Multiple people have e-mailed me begging for help with data recovery on Surface computers with BitLocker. Apparently they enable TPM secureboot BitLocker by default, but it's a brittle mess and any number of random things can change the PCRs and lock people out forever.
-
-
Obviously I can't do anything for these people, as they invariably have no detailed knowledge of what they did to trigger the PCR mismatch, or have made things worse by messing with the UEFI setup further (which nobody warns you about).
Show this thread -
Looking at reports of people with the same issue, unsurprisingly random updates that may include firmware updates can set this off. Also apparently it can happen if you have the **keyboard attached** to a tablet, and detaching it lets it boot‽
Show this thread
End of conversation
New conversation -
-
-
I've been using BitLocker with TPM+pin for many years, and never had any issues (beside needing a recovery key after TPM firmware updates or hw changes) also by default BitLocker will back up recovery key to the MS account which you can look at through the web interface
-
and ms account is basically forced on you, and it's very hard to opt out of, and at this point you have to assume people know what they're doing
End of conversation
New conversation -
-
-
It works fine for me. Also just to note it here, the default deployment also stores the recovery key within your microsoft account and can be viewed by: https://support.microsoft.com/en-us/help/4530477/windows-10-finding-your-bitlocker-recovery-key …
-
Yes, it works fine for everyone until it doesn't. The point is that "it doesn't" is not an acceptable outcome when it comes to people's data. That online recovery key stuff clearly isn't working properly all the time, as these people can't find their keys there.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.