Windows 10: You better add Pin Protection to your Bitlocker configuration

Discus and support You better add Pin Protection to your Bitlocker configuration in Windows 10 News to solve the problem; Bitlocker is a popular encryption technology by Microsoft that is used to protect data on Windows devices. Home users and Enterprise customers may... Discussion in 'Windows 10 News' started by GHacks, Jul 30, 2021.

  1. GHacks
    GHacks New Member

    You better add Pin Protection to your Bitlocker configuration


    Bitlocker is a popular encryption technology by Microsoft that is used to protect data on Windows devices. Home users and Enterprise customers may protect the system and data using Bitlocker.

    Bitlocker works in a convenient way by default, as users don't need to enter a pin or password during boot, as all of this is handled by the system automatically.

    Tip: check out our how to setup Bitlocker on Windows 10 guide.

    Setting up a pin is optional, but highly recommended, as a recent story on Dolos Group's blog suggest. The company received a laptop from an organization that was configured with the standard security stack of the organization. The laptop was fully encrypted with TPM and Bitlocker, had a BIOS password set, locked BIOS boot order and used secure boot to prevent unsigned operating systems from booting.

    You better add Pin Protection to your Bitlocker configuration turn-on-bitlocker.jpg

    The security researchers discovered that the system was booting right to the Windows 10 login screen; this meant that users did not have to type a pin or password prior to that, and that the key was pulled from TPM.

    The researchers looked up information on the TPM chip and discovered how it communicates. Bitlocker is not using "any of the encrypted communication features of the TPM 2.0 standard", and that means that communication is in plain text.

    The laptop was opened and probes were used to record data during boot. The open source tool https://github.com/FSecureLABS/bitlocker-spi-toolkit was used to detect the Bitlocker key in the data; it was then used to decrypt the Solid State Drive of the laptop.

    The researchers managed to get into the sytem after booting its image in a virtual environment. From there, they managed to connect to the company VPN.

    Mitigation

    Bitlocker supports setting a pre-boot authentication key. If that key is set, it needs to be entered before the system boots; this works similarly to how VeraCrypt and other third-party encryption programs work. VeraCrypt displays a password and PIM prompt during boot if the system drive is encrypted. Users need to type the correct password and PIM to get the drive to be decrypted and the operating system booted.

    The researchers suggest that users set the PIN to protect the system and its data.


    Pre-boot authentication set to TPM with a PIN protector (with a sophisticated alphanumeric PIN [enhanced pin] to help the TPM anti-hammering mitigation).
    Setting up a Bitlocker pre-boot authentication PIN


    Note: Bitlocker Drive Encryption is available on Windows 10 Pro and Enterprise. Home devices have drive encryption, which is different. You may want to consider using VeraCrypt instead to better protect the data on your Home devices. On Windows 10, you can check if Device Decryption is used by opening the Settings, searching for device decryption and selecting the option from the results.

    1. Open the Group Policy Editor:
      1. Use the keyboard shortcut Windows-R
      2. Type gpedit.msc and press the Enter-key.
    2. Go to Computer Configuration > Administrative Templates > Windows Components > BitLocker Drive Encryption > Operating System Drives using the folder structure of the sidebar.
    3. Double-click on Require Additional Authentication at Startup in the main pane.
    4. Set the policy to Enabled.
    5. Select the menu under "Configure TPM startup PIN" and set it to "Require startup PIN with TPM".
    6. Click OK to save the changes that you just made.

    You have prepared the system to accept a PIN as a pre-boot authentication method, but you have not set the PIN yet.

    1. Open Start.
    2. Type cmd.exe.
    3. Select Run as Administrator to launch an elevated command prompt window.
    4. Run the following command to set a pre-boot PIN: manage-bde -protectors -add C: -TPMAndPIN
    5. You are prompted to type the PIN and to confirm it to make sure it is identical.

    The PIN is set, and you will be prompted to enter it on the next boot. You may run the command manage-bde -status to check the status.

    Now You: do you encrypt your hard drives? (via Born)

    Thank you for being a Ghacks reader. The post You better add Pin Protection to your Bitlocker configuration appeared first on gHacks Technology News.

    read more...
     
