Multiple people have e-mailed me begging for help with data recovery on Surface computers with BitLocker. Apparently they enable TPM secureboot BitLocker by default, but it's a brittle mess and any number of random things can change the PCRs and lock people out forever.
-
Show this thread
-
Replying to @marcan42
Default is for it to only be sealed to PCR 7, and there's a very finite number of things that should change that (also, default is for the recovery key to be escrowed with Microsoft)
1 reply 0 retweets 5 likes
Replying to @mjg59
Tell that to Surface Book 2 owners where having the *keyboard connected* breaks the sealing.https://www.reddit.com/r/Surface/comments/94ld4z/august_4_firmware_update_warning_surface_book_2/ …
0 replies
0 retweets
7 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.