Multiple people have e-mailed me begging for help with data recovery on Surface computers with BitLocker. Apparently they enable TPM secureboot BitLocker by default, but it's a brittle mess and any number of random things can change the PCRs and lock people out forever.
-
-
Doesn't it just need the file/printout with the bitlocker encryption key? I had that issue before (https://flameeyes.blog/2018/02/12/windows-10-bitlocker-pin-bios-update/ …) when updating fw...
-
You need the recovery key, yes. How many end-users do you think are aware that that exists, never mind that they need to keep it safe forever in case their computer decides to lock them out of all of their data? :-)
- Show replies
New conversation -
-
-
The fwupd project attempts TPM eventlog reconstruction these days and apparently find errors quite often. It's a tiny bit concerninghttps://github.com/fwupd/missing-firmware-lenovo-thinkpad/issues …
-
We're about to make reconstitution failures a lot more prominent -- more exciting details coming soon :)
- Show replies
New conversation -
-
-
but if you can get into command prompt on safe mode you can use the this command - manage-bde -protectors C: -get it will show all bitlocker keys that is stored, i've done this plenty of times on surface pro for my users who lost there keys. you can even disable tpm in command
-
You can't get into anything once you're already locked out. Once the TPM says no it says no, there is no safe mode.
End of conversation
New conversation -
-
-
This happened to a coworker of mine. Laptop would not boot without the DOCK! Luckily he travels for work, so not a problem at all... He has to use the recovery key whenever he boots without the dock now.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Yup, I have a T490 which refuses to boot when a Kensington Thunderbolt dock is plugged in. If you type in the password, it'll refuse to boot after you plug it out. It's amazing.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
oh I hate the Surface UEFI, it doesn't conform to the UEFI specification -at all- - UEFI boot order can't be modified and new entries get clobbered on reboot - Only FAT32 ESP is supported from coldboot - El Torito/ISO, FAT12, FAT16 require Win10 to chainload because Reasons?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.