Get the latest tech news

Microsoft's Bitlocker & TPM encryption combo defeated with a $10 Raspberry Pi


Your laptop probably isn't as secure as you thought.

Long story short, Stacksmashing physically intercepts signals from the TPM chip and isolates the master encryption key. To make the process of physically connecting to the laptop's TPM chip simpler, Stacksmashing cooked up a bespoke Raspberry Pi Pico PCB to which spring loaded contact pins were attached in an arrangement to perfectly align with the contact pads for the TPM in the Lenovo laptop that was subject to the attack. Just pull the back cover of the laptop off, uncover the TPM contact points, physically apply the modded Pi's pins, boot the machine and—boom!—within a few seconds you have your enrcyption keys, allowing the SSD to be fully decrypted.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Microsoft

Microsoft

Photo of Raspberry Pi

Raspberry Pi

Photo of encryption combo

encryption combo

Related news:

News photo

Microsoft Relents, Will Support VS Code On Ubuntu 18.04 For One More Year

News photo

Microsoft: Outlook clients not syncing over Exchange ActiveSync

News photo

Microsoft hints at the future of AI in Windows with a smarter Copilot