Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.dbzer0.com

2 replies

So that you can decrypt in case you forget the password, of course. You can also do that in LUKS it seems. IIRC, hash of your password encrypts Volume Master Key, and another copy of VMK is encrypted with your recovery key. If you use a TPM, VMK is stored inside it instead of storing an VMK encrypted with your password.

4

Not 100% sure but in my previous use cases in work atmospheres bitlocker recovery keys we would auto collect/store in Active Roles/active directory. So if windows did an update and messed up something or a user forgot their password to get passed it we could search ARS/AD and get the machine back up and running.

3

You reached the end

Why does bitlocker password only need a recovery key? | Spyke