    GHacks, Jul 30, 2021
    #1
  2. windoc Win User

    extend bitlocker protection with pin, usb pen drive, or TPM

    Hi, I was reading elsewhere, and not covered by this guide, that I could extend bitlocker protection with a pin and even an usb pen drive in addition to the key stored in the tpm. Is there a simple step by the step guide that shows you how to do this correctly? I was briefly looking at different settings in the local group policy editor and found some relevant options, however, I don't want to try to turn it on without having some guidance. Thank-you.
     
    windoc, Jul 30, 2021
    #2
  3. Paola Gar Win User
    Need to turn off Bitlocker to install Windows 10

    Hi,

    We suggest doing the following steps again to resolve the issue. To complete the procedure, make sure that you have the following information:

    • You must be able to provide administrative credentials.
    • The drive must be BitLocker-protected.
    To suspend BitLocker Drive Encryption on an operating system drive, please follow the steps below:

    • Click Start, click Control Panel, click
      System and Security, and then click BitLocker Drive Encryption.
    • Click Suspend Protection for the operating system drive.
    • A message is displayed, informing you that your data will not be protected while BitLocker is suspended and asking if you want to suspend BitLocker Drive Encryption.
    • Click Yes to continue and suspend BitLocker on the drive.

    Let us know how it goes.
     
    Paola Gar, Jul 30, 2021
    #3
  4. You better add Pin Protection to your Bitlocker configuration

    BitLocker encryption missing PIN configuration

    Hi,

    I need some help on the BitLocker. We have corporate Windows 10 Enterprise OS and need to configure BitLocker to encrypt C drive.

    However, BitLocker doesn't have PIN option to configure. Anyone can help? Any idea ?


    You better add Pin Protection to your Bitlocker configuration ea555d95-a4f3-406d-8b45-567aede1976c?upload=true.jpg
     
    healermaxxx, Jul 30, 2021
    #4
Thema:

You better add Pin Protection to your Bitlocker configuration

Loading...
  1. You better add Pin Protection to your Bitlocker configuration - Similar Threads - better add Pin

  2. Configure hardware BitLocker with startup PIN?

    in Windows 10 Gaming
    Configure hardware BitLocker with startup PIN?: Is it possible to use a startup PIN with hardware BitLocker? By hardware BitLocker I am referring to BitLocker managing a drive's built-in encryption key. For example, for a TCG Opal 2.0 SSD. Or is a startup PIN only an option for software BitLocker? Thanks....
  3. Configure hardware BitLocker with startup PIN?

    in Windows 10 Software and Apps
    Configure hardware BitLocker with startup PIN?: Is it possible to use a startup PIN with hardware BitLocker? By hardware BitLocker I am referring to BitLocker managing a drive's built-in encryption key. For example, for a TCG Opal 2.0 SSD. Or is a startup PIN only an option for software BitLocker? Thanks....
  4. Configure hardware BitLocker with startup PIN?

    in AntiVirus, Firewalls and System Security
    Configure hardware BitLocker with startup PIN?: Is it possible to use a startup PIN with hardware BitLocker? By hardware BitLocker I am referring to BitLocker managing a drive's built-in encryption key. For example, for a TCG Opal 2.0 SSD. Or is a startup PIN only an option for software BitLocker? Thanks....
  5. Your organization requires you to change your pin

    in Windows 10 Software and Apps
    Your organization requires you to change your pin: I make use of windows 11 and it said “your organization requires you to change your pin” i have tried changing the password but my alphabet keys are not working and the number keys are working. Meanwhile I am able to put in my old password alphabet which took me to the page...
  6. "Your Organization Requires You Change Your Pin"

    in Windows 10 Software and Apps
    "Your Organization Requires You Change Your Pin": I do not have an organization. this is a personal computer and I have tried every trick in the community I feel. Any help would be great. Again, this is a personal laptop HP Spectre...
  7. BitLocker encryption missing PIN configuration

    in Windows 10 Customization
    BitLocker encryption missing PIN configuration: Hi, I need some help on the BitLocker. We have corporate Windows 10 Enterprise OS and need to configure BitLocker to encrypt C drive. However, BitLocker doesn't have PIN option to configure. Anyone can help? Any idea ? [ATTACH]...
  8. Bitlocker to protect your PC

    in AntiVirus, Firewalls and System Security
    Bitlocker to protect your PC: Recently, I understood that Bitlocker is more meant for laptops than for personal computers. It is not clear to me. If a person steals your laptop he cannot retrieve any data when Bitlocker is in use. A person can also steal a computer, but that happens less frequently...
  9. Which configuration is better for gaming?

    in Windows 10 Gaming
    Which configuration is better for gaming?: #1: i7 7700 gtx 1050 12 gb ddr4 ram #2: i5 7300HQ gtx 1060 8 gb ddr4 ram and why? Thanks. 88722
  10. Add Suspend BitLocker protection to Context Menu in Windows

    in Windows 10 Tutorials
    Add Suspend BitLocker protection to Context Menu in Windows: How to: Add Suspend BitLocker protection to Context Menu in Windows How to Add 'Suspend BitLocker protection' to Context Menu of Drives in Windows [img] Information You can use BitLocker Drive Encryption to help protect your files on an entire drive. BitLocker can...