Multiple people have e-mailed me begging for help with data recovery on Surface computers with BitLocker. Apparently they enable TPM secureboot BitLocker by default, but it's a brittle mess and any number of random things can change the PCRs and lock people out forever.
-
Show this thread
-
It's patently obvious to anyone with half a brain that UEFI secureboot breaks if you look at it wrong and TPM-backed encryption is absolutely **not** ready for wide roll-out outside of enterprise deployments with recovery key management. Why is MS doing this? Are they nuts?
3 replies 0 retweets 27 likesShow this thread -
Replying to @marcan42
I've been using BitLocker with TPM+pin for many years, and never had any issues (beside needing a recovery key after TPM firmware updates or hw changes) also by default BitLocker will back up recovery key to the MS account which you can look at through the web interface
2 replies 0 retweets 0 likes -
Replying to @13xforever
... so you did need the recovery key. That's the entire problem here. End users don't realize they might need the recovery key. Most don't even know what it is. Relying on the recovery key means the system is a failure and unsuitable for the average user.
1 reply 0 retweets 5 likes
It's obvious that the MS account thing isn't working because people are getting locked out and finding no recovery keys in their account.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.