Vietnam.vn - Nền tảng quảng bá Việt Nam

Microsoft's BitLocker tool was cracked in just 43 seconds.

Báo Thanh niênBáo Thanh niên09/02/2024


According to TechSpot , although BitLocker is integrated into Windows 11 Pro, Enterprise, and Education versions to enhance data security using the AES encryption algorithm, a recent study shows that this encryption tool can be easily cracked with just a low-cost device.

Accordingly, in a YouTube video , security researcher Stacksmashing demonstrated how hackers could extract BitLocker encryption keys from a Windows computer in just 43 seconds using a Raspberry Pi Pico device. According to the researcher, targeted attacks can bypass BitLocker encryption by directly accessing the hardware and extracting the encryption key stored in the computer's Trusted Platform Module (TPM) via the LPC port.

Công cụ BitLocker của Microsoft bị bẻ khóa chỉ trong 43 giây- Ảnh 1.

Microsoft's well-known data encryption tool can be easily bypassed.

The vulnerability stems from a design flaw found in devices with dedicated TPMs, such as newer laptops and desktops. As the researchers explain, BitLocker sometimes uses an external TPM to store critical key information, such as Platform Configuration Registers and Volume Master Keys. However, the communication channels (LPC ports) between the CPU and the external TPM are not encrypted at boot, allowing attackers to monitor any traffic between the two components and extract the encryption key.

To perform the demonstration attack, Stacksmashing used a 10-year-old laptop that had been encrypted with BitLocker, then programmed a Raspberry Pi Pico to read the raw binary code from the TPM to obtain the Volume Master Key. He then used Dislocker with the newly obtained Volume Master Key to decrypt the drive.

This isn't the first time BitLocker has been cracked. Last year, cybersecurity researcher Guillaume Quéré demonstrated how BitLocker's full-drive encryption system allowed users to monitor any information between a separate TPM chip and the CPU via the SPI port. However, Microsoft claims that breaking BitLocker encryption is a long and complex process, requiring extensive access to the hardware.

The latest attack method shows that BitLocker can be bypassed much more easily than previously thought, raising important questions about current encryption methods. Whether Microsoft will fix this specific vulnerability in BitLocker remains to be seen, but in the long run, cybersecurity researchers need to do a better job of identifying and patching potential security vulnerabilities before they become a problem for users.



Source link

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

A close-up view of the workshop making the LED star for Notre Dame Cathedral.
The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.
Huynh Nhu makes history at the SEA Games: A record that will be very difficult to break.
The stunning church on Highway 51 lit up for Christmas, attracting the attention of everyone passing by.

Same author

Heritage

Figure

Enterprise

Farmers in Sa Dec flower village are busy tending to their flowers in preparation for the Festival and Tet (Lunar New Year) 2026.

News

Political System

Destination

Product