Cool #38c3 talk about bypassing #BitLocker in TPM only mode. A downgrade attack allows you to exploit "bitpixie" again.

https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver

PXE Boot → boot downgraded/vulnerable #Windows boot loader → decrypt disk using TPM → reboot → key stays in memory → boot Linux → read key

#pentest

Windows BitLocker: Screwed without a Screwdriver

Ever wondered how Cellebrite and law enforcement gain access to encrypted devices without knowing the password? In this talk, we’ll demon...

media.ccc.de