Windows 10 Installation and Upgrade
    Problem installing Feature update 2004: I have tried 3 times to install the Feature update 2004 on my laptop. I get the error 0x800701b1 and have search for a solution. Most of the solutions talk about an external hard drive problem. That is not the case for me. I found one comment that said to run the bcdedit...
  4. Windows feature update 2004 - bricking DELL Latitude laptops

    in Windows 10 Installation and Upgrade
    Windows feature update 2004 - bricking DELL Latitude laptops: Hi all. We've started deploying the 2004 feature update to our corporate laptops and we've noticed a number of laptops running the update but after another reboot the laptops get stuck at auto repair. I assume if has corrupted the OS, but weirdly not all laptops of the same...
  5. MAY UPDATE 2004

    in Windows 10 Installation and Upgrade
    MAY UPDATE 2004: - JUST DOWNLOADED AUTOMATICALLY ON OTHER LAPTOP NOW IT WANTS A BITBLOCKER NUMER- WHAT IS THIS AND IS THIS UPDATE REAL- I CANNOT EVEN REINSTALL WINDOWS- DELETE CURRENTS UPDATE. - IT SAYS I HAVE NO ACCESS UNLESS I ENTER NUMBER- IT ON THE PAGE HAS A RECOVERY ID- THAT DOES...
  6. 2004 May 2020 Feature Update

    in Windows 10 Installation and Upgrade
    2004 May 2020 Feature Update: A couple of weeks ago I received a notification that the latest feature update was due to be installed on my computer 2004. I postponed the update for a week because I was working on something. But a week later when I pressed "update and restart" on the main menu, nothing....
  7. What to do if an update "bricks" your system

    in Windows 10 Installation and Upgrade
    What to do if an update "bricks" your system: The problem of updates rendering Windows 10 computers non-functional is becoming widespread. It is important that everyone have a Windows 10 installation disk in case this happens. 1. Boot from DVD, select Repair, and then Command Prompt. 2. Copy the entire Windows drive...
  8. your os sucks

    in Windows 10 Installation and Upgrade
    your os sucks: i will never buy Microsoft again. your autoupdate feature forced me to lose all my work again 5 hours of typing gone because you suck. ATTENTION IDIOTS FORCED ANYTHING IS BAD...
  9. Some of your features are managed by your organization

    in Windows 10 Updates and Activation
    Some of your features are managed by your organization: Hello. I just builded a PC. And at my school, we got free Windows 10 ISO image and product key to use it as we want. So I entered this key, everything is perfectly activated... but I get this thing saying: "Some of your features are managed by your organization". It's my own...
  10. BitLocker encryption is enabled on your OS

    in Windows 10 BSOD Crashes and Debugging
    BitLocker encryption is enabled on your OS: ***Modify title from: Trying to change boot configuration, but BitLocker prompts recovery mode - except I run Windows 10 Home, and don't have BitLocker installed?*** I am optimizing my Wintows 10 laptop by changing the boot settings to use all of my processors, not GUI...