@SecurityWriter
The VMK is definitely not in clear text.
Yes it's on the drive, but it's encrypted using values in the TPM.
Yes, it's somewhat flawed. But it's nowhere near as broken as having the decryption key in plain text. See also:
https://neodyme.io/en/blog/bitlocker_screwed_without_a_screwdriver/
=> More informations about this toot | View the thread | More toots from wdormann@infosec.exchange
=> View SecurityWriter@infosec.exchange profile
text/gemini
This content has been proxied by September (ba2dc).