Your Gateway to Tomorrow's Tech - Explore, Discover, Shop with DigitalTechHub!

Microsoft BitLocker encryption hacked by a cheap off-the-shelf Raspberry Pi Pico

Safety researcher Stacksmashing confirmed how hackers could use a $4 Raspberry Pi Pico to retrieve the BitLocker encryption key from Home windows PCs in simply 43 seconds, in a YouTube video. The researcher claims that particular assaults can get past BitLocker’s encryption by straight accessing the {hardware} and retrieving the encryption keys stored within the pc’s Trusted Platform Module (TPM) viz the LPC bus.

It has been proven that the encryption key requires bodily entry to the system and a few prolonged know-how or experience — so that is not an prolonged menace throughout the web. In fact, BitLocker’s reliance on a TPM for safety could also be its personal downfall on this specific escapade.

The devoted Trusted Module, or TPM has a design flaw that the YouTuber took benefit of. In particular setups, Bitlocker relies on an exterior TPM to retailer important information, together with the Quantity Grasp Key and Platform Configuration Registers (that are included in sure CPUs). When utilizing an exterior TPM, the CPU and TPM talk over an LPC bus to ship the encryption keys wanted to unlock the info on the disk. So the safety hacker, Stacksmashing (YouTube), discovered the communication lanes (LPC bus) between the exterior TPM and the CPU are fully unencrypted on boot-up. This allowed the hacker to search out important information when it moved between the 2 models — and he was in a position to hack the encryption keys.

Remember the fact that the hacker used an outdated laptop computer that had BitLocker encryption — although the identical sort of assault can be utilized on newer motherboards that use an exterior TPM. Additionally, the newer motherboards require extra work and legwork to intercept the bus visitors. Safety researcher Stacksmashing made it clear that the Home windows BitLocker and exterior TPMs aren’t as foolproof as many people and corporations suppose.

In case your CPU has a built-in TPM, like those present in fashionable AMD and Intel CPUs, you need to be protected from this safety flaw since all TPM communication happens throughout the CPU.

Featured Picture Credit score: Photograph by George Becker; Pexels

Deanna Ritchie

Managing Editor at ReadWrite

Deanna is an editor at ReadWrite. Beforehand she labored because the Editor in Chief for Startup Grind, Editor in Chief for Calendar, editor at Entrepreneur media, and has over 20+ years of expertise in content material administration and content material growth.

Trending Merchandise

0
Add to compare
Google Pixel 7a and Pixel 30W Charger Bundle – Unlocked Android 5G Smartphone with Wide-Angle Lens and 24-Hour Battery – Sea (Amazon Exclusive)
0
Add to compare
£379.00
16%
0
Add to compare
AGM NOTE N1 Smartphone Unlocked (2023), Android 13 Phone, 8 GB + 128 GB, Dual 50 MP Camera + 2 MP Micro Camera, 6.52″ HD+, 4900 mAh Battery, 4G Dual SIM Phone, Face ID/Fingerprint/OTG/GPS Grey
0
Add to compare
£119.98
33%
0
Add to compare
Gigaset GX290 15.5 cm (6.1″) 3 GB 32 GB Hybrid Dual SIM Grey 6200 mAh GX290 TITANIUM GREY, 15.5 cm (6.1″), 3 GB, 32 GB, 13 MP, Android 9.0, Grey
0
Add to compare
£209.21
0
Add to compare
OPPO A94 5G – 8GB RAM and 128 +Extendable Storage SIM Free Smartphone (48MP AI Quad Camera, 6.4′ AMOLED Screen, 30W fast charge) – Fluid Black
0
Add to compare
£199.99
5%
0
Add to compare
UMIDIGI G5 Mecha Rugged Phone Android 13 Rugged Smartphone, 16+128GB/1TB Unbreakable Phone,6.6HD+Screen,50MP Night Vision,6000mAh Battery,IP68/IP69K Waterproof Phone,Face ID/OTG UK Version(Black)
0
Add to compare
£143.99
35%
.

We will be happy to hear your thoughts

Leave a reply

Tech
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart