Multiple people have e-mailed me begging for help with data recovery on Surface computers with BitLocker. Apparently they enable TPM secureboot BitLocker by default, but it's a brittle mess and any number of random things can change the PCRs and lock people out forever.
-
Show this thread
-
It's patently obvious to anyone with half a brain that UEFI secureboot breaks if you look at it wrong and TPM-backed encryption is absolutely **not** ready for wide roll-out outside of enterprise deployments with recovery key management. Why is MS doing this? Are they nuts?
3 replies 0 retweets 27 likesShow this thread -
Obviously I can't do anything for these people, as they invariably have no detailed knowledge of what they did to trigger the PCR mismatch, or have made things worse by messing with the UEFI setup further (which nobody warns you about).
1 reply 0 retweets 18 likesShow this thread -
Looking at reports of people with the same issue, unsurprisingly random updates that may include firmware updates can set this off. Also apparently it can happen if you have the **keyboard attached** to a tablet, and detaching it lets it boot‽
6 replies 0 retweets 30 likesShow this thread -
Replying to @marcan42
but if you can get into command prompt on safe mode you can use the this command - manage-bde -protectors C: -get it will show all bitlocker keys that is stored, i've done this plenty of times on surface pro for my users who lost there keys. you can even disable tpm in command
1 reply 0 retweets 0 likes
You can't get into anything once you're already locked out. Once the TPM says no it says no, there is no safe mode.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.